Dynamic Encryption Policy Selection for Packet Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure communication methods are vulnerable to cracking as they often use a single encryption policy for all packets in the same traffic, making it easier for attackers to decipher the encryption policy once it is cracked, even with session key updates.

Innovation Solution

Implementing a method where different packets in the same traffic are encrypted using different encryption policies from a policy group, increasing the difficulty for attackers to crack the encryption by varying the encryption algorithms and session keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single encryption policy is used for all packets in the same traffic, then the encryption process is simple and efficient, but the security is reduced as attackers can easier crack the encryption policy

Engineering Contradiction:
Improvecommunication securityVSAvoidencryption process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The encryption policy is segmented into multiple encryption policies, where each packet in the same traffic is encrypted using a different encryption policy from the group. This segmentation prevents attackers from cracking a single policy to decrypt all packets, as each packet has its own unique encryption policy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different packets within the same traffic are assigned different encryption policies based on their individual characteristics or positions. This local differentiation ensures that each packet has customized encryption protection, making it harder for attackers to find patterns or crack the encryption systematically.

Inventive Principle:
Principle #3Local quality

2Reliability

If different encryption policies are used for different packets in the same traffic, then the security is improved, but the encryption process becomes more complex

Engineering Contradiction:
Improvecommunication securityVSAvoidencryption operation simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system uses a universal encryption policy group that can be applied to multiple packets. The encryption apparatus selects different policies from this group for different packets, providing multi-functionality where a single group serves multiple encryption needs while maintaining operational simplicity through standardized selection processes.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The encryption policy selection is dynamic rather than static. The system dynamically selects different encryption policies from the group for different packets based on various criteria, making the encryption process adaptable and flexible while maintaining security. This dynamic approach prevents attackers from predicting which policy will be used for which packet.

Inventive Principle:
Principle #15Dynamics

3Reliability

If session key updates are implemented, then the security is improved, but attackers can still quickly crack the encryption policy once they master the cracking rule

Engineering Contradiction:
Improveencryption securityVSAvoidtime for attackers to crack encryption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system preliminarily establishes multiple encryption policies in a group before encryption operations begin. This preliminary preparation ensures that when packets are encrypted, the system can immediately select from pre-configured diverse policies, preventing attackers from mastering a single cracking rule that would work across all packets and sessions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system changes encryption parameters by using different encryption policies with potentially different algorithms, keys, or configurations for different packets. This parameter variation ensures that even if attackers master the cracking rule for one packet or session, they cannot efficiently crack other packets that use different parameter sets from the encryption policy group.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP4040750B1Secure communication method and apparatus
Publication Date: 2024.11.27 HUAWEI TECH CO LTD
  • EP4040750B1 patent drawingFigure 1
  • EP4040750B1 patent drawingFigure 2
  • EP4040750B1 patent drawingFigure 3

AI summary

Embodiments of this application relate to the field of security technologies, and provide a secure communication method, apparatus, and system, to encrypt different packets in same traffic by using different encryption policies, thereby increasing a difficulty of cracking by an attacker and improving communication security. The method includes: A first network device receives a first packet and a second packet, where the first packet and the second packet belong to first traffic, and all packets included in the first traffic match a first traffic differentiation rule. Based on a mapping relationship between the first traffic and a first encryption policy group, the first network device encrypts the first packet by using a first encryption policy to obtain a third packet, and encrypts the second packet by using a second encryption policy to obtain a fourth packet, where the first encryption policy group includes the second encryption policy and the first encryption policy, and the first encryption policy and the second encryption policy are different encryption policies. The first network device sends the third packet and the fourth packet to a second network device.