Inhibition Unit for Secure Handshake Algorithm Selection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing encryption communication protocols, such as SSL/TLS, do not effectively control the use of unsafe hash algorithms during the handshake phase, which can compromise security, especially in high-security environments where continuous use of algorithms beyond their recommended lifespan can lead to information leakage.

Innovation Solution

An information processing apparatus is designed to inhibit the use of sets of algorithms that do not meet predetermined safety conditions, specifically during the handshake phase, by controlling the Cipher Suite used in encryption communication protocols, ensuring only safe hash algorithms are employed, such as SHA2, to prevent the use of weak hash algorithms like SHA1 or MD5.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing encryption communication protocols are used without additional control mechanisms, then ease of operation is maintained, but security is compromised due to use of unsafe hash algorithms during handshake phase

Engineering Contradiction:
ImprovesecurityVSAvoidcontrol mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The inhibition unit performs preliminary action by controlling the selection of Cipher Suites before the handshake phase begins. It pre-configures which algorithm sets are permitted based on safety criteria, preventing unsafe algorithms from being selected during the handshake process. This advance control ensures security requirements are met without requiring complex real-time monitoring during communication.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The inhibition unit acts as an intermediary between the encryption communication protocol and the algorithm selection process. It mediates by filtering and controlling which Cipher Suites can be used, standing between the protocol requirements and the actual algorithm implementation. This intermediary layer enforces security policies without disrupting the overall communication flow.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If control mechanisms are added to prevent use of unsafe hash algorithms, then security is improved, but ease of operation deteriorates due to additional control requirements

Engineering Contradiction:
ImprovesecurityVSAvoidoperation simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The inhibition unit implements self-service by automatically controlling algorithm selection based on pre-configured safety criteria. It autonomously determines which Cipher Suites are permitted without requiring manual intervention or complex configuration by operators. The system serves itself by maintaining security policies and enforcing them automatically, reducing operational burden while ensuring security compliance.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If all algorithm sets are permitted during handshake phase, then adaptability is improved, but security deteriorates due to potential use of weak hash algorithms

Engineering Contradiction:
Improvealgorithm selection flexibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The inhibition unit applies local quality by differentiating between safe and unsafe algorithm sets. Instead of uniformly permitting or blocking all algorithms, it selectively controls which specific Cipher Suites are allowed based on their security characteristics. This localized control enables adaptability for safe algorithms while blocking unsafe ones, achieving both flexibility and security through differentiated treatment of different algorithm sets.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10230716B2Information processing apparatus and encryption communicating method
Publication Date: 2019.03.12 CANON KK
  • US10230716B2 patent drawing
  • US10230716B2 patent drawing
  • US10230716B2 patent drawing

AI summary

An information processing apparatus for performing encryption communication with an external apparatus by an encryption communication protocol has an inhibition unit for inhibiting use of a set of algorithms which do not satisfy a predetermined condition among a plurality of sets of algorithms used in the encryption communication protocol. The set of algorithms whose use if inhibited is a set of algorithms which need to transmit a message with a signature of the information processing apparatus to the external apparatus at the time of handshake performed with the external apparatus prior to the encryption communication.