Non-Repudiatable Data Stream Authentication via Key Frame Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current technologies fail to provide a non-repudiable record of real-time or quasi-real-time communication sessions, especially in digital communications, due to limitations in verifying authenticity and integrity, particularly in voice, video, and data communications, where tampering is a significant concern and existing security measures like digital signatures are not applicable.
Innovation Solution
A method and system that segment a communication data stream into defined frames, generate a key frame containing integrity and authentication information, and insert it as an additional frame, creating an authenticated data stream, which includes identification, integrity, and signature blocks, ensuring data integrity and authenticity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If digital signatures are used for authentication, then data integrity and authenticity are improved, but real-time communication capability deteriorates
Solution Approach 1:
The patent segments the authentication process by dividing the data stream into frames and inserting key frames at specific intervals. Each key frame contains authentication information for a group of frames, allowing verification without processing every single frame in real-time, thus maintaining data integrity while enabling real-time communication capability
Solution Approach 2:
The patent performs preliminary authentication by generating key frames in advance that contain authentication information for multiple subsequent frames. This preliminary action allows the system to verify data integrity efficiently without requiring continuous real-time signature verification, resolving the contradiction between reliability and speed
2Reliability
If authentication information is added to each frame, then data authenticity is improved, but device complexity deteriorates
Solution Approach 1:
The patent divides authentication information into key frames that are inserted periodically rather than adding authentication data to every single frame. This segmentation reduces the overall system complexity while maintaining data authenticity verification capability across the communication stream
Solution Approach 2:
The key frame serves multiple functions: it contains authentication information, integrity verification data, and acts as a synchronization point. This multi-functionality reduces the need for separate authentication mechanisms, thereby reducing device complexity while maintaining strong authenticity verification
3Reliability
If media are used for recording and storage, then communication recording capability is improved, but security against tampering deteriorates
Solution Approach 1:
The patent applies preliminary authentication by embedding key frames with integrity verification information into the data stream before storage. This preliminary action creates a tamper-evident record that can detect any modifications after storage, maintaining recording capability while protecting against tampering
Solution Approach 2:
The authentication information in key frames provides feedback mechanism that allows verification of data integrity after storage. Any tampering with recorded data can be detected by verifying the authentication information, thus protecting against tampering while maintaining recording capability
Data Source
AI summary
A system and method for generating a non-repudiatable record of a communications data stream is provided, which is applicable to real-time and quasi-real-time data streams. A binary communication data stream is captured and segmented into defined frames. A key frame is generated for each of a number of data frames containing integrity and authentication information. The key frame is inserted into the data stream to provide an authenticated data stream.


