Key Distribution to Routers via Path Handshake

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication protocols face challenges in balancing security and quality of service (QoS) in data transmission over networks, particularly due to the limitations of IPsec protocols which hinder QoS requirements and make it difficult to prevent Man-in-The-Middle attacks and spam filtering.

Innovation Solution

A method and system that perform a 'path handshake' to securely distribute keys along a specific network path, allowing only nodes on that path to receive the key, thereby enabling high QoS without additional higher-layer security protocols and ensuring authenticity and position verification of nodes through hashing and token verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IPsec protocol is used to encrypt data for security, then security and confidentiality are improved, but QoS requirements cannot be met and router processing capability deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidQoS
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the encryption approach by introducing a hybrid scheme: IPsec encrypts only the header portion of packets (providing security and enabling router processing), while the payload remains unencrypted or uses application-layer encryption. This segmentation allows different parts of the data to be treated differently, resolving the contradiction between full encryption and QoS requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by providing security at the network layer through IPsec header encryption while maintaining QoS capabilities at the same layer. Routers can process and prioritize traffic based on unencrypted or selectively encrypted headers, while end-to-end security is maintained for sensitive payload data through application-layer protocols.

Inventive Principle:
Principle #3Local quality

2Reliability

If IPsec protocol is used to encrypt data, then security is improved, but ability to perform transcoding and traffic analysis deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidtranscoding capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the data into header and payload portions, applying different encryption treatments. The header is encrypted with IPsec to maintain security, while the payload can be selectively decrypted at intermediate nodes for transcoding operations, then re-encrypted before forwarding. This enables adaptive processing while maintaining overall security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces trusted intermediate nodes or application-layer proxies that act as intermediaries. These intermediaries can receive encrypted packets, selectively decrypt the payload portion using their credentials, perform transcoding or content analysis, then re-encrypt and forward the modified data. This mediator approach maintains security while enabling necessary processing.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If full encryption is applied to prevent unauthorized access, then security is improved, but ability to filter unwanted traffic deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidtraffic filtering capability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments encryption scope to apply IPsec primarily to headers containing routing and control information, while leaving payload data either unencrypted or encrypted with application-layer protocols. This segmentation allows routers and firewalls to inspect header information for traffic filtering, spam detection, and policy enforcement while still providing security for the actual data content.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the encryption parameter scope from full-packet encryption to selective header encryption. By adjusting the encryption coverage parameter, the system maintains security for control information while preserving the ability to filter and analyze traffic based on header contents, enabling effective spam filtering and traffic management.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP2329621B1Key distribution to a set of routers
Publication Date: 2020.09.23 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP2329621B1 patent drawingFigure 1~2
  • EP2329621B1 patent drawingFigure 3~4
  • EP2329621B1 patent drawingFigure 5a~5c

AI summary

Before actually communicating information/data between two endpoints (C, S) connected to a network a secure and confidential distribution of a special key (K h) is performed to nodes (R j) along a path in the network. This is allowed by performing a path handshaking procedure in which first a hint token is forwarded along the path in a first direction and then a disclosure token is forwarded in the opposite direction. In forwarding the disclosure token it is verified in the nodes against the already received hint token. This assures that only nodes onthe particular path will receive the special key or possibly some other information related thereto.