Adaptive Encryption for Multipath Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication networks face inefficiencies in encryption processes, leading to increased computational overhead and latency, particularly in trusted environments like 3GPP ATSSS and Hybrid Access scenarios, where encryption is inefficient and not optimized for multipath communication.

Innovation Solution

A method for adapting the security level of data packets based on the trustiness of communication sections, where data packets are sent with lower or no encryption over trusted sections and encrypted over less trusted sections, using security-level-adaption means to optimize communication protocols like QUIC, DCCP, and MP-DCCP, and converting them to standard QUIC protocols when necessary.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption is applied to all data packets in communication networks, then security level is improved, but computational overhead and latency increase

Engineering Contradiction:
Improvesecurity levelVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies different encryption levels to different communication sections based on their trust characteristics. Trusted sections (e.g., within 3GPP ATSSS or Hybrid Access networks) use lower or no encryption, while untrusted sections use higher encryption. This local differentiation resolves the contradiction by eliminating unnecessary encryption in trusted environments, reducing computational overhead and latency while maintaining security where needed.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent dynamically changes the encryption parameter (security level) based on the trustiness level of the communication section. The system adjusts encryption intensity as a variable parameter rather than applying a fixed high encryption level universally. This allows optimization of the security-latency tradeoff by adapting encryption strength to the specific trust characteristics of each communication path.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If encryption is applied to all data packets, then security level is improved, but computational overhead increases

Engineering Contradiction:
Improvesecurity levelVSAvoidcomputational overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements local quality by applying encryption selectively based on the trust characteristics of individual communication sections. Within trusted environments like 3GPP ATSSS or Hybrid Access networks, the system uses lower or no encryption, eliminating unnecessary computational overhead. This resolves the contradiction by concentrating computational resources only where security is actually needed.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent applies partial encryption action rather than full encryption universally. Instead of encrypting all data packets with maximum security, the system applies encryption only to the extent necessary for each communication section's security requirements. This partial action reduces computational overhead significantly while maintaining adequate security levels.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If standard QUIC protocol with encryption is used, then security is maintained, but multipath transport optimization is reduced in trusted environments

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent makes the protocol behavior dynamic by adapting encryption levels according to the trustiness of the communication section. In trusted environments, the system dynamically switches to lower encryption or alternative protocols optimized for multipath transport, while maintaining security protocols in untrusted environments. This dynamic adaptation resolves the contradiction between security and network efficiency.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies different protocol optimizations to different communication sections based on trust characteristics. In trusted sections, the system uses protocol variations optimized for multipath transport with reduced encryption, while standard secure QUIC is used in untrusted sections. This local differentiation enables network efficiency optimization where appropriate without compromising overall security.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP4246883A1Techniques to decrease the level of encryption in a trusted communication environment
Publication Date: 2023.09.20 DEUTSCHE TELEKOM AG
  • EP4246883A1 patent drawingFigure 1
  • EP4246883A1 patent drawingFigure 2
  • EP4246883A1 patent drawingFigure 3

AI summary

Techniques for transmitting data packets of one communication service from a first network entity, in particular a sending entity, to a second network entity, in particular a receiving entity, over a communication path, wherein the communication path comprises a first communication section and a second communication section, and wherein security-level-adaption means are provided between the first communication section and the second communication section to adapt a security level of the data packets, the method comprising the steps of: • determining a level of trustiness of the first and/or the second communication section by the first network entity; • comparing the level of trustiness to a predefined trustiness threshold; • providing the data packets with a security level depending on the outcome of the comparison as follows: o if the level of trustiness of the first communication section is higher than the predefined trustiness threshold: sending the data packets by the first network entity with a lower security level over the first communication section and increasing the security level of the data packets from the lower security level to a higher security level when the data packets are entering the second communication section; o or if the level of trustiness of the first communication section is below the predefined trustiness threshold: sending the data packets by the first network entity with a higher security level over the first communication section.