Virtual Dispersive Routing for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional networks are vulnerable to attacks and fragile due to reliance on centralized routers, making them insecure for network communications, especially for servers that need to keep ports open for client connections, leading to risks of Denial of Service (DoS) attacks.

Innovation Solution

Implementing virtual dispersive routing (VDR) that uses virtual machines to spawn multiple connections with changing network addresses and ports, allowing data to be transmitted securely and dynamically, thereby distributing routing functionality across client devices and reducing reliance on central routers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If centralized routers are used for network routing, then routing functionality is consolidated and simplified, but network security and reliability deteriorate due to vulnerability to attacks and fragility

Engineering Contradiction:
Improverouting functionality consolidationVSAvoidnetwork security and robustness
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments centralized routing functionality into distributed virtual routing instances deployed across multiple client devices. Each client device runs virtual machines that perform routing tasks independently, dividing the monolithic router function into multiple secure, isolated segments that cannot compromise each other, thereby improving reliability while maintaining routing consolidation benefits

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces virtual machines as intermediary components between network applications and physical network infrastructure. These virtual machines act as mediators that perform routing functions in a virtualized environment, isolating critical routing logic from direct exposure to network attacks while maintaining consolidated routing capabilities through virtual network interfaces

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If servers keep ports open for client connections, then connection establishment is simplified and faster, but vulnerability to Denial of Service attacks increases

Engineering Contradiction:
Improveconnection establishmentVSAvoidDenial of Service attack vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic port allocation and connection management through virtualized routing. Instead of static open ports, the system dynamically assigns ports and routes connections through multiple virtual network paths, allowing rapid connection establishment while making DoS attacks ineffective due to the dynamic nature of the virtual routing table and port assignments

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent prepares multiple virtual routing paths and port assignments in advance before actual connections are needed. This pre-configured virtual infrastructure provides a cushion against DoS attacks by having备用 routes ready, allowing the system to absorb attack traffic through virtual machines that are pre-positioned to handle connection requests before they reach vulnerable server ports

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

3Reliability

If virtual machines are spawned for multiple network connections, then network security and routing distribution are improved, but system complexity and resource consumption increase

Engineering Contradiction:
Improvenetwork security and routing distributionVSAvoidsystem complexity and virtual machine management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements universal virtual machine templates that can perform multiple routing functions. Rather than creating specialized VMs for each function, a single multi-functional virtual machine image can be deployed across different client devices to handle various routing tasks, reducing the diversity of system components while maintaining distributed security benefits

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent enables virtual machines to self-manage their own routing functions through automated virtual network configuration. Virtual machines automatically discover available network paths, configure their own virtual interfaces, and manage connection routing without requiring complex centralized management, thereby reducing system complexity while maintaining distributed routing capabilities

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10848426B2Virtual dispersive networking systems and methods
Publication Date: 2020.11.24 ASSET RECOVERY ASSOC
  • US10848426B2 patent drawing
  • US10848426B2 patent drawing
  • US10848426B2 patent drawing

AI summary

A method for network communications from a first device to a second device includes communicating data from the first device to the second device by spawning a first virtual machine for a first network connection that virtualizes network capabilities of the electronic device, and using the virtualized network capabilities of the first virtual machine, transmitting a plurality of packets for communication to a first network address and port combination associated with the second device. The method further includes repeatedly changing to a respective another network address and port combination by repeatedly spawning a respective another virtual machine for a respective another network connection that virtualizes network capabilities of the electronic device, and using the virtualized network capabilities of the spawned respective another virtual machine, transmitting a plurality of packets for communication to the respective another network address and port combination associated with the second device.