Encryption Device Passing Unencrypted Network Metrics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure communication systems do not provide entities with network metric data, such as cost and quality-of-service information, necessary for informed decision-making, as all data transferred over the network is encrypted, preventing entities from accessing this critical information.

Innovation Solution

Incorporating an encryption device that decrypts data from a destination while passing network metric data unencrypted to the entity, allowing access to network attributes like data transfer cost and quality-of-service data without subjecting it to decryption, while ensuring secure two-way communication and reducing exposure to malicious data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all data transferred over the network is encrypted, then security is improved, but entities cannot access network metric data such as cost and quality-of-service information

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork metric data accessibility
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments network data into two distinct categories: encrypted data (for security-sensitive information) and unencrypted metric data (for network management information). The encryption device processes and separates these data types, allowing metric data to be transmitted in plain text while other data remains encrypted, thus resolving the contradiction between security and information accessibility

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The encryption device acts as an intermediary between the network and entities. It selectively decrypts and passes through network metric data without applying decryption algorithms, while maintaining encryption for other data. This intermediary function enables entities to access necessary network information without compromising overall security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If network metric data is transmitted in encrypted form, then security is maintained, but entities cannot make informed decisions about network usage

Engineering Contradiction:
ImprovesecurityVSAvoidinformed decision-making capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts network metric data from the encrypted data stream and transmits it separately in unencrypted form. This extraction allows entities to access cost, quality-of-service, and routing metric information needed for informed decision-making, while the remaining data stays encrypted to maintain security

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If decryption algorithms are applied to all incoming data, then all data becomes accessible, but processing time and computational resources increase

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata processing time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The encryption device applies decryption algorithms only to necessary data and passes network metric data through without decryption. This partial action approach reduces unnecessary computational overhead and processing time while still providing entities with the information they need for network management decisions

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9781076B2Secure communication system
Publication Date: 2017.10.03 AIRBUS DEFENCE AND SPACE LTD
  • US9781076B2 patent drawing
  • US9781076B2 patent drawing
  • US9781076B2 patent drawing

AI summary

A communications system (40) comprises a first entity (42), a first encryption device (48) and a network (46). The first encryption device (48) is adapted to decrypt, using a first decryption algorithm, data sent from a first destination to said first entity via said network (46). The first encryption device (48) is adapted to pass network metric data concerning at least one route between said first entity and said first destination to said first entity without subjecting said network metric data to said first decryption algorithm.