Integrated Encryption Transport Device Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network encryption systems are inefficient and costly due to the separation of ownership and management of encryption and transport functionalities between customers and service providers, limiting flexibility and inter-accessibility, which restricts effective network security and management.

Innovation Solution

A method and system that integrates encryption and transport functionalities into a single device, allowing customers and service providers to share access to hardware resources, with restricted access controls and user authentication, enabling flexible ownership and management while maintaining security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption and transport functionalities are separated and owned by different parties (customer and service provider), then security control and service management are maintained separately, but infrastructure cost and system complexity increase significantly

Engineering Contradiction:
Improvesecurity controlVSAvoidinfrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines encryption functionality and transport functionality into a single integrated network device. The encryption unit and transport unit share common hardware resources including processor, memory, and communication interfaces, eliminating the need for separate customer-owned encryption devices and provider-owned transport devices. This integration maintains security control while reducing infrastructure complexity and cost.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The integrated network device performs multiple functions within a single system: encryption, decryption, data transport, and protocol handling. The device can operate in different modes (encrypted transport, unencrypted transport) and serve both customer security requirements and provider service management needs, replacing multiple specialized devices with one multi-functional unit.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If customer-owned encryption devices are used, then customer security requirements are met, but service provider access to transport functions is restricted

Engineering Contradiction:
Improvecustomer securityVSAvoidservice provider access
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The integrated device segments access rights by functional unit rather than by ownership. The encryption unit maintains customer security control while the transport unit allows service provider access. The processor and memory can execute different instruction sets for different users, providing tailored access levels: customers access encryption functions, providers access transport functions, and both can interact through defined interfaces.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The integrated device acts as an intermediary between customer security requirements and service provider transport needs. The encryption unit processes data according to customer security policies while the transport unit handles data movement according to service provider routing and delivery requirements. The unified system mediates between these two sets of requirements without requiring separate devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If service provider-owned transport devices are used, then service management is simplified, but customer access to encryption functions is restricted

Engineering Contradiction:
Improveservice managementVSAvoidcustomer access
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The system segments access rights by functional unit rather than by ownership. The transport unit provides simplified service management for the service provider while the encryption unit provides secure access for the customer. The processor can execute different instruction sets for different users, allowing customers to access encryption functions and service providers to access transport functions within the same integrated device.

Inventive Principle:
Principle #1Segmentation

4Adaptability or versatility

If separate infrastructure is acquired and maintained by customer and service provider, then functional requirements are met, but cost and efficiency deteriorate

Engineering Contradiction:
Improvefunctional requirementsVSAvoidcost
Core Design Contradiction:
Adaptability or versatilityVSLoss of energy

Solution Approach 1:

The patent merges customer encryption functions and service provider transport functions into a single shared infrastructure. Both parties utilize the same hardware resources (processor, memory, communication interfaces) of the integrated network device, eliminating the need for duplicate infrastructure acquisition and maintenance. This shared approach reduces overall system cost while maintaining all required functional capabilities.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The integrated device provides universal functionality that serves both customer and service provider requirements. The same hardware platform can operate in encrypted transport mode or unencrypted transport mode, can handle multiple protocols, and can serve multiple customers. This multi-functionality eliminates the need for separate specialized infrastructure for each function or user type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9584485B2Key encryption system, method, and network devices
Publication Date: 2017.02.28 SUPERNA INC
  • US9584485B2 patent drawing
  • US9584485B2 patent drawing
  • US9584485B2 patent drawing

AI summary

A network includes encryption devices at customer sites and transport devices provide transport functionality for encrypted data for transmission across networks. A method of controlling access to a first plurality of functions of the encryption devices and access to a second plurality functions of the transport devices is disclosed. The method involves providing a customer with access to at least some of the first plurality of functions and providing a network service provider with access to at least some of the second plurality of functions. The method also involves providing the network service provider with restricted access to a first subset of the first plurality of functions and/or providing the network service provider with restricted access to a second subset of the second plurality of functions. This allows the customer and the service provider to share access to hardware resources such as the encryption devices and the transport devices.