Interface Identifier for Secured Communication Channel Sessions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face challenges in establishing secure communication channels between peer devices when physical ports are shared among applications, as they require separate secure communication channels and appropriate protocol sockets and security policies, which are not efficiently managed.
Innovation Solution
A method and system that involve an upper-level protocol application requesting an interface identifier, determining the association with a protocol socket, and using a security module to establish a secure communication channel based on an additional information set, ensuring proper socket and security policy selection for each application.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If multiple applications share a physical port, then resource utilization is improved, but managing separate secure communication channels and security policies becomes more complex
Solution Approach 1:
The patent introduces an intermediary mechanism (interface identifier and association data structure) that mediates between multiple applications sharing a physical port and the security module. This intermediary enables the system to track and manage protocol socket associations for each application without requiring complex manual configuration, thus resolving the contradiction by maintaining resource sharing while simplifying security channel management.
Solution Approach 2:
The patent segments the security management process by creating distinct interface identifiers and association records for each application using the shared port. This segmentation allows the security module to handle each application's secure communication channel independently through structured data associations, reducing overall management complexity while enabling multiple applications to share the physical port efficiently.
2Reliability
If separate secure communication channels are established for each application, then security reliability is improved, but system complexity increases
Solution Approach 1:
The patent applies preliminary action by pre-establishing interface identifiers and creating association data structures that link each interface identifier to its corresponding protocol socket and security policy. This preliminary setup eliminates the need for complex real-time socket selection during secure channel establishment, thereby maintaining high security reliability while reducing system complexity.
Solution Approach 2:
The security module performs self-service by automatically determining the appropriate protocol socket through the pre-configured association data structure. This self-service mechanism eliminates manual intervention and complex selection logic, allowing the system to establish separate secure communication channels for each application with high reliability while keeping the system manageable.
3Measurement precision
If interface identifiers and association data structures are used, then protocol socket selection precision is improved, but information processing overhead increases
Solution Approach 1:
The patent changes the parameter representation by using compact interface identifiers instead of complex application descriptors. This parameter transformation enables precise protocol socket selection through simple identifier matching, achieving high selection precision while minimizing the information processing overhead associated with managing large volumes of application-specific data.
Data Source
AI summary
Embodiments described herein relate to techniques for establishing a secure communication channel. The techniques may include making, by an upper level protocol application, a request for an interface identifier using an interface information set; receiving the interface identifier in response to the request; providing the interface identifier and an additional information set to a security module; making a first determination, by the security module, that a protocol socket is associated with the interface identifier; making a second determination, by the security module and based on the additional information set, that a security policy is configured for establishing the secure communication channel with a remote peer device; and establishing, using the protocol socket and the security policy, the secure communication channel with the remote peer device.


