Dynamic Cipher Suite Selection for Secure Transport Channels

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cryptographic methods for securing computing resources and data require high computational resources, leading to performance constraints and unnecessary expenses, especially in devices with limited capabilities, and do not efficiently adapt to varying security needs across different transactions.

Innovation Solution

Implementing dynamic cipher suite selection during handshake negotiations, where clients and servers choose mutually acceptable cipher suites based on planned session use, favoring performance characteristics for less sensitive data and stronger cryptographic properties for sensitive information, and using a cryptography algorithm hopping model to change algorithms over time.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If higher levels of cryptographic protection are applied to all transactions, then data security is improved, but computational resource consumption increases and performance decreases

Engineering Contradiction:
Improvedata securityVSAvoidtransaction performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies different cryptographic protection levels to different transactions based on their specific security requirements. Sensitive transactions receive stronger encryption while non-sensitive transactions use weaker encryption, optimizing the balance between security and performance for each individual transaction rather than applying uniform protection across all transactions.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically changes cryptographic parameters such as key length and algorithm strength based on the sensitivity classification of each transaction. This allows the cryptographic protection level to be adjusted according to actual security needs, reducing unnecessary computational overhead for less sensitive transactions while maintaining adequate security for sensitive ones.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If stronger cryptographic algorithms are used for all data transmissions, then security is enhanced, but computational resource expenditure increases unnecessarily

Engineering Contradiction:
Improvetransmission securityVSAvoidcomputational energy
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent implements differentiated cryptographic protection where different transmission channels or data types receive different security levels. Non-sensitive data transmissions use lighter cryptographic algorithms while sensitive data receives stronger protection, ensuring that computational energy is not wasted on applying maximum security to all transmissions uniformly.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system applies cryptographic protection selectively based on actual security requirements rather than applying full-strength encryption to all transactions. This partial action approach ensures adequate security for each transaction type without the excessive energy consumption that would result from uniform application of strongest cryptographic algorithms.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If uniform high-level encryption is applied to all communications, then security consistency is maintained, but bandwidth efficiency decreases due to larger data overhead

Engineering Contradiction:
Improvesecurity consistencyVSAvoidbandwidth efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent dynamically adjusts cryptographic parameters such as encryption key length and algorithm selection based on the sensitivity classification of each transaction. This results in variable encryption overhead where sensitive transactions use stronger encryption with larger overhead while non-sensitive transactions use lighter encryption with smaller overhead, optimizing bandwidth efficiency while maintaining security consistency appropriate to each transaction type.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10523707B2Secure transport channel using multiple cipher suites
Publication Date: 2019.12.31 AMAZON TECH INC
  • US10523707B2 patent drawing
  • US10523707B2 patent drawing
  • US10523707B2 patent drawing

AI summary

A plurality of cipher suites is negotiated as part of a handshake process to establish a cryptographically protected communications session. The handshake process is completed to establish the cryptographically protected communications session. A message is communicated over the established cryptographically protected communications session using at least two cipher suites of the plurality of cipher suites.