Device Trust Verification for Secure IP Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Secure communications with Internet appliances increase computational and power demands due to the use of encryption schemes like VPN and SSH, which can strain resources when accessing these devices.

Innovation Solution

An apparatus and method that determine if a correspondent device is trusted, allowing unencrypted communications if trusted, thereby reducing computational and power demands by using an IP interface, processor, and memory to store trust data and negotiate compression levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption schemes like VPN and SSH are used for secure communications, then communication security is improved, but computational and power demands increase

Engineering Contradiction:
Improvecommunication securityVSAvoidcomputational and power demands
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies local quality by differentiating communication handling based on trust relationships. Trusted devices receive unencrypted communications with reduced computational overhead, while untrusted devices undergo full encryption/decryption processes. This selective approach optimizes resource allocation by applying security measures only where necessary rather than uniformly to all communications.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements preliminary action by establishing trust relationships and device profiles before communications occur. The system pre-configures encryption credentials, trust levels, and communication parameters in advance, allowing the processor to bypass computationally intensive security handshakes for trusted devices and directly establish efficient communication channels.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If encryption schemes are used for all communications, then security is maintained, but resource consumption increases

Engineering Contradiction:
ImprovesecurityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system applies different security measures to different communication streams based on trust assessments. Trusted device communications use minimal or no encryption, while untrusted device communications receive full security processing. This differentiated approach maintains overall system security while significantly reducing average resource consumption across all communications.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial action by applying security measures only to the extent necessary for each communication partner. Rather than applying maximum security uniformly, the system adjusts security intensity based on trust levels, using full encryption only when absolutely necessary and minimal or no encryption for trusted relationships, thereby optimizing the security-to-resource-ratio.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10917386B2Determining if a correspondent device is trusted
Publication Date: 2021.02.09 LENOVO SWITZERLAND INTERNATIONAL GMBH
  • US10917386B2 patent drawing
  • US10917386B2 patent drawing
  • US10917386B2 patent drawing

AI summary

For secure communications, a processor determines if a correspondent device is trusted. In response to the correspondent device not being trusted, the processor terminates communications with the correspondent device. In response to the correspondent device being trusted, the processor exchanges unencrypted communications with the correspondent device over an IP interface.