Intermediary Communication Device for Secure PAN Media Sessions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current communication systems for personal mobile devices lack secure and efficient methods for establishing and managing encrypted media sessions between endpoints, particularly in wireless communication scenarios where radio signals can be easily intercepted.

Innovation Solution

A communication system that includes a communication device, a local endpoint, and a remote endpoint, where the communication device exchanges media-session control data and relays encrypted media-session payload data between endpoints using cryptographic keys and digital signatures, ensuring secure communication through a Personal Area Network (PAN) link, such as Bluetooth, while minimizing modifications to existing Bluetooth profiles.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic endpoints directly establish media sessions with each other, then communication security is improved, but device complexity and protocol implementation difficulty increase

Engineering Contradiction:
Improvecommunication securityVSAvoidprotocol implementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a communication device as an intermediary that facilitates media session establishment between cryptographic endpoints. The communication device exchanges media-session control data with endpoints, relay's encrypted payload data, and coordinates session setup without endpoints needing direct complex protocol interactions. This mediator approach maintains security while reducing endpoint complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If existing Bluetooth profiles are extensively modified to support secure media sessions, then communication security is improved, but compatibility and ease of operation deteriorate

Engineering Contradiction:
Improvecommunication securityVSAvoidBluetooth profile compatibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies partial modification to Bluetooth profiles by introducing only the necessary media-session control data exchange and encrypted payload relay mechanisms, rather than comprehensively redesigning existing profiles. This selective approach adds security functionality while preserving most existing Bluetooth profile compatibility and operational simplicity.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If cryptographic endpoints use direct encrypted communication, then communication security is improved, but interoperability and adaptability across different devices decrease

Engineering Contradiction:
Improvecommunication securityVSAvoiddevice interoperability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The communication device serves as a universal intermediary that can facilitate secure media sessions between different types of cryptographic endpoints (headsets, telephones, computers, etc.). By centralizing the protocol coordination function in a multi-functional device, the system achieves both security and broad device interoperability without requiring each endpoint type to implement complex direct-communication protocols.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3304850B1Methods and systems for communication-session arrangement on behalf of cryptographic endpoints
Publication Date: 2021.08.04 NAGRAVISION SA
  • EP3304850B1 patent drawingFigure 1
  • EP3304850B1 patent drawingFigure 2
  • EP3304850B1 patent drawingFigure 3

AI summary

In an embodiment, a communication device receives a request to establish a media session with a remote endpoint. In response to receiving the request, the communication device exchanges media-session control data with the remote endpoint on behalf of a local endpoint to establish the requested media session between the local endpoint and the remote endpoint. The communication device is communicatively connected to the local endpoint via a Personal Area Network (PAN) communication link. The communication device relays media-session payload data between the local and remote endpoints. The media-session payload data (i) is associated with the media session and (ii) is encrypted based on at least one payload-data cryptographic key that is not accessible to the communication device.