Dynamic Cipher Suite Selection for Secure Transport Channels
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cryptographic methods for securing computing resources and data require high computational resources, leading to performance constraints and unnecessary expenses, especially in devices with limited capabilities, and do not efficiently adapt to varying security needs across different transactions.
Innovation Solution
Implementing dynamic cipher suite selection during handshake negotiations, where clients and servers choose mutually acceptable cipher suites based on planned session use, favoring performance characteristics for less sensitive data and stronger cryptographic properties for sensitive information, and using a cryptography algorithm hopping model to change algorithms over time.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If higher levels of cryptographic protection are applied to all transactions, then data security is improved, but computational resource consumption increases and performance decreases
Solution Approach 1:
The patent applies different cryptographic protection levels to different transactions based on their specific security requirements. Sensitive transactions receive stronger encryption while non-sensitive transactions use weaker encryption, optimizing the balance between security and performance for each individual transaction rather than applying uniform protection across all transactions.
Solution Approach 2:
The system dynamically changes cryptographic parameters such as key length and algorithm strength based on the sensitivity classification of each transaction. This allows the cryptographic protection level to be adjusted according to actual security needs, reducing unnecessary computational overhead for less sensitive transactions while maintaining adequate security for sensitive ones.
2Reliability
If stronger cryptographic algorithms are used for all data transmissions, then security is enhanced, but computational resource expenditure increases unnecessarily
Solution Approach 1:
The patent implements differentiated cryptographic protection where different transmission channels or data types receive different security levels. Non-sensitive data transmissions use lighter cryptographic algorithms while sensitive data receives stronger protection, ensuring that computational energy is not wasted on applying maximum security to all transmissions uniformly.
Solution Approach 2:
The system applies cryptographic protection selectively based on actual security requirements rather than applying full-strength encryption to all transactions. This partial action approach ensures adequate security for each transaction type without the excessive energy consumption that would result from uniform application of strongest cryptographic algorithms.
3Reliability
If uniform high-level encryption is applied to all communications, then security consistency is maintained, but bandwidth efficiency decreases due to larger data overhead
Solution Approach 1:
The patent dynamically adjusts cryptographic parameters such as encryption key length and algorithm selection based on the sensitivity classification of each transaction. This results in variable encryption overhead where sensitive transactions use stronger encryption with larger overhead while non-sensitive transactions use lighter encryption with smaller overhead, optimizing bandwidth efficiency while maintaining security consistency appropriate to each transaction type.
Data Source
AI summary
A plurality of cipher suites is negotiated as part of a handshake process to establish a cryptographically protected communications session. The handshake process is completed to establish the cryptographically protected communications session. A message is communicated over the established cryptographically protected communications session using at least two cipher suites of the plurality of cipher suites.


