Encryption Negotiation for Telephony Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data streams between Telephony Client (TC) and Telephony Server (TS) in home networks are vulnerable to interception and alteration by illegal devices, lacking secure transmission mechanisms.

Innovation Solution

A method and device for negotiating encryption information, involving obtaining and determining encryption capabilities between devices, authenticating through certificate information, and using encryption protocols like SSL/TLS to secure data streams, ensuring secure encryption and decryption of data transmitted between TC and TS.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data streams are transmitted between TC and TS in home network, then communication functionality is achieved, but security against interception and alteration is compromised

Engineering Contradiction:
Improvedata transmission securityVSAvoidinterception and alteration by illegal devices
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by performing certificate authentication and encryption capability negotiation before actual data stream transmission. The control point authenticates devices using certificates and pre-establishes encryption parameters, so that when data transmission occurs, security measures are already in place to prevent interception and alteration by illegal devices

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The control point serves as an intermediary that facilitates secure communication between TC and TS. It manages certificate authentication, negotiates encryption capabilities, and distributes encryption information to communicating devices, thereby establishing a trusted security framework without which direct communication would be vulnerable

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption information negotiation is implemented between devices, then data transmission security is improved, but communication protocol complexity increases

Engineering Contradiction:
Improveencryption securityVSAvoidencryption negotiation protocol
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The control point acts as a mediator that simplifies the encryption negotiation process for end devices. Instead of requiring TC and TS to directly negotiate complex encryption parameters, the control point handles certificate verification, capability exchange, and encryption information distribution, thereby maintaining security while reducing protocol complexity at the device level

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent uses parameter changes by dynamically determining encryption capabilities and selecting appropriate encryption algorithms and key lengths based on device capabilities. The system negotiates and adapts security parameters (such as encryption algorithm type, key length, and mode) to match the capabilities of communicating devices, achieving strong security without imposing unnecessary complexity on devices with limited capabilities

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9055047B2Method and device for negotiating encryption information
Publication Date: 2015.06.09 HUAWEI TECH CO LTD
  • US9055047B2 patent drawing
  • US9055047B2 patent drawing
  • US9055047B2 patent drawing

AI summary

A method and a device for negotiating encryption information are provided. In one embodiment, the method for negotiating encryption information includes: obtaining information about encryption capabilities of a first device and information about encryption capabilities of a second device; determining encryption information applicable to the first device and the second device according to the information about encryption capabilities of the first device and the information about encryption capabilities of the second device; and sending the encryption information to the first device and the second device, wherein the encryption information serves as a basis for encrypting and/or decrypting data streams between the first device and the second device. Embodiments of the present invention ensure security of data streams transmitted between a Telephony Client (TC) and a Telephony Server (TS).