Group Management Processor for Secure Patched Communication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In communication systems like TETRA, patching groups with different security capabilities for encrypted communications is challenging, as existing systems struggle to maintain security while allowing encrypted communications to be shared among terminals with varying encryption capabilities.
Innovation Solution
A communication system with a group management processor that divides patched groups into sub-sets for encrypted, selectable-clear, and clear communications, using a translator to convert encryption forms, ensuring secure communication across terminals with different security levels without degrading encryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If groups with different security capabilities are patched together for communication, then communication versatility is improved, but security is degraded because encrypted communications must be downgraded to clear form
Solution Approach 1:
The patched group is segmented into multiple subgroups based on security capability levels. Each subgroup maintains its own security characteristics (encrypted or clear), allowing the system to support both secure and non-secure terminals simultaneously without forcing encryption downgrade across the entire group.
Solution Approach 2:
The system introduces an intermediary mechanism (the group management processor) that manages different security domains within the patched group. This intermediary enables encrypted communications to be routed appropriately to terminals with matching security capabilities, preventing unauthorized clear transmission of encrypted content.
2Adaptability or versatility
If encrypted communications are transmitted to terminals with different security capabilities, then communication coverage is improved, but device complexity increases due to multiple encryption management requirements
Solution Approach 1:
The group management processor is designed with multi-functionality to handle diverse security requirements. It can manage multiple encryption keys, identify terminal security capabilities, route communications appropriately, and maintain subgroup configurations, thereby reducing the overall system complexity despite supporting multiple security levels.
Solution Approach 2:
The system dynamically changes security parameters (encryption keys, security levels) based on terminal capabilities and communication requirements. The group management processor adjusts encryption parameters automatically, allowing encrypted communications to reach appropriate terminals without manual configuration complexity.
3Ease of operation
If all terminals in a patched group use clear communications, then ease of operation is improved, but security is compromised
Solution Approach 1:
Different security qualities are applied locally to different subgroups within the patched group. Terminals with higher security capabilities operate in encrypted subgroups, while terminals with lower capabilities operate in clear subgroups. This local differentiation maintains security where needed while preserving operational simplicity where appropriate.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A communication system (100) including a group management processor (144) operable to divide an enlarged group of user terminals formed by patching of smaller groups into sub-sets of user terminals including: (1) an encrypted sub-set of terminals (103, 113, 123) which are operable to undertake only encrypted communications; and (2) a selectable-clear sub-set of terminals (105, 115, 125) which includes: (i) selectable terminals that are able to undertake clear communications and, when selected, encrypted communications; and (ii) clear terminals that are operable to undertake only clear communications; and a translator (143) operable to translate a communication sent in a first encrypted form from a user terminal (103) of one of the sub-sets into the second encrypted form suitable for decryption by user terminals (105, 115) of the other sub-set. Also described is a method (300) and a processor (144) for use in the system.