Nested VPN Tunnels for Secure Multicast in Wireless Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing layered commercial cryptography solutions are inadequate for securing military communications in wireless cooperative broadcast networks, particularly due to their inability to support multicast communications, which are essential for applications like handheld radios and unmanned aerial vehicles (UAVs).
Innovation Solution
The proposed solution involves encrypting datagrams twice in a wireless cooperative broadcast network, using an inner layer key shared among a subset of devices and an outer layer key shared among a superset of devices, with each key being distinct and established through server-centric or serverless group key management protocols, ensuring secure communication by decrypting the datagrams in reverse order at receiving devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If layered commercial cryptography (COTS VPN components) is used to secure communications, then cost is reduced, but multicast communication capability is lost
Solution Approach 1:
The patent implements nested VPN tunnels where an inner VPN component encrypts data with its own keys, and an outer VPN component further encrypts the already-encrypted data with separate keys. This multi-layered nesting structure enables multicast communication capability while maintaining cost-effectiveness by using commercial off-the-shelf components in a layered configuration.
2Reliability
If traditional Type 1 cryptographic devices are used, then cryptographic security is improved, but per-unit cost increases significantly
Solution Approach 1:
The patent replaces expensive Type 1 cryptographic devices with commercial off-the-shelf VPN components that are significantly cheaper. While individual COTS components have lower security credentials, the layered configuration of multiple independent COTS VPN components achieves comparable overall security at a fraction of the cost, making encryption feasible for small, inexpensive platforms.
Solution Approach 2:
The patent creates a composite security architecture by combining multiple different COTS VPN components from different vendors into a layered system. This composite approach leverages the strengths of each component while achieving overall cryptographic security that rivals traditional Type 1 devices, but at much lower per-unit cost.
3Reliability
If double encryption with nested VPN tunnels is implemented, then security is improved, but device complexity increases
Solution Approach 1:
The patent divides the encryption system into distinct segmented layers: an inner VPN component and an outer VPN component. Each layer operates independently with its own key management and encryption processes. This segmentation allows each component to be configured and managed separately, reducing overall system complexity despite the enhanced security provided by double encryption.
Data Source
AI summary
Cryptographically secure data communications between layered groups of devices in a wireless cooperative broadcast network encrypts datagrams twice prior to transmission by a source device, first using an inner layer key that is shared by a first group of devices, and second using an outer layer key that is shared by a second group of devices; the devices of the first group being members of the second group. Received datagrams are recovered by first decrypting with the outer layer key and second decrypting with the inner layer key.


