Inhibition Unit for Secure Handshake Algorithm Selection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing encryption communication protocols, such as SSL/TLS, do not effectively control the use of unsafe hash algorithms during the handshake phase, which can compromise security, especially in high-security environments where continuous use of algorithms beyond their recommended lifespan can lead to information leakage.
Innovation Solution
An information processing apparatus is designed to inhibit the use of sets of algorithms that do not meet predetermined safety conditions, specifically during the handshake phase, by controlling the Cipher Suite used in encryption communication protocols, ensuring only safe hash algorithms are employed, such as SHA2, to prevent the use of weak hash algorithms like SHA1 or MD5.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing encryption communication protocols are used without additional control mechanisms, then ease of operation is maintained, but security is compromised due to use of unsafe hash algorithms during handshake phase
Solution Approach 1:
The inhibition unit performs preliminary action by controlling the selection of Cipher Suites before the handshake phase begins. It pre-configures which algorithm sets are permitted based on safety criteria, preventing unsafe algorithms from being selected during the handshake process. This advance control ensures security requirements are met without requiring complex real-time monitoring during communication.
Solution Approach 2:
The inhibition unit acts as an intermediary between the encryption communication protocol and the algorithm selection process. It mediates by filtering and controlling which Cipher Suites can be used, standing between the protocol requirements and the actual algorithm implementation. This intermediary layer enforces security policies without disrupting the overall communication flow.
2Reliability
If control mechanisms are added to prevent use of unsafe hash algorithms, then security is improved, but ease of operation deteriorates due to additional control requirements
Solution Approach 1:
The inhibition unit implements self-service by automatically controlling algorithm selection based on pre-configured safety criteria. It autonomously determines which Cipher Suites are permitted without requiring manual intervention or complex configuration by operators. The system serves itself by maintaining security policies and enforcing them automatically, reducing operational burden while ensuring security compliance.
3Adaptability or versatility
If all algorithm sets are permitted during handshake phase, then adaptability is improved, but security deteriorates due to potential use of weak hash algorithms
Solution Approach 1:
The inhibition unit applies local quality by differentiating between safe and unsafe algorithm sets. Instead of uniformly permitting or blocking all algorithms, it selectively controls which specific Cipher Suites are allowed based on their security characteristics. This localized control enables adaptability for safe algorithms while blocking unsafe ones, achieving both flexibility and security through differentiated treatment of different algorithm sets.
Data Source
AI summary
An information processing apparatus for performing encryption communication with an external apparatus by an encryption communication protocol has an inhibition unit for inhibiting use of a set of algorithms which do not satisfy a predetermined condition among a plurality of sets of algorithms used in the encryption communication protocol. The set of algorithms whose use if inhibited is a set of algorithms which need to transmit a message with a signature of the information processing apparatus to the external apparatus at the time of handshake performed with the external apparatus prior to the encryption communication.


