EDITH Double Encryption for Multicast Data Overhead Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current end-to-end data-in-transit protection solutions for tactical IP networks fail to meet requirements such as protecting classified information, supporting multicast transmissions, and minimizing network overhead, particularly in bandwidth-constrained environments, while being compliant with the NSA's CSfC Mobile Access Capability Package.

Innovation Solution

The EDITH method employs bandwidth-efficient IPsec packet framing, secure multicast capabilities, and differentiated services code point pass-through for QoS support, using double encryption and compression to reduce packet overhead and ensure data security across various network technologies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional IPsec encryption is used for data protection, then data security is improved, but network overhead increases to 14%

Engineering Contradiction:
Improvedata securityVSAvoidnetwork overhead
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent implements nested encryption by encapsulating the original IP packet inside an IPsec tunnel, creating a packet-inside-a packet structure. The inner packet contains the original unencrypted data while the outer packet provides encryption and security parameters, allowing traditional IPsec security mechanisms to be applied without requiring complete protocol redesign.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent modifies IPsec packet parameters by compressing the outer IP header and removing redundant fields. Specifically, the source and destination addresses in the outer packet are replaced with tunnel endpoints, and the protocol field is set to indicate IPsec encapsulation. This parameter optimization reduces overhead while maintaining security functionality.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If CSfC-qualified VPN products are used for data protection, then security compliance is improved, but multicast support and bandwidth efficiency are lost

Engineering Contradiction:
Improvesecurity complianceVSAvoidmulticast support
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal IPsec implementation that handles multiple packet types including unicast, multicast, and anycast through a single encapsulation mechanism. The system determines packet type by examining the destination address and applies appropriate routing while maintaining the same security processing pipeline, thus achieving multi-functionality without sacrificing compliance.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments the IPsec processing into distinct functional components: packet reception, type determination (unicast/multicast/anycast), security processing, and transmission. This segmentation allows the system to maintain compliance for standard unicast traffic while extending capabilities to multicast and anycast scenarios through the same modular architecture.

Inventive Principle:
Principle #1Segmentation

3Quantity of substance

If bandwidth-efficient packet framing is implemented, then network overhead is reduced to less than 6%, but device complexity increases

Engineering Contradiction:
Improvenetwork overheadVSAvoidpacket processing complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent performs preliminary actions by pre-computing and storing compression tables and encryption parameters before actual data transmission occurs. The system establishes security associations and pre-processes packet headers to determine optimal encoding paths, reducing the computational burden during high-speed packet forwarding and minimizing real-time processing complexity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12192181B2Systems and methods for encrypting and transmitting data packets using a unicast address
Publication Date: 2025.01.07 ARCHITECTURE TECH CORP
  • US12192181B2 patent drawing
  • US12192181B2 patent drawing
  • US12192181B2 patent drawing

AI summary

Disclosed herein are embodiments of systems, methods, and products comprising a computing device, which provides Efficient Data-In-Transit Protection Techniques for Handheld Devices (EDITH) to protect data-in-transit. An end user device (EUD) may generate a multicast data packet. The EDITH module of the EUD encapsulates the data packet in a GRE packet and directs the GRE packet to a unicast destination address of an EDITH Multicast Router included in an infrastructure. The EDITH module on the EUD double compresses and double encrypts the GRE packet. The EDITH module on the infrastructure decrypts and decompresses the double compressed and double encrypted GRE packet to recreate the GRE packet. The EDITH module on the infrastructure decapsulates the GRE packet to derive the original multicast data packet, and distributes the original multicast data packet to the multiple group member based on the multicast destination address included in the original multicast data packet.