Encrypted Sub-Meeting Key Management in Video Conferences
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing video conferencing systems face challenges in securely facilitating sub-meetings within encrypted conferences, as they require participants to generate and distribute cryptographic keys, which can lead to access issues and potential eavesdropping by the video conference provider.
Innovation Solution
The system allows the video conference provider to select and notify a sub-meeting host from the participants, who generates and distributes unique encryption and decryption keys for sub-meetings, ensuring that the provider lacks access to these keys and maintaining end-to-end encryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the video conference provider facilitates sub-meetings with end-to-end encryption, then security is improved, but the provider loses the ability to access or monitor communication content
Solution Approach 1:
The patent divides the encryption scope into two segments: main meeting encryption (where the provider has access) and sub-meeting encryption (where the provider lacks access). This segmentation allows different security levels for different communication contexts, enabling the provider to maintain oversight of main meetings while ensuring enhanced privacy for sub-meetings.
Solution Approach 2:
The patent applies different encryption qualities to different parts of the system. Sub-meetings receive end-to-end encryption with keys unknown to the provider, creating a localized security zone. This local quality approach allows the provider to maintain overall system control while implementing enhanced security for specific sub-meeting communications.
2Reliability
If participants generate and distribute cryptographic keys for sub-meetings, then end-to-end encryption is achieved, but access control and key management complexity increase
Solution Approach 1:
The patent introduces sub-meeting hosts as intermediary entities who facilitate key distribution within sub-meetings. These hosts receive encryption keys and distribute them to appropriate participants, simplifying the key management process. The intermediary approach reduces the complexity of direct peer-to-peer key distribution while maintaining end-to-end encryption security.
Solution Approach 2:
The patent implements preliminary key generation and distribution before sub-meetings begin. The host generates encryption keys in advance and distributes them to participants prior to the sub-meeting start time. This preliminary action ensures that all necessary cryptographic materials are ready before communication begins, streamlining the key management process.
3Reliability
If the provider lacks access to encryption keys for sub-meetings, then privacy is improved, but the provider cannot facilitate recording or transcription of sub-meeting content
Solution Approach 1:
The patent segments the service capabilities by encryption scope. Recording and transcription services are provided for main meetings where the provider has key access, while sub-meetings maintain privacy through end-to-end encryption without provider key access. This segmentation allows the provider to offer versatile services for main meetings while preserving the privacy benefits of unmonitored sub-meetings.
Data Source
AI summary
One example method includes facilitating communications between a plurality of participants in a main meeting of a video conference, the communications encrypted using a first encryption key, the video conference provider lacking access to the first encryption key and a first decryption key; in response to receiving a command from a host to establish one or more sub-meetings, establishing the sub-meetings; for each sub-meeting, selecting a sub-meeting host; transmitting an indication that the selected sub-meeting host is a sub-meeting host; in response to receiving a request from a first participant to join a first sub-meeting, joining the first participant to the first sub-meeting; and facilitating sub-meeting communications between the sub-meeting host and the first participant, the sub-meeting communications encrypted using second encryption and decryption keys, the second encryption and decryption keys different than the first encryption and decryption keys, the video conference provider lacking access to the second encryption and decryption keys.


