EDITH Double Encryption for Multicast Data Overhead Reduction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current end-to-end data-in-transit protection solutions for tactical IP networks fail to meet requirements such as protecting classified information, supporting multicast transmissions, and minimizing network overhead, particularly in bandwidth-constrained environments, while being compliant with the NSA's CSfC Mobile Access Capability Package.
Innovation Solution
The EDITH method employs bandwidth-efficient IPsec packet framing, secure multicast capabilities, and differentiated services code point pass-through for QoS support, using double encryption and compression to reduce packet overhead and ensure data security across various network technologies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional IPsec encryption is used for data protection, then data security is improved, but network overhead increases to 14%
Solution Approach 1:
The patent implements nested encryption by encapsulating the original IP packet inside an IPsec tunnel, creating a packet-inside-a packet structure. The inner packet contains the original unencrypted data while the outer packet provides encryption and security parameters, allowing traditional IPsec security mechanisms to be applied without requiring complete protocol redesign.
Solution Approach 2:
The patent modifies IPsec packet parameters by compressing the outer IP header and removing redundant fields. Specifically, the source and destination addresses in the outer packet are replaced with tunnel endpoints, and the protocol field is set to indicate IPsec encapsulation. This parameter optimization reduces overhead while maintaining security functionality.
2Reliability
If CSfC-qualified VPN products are used for data protection, then security compliance is improved, but multicast support and bandwidth efficiency are lost
Solution Approach 1:
The patent creates a universal IPsec implementation that handles multiple packet types including unicast, multicast, and anycast through a single encapsulation mechanism. The system determines packet type by examining the destination address and applies appropriate routing while maintaining the same security processing pipeline, thus achieving multi-functionality without sacrificing compliance.
Solution Approach 2:
The patent segments the IPsec processing into distinct functional components: packet reception, type determination (unicast/multicast/anycast), security processing, and transmission. This segmentation allows the system to maintain compliance for standard unicast traffic while extending capabilities to multicast and anycast scenarios through the same modular architecture.
3Quantity of substance
If bandwidth-efficient packet framing is implemented, then network overhead is reduced to less than 6%, but device complexity increases
Solution Approach 1:
The patent performs preliminary actions by pre-computing and storing compression tables and encryption parameters before actual data transmission occurs. The system establishes security associations and pre-processes packet headers to determine optimal encoding paths, reducing the computational burden during high-speed packet forwarding and minimizing real-time processing complexity.
Data Source
AI summary
Disclosed herein are embodiments of systems, methods, and products comprising a computing device, which provides Efficient Data-In-Transit Protection Techniques for Handheld Devices (EDITH) to protect data-in-transit. An end user device (EUD) may generate a multicast data packet. The EDITH module of the EUD encapsulates the data packet in a GRE packet and directs the GRE packet to a unicast destination address of an EDITH Multicast Router included in an infrastructure. The EDITH module on the EUD double compresses and double encrypts the GRE packet. The EDITH module on the infrastructure decrypts and decompresses the double compressed and double encrypted GRE packet to recreate the GRE packet. The EDITH module on the infrastructure decapsulates the GRE packet to derive the original multicast data packet, and distributes the original multicast data packet to the multiple group member based on the multicast destination address included in the original multicast data packet.


