Initialization Vector Generation Using Network Information

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication systems using symmetrical encryption methods, such as AES, face security vulnerabilities due to the potential for identical initialization vectors in high-data-rate transmissions, especially in extensive communication networks with uniform keys, allowing unauthorized inference of unencrypted data.

Innovation Solution

A communication device and method that generates initialization vectors based on network information, combining a random portion with unique network parameters, ensuring each vector is distinct and unambiguously assigned, and transmitting only the unknown parts of the initialization vector to maintain high security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If random initialization vectors are assigned for encryption, then encryption speed and data rate are improved, but security is worsened because identical vectors may occur allowing unauthorized inference

Engineering Contradiction:
Improvedata rateVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent changes the parameters of initialization vectors from purely random to a composite structure including a random portion and a network information portion. This parameter change ensures uniqueness while maintaining generation speed, resolving the contradiction between high data rate and security.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The initialization vector is constructed as a composite of multiple components: a random portion and a network information portion (which may include network identification number, sender address, packet number, block number). This composite structure ensures both uniqueness and security without sacrificing generation speed.

Inventive Principle:
Principle #40Composite materials

2Reliability

If unique initialization vectors are generated based on network information, then security is improved by preventing identical vectors, but device complexity increases due to additional generation requirements

Engineering Contradiction:
ImprovesecurityVSAvoidinitialization vector generation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system uses readily available network information (network identification number, sender address, packet number, block number) that is already present in the communication process to generate the initialization vector. This self-service approach avoids additional complex generation mechanisms while ensuring uniqueness.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The network information portion of the initialization vector serves multiple functions: it ensures uniqueness across the network, provides structural organization, and can be derived from existing communication metadata. This multi-functionality reduces overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2756625B1Encryption based on network information
Publication Date: 2019.10.09 ROHDE & SCHWARZ GMBH & CO KG
  • EP2756625B1 patent drawingFigure 1~2A
  • EP2756625B1 patent drawingFigure 2B~4
  • EP2756625B1 patent drawingFigure 3

AI summary

A communication device according to the invention for communicating in a communication network comprises an encryption unit (6) and an initialization vector generator (100). The encryption unit (6) encrypts outgoing messages at least in part by means of a code and an initialization vector (140), which is created by the initialization vector generator (100). In the process, the initialization vector (140) is thereby produced at least in part on the basis of network information of the communication network.