Secure Data Packet Transmission via Dual Encryption and Hash Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for secure data packet transmission between networks with different security levels, such as black and red networks, face challenges in ensuring correct logical transmission channels, leading to potential misrouting and manipulation of data packets due to insecure parameter storage in allocation tables.
Innovation Solution
Implementing a method that uses a second encryption and decryption unit on both sides of the network interface and encryption unit, with a shared key, to ensure secure transmission by encrypting data packets in the transport mode and integrating a hash function to verify data integrity, along with individual sequence values and initialization data for enhanced security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If a single common physical transmission channel is used to connect multiple encryption/decryption units and network interfaces, then cost is reduced, but security against manipulation and misrouting deteriorates
Solution Approach 1:
The patent segments the transmission channel into multiple virtual logical channels within the single physical channel. Each encryption/decryption unit is assigned a specific logical channel identified by unique parameters (IP address, port, protocol), preventing manipulation and misrouting while sharing the physical infrastructure.
Solution Approach 2:
The patent introduces a channel identification and verification mechanism as an intermediary layer between the physical channel and encryption/decryption units. This intermediary verifies packet parameters and ensures correct routing, maintaining security despite the shared physical channel.
2Ease of manufacture
If encryption/decryption units are integrated into a single device, then cost is reduced, but device complexity increases
Solution Approach 1:
The patent merges multiple encryption/decryption units and network interfaces into a single physical device. The device includes a control unit that manages channel identification, parameter verification, and routing decisions, coordinating the integrated components.
Solution Approach 2:
The single device performs multiple functions: it acts as both a network device with multiple interfaces and a cryptographic device with multiple encryption/decryption units. The control unit handles channel management, parameter verification, and routing, making the device universal and multi-functional.
3Productivity
If parameter sets are stored in allocation tables for routing and encryption, then transmission efficiency is improved, but vulnerability to manipulation increases
Solution Approach 1:
The patent implements feedback mechanisms where the receiving encryption/decryption unit verifies packet parameters against its allocation table and sends acknowledgment or rejection signals. The transmitting unit adjusts based on this feedback, ensuring parameter integrity and detecting manipulation attempts.
Solution Approach 2:
The patent performs preliminary verification of packet parameters (IP address, port, protocol) against allocation tables before routing and processing. This preliminary check prevents manipulation by validating parameters early in the transmission process, before the packet is fully processed.
Data Source
AI summary
The invention relates to a method and a system for transmitting a data packet between a first (black) network (11, ...,1N) without transmission security and at least one second (red) network (151, ...,15N), each with specific transmission security. For the secure transmission of data packets on a correct logical transmission channel between an encryption and decryption unit (61, ..., 6N) belonging to the respective red network (151, ...,15N) and a network interface (91, ..., 9N) belonging to the same red network (151, ...,15N), a second encryption and decryption unit (71, ...,7N) is provided for the second encryption of the data packet.