Dynamic Security Establishment for Multimedia Streams

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In network security, especially over packet networks, end-to-end cryptographic protection for multimedia communication is challenging due to the need for access to cleartext for transcoding and the variability in media security capabilities among endpoints, leading to situations where end-to-middle security is necessary but difficult to establish.

Innovation Solution

A method that allows for the dynamic establishment of end-to-end (e2e) or end-to-middle (e2m) security for multimedia streams by probing for e2e security and falling back to e2m security if not supported, with the option to establish no security if both fail, using signaling and media relays to manage security parameters and routes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If end-to-end cryptographic protection is applied to multimedia communication over packet networks, then security against eavesdropping is improved, but compatibility with endpoints having limited security capabilities deteriorates

Engineering Contradiction:
Improvesecurity protectionVSAvoidendpoint compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic security establishment by first attempting to set up end-to-end encrypted media streams, and if that fails due to endpoint incompatibility, automatically falling back to end-to-middle security or unsecured streams. This dynamic approach allows the system to adapt security levels based on real-time capability assessment of communication endpoints.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent segments the security protection scope into different levels: end-to-end security (full path encryption), end-to-middle security (encryption only to network relay), and no security. This segmentation allows selective application of security measures based on endpoint capabilities, resolving the contradiction between providing strong security and maintaining broad compatibility.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If key management protocols are used to enable network elements to access cryptographic keys for transcoding, then media processing flexibility is improved, but security against unauthorized access deteriorates

Engineering Contradiction:
Improvemedia processing capabilityVSAvoidcryptographic security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces signaling relays as intermediaries that facilitate key management protocols between endpoints and network elements requiring transcoding. These relays securely transmit cryptographic keys and parameters without exposing the media content, enabling authorized network elements to perform transcoding while maintaining security through controlled key distribution.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If signaling messages are protected using cryptographic protocols between each pair of entities, then signaling security is improved, but system complexity deteriorates

Engineering Contradiction:
Improvesignaling securityVSAvoidcryptographic protocol implementation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent employs universal cryptographic protocols (IPsec ESP or TLS) that can be applied uniformly to protect all signaling messages between different entity pairs. This multi-functional approach allows the same cryptographic mechanisms to serve multiple security needs (endpoint-to-relay, relay-to-relay communication), reducing overall system complexity compared to implementing specialized protocols for each communication pair.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2441225B1Methods, apparatuses, and related computer program product for network security
Publication Date: 2017.09.06 NOKIA SOLUTIONS & NETWORKS OY
  • EP2441225B1 patent drawingFigure 1
  • EP2441225B1 patent drawingFigure 2
  • EP2441225B1 patent drawingFigure 3

AI summary

It is disclosed a method (and related apparatus) comprising selecting, at a first endpoint entity, at least one range of protection to be granted, the range of protection relating to one of a plurality of network elements in at least one access network and at least one core network and to a second endpoint entity, and transmitting, to a network element entity, a signaling message comprising first establishment information indicating the at least one range of protection to be granted; and a method (and related apparatus) comprising receiving, at the network element entity, the signaling message from the first endpoint entity, obtaining, from a second endpoint entity and based on the first establishment information, second establishment information indicating protection granted by the second endpoint entity, and signaling, from the network element entity to the first endpoint entity, third establishment information indicating the protection granted to the first endpoint entity.