Communication Channel Security Claims Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Ensuring data protection during electronic transfers is challenging due to the variety of methods and lack of trust in the security measures employed by computers when transferring data across different communication channels.

Innovation Solution

A set of security claims is obtained for a communication channel, digitally signed by a trust authority, and compared to a computing device's security policy to determine necessary security precautions for data transfer, using a channel security descriptor that includes a channel identifier, security claims, and digital signature.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data is transferred electronically across different communication channels, then data transfer capability is improved, but data security and trustworthiness deteriorate

Engineering Contradiction:
Improvedata transfer capabilityVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary verification of security claims and digital signatures before data transfer occurs. The computing device obtains and validates security claims about the communication channel, verifies digital signatures from trust authorities, and determines necessary security precautions in advance, ensuring security is established before the actual data transfer takes place

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces security claims and digital signatures as intermediary elements between the computing device and the communication channel. These intermediaries carry verification information from trust authorities, allowing the computing device to assess the trustworthiness of communication channels without directly trusting the channels themselves, thus enabling secure transfers across diverse channels

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security precautions are implemented for data transfer, then data protection is improved, but system complexity increases

Engineering Contradiction:
Improvedata protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments security verification into distinct components: obtaining security claims, verifying digital signatures, comparing against security policies, and determining specific precautions. This segmentation allows each security function to be independently implemented and managed, reducing overall system complexity while maintaining comprehensive data protection

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The computing device autonomously verifies security claims and determines appropriate security precautions based on its own security policy. The system self-manages the security verification process without requiring external intervention for each data transfer, reducing complexity by making the device self-sufficient in security decisions

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8914874B2Communication channel claim dependent security precautions
Publication Date: 2014.12.16 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8914874B2 patent drawing
  • US8914874B2 patent drawing
  • US8914874B2 patent drawing

AI summary

A set of security claims for a communication channel are obtained, the set of security claims including one or more security claims each identifying a security characteristic of the communication channel. The security claims are stored, as is a digital signature generated over the set of security claims by an entity. The security claims and digital signature are subsequently accessed when a computing device is to transfer data to and/or from the communication channel. The set of security claims is compared to a security policy of the computing device, and the entity that digitally signed the set of security claims is identified. One or more security precautions that the computing device is to use in transferring data to and/or from the communication channel are determined based at least in part on the comparing and the entity that has digitally signed the set of security claims.