Authorized Media Relay for Secure Communication Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication systems lack effective methods to ensure secure and authorized routing of communication sessions, particularly in scenarios where government agencies need to intercept communications while maintaining encryption integrity.

Innovation Solution

A method and system where a media relay receives and decrypts encrypted payloads from endpoints using preconfigured keys, ensuring only authorized media relays can route the communications, and optionally re-encrypts them for secure transmission, including legal intercept endpoints.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If communication sessions are encrypted to prevent interception by third parties, then security against unauthorized access is improved, but government agencies cannot legally intercept communications for security purposes

Engineering Contradiction:
Improvesecurity against unauthorized interceptionVSAvoidability to allow legal intercepts
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an authorized media relay as an intermediary component that possesses special decryption capabilities. This relay acts as a trusted mediator that can legally intercept and decrypt communications while ordinary third parties cannot, thus resolving the contradiction between preventing unauthorized interception and allowing authorized legal intercepts

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies different encryption and decryption properties to different parts of the communication system. Endpoints use strong encryption that prevents unauthorized access, while the authorized media relay has special local qualities (decryption keys and capabilities) that allow it to legally intercept and decrypt communications, creating localized security exceptions

Inventive Principle:
Principle #3Local quality

2Reliability

If endpoints use strong encryption with public and private keys, then confidentiality is improved, but routing control and authorized interception become more difficult

Engineering Contradiction:
Improveconfidentiality of communicationVSAvoidcomplexity of key management and routing control
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-configuring the authorized media relay with decryption keys and routing information before communication sessions begin. This pre-configuration simplifies real-time key management and routing control, as the relay is already prepared to decrypt and route communications from multiple endpoints without complex runtime key distribution

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authorized media relay serves as a trusted intermediary that manages the complexity of key distribution and routing. Instead of endpoints directly managing complex key exchanges and routing decisions, the relay mediates these functions, simplifying the overall system architecture while maintaining strong encryption

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If a media relay decrypts and re-encrypts payloads, then authorized routing and legal intercept are enabled, but the risk of unauthorized access at the relay increases

Engineering Contradiction:
Improveability to route and intercept communicationsVSAvoidrisk of unauthorized access at relay point
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the communication system into distinct trusted zones: endpoints with strong encryption, authorized media relays with controlled decryption capabilities, and legal intercept points. This segmentation isolates the decryption risk to specific authorized components rather than exposing the entire communication path to potential unauthorized access

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10348698B2Methods and systems for link-based enforcement of routing of communication sessions via authorized media relays
Publication Date: 2019.07.09 NAGRAVISION SA
  • US10348698B2 patent drawing
  • US10348698B2 patent drawing
  • US10348698B2 patent drawing

AI summary

Disclosed herein are methods and systems for link-based enforcement of routing of communication sessions via authorized media relays. In an embodiment, a media relay receives encrypted first payloads from a first endpoint and encrypted second payloads from a second endpoint as part of a session. The encrypted first payloads require a first key for decryption and the encrypted second payloads requite a second key for decryption. The media relay is preconfigured prior to the session with secrets useable for identifying the first and second keys. The media relay decrypts the first payloads using the first key and decrypts the second payloads using the second key, and transmits the first payloads to the second endpoint and the second payloads to the first endpoint as part of the session.