Variable Security Tag Placement for Network Packet Integrity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure packet communication systems face challenges as security tags within packets are often removed or misinterpreted by network elements like proxy servers and firewalls, reducing the effectiveness of secure communications across networks.

Innovation Solution

A method and system that allow for the variable placement of security tags within packets, enabling them to pass through network impediments by determining optimal placement locations based on known network conditions, using a sending node and receiving node negotiation, and automated testing to ensure security tags remain intact.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security tags are placed in fixed locations within packets, then the structure is simple and easy to implement, but network elements like proxy servers and firewalls may remove or misinterpret these tags

Engineering Contradiction:
Improvesecurity tag integrityVSAvoidsecurity tag placement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic security tag placement by allowing the security tag to be positioned at multiple different locations within the packet depending on network conditions. The sending node determines optimal placement locations and can vary the tag position across different packets or communication sessions, making the system adaptive rather than static.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of security tag location from a fixed value to a variable that can take multiple positions within the packet. By modifying the location parameter dynamically based on network impediments and communication requirements, the system achieves better reliability without permanent structural complexity.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If security tags are placed in multiple locations within packets, then the likelihood of tags surviving network impediments increases, but the complexity of determining and checking tag locations increases

Engineering Contradiction:
Improvesecurity tag survival rateVSAvoidtag location determination
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies preliminary action by having the sending node determine and establish the security tag placement location before actual data transmission begins. The sending and receiving nodes negotiate and agree upon the placement location in advance, so that during normal communication, both nodes already know where to place and look for the security tag, simplifying the operation during active transmission.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where the receiving node can inform the sending node about successful or unsuccessful reception of security tags at specific locations. This feedback allows the system to learn from actual network conditions and adjust future tag placement decisions, making the process easier over time as the system accumulates experience about which locations work best.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8990573B2System and method for using variable security tag location in network communications
Publication Date: 2015.03.24 CITRIX SYSTEMS INC
  • US8990573B2 patent drawing
  • US8990573B2 patent drawing
  • US8990573B2 patent drawing

AI summary

A method of packet security management to ensure a secure connection from one network node to another. The method includes creating a security tag for each packet in a network session, selecting one of a number of possible tag locations within the packet, inserting the security tag at that location, transmitting the tagged packets from a sending node to the receiving node, authenticating the packets' security tags at the receiving node, and dropping non-authenticated packets. The method also includes determining best possible tag locations when sending a packet and locating a security tag when receiving a packet.