Dynamic Security Establishment for Multimedia Streams
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In network security, especially over packet networks, end-to-end cryptographic protection for multimedia communication is challenging due to the need for access to cleartext for transcoding and the variability in media security capabilities among endpoints, leading to situations where end-to-middle security is necessary but difficult to establish.
Innovation Solution
A method that allows for the dynamic establishment of end-to-end (e2e) or end-to-middle (e2m) security for multimedia streams by probing for e2e security and falling back to e2m security if not supported, with the option to establish no security if both fail, using signaling and media relays to manage security parameters and routes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If end-to-end cryptographic protection is applied to multimedia communication over packet networks, then security against eavesdropping is improved, but compatibility with endpoints having limited security capabilities deteriorates
Solution Approach 1:
The patent implements dynamic security establishment by first attempting to set up end-to-end encrypted media streams, and if that fails due to endpoint incompatibility, automatically falling back to end-to-middle security or unsecured streams. This dynamic approach allows the system to adapt security levels based on real-time capability assessment of communication endpoints.
Solution Approach 2:
The patent segments the security protection scope into different levels: end-to-end security (full path encryption), end-to-middle security (encryption only to network relay), and no security. This segmentation allows selective application of security measures based on endpoint capabilities, resolving the contradiction between providing strong security and maintaining broad compatibility.
2Adaptability or versatility
If key management protocols are used to enable network elements to access cryptographic keys for transcoding, then media processing flexibility is improved, but security against unauthorized access deteriorates
Solution Approach 1:
The patent introduces signaling relays as intermediaries that facilitate key management protocols between endpoints and network elements requiring transcoding. These relays securely transmit cryptographic keys and parameters without exposing the media content, enabling authorized network elements to perform transcoding while maintaining security through controlled key distribution.
3Reliability
If signaling messages are protected using cryptographic protocols between each pair of entities, then signaling security is improved, but system complexity deteriorates
Solution Approach 1:
The patent employs universal cryptographic protocols (IPsec ESP or TLS) that can be applied uniformly to protect all signaling messages between different entity pairs. This multi-functional approach allows the same cryptographic mechanisms to serve multiple security needs (endpoint-to-relay, relay-to-relay communication), reducing overall system complexity compared to implementing specialized protocols for each communication pair.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
It is disclosed a method (and related apparatus) comprising selecting, at a first endpoint entity, at least one range of protection to be granted, the range of protection relating to one of a plurality of network elements in at least one access network and at least one core network and to a second endpoint entity, and transmitting, to a network element entity, a signaling message comprising first establishment information indicating the at least one range of protection to be granted; and a method (and related apparatus) comprising receiving, at the network element entity, the signaling message from the first endpoint entity, obtaining, from a second endpoint entity and based on the first establishment information, second establishment information indicating protection granted by the second endpoint entity, and signaling, from the network element entity to the first endpoint entity, third establishment information indicating the protection granted to the first endpoint entity.