Interface Identifier for Secured Communication Channel Sessions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in establishing secure communication channels between peer devices when physical ports are shared among applications, as they require separate secure communication channels and appropriate protocol sockets and security policies, which are not efficiently managed.

Innovation Solution

A method and system that involve an upper-level protocol application requesting an interface identifier, determining the association with a protocol socket, and using a security module to establish a secure communication channel based on an additional information set, ensuring proper socket and security policy selection for each application.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If multiple applications share a physical port, then resource utilization is improved, but managing separate secure communication channels and security policies becomes more complex

Engineering Contradiction:
Improveresource utilizationVSAvoidsecurity channel management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary mechanism (interface identifier and association data structure) that mediates between multiple applications sharing a physical port and the security module. This intermediary enables the system to track and manage protocol socket associations for each application without requiring complex manual configuration, thus resolving the contradiction by maintaining resource sharing while simplifying security channel management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the security management process by creating distinct interface identifiers and association records for each application using the shared port. This segmentation allows the security module to handle each application's secure communication channel independently through structured data associations, reducing overall management complexity while enabling multiple applications to share the physical port efficiently.

Inventive Principle:
Principle #1Segmentation

2Reliability

If separate secure communication channels are established for each application, then security reliability is improved, but system complexity increases

Engineering Contradiction:
Improvesecure communication reliabilityVSAvoidprotocol socket selection complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-establishing interface identifiers and creating association data structures that link each interface identifier to its corresponding protocol socket and security policy. This preliminary setup eliminates the need for complex real-time socket selection during secure channel establishment, thereby maintaining high security reliability while reducing system complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security module performs self-service by automatically determining the appropriate protocol socket through the pre-configured association data structure. This self-service mechanism eliminates manual intervention and complex selection logic, allowing the system to establish separate secure communication channels for each application with high reliability while keeping the system manageable.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If interface identifiers and association data structures are used, then protocol socket selection precision is improved, but information processing overhead increases

Engineering Contradiction:
Improveprotocol socket selection precisionVSAvoiddata structure information volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent changes the parameter representation by using compact interface identifiers instead of complex application descriptors. This parameter transformation enables precise protocol socket selection through simple identifier matching, achieving high selection precision while minimizing the information processing overhead associated with managing large volumes of application-specific data.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11223654B2System and method for managing secured communication channel sessions for applications sharing a port
Publication Date: 2022.01.11 EMC IP HLDG CO LLC
  • US11223654B2 patent drawing
  • US11223654B2 patent drawing
  • US11223654B2 patent drawing

AI summary

Embodiments described herein relate to techniques for establishing a secure communication channel. The techniques may include making, by an upper level protocol application, a request for an interface identifier using an interface information set; receiving the interface identifier in response to the request; providing the interface identifier and an additional information set to a security module; making a first determination, by the security module, that a protocol socket is associated with the interface identifier; making a second determination, by the security module and based on the additional information set, that a security policy is configured for establishing the secure communication channel with a remote peer device; and establishing, using the protocol socket and the security policy, the secure communication channel with the remote peer device.