Encrypted Session Priority Management via Handshake Cryptographic Embedding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network communication protocols face challenges in ensuring real-time priority-based communications over encrypted sessions, particularly in balancing streaming media with security and system performance, while also dealing with complexities such as firewalls and NAT devices, which can hinder the delivery of media streams like RTP/UDP.
Innovation Solution
The method establishes an encrypted communication session using cryptographic information in a pre-defined portion of the handshake network communication, allowing for the prioritization and management of sub-media streams, including the decryption and assembly of playable media streams, and the processing of data payloads based on identified purposes and parameters, ensuring secure and efficient transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic information is embedded in the random byte section of network communications to establish encrypted sessions, then security against snooping and reverse engineering is improved, but the complexity of detecting and measuring the cryptographic information increases
Solution Approach 1:
The patent converts the potentially harmful effect of embedding cryptographic information in a reserved section into a benefit by using the random byte section's existing purpose for bandwidth detection. The cryptographic information is hidden within this section, making it invisible to both attackers and standard protocol analyzers, while still allowing the section to serve its original function.
2Productivity
If real-time priority-based communications are implemented over encrypted sessions, then the ability to prioritize media streams is improved, but the device complexity increases
Solution Approach 1:
The patent segments the network communication into distinct functional parts: a reserved section for cryptographic information and the standard payload for media data. This segmentation allows the cryptographic layer to operate independently from the media streaming layer, enabling priority-based communications without requiring complex integration of encryption and prioritization mechanisms.
Solution Approach 2:
The reserved section of the network communication serves multiple functions: it provides cryptographic information for session establishment, maintains compatibility with existing protocols by occupying a reserved space, and enables bandwidth detection. This multi-functionality reduces the need for separate mechanisms, thereby reducing overall system complexity.
3Reliability
If cryptographic information is inserted into the reserved section of network communications, then secure transmission is improved, but the ease of operation decreases
Solution Approach 1:
The patent performs preliminary action by pre-defining the reserved section in the network communication protocol before actual cryptographic operations begin. This pre-allocation of space and establishment of rules for embedding cryptographic information simplifies the operational process, as the structure is already in place and requires no complex runtime decisions.
4Reliability
If alterations during transmission are detected to prevent malicious interventions, then security is improved, but the loss of time increases due to verification processes
Solution Approach 1:
The patent implements feedback mechanisms where the receiving end verifies the cryptographic information and detects alterations in the reserved section. This feedback loop ensures security by confirming the integrity of transmitted data while maintaining efficient verification processes that minimize time loss.
Data Source
AI summary
This specification describes technologies relating to imparting real-time priority-based network communications in an encrypted session. In general, aspects of the subject matter described can be embodied in methods that include establishing, based on cryptographic information in a reserved, random-data portion of a handshake communication, a session, receiving parameter values relating to a sub media stream, included in a header of a network communication, storing the parameter values, obtaining state information and a data payload included in a second network communication, identifying, from the state information, a purpose of the second network communication, and whether a header of the second network communication includes one or more new values corresponding to one or more of the parameters, updating one or more of the stored values based on the one or more new values, and processing the data payload based on the identified purpose and the stored parameter values.


