Frame-Header Security Modes for Multi-Device Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptographic systems in electronic communications lack flexibility in setting security parameters, particularly when communicating with multiple devices, as they often require separate parameter settings for each communication, limiting adaptability and efficiency.

Innovation Solution

A method and apparatus that dynamically adjust security levels on a frame-by-frame basis using security mode and integrity level bits in the header of data frames, allowing flexible security settings based on recipient requirements and frame type, with optional encryption and authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate security parameters are set for each communication with multiple devices, then security requirements for each device can be met, but system complexity and configuration overhead increase

Engineering Contradiction:
Improvesecurity requirements complianceVSAvoidparameter configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments security parameters into frame-type-specific configurations rather than device-specific configurations. Each frame type (management, data, confirmation) has its own security parameter set, allowing generic security policies to be applied across multiple devices while maintaining device-specific security requirements through frame type differentiation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent enables dynamic adjustment of security parameters based on frame type and communication context. Security mode, integrity level, and encryption settings can be changed per frame type without requiring separate device configurations, thus meeting diverse security requirements while simplifying overall system management.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If security parameters are set in advance for each frame type, then configuration is simplified, but flexibility to adapt to different communication scenarios is reduced

Engineering Contradiction:
Improveparameter configuration easeVSAvoidsecurity parameter flexibility
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent introduces dynamic security parameter adjustment within a structured framework. While baseline parameters are configured for each frame type, the system allows real-time modification of security mode, integrity level, and encryption settings based on communication needs, achieving both ease of initial configuration and operational flexibility.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent creates a universal security configuration framework that works across all frame types and communication scenarios. The same parameter structure (security mode, integrity level, encryption settings) applies universally, but can be instantiated differently for each frame type, providing both consistency and adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If encryption and authentication are applied to all frames, then security is maximized, but bandwidth usage and processing overhead increase

Engineering Contradiction:
Improvesecurity protection levelVSAvoidbandwidth efficiency
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies security measures locally rather than universally. Different frame types receive different security treatments based on their specific requirements - management frames may use one security level while data frames use another, and confirmation frames may have different authentication needs. This optimizes bandwidth usage by applying encryption and authentication only where necessary.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial security application rather than full security on all frames. By selectively applying encryption and authentication based on frame type and security parameters, the system achieves adequate security protection without the excessive overhead of universal application, optimizing the balance between security and efficiency.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12407692B2Method and apparatus for providing an adaptable security level in an electronic communication
Publication Date: 2025.09.02 BLACKBERRY LTD
  • US12407692B2 patent drawing
  • US12407692B2 patent drawing
  • US12407692B2 patent drawing

AI summary

A method of communicating in a secure communication system, comprises the steps of assembling a message at a sender, then determining a frame type, and including an indication of the frame type in a header of the message. The message is then sent to a recipient and the frame type used to perform a policy check.