Selective Application Layer Security for Message Integrity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data communication systems lack end-to-end security, particularly when data passes through intermediate nodes, and they inefficiently apply security measures to all communications, leading to high operational costs and performance issues.

Innovation Solution

A system and method for selective end-to-end message level security, utilizing a logic unit with modules for security, messaging, message class definition, security level mapping, encryption, decryption, signature, and verification to apply security features at the application layer, ensuring message integrity and privacy based on message class, and preserving security during storage and transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If SSL is implemented for data communication, then link level security is provided, but end-to-end security is not ensured and data is insecure during storage on intermediate nodes

Engineering Contradiction:
Improveend-to-end securityVSAvoidsecurity implementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security implementation into distinct components: a security module that processes messages, a messaging module that handles communication, and a message class definition module that categorizes messages. This segmentation allows end-to-end security to be achieved without overwhelming complexity by dividing the security function into manageable, independent parts that can be implemented systematically across the communication system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a security module as an intermediary component that operates between the messaging modules of different nodes. This intermediary security module applies security transformations (encryption, signing) to messages before they are transmitted, ensuring end-to-end security while maintaining a clear separation of concerns between security processing and message transmission functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If SSL protects all communications, then security coverage is maximized, but operating cost increases due to processing requirements

Engineering Contradiction:
Improvesecurity coverageVSAvoidprocessing cost
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies local quality by differentiating security treatment based on message characteristics. The message class definition module categorizes messages into different types, and the security module applies appropriate security measures selectively. Not all messages require the same level of security protection, allowing the system to maximize security coverage for critical messages while reducing processing costs for less sensitive communications.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial action by applying security measures only where necessary rather than uniformly to all communications. The security module can be configured to apply encryption and signing only to messages belonging to specific classes that require protection, avoiding the excessive processing cost of securing every message while maintaining adequate security coverage for critical data transmissions.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If S-HTTP is used for application layer security, then message level security is provided, but it is protocol-specific and does not provide true end-to-end security in multi-node systems

Engineering Contradiction:
Improvemessage level securityVSAvoidprotocol compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent achieves universality by designing a security module that operates independently of specific application protocols. The security module processes messages at the application layer but maintains protocol-agnostic functionality, allowing the same security mechanisms to protect various types of messages across different protocols. This multi-functional approach enables end-to-end security without being constrained to a single protocol like S-HTTP.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7644266B2Apparatus, system, and method for message level security
Publication Date: 2010.01.05 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US7644266B2 patent drawing
  • US7644266B2 patent drawing
  • US7644266B2 patent drawing

AI summary

An apparatus, system, and method are disclosed for selective, end-to-end message level security. The apparatus includes a message class definition module, a security module, and a messaging module. The message class definition module identifies a predetermined message class of an internode message. The security module applies security to the message at an application layer. The security that is applied to the message corresponds to a security level, which depends on the message class of the message. The security may include encryption, authentication, and/or other security features. The messaging module communicates the message between a first node and a second node. A third node, such as a broker, may be interposed between the first and second nodes, in which case the security of the message is preserved at the third node.