Gatekeeper Session Key Distribution via Pre-distribution and Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In H.323 communication systems with multiple Gatekeeper (GK) zones, existing methods for distributing session keys in direct-routing mode are inflexible and insecure, leading to increased time delays and poor information security due to session key exposure across multiple GKs.
Innovation Solution
A method and system that allow a caller's and callee's Gatekeepers to select a session key distribution mode based on supported modes, enabling flexible key distribution and improving security by configuring pre-defined rules for selecting the appropriate mode, including DH negotiation or GK-generated keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If session key is distributed across multiple GKs in direct-routing mode, then communication security is improved, but time delay increases due to key distribution overhead
Solution Approach 1:
The patent implements preliminary action by pre-distributing session keys to GKs before actual communication occurs. During the RAS message exchange phase, GKs along the routing path already possess the session keys, eliminating the need for real-time key distribution during Q.931 message transmission. This pre-positioning of keys resolves the contradiction by securing communication without adding delay during the actual data transfer phase.
Solution Approach 2:
The patent applies dynamics by making the key distribution timing flexible - keys are distributed during the setup phase when GKs are establishing routing paths, and the system dynamically adapts to different communication scenarios. GKs can cache keys for multiple potential communication sessions, allowing the system to respond efficiently to varying security requirements without fixed time penalties.
2Adaptability or versatility
If session key is exposed across multiple GKs for distribution, then key distribution capability is improved, but information security deteriorates due to key exposure
Solution Approach 1:
The patent segments the session key into multiple encrypted portions, with each GK receiving only its specific encrypted segment. GKs cannot reconstruct the full session key independently - they must cooperate with other GKs along the path, each contributing their encrypted portion. This segmentation enables key distribution across multiple GKs while preventing any single GK from exposing the complete key, thus resolving the contradiction between distribution capability and security.
Solution Approach 2:
The patent introduces encrypted key segments as intermediaries between the session key and individual GKs. Rather than distributing the complete session key directly to each GK, the system uses encrypted portions that serve as intermediaries - these segments are useless without the corresponding decryption keys held by other GKs. This intermediary mechanism enables versatile key distribution while maintaining security through cryptographic protection at each stage.
3Reliability
If multiple pre-call appointment mechanisms are employed for shared keys, then authentication reliability is improved, but device complexity increases
Solution Approach 1:
The patent applies universality by designing a unified key distribution mechanism that serves multiple functions: it establishes session keys for encryption, enables authentication across GK boundaries, and provides routing information simultaneously. The same encrypted key segment structure used for key distribution also serves as an authentication credential and routing identifier. This multi-functionality reduces system complexity while maintaining authentication reliability across multiple GKs.
Data Source
AI summary
A method for distributing a session key across GateKeeper (GK) zones in a direct-routing mode, including the following steps: a caller's GK and a callee's GK determine a session key distributing mode for a caller and a callee to distribute the session key according to information contained in a received message and pre-configured rules for selecting the session key distribution mode. An embodiment of the present invention also provides a system for distributing a session key across GK zones in a direct-routing mode. The method and the system make it possible for the caller's GK and the callee's GK to select the session key distribution mode, and improves the flexibility of the session key distribution for the GKs.


