Dynamic Encrypted Tunnel Establishment for Constrained-Band Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current encryption solutions for constrained-bandwidth communication networks, such as satellite links, are costly and inefficient, particularly for real-time applications like VoIP, as they require permanent tunnels with guaranteed bandwidth, making it difficult to control and optimize encryption and quality of service (QoS) effectively.

Innovation Solution

A method and system architecture that dynamically establish encrypted tunnels using IPSec encryption, where each communication or traffic type is configured with a unique encryption key and tunnel identifier, allowing for flexible encryption and QoS management, reducing bandwidth consumption and costs by encrypting only necessary streams and assigning appropriate QoS on a per-flow basis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a permanent encrypted tunnel with guaranteed bandwidth is opened for real-time applications like VoIP, then quality of service is improved, but communication costs increase and flexibility to control encryption is reduced

Engineering Contradiction:
Improvequality of serviceVSAvoidencryption control flexibility
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic tunnel establishment where encrypted tunnels are created on-demand for each communication session rather than being permanently open. The system dynamically allocates bandwidth and encryption resources based on real-time communication needs, allowing tunnels to be established when a call starts and torn down when it ends, thus providing both QoS guarantees and operational flexibility

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent segments the network traffic into different communication sessions, each with its own encrypted tunnel. Instead of a single permanent tunnel for all traffic, the system creates separate encrypted channels for each VoIP call or data stream, allowing independent control and optimization of each segment while reducing overall resource consumption

Inventive Principle:
Principle #1Segmentation

2Reliability

If encryption is applied to all data streams, then security is improved, but bandwidth consumption increases and costs rise

Engineering Contradiction:
ImprovesecurityVSAvoidbandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies encryption selectively rather than uniformly to all data streams. The system identifies which specific traffic flows require security protection and applies encryption only to those streams, leaving other traffic unencrypted. This localized approach maintains security where needed while minimizing bandwidth consumption and costs

Inventive Principle:
Principle #3Local quality

3Reliability

If a global encrypted tunnel is opened for all communications, then security is improved, but it becomes difficult to control start and end of individual calls and optimize bandwidth

Engineering Contradiction:
ImprovesecurityVSAvoidcall control flexibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system dynamically establishes and terminates encrypted tunnels based on communication session state. When a VoIP call or data transfer is initiated, the system creates an encrypted tunnel; when the communication ends, the tunnel is automatically torn down. This dynamic approach provides both security and precise control over resource allocation for each individual call

Inventive Principle:
Principle #15Dynamics

4Reliability

If streaming tunnel with guaranteed bandwidth is used for encryption, then quality of service is improved, but cost increases significantly for bandwidth-constrained networks

Engineering Contradiction:
Improvequality of serviceVSAvoidcommunication cost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies QoS guarantees and encryption only to the extent necessary for each specific communication need. Rather than over-provisioning all traffic with guaranteed bandwidth streaming tunnels, the system applies these resources partially and selectively only to traffic flows that require them, reducing overall communication costs while maintaining necessary service quality

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP2628327B1Method and system for dynamically establishing encrypted tunnels on constrained-band networks
Publication Date: 2020.11.25 THALES SA
  • EP2628327B1 patent drawingFigure 1
  • EP2628327B1 patent drawingFigure 2
  • EP2628327B1 patent drawingFigure 3

AI summary

The invention relates to a method and a system architecture making it possible to establish in a dynamic manner one or more encrypted tunnels on constrained-band communication networks. It makes it possible in particular to encrypt one or more data streams while guaranteeing the quality of services on the constrained-band systems, in particular for encrypted streams of voice over IP type (Internet protocol) or of data type. These tunnels are thus adapted most suitably to the useful data streams while making it possible to control and assign the necessary values for the quality of service or QoS on these networks.