Dynamic Cipher Suite Selection for Resource Optimization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cryptographic methods provide high security but come at the cost of increased computational resources and latency, as they apply high levels of encryption unnecessarily for all transactions, even when lower security levels are sufficient.

Innovation Solution

Implementing dynamic cipher suite selection based on planned session use during the handshake process, where clients indicate the planned use of a session to servers, allowing servers to select appropriate cipher suites that match the required security level, thereby optimizing resource usage and reducing unnecessary encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If high-level cryptographic protection is applied to all transactions, then data security is improved, but computational resources and latency increase

Engineering Contradiction:
Improvedata securityVSAvoidcomputational resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies different cryptographic protection levels to different data transactions based on their specific security requirements. Instead of uniformly applying high-level encryption to all transactions, the system evaluates each transaction's security needs and applies appropriate cipher suites, thereby reducing unnecessary computational overhead while maintaining adequate security for each specific case

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically changes cryptographic parameters (cipher suite selection) based on transaction characteristics and security requirements. By adjusting the level of cryptographic protection as a variable parameter rather than using a fixed high-level setting for all transactions, the system optimizes the balance between security and computational resource consumption

Inventive Principle:
Principle #35Parameter changes

2Reliability

If high-level cryptographic protection is applied to all transactions, then data security is improved, but latency increases

Engineering Contradiction:
Improvedata securityVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements localized cryptographic protection tailored to each transaction's security requirements. By selecting appropriate cipher suites based on the specific data and transaction context rather than applying uniform high-level encryption, the system reduces processing time and latency while maintaining necessary security levels for each individual transaction

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts cryptographic parameters including cipher suite selection based on transaction characteristics. This parameter adaptation allows the system to reduce computational overhead and latency for transactions that do not require maximum security, while maintaining high security where needed

Inventive Principle:
Principle #35Parameter changes

3Reliability

If uniform high security is applied to all sessions, then security consistency is improved, but resource efficiency deteriorates

Engineering Contradiction:
Improvesecurity consistencyVSAvoidresource efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements localized cryptographic protection tailored to each transaction's security requirements. By selecting appropriate cipher suites based on the specific data and transaction context rather than applying uniform high-level encryption, the system reduces processing time and latency while maintaining necessary security levels for each individual transaction

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts cryptographic parameters including cipher suite selection based on transaction characteristics. This parameter adaptation allows the system to reduce computational overhead and latency for transactions that do not require maximum security, while maintaining high security where needed

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10826879B2Resource-based cipher suite selection
Publication Date: 2020.11.03 AMAZON TECH INC
  • US10826879B2 patent drawing
  • US10826879B2 patent drawing
  • US10826879B2 patent drawing

AI summary

Cipher suites and/or other parameters for cryptographic protection of communications are dynamically selected to more closely match the intended uses of the sessions. A client indicates a planned use of a session to a server. The client's indication of the planned use may be explicit or implicit. The server selects an appropriate set of parameters for cryptographic protection of communications based at least in part on the indicated planned use and the client and server complete a handshake process to establish a cryptographically protected communications session to use the selected set of parameters.