Encrypted Data Stream Analysis via Key Packet Insertion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In communication networks, particularly in Voice over IP, diagnosing errors in encrypted data streams transmitted using the RTP protocol is challenging due to the unavailability of key information during connection signaling, which is encrypted and not accessible for analysis or diagnosis.

Innovation Solution

Inserting key data packets into the data streams that contain data-stream-specific key information, allowing for the decryption of the streams during analysis, with the key information being transmitted in a way that it cannot be read by standard network protocol receivers, and using a new or unused payload type to ensure security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data streams are encrypted for security, then security is improved, but the ability to analyze or diagnose errors in the data streams deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoiderror analysis capability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces an intermediary mechanism by inserting key data packets into the encrypted data streams. These key data packets serve as mediators that carry decryption information without compromising the overall encryption security. The intermediary allows the analysis device to obtain necessary key information while the standard RTP receiver remains unable to access it, thus resolving the contradiction between maintaining security and enabling error analysis.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Difficulty of detecting and measuring

If key information is made available for data stream analysis, then error diagnosis capability is improved, but security deteriorates as key information becomes accessible

Engineering Contradiction:
Improveerror diagnosis capabilityVSAvoidsecurity
Core Design Contradiction:
Difficulty of detecting and measuringVSReliability

Solution Approach 1:

The patent applies local quality by making key information available only at specific locations (key data packets inserted into the stream) and only to specific devices (analysis devices with special capability). The standard RTP receivers continue to see only encrypted data. This localized availability of decryption information enables error diagnosis without compromising overall system security, as the key information is not universally accessible.

Inventive Principle:
Principle #3Local quality

3Productivity

If multiple data streams are transmitted simultaneously, then communication efficiency is improved, but the administrative effort for analyzing each stream individually increases

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidadministrative effort for analysis
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent merges the key information transmission with the data stream transmission by inserting key data packets directly into the encrypted streams. This combining approach allows a single analysis device to access and process key information for multiple simultaneously transmitted data streams through one unified interface, eliminating the need for separate administrative operations for each stream and thus reducing overall administrative effort while maintaining high communication efficiency.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP2186261B1Method and communication system for analyzing simultaneously transmitted, encoded data streams
Publication Date: 2016.09.14 UNIFY GMBH & CO KG
  • EP2186261B1 patent drawingFigure 1~2
  • EP2186261B1 patent drawing
  • EP2186261B1 patent drawing

AI summary

In a data stream individually encoded data stream (dsl..n), data packets formed as key data packets (spl..n) are to be inserted, with which the data stream-individual key information (sil..n) is transmitted with the associated data stream (dsl..n). For analyzing and/or recording, at least one key data packet (spl..n) is searched for in the associated data stream (dsl..n), and the data stream-individual key information (sil..n) is determined. By means of the data stream-individual key information (sil..n), the associated data stream (dsl..n) is decoded. The generation and insertion of key information (sil..n) can be achieved with minor administrative effort, thus considerably reducing the effort for the analysis or diagnosis (dsl..n) of the simultaneously transmitted, encoded data streams (dsl..n). Advantageously, the insertion of key data packets can only be activated or initiated if the diagnosis or analysis and/or recording of the data streams is currently carried out.