Community Gateway Controller for Inter-Enclave Encryption Negotiation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure communities face challenges in establishing electronic communications connections with other secure communities while maintaining high security levels, as they often have isolated and incompatible communication resources, and there is a need for dynamic access to facilitate communication during incidents or events without compromising security.

Innovation Solution

The system employs a community gateway controller with an identification module, secure community database, encryption compatibility module, and graphical user interface to establish secure connections between secure communities, using dual-gated access and media transmission encryption schemes, ensuring that only authorized communications resources can connect and share information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secure communities maintain isolated and enclaved communication resources to preserve high security levels, then security is improved, but communication interoperability between different secure communities deteriorates

Engineering Contradiction:
Improvesecurity levelVSAvoidcommunication interoperability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a trusted intermediary system that acts as a mediator between isolated secure communities. This intermediary establishes and manages secure connections, enabling communication between communities without requiring them to open their boundaries. The intermediary verifies credentials, negotiates encryption schemes, and controls access, thus maintaining security while enabling interoperability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the communication architecture into distinct secure community enclaves that maintain their isolation while being connected through a controlled intermediary layer. Each community remains a separate, secure unit with its own resources and access controls, but can selectively communicate with other segments through the trusted intermediary when needed.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If secure communities establish persistent open access to other communities for communication, then communication capability is improved, but security risk increases

Engineering Contradiction:
Improvecommunication capabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic access control where communication connections between secure communities are not persistent or permanently open, but are established temporarily on-demand and terminated when no longer needed. Access rights and connection states change dynamically based on operational requirements, reducing the window of exposure to security risks while maintaining communication capability when required.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system employs periodic re-evaluation and re-establishment of secure connections rather than maintaining continuous open access. Connections are activated periodically or event-driven when communication is needed, and systematically closed afterward, creating a rhythm of controlled access that balances communication needs with security protection.

Inventive Principle:
Principle #19Periodic action

3Adaptability or versatility

If different secure communities use incompatible communication technologies to maintain their own standards, then community autonomy is improved, but system interoperability deteriorates

Engineering Contradiction:
Improvecommunity autonomyVSAvoidtechnology compatibility
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent utilizes parameter changes, specifically encryption scheme negotiation, as a mechanism to bridge incompatible technologies. The intermediary system dynamically adjusts cryptographic parameters and communication protocols to find compatible configurations between different secure communities, allowing them to maintain their internal technology standards while achieving external interoperability through parameter adaptation.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP2974217B1Enabling ad hoc trusted connections among enclaved communication communities
Publication Date: 2020.06.24 MUTUALINK INC
  • EP2974217B1 patent drawingFigure 1
  • EP2974217B1 patent drawingFigure 2
  • EP2974217B1 patent drawingFigure 3

AI summary

The present invention is directed to systems and methods for establishing an electronic communications connection between two or more secure communities (1010, 1020). A secure community (1010, 1020) includes a collection of communication resources (1013, 1023) having an administrator that maintains control over the secure community (1010, 1020). In an embodiment, a system for establishing an electronic communications connection between two or more secure communities (1010, 1020) includes a community gateway controller (1015, 1025), an identification module, a secure community database configured to store secure community information, and an encryption compatibility module configured to determine a media transmission encryption scheme for a connection between a host secure community (1010) and a second secure community (1020). Upon receipt of a request to establish the connection between secure communities (1010, 1020), the community gateway controller (1015, 1025) determines whether to grant the request based on information stored in the secure community database and assigns a media transmission encryption scheme for the connection based on the determination made by the encryption compatibility module.