Gatekeeper Session Key Distribution via Pre-distribution and Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In H.323 communication systems with multiple Gatekeeper (GK) zones, existing methods for distributing session keys in direct-routing mode are inflexible and insecure, leading to increased time delays and poor information security due to session key exposure across multiple GKs.

Innovation Solution

A method and system that allow a caller's and callee's Gatekeepers to select a session key distribution mode based on supported modes, enabling flexible key distribution and improving security by configuring pre-defined rules for selecting the appropriate mode, including DH negotiation or GK-generated keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If session key is distributed across multiple GKs in direct-routing mode, then communication security is improved, but time delay increases due to key distribution overhead

Engineering Contradiction:
Improvecommunication securityVSAvoidtime delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-distributing session keys to GKs before actual communication occurs. During the RAS message exchange phase, GKs along the routing path already possess the session keys, eliminating the need for real-time key distribution during Q.931 message transmission. This pre-positioning of keys resolves the contradiction by securing communication without adding delay during the actual data transfer phase.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies dynamics by making the key distribution timing flexible - keys are distributed during the setup phase when GKs are establishing routing paths, and the system dynamically adapts to different communication scenarios. GKs can cache keys for multiple potential communication sessions, allowing the system to respond efficiently to varying security requirements without fixed time penalties.

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If session key is exposed across multiple GKs for distribution, then key distribution capability is improved, but information security deteriorates due to key exposure

Engineering Contradiction:
Improvekey distribution capabilityVSAvoidinformation security
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the session key into multiple encrypted portions, with each GK receiving only its specific encrypted segment. GKs cannot reconstruct the full session key independently - they must cooperate with other GKs along the path, each contributing their encrypted portion. This segmentation enables key distribution across multiple GKs while preventing any single GK from exposing the complete key, thus resolving the contradiction between distribution capability and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces encrypted key segments as intermediaries between the session key and individual GKs. Rather than distributing the complete session key directly to each GK, the system uses encrypted portions that serve as intermediaries - these segments are useless without the corresponding decryption keys held by other GKs. This intermediary mechanism enables versatile key distribution while maintaining security through cryptographic protection at each stage.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If multiple pre-call appointment mechanisms are employed for shared keys, then authentication reliability is improved, but device complexity increases

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by designing a unified key distribution mechanism that serves multiple functions: it establishes session keys for encryption, enables authentication across GK boundaries, and provides routing information simultaneously. The same encrypted key segment structure used for key distribution also serves as an authentication credential and routing identifier. This multi-functionality reduces system complexity while maintaining authentication reliability across multiple GKs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7983280B2Method and system for distributing session key across gatekeeper zones in a direct-routing mode
Publication Date: 2011.07.19 HUAWEI TECH CO LTD
  • US7983280B2 patent drawing
  • US7983280B2 patent drawing
  • US7983280B2 patent drawing

AI summary

A method for distributing a session key across GateKeeper (GK) zones in a direct-routing mode, including the following steps: a caller's GK and a callee's GK determine a session key distributing mode for a caller and a callee to distribute the session key according to information contained in a received message and pre-configured rules for selecting the session key distribution mode. An embodiment of the present invention also provides a system for distributing a session key across GK zones in a direct-routing mode. The method and the system make it possible for the caller's GK and the callee's GK to select the session key distribution mode, and improves the flexibility of the session key distribution for the GKs.