Non-Repudiatable Data Stream Authentication via Key Frame Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies fail to provide a non-repudiable record of real-time or quasi-real-time communication sessions, especially in digital communications, due to limitations in verifying authenticity and integrity, particularly in voice, video, and data communications, where tampering is a significant concern and existing security measures like digital signatures are not applicable.

Innovation Solution

A method and system that segment a communication data stream into defined frames, generate a key frame containing integrity and authentication information, and insert it as an additional frame, creating an authenticated data stream, which includes identification, integrity, and signature blocks, ensuring data integrity and authenticity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If digital signatures are used for authentication, then data integrity and authenticity are improved, but real-time communication capability deteriorates

Engineering Contradiction:
Improvedata integrityVSAvoidreal-time communication
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent segments the authentication process by dividing the data stream into frames and inserting key frames at specific intervals. Each key frame contains authentication information for a group of frames, allowing verification without processing every single frame in real-time, thus maintaining data integrity while enabling real-time communication capability

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary authentication by generating key frames in advance that contain authentication information for multiple subsequent frames. This preliminary action allows the system to verify data integrity efficiently without requiring continuous real-time signature verification, resolving the contradiction between reliability and speed

Inventive Principle:
Principle #10Preliminary action

2Reliability

If authentication information is added to each frame, then data authenticity is improved, but device complexity deteriorates

Engineering Contradiction:
Improvedata authenticityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides authentication information into key frames that are inserted periodically rather than adding authentication data to every single frame. This segmentation reduces the overall system complexity while maintaining data authenticity verification capability across the communication stream

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The key frame serves multiple functions: it contains authentication information, integrity verification data, and acts as a synchronization point. This multi-functionality reduces the need for separate authentication mechanisms, thereby reducing device complexity while maintaining strong authenticity verification

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If media are used for recording and storage, then communication recording capability is improved, but security against tampering deteriorates

Engineering Contradiction:
Improverecording capabilityVSAvoidtampering risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary authentication by embedding key frames with integrity verification information into the data stream before storage. This preliminary action creates a tamper-evident record that can detect any modifications after storage, maintaining recording capability while protecting against tampering

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication information in key frames provides feedback mechanism that allows verification of data integrity after storage. Any tampering with recorded data can be detected by verifying the authentication information, thus protecting against tampering while maintaining recording capability

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8694789B2System and method for generating a non-repudiatable record of a data stream
Publication Date: 2014.04.08 NORTEL NETWORKS LTD
  • US8694789B2 patent drawing
  • US8694789B2 patent drawing
  • US8694789B2 patent drawing

AI summary

A system and method for generating a non-repudiatable record of a communications data stream is provided, which is applicable to real-time and quasi-real-time data streams. A binary communication data stream is captured and segmented into defined frames. A key frame is generated for each of a number of data frames containing integrity and authentication information. The key frame is inserted into the data stream to provide an authenticated data stream.