Secure Communications Authentication Key Infrastructure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current secure communication systems face challenges in achieving end-to-end security without becoming a single point of failure or resource-intensive, as they either rely on central units that are vulnerable to network amplification attacks or require significant processing power for encryption and decryption.

Innovation Solution

Implementing a method where an infrastructure device receives authentication keys from a key-management server, authenticates packets without decrypting or encrypting them, and forwards them to destination devices, while the key-management server distributes keys enabling authentication and encryption, but not decryption, thereby reducing the central unit's processing load and avoiding single-point failures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If the central unit functions as a translator to forward packets, then the device complexity is reduced, but the system becomes vulnerable to network amplification attacks and loses reliability

Engineering Contradiction:
Improvecentral unit complexityVSAvoidsecurity against amplification attacks
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent extracts the cryptographic verification function from the central unit by implementing authentication tags directly in the RTP packets at the endpoint devices. This allows the central unit to forward packets without cryptographic processing, reducing its complexity while maintaining security through endpoint-based authentication verification.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces authentication tags as an intermediary mechanism that enables the central unit to forward packets without full cryptographic processing. The authentication tags serve as a lightweight verification layer that prevents amplification attacks while allowing the central unit to operate with reduced complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the central unit functions as a mixer to cryptographically modify packets, then security is improved, but the processing power requirement and device complexity increase significantly

Engineering Contradiction:
Improveend-to-end securityVSAvoidprocessing power
Core Design Contradiction:
ReliabilityVSPower

Solution Approach 1:

The patent extracts the heavy cryptographic processing (encryption and decryption) from the central unit and relocates it to the endpoint devices. The central unit only performs lightweight authentication tag verification, while endpoints handle the computationally intensive encryption/decryption operations, thereby reducing the central unit's processing power requirements while maintaining end-to-end security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the cryptographic processing functions into different components distributed across the network: authentication tag generation and verification at endpoints, and minimal forwarding logic at the central unit. This segmentation allows the central unit to avoid heavy processing while maintaining overall system security.

Inventive Principle:
Principle #1Segmentation

3Reliability

If the central unit decrypts and re-encrypts packets, then security is maintained, but the central unit becomes a single point of failure and attack target

Engineering Contradiction:
ImprovesecurityVSAvoidcentral unit as attack point
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the cryptographic key management and decryption/encryption functions from the central unit, placing them exclusively at the endpoint devices. The central unit only handles packet forwarding with minimal authentication tag verification, eliminating it as a cryptographic attack point and single point of failure while maintaining security through endpoint-based encryption.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8582779B2System and method for secure communications in a communication system
Publication Date: 2013.11.12 MOTOROLA SOLUTIONS INC
  • US8582779B2 patent drawing
  • US8582779B2 patent drawing
  • US8582779B2 patent drawing

AI summary

A system and method for secure communications in a communication system, wherein the system programs a computer to perform the method, which includes: receiving at least one authentication key, without an encryption key, from a key-management server; receiving a packet, which is encrypted, from a source device; authenticating the packet, using the at least one authentication key, without cryptographically altering the packet; and forwarding the authenticated packet to a destination device of the packet.