Communication Device Packet Analysis and Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication systems face delays due to multiple encryption and decryption processes when monitoring for unauthorized communication, especially in large systems, which can lead to inefficiencies and increased risk during cyber attacks.

Innovation Solution

A communication device that performs simplified analysis and encrypts communication packets once, allowing them to be transmitted to a control device for further analysis, reducing the need for multiple encryption and decryption processes and minimizing communication delay.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple encryption and decryption processes are performed for communication monitoring, then communication security is maintained, but communication delay increases

Engineering Contradiction:
Improvecommunication securityVSAvoidcommunication delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts the decryption function from the communication monitoring path by having the communication device perform decryption locally before analysis. The analysis device only needs to receive already-decrypted packets, removing the time-consuming decryption step from the critical monitoring path while maintaining security through selective re-encryption of suspicious packets.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The communication device performs decryption of communication packets before they are sent to the analysis device. This preliminary decryption action allows the analysis device to focus solely on analysis without performing decryption, thereby reducing overall processing delay while maintaining security through subsequent re-encryption of suspicious packets.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If individual communication devices perform detection of unauthorized communication, then detection precision is improved, but device complexity increases

Engineering Contradiction:
Improvedetection precisionVSAvoiddevice complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the communication monitoring system into two specialized components: communication devices that handle decryption and packet forwarding, and analysis devices that perform unauthorized communication detection. This segmentation allows each device to be optimized for its specific function, improving detection precision while avoiding the complexity of making every device a full-featured analysis device.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The analysis device acts as an intermediary between the communication devices and the unauthorized communication detection process. Communication devices decrypt and forward packets to the analysis device, which specializes in detection. This intermediary role allows detection precision to be improved through dedicated analysis hardware without requiring all communication devices to have complex detection capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If communication content is encrypted for security, then information leakage is prevented, but analysis capability is reduced

Engineering Contradiction:
Improveinformation securityVSAvoidanalysis capability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent applies different encryption states to different locations in the system. Communication devices decrypt packets locally for analysis purposes, allowing the analysis device to examine plaintext content. Suspicious packets are then re-encrypted before forwarding. This local quality approach maintains information security overall while enabling analysis capability where needed.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The encryption parameter of communication packets is dynamically changed based on their security status. Normal packets remain encrypted during transmission, while suspicious packets identified by the analysis device are decrypted and re-encrypted with appropriate security measures. This parameter change allows the system to maintain information security while enabling analysis of potentially malicious content.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11463879B2Communication device, information processing system and non-transitory computer readable storage medium
Publication Date: 2022.10.04 KK TOSHIBA
  • US11463879B2 patent drawing
  • US11463879B2 patent drawing
  • US11463879B2 patent drawing

AI summary

According to one embodiment, a communication device belongs to a communication network including a control device and a plurality of communication devices connected to the control device, and transmits a communication packet to a transmission destination communication device. The communication device and the transmission destination communication device are differently one of the plurality of communication devices. In the communication device, a memory stores first information for judging a normality of the communication packet. An analyzing unit judges the normality of a received communication packet based on the received communication packet and the first information. A transmission destination determining unit determines the transmission destination communication device and the control device as transmission destinations of the received communication packet when the analyzing unit judges that the received communication packet is not normal. A generating unit encrypts the communication packet to be transmitted to the transmission destinations.