Communication Device Packet Analysis and Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication systems face delays due to multiple encryption and decryption processes when monitoring for unauthorized communication, especially in large systems, which can lead to inefficiencies and increased risk during cyber attacks.
Innovation Solution
A communication device that performs simplified analysis and encrypts communication packets once, allowing them to be transmitted to a control device for further analysis, reducing the need for multiple encryption and decryption processes and minimizing communication delay.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple encryption and decryption processes are performed for communication monitoring, then communication security is maintained, but communication delay increases
Solution Approach 1:
The patent extracts the decryption function from the communication monitoring path by having the communication device perform decryption locally before analysis. The analysis device only needs to receive already-decrypted packets, removing the time-consuming decryption step from the critical monitoring path while maintaining security through selective re-encryption of suspicious packets.
Solution Approach 2:
The communication device performs decryption of communication packets before they are sent to the analysis device. This preliminary decryption action allows the analysis device to focus solely on analysis without performing decryption, thereby reducing overall processing delay while maintaining security through subsequent re-encryption of suspicious packets.
2Measurement precision
If individual communication devices perform detection of unauthorized communication, then detection precision is improved, but device complexity increases
Solution Approach 1:
The patent segments the communication monitoring system into two specialized components: communication devices that handle decryption and packet forwarding, and analysis devices that perform unauthorized communication detection. This segmentation allows each device to be optimized for its specific function, improving detection precision while avoiding the complexity of making every device a full-featured analysis device.
Solution Approach 2:
The analysis device acts as an intermediary between the communication devices and the unauthorized communication detection process. Communication devices decrypt and forward packets to the analysis device, which specializes in detection. This intermediary role allows detection precision to be improved through dedicated analysis hardware without requiring all communication devices to have complex detection capabilities.
3Reliability
If communication content is encrypted for security, then information leakage is prevented, but analysis capability is reduced
Solution Approach 1:
The patent applies different encryption states to different locations in the system. Communication devices decrypt packets locally for analysis purposes, allowing the analysis device to examine plaintext content. Suspicious packets are then re-encrypted before forwarding. This local quality approach maintains information security overall while enabling analysis capability where needed.
Solution Approach 2:
The encryption parameter of communication packets is dynamically changed based on their security status. Normal packets remain encrypted during transmission, while suspicious packets identified by the analysis device are decrypted and re-encrypted with appropriate security measures. This parameter change allows the system to maintain information security while enabling analysis of potentially malicious content.
Data Source
AI summary
According to one embodiment, a communication device belongs to a communication network including a control device and a plurality of communication devices connected to the control device, and transmits a communication packet to a transmission destination communication device. The communication device and the transmission destination communication device are differently one of the plurality of communication devices. In the communication device, a memory stores first information for judging a normality of the communication packet. An analyzing unit judges the normality of a received communication packet based on the received communication packet and the first information. A transmission destination determining unit determines the transmission destination communication device and the control device as transmission destinations of the received communication packet when the analyzing unit judges that the received communication packet is not normal. A generating unit encrypts the communication packet to be transmitted to the transmission destinations.


