Dynamic Encrypted Tunnel Establishment for Constrained-Band Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current encryption solutions for constrained-bandwidth communication networks, such as satellite links, are costly and inefficient, particularly for real-time applications like VoIP, as they require permanent tunnels with guaranteed bandwidth, making it difficult to control and optimize encryption and quality of service (QoS) effectively.
Innovation Solution
A method and system architecture that dynamically establish encrypted tunnels using IPSec encryption, where each communication or traffic type is configured with a unique encryption key and tunnel identifier, allowing for flexible encryption and QoS management, reducing bandwidth consumption and costs by encrypting only necessary streams and assigning appropriate QoS on a per-flow basis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a permanent encrypted tunnel with guaranteed bandwidth is opened for real-time applications like VoIP, then quality of service is improved, but communication costs increase and flexibility to control encryption is reduced
Solution Approach 1:
The patent implements dynamic tunnel establishment where encrypted tunnels are created on-demand for each communication session rather than being permanently open. The system dynamically allocates bandwidth and encryption resources based on real-time communication needs, allowing tunnels to be established when a call starts and torn down when it ends, thus providing both QoS guarantees and operational flexibility
Solution Approach 2:
The patent segments the network traffic into different communication sessions, each with its own encrypted tunnel. Instead of a single permanent tunnel for all traffic, the system creates separate encrypted channels for each VoIP call or data stream, allowing independent control and optimization of each segment while reducing overall resource consumption
2Reliability
If encryption is applied to all data streams, then security is improved, but bandwidth consumption increases and costs rise
Solution Approach 1:
The patent applies encryption selectively rather than uniformly to all data streams. The system identifies which specific traffic flows require security protection and applies encryption only to those streams, leaving other traffic unencrypted. This localized approach maintains security where needed while minimizing bandwidth consumption and costs
3Reliability
If a global encrypted tunnel is opened for all communications, then security is improved, but it becomes difficult to control start and end of individual calls and optimize bandwidth
Solution Approach 1:
The system dynamically establishes and terminates encrypted tunnels based on communication session state. When a VoIP call or data transfer is initiated, the system creates an encrypted tunnel; when the communication ends, the tunnel is automatically torn down. This dynamic approach provides both security and precise control over resource allocation for each individual call
4Reliability
If streaming tunnel with guaranteed bandwidth is used for encryption, then quality of service is improved, but cost increases significantly for bandwidth-constrained networks
Solution Approach 1:
The patent applies QoS guarantees and encryption only to the extent necessary for each specific communication need. Rather than over-provisioning all traffic with guaranteed bandwidth streaming tunnels, the system applies these resources partially and selectively only to traffic flows that require them, reducing overall communication costs while maintaining necessary service quality
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to a method and a system architecture making it possible to establish in a dynamic manner one or more encrypted tunnels on constrained-band communication networks. It makes it possible in particular to encrypt one or more data streams while guaranteeing the quality of services on the constrained-band systems, in particular for encrypted streams of voice over IP type (Internet protocol) or of data type. These tunnels are thus adapted most suitably to the useful data streams while making it possible to control and assign the necessary values for the quality of service or QoS on these networks.