Dynamic VM Path Reordering for Identity Masking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network communication methods fail to provide the ability to route communications through intermediate locations to mask the source or identity, limiting control over routing within and across commercial clouds.

Innovation Solution

The implementation of a method that defines and modifies data unit paths using virtual machines across multiple networks, allowing for dynamic reordering of virtual machine paths to change the routing of data units, coupled with the use of a virtualization platform like Nicira Network Virtualization Platform (NVP) to create secure, identity-protected networks and VPNs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If routing is performed at the network layer based on external IP address, then communication efficiency is improved, but the ability to mask source identity is lost

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidsource identity exposure
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent introduces virtual machines as intermediary nodes between the source device and destination. These VMs receive data units, forward them to the destination, and simultaneously mask the source identity. The intermediary VMs break the direct routing path, allowing identity protection while maintaining communication efficiency through automated forwarding.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the traditional single-path routing into multiple hops through virtual machines. Instead of direct source-to-destination routing, data units are divided into segments passed through intermediate VMs, each handling a portion of the transmission. This segmentation enables identity masking at each hop while preserving overall communication efficiency.

Inventive Principle:
Principle #1Segmentation

2Device complexity

If fixed routing paths are used, then network simplicity is maintained, but control over routing is limited

Engineering Contradiction:
Improvenetwork simplicityVSAvoidrouting control
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic routing where the system can modify data unit paths based on requirements. Virtual machines can be added, removed, or repositioned in the routing path dynamically. The network controller can adjust routing configurations in real-time, providing adaptability while maintaining operational simplicity through automated management.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The virtual machine infrastructure provides multi-functionality, serving both as simple forwarding nodes and as controllable routing intermediaries. The same VM infrastructure can operate in straightforward modes for simple cases or be configured for complex routing scenarios, providing versatility without requiring separate systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Length of moving object

If direct routing is implemented, then path length is minimized, but identity protection capability is reduced

Engineering Contradiction:
Improvedata unit path lengthVSAvoididentity traceability
Core Design Contradiction:
Length of moving objectVSObject-affected harmful factors

Solution Approach 1:

Virtual machines are positioned as intermediaries in the data unit path, adding necessary hops for identity protection. The intermediaries process and forward data units, extending the path length minimally while effectively masking source identity through multiple forwarding points.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system allows data units to rush through the network efficiently by using high-speed forwarding in virtual machines. While additional hops are introduced for identity protection, the forwarding operations are optimized to minimize actual transmission time, effectively skipping delays despite increased path length.

Inventive Principle:
Principle #21Skipping (Rushing through)

Data Source

PatentUS11683386B2Systems and methods for protecting an identity in network communications
Publication Date: 2023.06.20 CONCEAL INC
  • US11683386B2 patent drawing
  • US11683386B2 patent drawing
  • US11683386B2 patent drawing

AI summary

In some embodiments, a method includes sending a first data unit, received from a source device, to a destination device via a first data unit path. The first data unit path includes (1) a first virtual machine and a second virtual machine that are included in a first network, and (2) a third virtual machine that is included in a second network. Furthermore, the first data unit path includes the first virtual machine, the second virtual machine, and the third virtual machine in a first order. The method includes sending a second data unit, received from the source device, to the destination device via a second data unit path from the source device to the destination device. The second data unit path includes each of the first virtual machine, the second virtual machine, and the third virtual machine in a second order different from the first order.