Bridging System LAN Packet Scramble Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current encryption communication systems between a server and a client via the internet lack robust authentication mechanisms, are vulnerable to device spoofing, and require significant rebuilding of communication devices, especially when using PPP or SSL protocols, and IPSec, which complicates terminal mounting and management across various OS versions.
Innovation Solution
A bridging system with a bridge that performs LAN packet scrambling and encryption key management using a key exchange mechanism, incorporating composite authentication with biometric recognition and a concealment/save mechanism to manage common keys and encrypt application payloads, allowing secure communication without rebuilding applications or relying on specific servers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If PPP tunneling with SIM-based authentication is used for wireless communication security, then authentication capability is provided, but device complexity increases and ease of operation deteriorates due to requiring multiple servers and complex setup
Solution Approach 1:
The patent extracts the authentication function from complex server-based systems and integrates it directly into the wireless communication device itself. The terminal equipment performs authentication operations locally using built-in authentication modules, eliminating the need for external authentication servers and reducing system complexity while maintaining security.
Solution Approach 2:
The terminal equipment is designed to perform self-authentication using built-in credentials and authentication mechanisms. The device autonomously verifies its own identity and establishes secure connections without requiring external authentication infrastructure, thereby simplifying the overall system architecture.
2Ease of operation
If built-in devices like portable telephones are used for authentication, then convenience is provided, but vulnerability to spoofing increases when devices are lost or stolen
Solution Approach 1:
The patent employs a cryptographic protocol layer that acts as a flexible protective shell around the authentication process. This protocol verifies device identity through cryptographic challenges and responses, ensuring that even if the physical device is compromised, the authentication credentials cannot be spoofed without the proper cryptographic keys.
Solution Approach 2:
The authentication mechanism combines multiple security layers including device identifiers, cryptographic keys, and protocol-based verification. This composite approach integrates physical device properties with cryptographic validation, creating a multi-factor authentication system that resists spoofing attacks even when the device is lost or stolen.
3Reliability
If SSL or IPSec is used for security communication, then encryption capability is provided, but application rebuilding is required which increases device complexity
Solution Approach 1:
The patent introduces a protocol translation layer that acts as an intermediary between standard communication protocols and encryption requirements. This mediator transparently applies encryption and authentication to existing communication streams without requiring application-level modifications, thereby maintaining compatibility while providing security.
Solution Approach 2:
The security functionality is segmented into independent protocol layers that can be applied to existing communications without modifying the application layer. Encryption and authentication are implemented as separate, pluggable components that operate at the transport or network layer, allowing applications to remain unchanged while gaining security capabilities.
4Reliability
If terminal drivers are mounted at driver level for security, then end-to-end security is improved, but software development complexity increases due to OS variations
Solution Approach 1:
The patent designs a universal authentication and encryption protocol that functions across multiple operating systems and device types without requiring OS-specific implementations. The protocol is implemented at a higher layer in the protocol stack where it can operate independently of underlying OS differences, providing consistent security functionality across diverse platforms.
Data Source
AI summary
Bridges 30, 40 are interposed between a server 10 or a client 20 having two channels 2ch, one of the two channels making a LAN connection to either the server or the client and the other channel making the LAN connection to the internet. Each of bridges 30, 40 performs a LAN packet scramble, a scramble purpose encryption key management, a scramble purpose encryption key management, and a bridging system authentication. Furthermore, each of bridges 30, 40 performs a LAN packet scramble, a scramble purpose encryption key management, and a bridging system authentication for a packet derived from the server or the client. Furthermore, a composite authentication having a plurality of authentication purpose interfaces is carried out in each of the bridges. Furthermore, a composite authentication having a plurality of authentication purpose interfaces is carried out in each of the bridges. The bridge has a plurality of authentication purpose interfaces to perform a composite authentication. Each of the bridges performs a key management to manage and hold the common key in the authentication and performs a non-decryption file management which manages and holds a file information encrypting and transmitting a payload of an application communicated with a common key at an internal of a transmission side bridge.


