Group Management Processor for Secure Patched Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In communication systems like TETRA, patching groups with different security capabilities for encrypted communications is challenging, as existing systems struggle to maintain security while allowing encrypted communications to be shared among terminals with varying encryption capabilities.

Innovation Solution

A communication system with a group management processor that divides patched groups into sub-sets for encrypted, selectable-clear, and clear communications, using a translator to convert encryption forms, ensuring secure communication across terminals with different security levels without degrading encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If groups with different security capabilities are patched together for communication, then communication versatility is improved, but security is degraded because encrypted communications must be downgraded to clear form

Engineering Contradiction:
Improvecommunication versatilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patched group is segmented into multiple subgroups based on security capability levels. Each subgroup maintains its own security characteristics (encrypted or clear), allowing the system to support both secure and non-secure terminals simultaneously without forcing encryption downgrade across the entire group.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary mechanism (the group management processor) that manages different security domains within the patched group. This intermediary enables encrypted communications to be routed appropriately to terminals with matching security capabilities, preventing unauthorized clear transmission of encrypted content.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If encrypted communications are transmitted to terminals with different security capabilities, then communication coverage is improved, but device complexity increases due to multiple encryption management requirements

Engineering Contradiction:
Improvecommunication coverageVSAvoidencryption management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The group management processor is designed with multi-functionality to handle diverse security requirements. It can manage multiple encryption keys, identify terminal security capabilities, route communications appropriately, and maintain subgroup configurations, thereby reducing the overall system complexity despite supporting multiple security levels.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system dynamically changes security parameters (encryption keys, security levels) based on terminal capabilities and communication requirements. The group management processor adjusts encryption parameters automatically, allowing encrypted communications to reach appropriate terminals without manual configuration complexity.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If all terminals in a patched group use clear communications, then ease of operation is improved, but security is compromised

Engineering Contradiction:
Improvecommunication simplicityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Different security qualities are applied locally to different subgroups within the patched group. Terminals with higher security capabilities operate in encrypted subgroups, while terminals with lower capabilities operate in clear subgroups. This local differentiation maintains security where needed while preserving operational simplicity where appropriate.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP2208371B1Secure communication system comprising terminals with different security capability levels
Publication Date: 2011.07.06 MOTOROLA SOLUTIONS INC
  • EP2208371B1 patent drawingFigure 1
  • EP2208371B1 patent drawingFigure 2
  • EP2208371B1 patent drawingFigure 3

AI summary

A communication system (100) including a group management processor (144) operable to divide an enlarged group of user terminals formed by patching of smaller groups into sub-sets of user terminals including: (1) an encrypted sub-set of terminals (103, 113, 123) which are operable to undertake only encrypted communications; and (2) a selectable-clear sub-set of terminals (105, 115, 125) which includes: (i) selectable terminals that are able to undertake clear communications and, when selected, encrypted communications; and (ii) clear terminals that are operable to undertake only clear communications; and a translator (143) operable to translate a communication sent in a first encrypted form from a user terminal (103) of one of the sub-sets into the second encrypted form suitable for decryption by user terminals (105, 115) of the other sub-set. Also described is a method (300) and a processor (144) for use in the system.