Virtual Dispersive Routing for Decentralized Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional networks are vulnerable to cyber attacks due to their centralized nature and reliance on algorithmic security measures that can be easily reverse-engineered, leading to compromised security and data theft, as seen in recent high-profile hacks.
Innovation Solution
The implementation of virtual dispersive routing (VDR) which distributes routing functionality across client devices, utilizing virtual machines and multiple routing protocols to create decentralized, robust network connections and enhance security through application-specific knowledge and encryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If centralized routing is used, then network management is simplified, but network security and reliability deteriorate due to single points of failure and vulnerability to attacks
Solution Approach 1:
The patent segments the centralized routing function into distributed routing capabilities across multiple client devices. Each client device is equipped with routing software that enables it to function as a routing node, thereby distributing the routing workload and eliminating single points of failure. This segmentation improves both reliability and security while maintaining manageable complexity through standardized protocols.
Solution Approach 2:
The patent introduces virtual machines as intermediary components between the physical network interface and the application layer. These virtual machines act as mediators that can implement routing protocols, encryption, and other network functions, adding layers of security and reliability without significantly complicating network management.
2Reliability
If algorithmic security measures are used, then security protection is provided, but security effectiveness deteriorates because these measures can be easily reverse-engineered and compromised
Solution Approach 1:
The patent replaces traditional algorithmic security measures with cryptographic protocols implemented at the network layer. Instead of relying on software-based security algorithms that can be reverse-engineered, the system uses mathematically proven cryptographic methods that provide security based on computational hardness assumptions, making them resistant to reverse engineering and adaptation by attackers.
Solution Approach 2:
The patent adds a new dimension to security by implementing encryption and security protocols at the network packet level rather than at the application layer. This dimensional shift allows security to be embedded in the network infrastructure itself, making it more difficult for attackers to compromise without affecting the entire network rather than just individual applications.
3Reliability
If virtual machines are spawned for each network connection, then network security and adaptability are improved, but device complexity increases
Solution Approach 1:
The patent designs virtual machines with universal, standardized interfaces and protocols that can handle multiple network functions. Each virtual machine is capable of implementing various routing protocols, encryption methods, and network layers, reducing the need for specialized virtual machines for each specific function. This universality maintains security and adaptability while reducing overall system complexity.
Solution Approach 2:
The patent merges multiple network functions and protocols within single virtual machine instances. Rather than creating separate virtual machines for each protocol or function, the system combines routing, encryption, and other network capabilities into integrated virtual machine components, thereby reducing the total number of virtual machines needed and simplifying system management while maintaining security.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method of communicating data using virtualization includes splitting, at endpoint software running on a first device, first data for communication to a destination device into a first plurality of data streams; selecting, at the first device by the endpoint software, a first plurality of deflects for use in communicating the first plurality of data streams; communicating each of the first plurality of data streams over a different one of the selected first plurality of deflects; splitting, at the first deflect, a particular data stream of the first plurality of data streams into a second plurality of data streams; selecting, at the first deflect, a second plurality of deflects for use in communicating the second plurality of data streams; and communicating each of the second plurality of data streams over a different one of the selected second plurality of deflects.