Secure Data Packet Transmission via Dual Encryption and Hash Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for secure data packet transmission between networks with different security levels, such as black and red networks, face challenges in ensuring correct logical transmission channels, leading to potential misrouting and manipulation of data packets due to insecure parameter storage in allocation tables.

Innovation Solution

Implementing a method that uses a second encryption and decryption unit on both sides of the network interface and encryption unit, with a shared key, to ensure secure transmission by encrypting data packets in the transport mode and integrating a hash function to verify data integrity, along with individual sequence values and initialization data for enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If a single common physical transmission channel is used to connect multiple encryption/decryption units and network interfaces, then cost is reduced, but security against manipulation and misrouting deteriorates

Engineering Contradiction:
ImprovecostVSAvoidsecurity against manipulation and misrouting
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent segments the transmission channel into multiple virtual logical channels within the single physical channel. Each encryption/decryption unit is assigned a specific logical channel identified by unique parameters (IP address, port, protocol), preventing manipulation and misrouting while sharing the physical infrastructure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a channel identification and verification mechanism as an intermediary layer between the physical channel and encryption/decryption units. This intermediary verifies packet parameters and ensures correct routing, maintaining security despite the shared physical channel.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If encryption/decryption units are integrated into a single device, then cost is reduced, but device complexity increases

Engineering Contradiction:
ImprovecostVSAvoiddevice complexity
Core Design Contradiction:
Ease of manufactureVSDevice complexity

Solution Approach 1:

The patent merges multiple encryption/decryption units and network interfaces into a single physical device. The device includes a control unit that manages channel identification, parameter verification, and routing decisions, coordinating the integrated components.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The single device performs multiple functions: it acts as both a network device with multiple interfaces and a cryptographic device with multiple encryption/decryption units. The control unit handles channel management, parameter verification, and routing, making the device universal and multi-functional.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If parameter sets are stored in allocation tables for routing and encryption, then transmission efficiency is improved, but vulnerability to manipulation increases

Engineering Contradiction:
Improvetransmission efficiencyVSAvoidvulnerability to manipulation
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements feedback mechanisms where the receiving encryption/decryption unit verifies packet parameters against its allocation table and sends acknowledgment or rejection signals. The transmitting unit adjusts based on this feedback, ensuring parameter integrity and detecting manipulation attempts.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs preliminary verification of packet parameters (IP address, port, protocol) against allocation tables before routing and processing. This preliminary check prevents manipulation by validating parameters early in the transmission process, before the packet is fully processed.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2830277B8Method and system for tamper-proof transmission of data packets
Publication Date: 2019.12.04 ROHDE & SCHWARZ SIT

AI summary

The invention relates to a method and a system for transmitting a data packet between a first (black) network (11, ...,1N) without transmission security and at least one second (red) network (151, ...,15N), each with specific transmission security. For the secure transmission of data packets on a correct logical transmission channel between an encryption and decryption unit (61, ..., 6N) belonging to the respective red network (151, ...,15N) and a network interface (91, ..., 9N) belonging to the same red network (151, ...,15N), a second encryption and decryption unit (71, ...,7N) is provided for the second encryption of the data packet.