Cryptological Tethering for Secure Cross-Network Device Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

High assurance cryptography systems face challenges in maintaining security and reliability across untrusted networks, particularly in mobile devices where radios are not under user control and can be vulnerable to exploitation, and existing solutions are costly, difficult to maintain, and not easily disposable.

Innovation Solution

A system and method that cryptologically tethers trusted user devices using paired encrypting devices to establish secure communication links across untrusted networks, employing a hybrid hardware-software cryptographic engine to ensure secure data transmission and decryption, while also providing auxiliary communication links for adaptation and security augmentation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic engines are used to establish trust boundaries between trusted and untrusted networks, then security and reliability of communication are improved, but device complexity and cost increase

Engineering Contradiction:
Improvesecurity and reliability of communicationVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary cryptographic engine that acts as a mediator between trusted and untrusted networks. This engine establishes trust boundaries without requiring complex modifications to existing devices, as it operates as a separate component that can be integrated into the network infrastructure rather than embedding complexity within each endpoint device.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The cryptographic system is segmented into distinct functional components: trust boundary establishment, data encryption/decryption, and communication management. This segmentation allows each component to be optimized independently and simplifies the overall system architecture by distributing functionality across multiple specialized modules rather than consolidating all cryptographic functions in single complex devices.

Inventive Principle:
Principle #1Segmentation

2Reliability

If multiple countermeasures are implemented to protect against breaches, then security against cyberattack is improved, but system complexity and difficulty of maintenance increase

Engineering Contradiction:
Improvesecurity against cyberattackVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements beforehand cushioning by pre-establishing trust boundaries and cryptographic protections before data transmission occurs. Multiple countermeasures are configured in advance, including encrypted communication channels and authentication mechanisms, so that when threats arise, the system is already protected rather than requiring complex real-time response mechanisms.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Solution Approach 2:

The cryptographic engine maintains continuous protection across trusted and untrusted networks through uninterrupted encrypted communication channels. This continuity eliminates the need for repeated authentication handshakes or re-establishment of security boundaries, simplifying the system by maintaining constant security rather than periodically renegotiating protections.

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If cryptographic engines are used to secure data transmission across untrusted networks, then integrity of communication is improved, but ease of operation and adaptability to changing technologies decrease

Engineering Contradiction:
Improveintegrity of communicationVSAvoidadaptability to changing technologies
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The cryptographic engine is designed with universal functionality that allows it to operate across different network protocols and communication standards. It can establish trust boundaries for various types of data transmission (file transfers, messaging, voice/video calls) without requiring protocol-specific implementations, making it adaptable to changing communication technologies while maintaining consistent security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system allows dynamic adjustment of cryptographic parameters such as encryption strength, key lengths, and protocol versions based on threat levels and performance requirements. This enables the cryptographic engine to adapt to evolving security requirements and technological changes without compromising the integrity of communication, as parameters can be modified through configuration rather than requiring system redesign.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12199958B1System and method for cryptologically tethering user devices to one another in adaptable manner for trusted communication across untrusted network
Publication Date: 2025.01.14 GOVERNMENT OF THE UNITED STATES AS REPRESENTED BY THE DIRECTOR NAT SECURITY AGENCY
  • US12199958B1 patent drawing
  • US12199958B1 patent drawing
  • US12199958B1 patent drawing

AI summary

A high assurance system provides for communication between trusted user devices with auxiliary adaptation for augmenting communication security across an untrusted environment. First and second main encrypting devices coupled to respective trusted user devices are cryptologically tethered to one another by a main communication link established across the untrusted environment between trusted user devices in cryptologically protected manner. An auxiliary encrypting device is cryptologically tethered to the first main encrypting device by an auxiliary communication link established across the untrusted environment between a trusted auxiliary device and one trusted user device in cryptologically protected manner. The main and auxiliary encrypting devices define portals traverse trust boundaries between trusted and untrusted environments, each including at least one encryption unit and a communication unit coupled thereto by a connectionless interconnect. The encryption unit encrypts and decrypts message data, while the communication unit transmits and receives encrypted message data through the communication links.