Secure Capability Negotiation Between Client and Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer-to-computer communication negotiations face challenges in ensuring that clients and servers implement the same security features and communication standards, leading to potential security compromises and data loss when one device reverts to an older standard.

Innovation Solution

Establishing an authenticated session between a client and server through a series of requests and responses, including a negotiate request, setup request, and validation request, which verifies the integrity of communication protocol dialects and security modes using a shared secret to prevent man-in-the-middle attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the client and server revert to an older communication standard to ensure compatibility, then the communication compatibility is improved, but the security level deteriorates

Engineering Contradiction:
Improvecommunication compatibilityVSAvoidsecurity level
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by conducting capability negotiation before the actual data transmission begins. The client and server exchange capability information packets to determine their respective security features and communication standards in advance. This allows them to negotiate and establish the highest common security standard before any sensitive data is transmitted, preventing the need to revert to insecure older standards during operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback through the capability negotiation process where each device sends capability information packets containing details about their security features and supported communication standards. The receiving device uses this feedback information to determine the appropriate negotiation outcome, ensuring both devices operate at the highest mutually supported security level rather than defaulting to older, less secure standards.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If the client and server use different security features or communication standards, then the adaptability is improved, but the data integrity deteriorates

Engineering Contradiction:
Improveprotocol flexibilityVSAvoiddata integrity
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent applies preliminary action by exchanging capability information packets before data transmission to establish mutual understanding of security features and communication standards. This preliminary negotiation ensures that both devices agree on the highest common standard, preventing data integrity issues that would arise from mismatched protocols during actual communication.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses capability information packets as intermediaries to bridge differences between devices with different security features. These negotiation packets act as mediators that convey each device's capabilities and facilitate agreement on a common standard, ensuring data integrity is maintained while allowing protocol flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Speed

If the client and server establish communication without verifying protocol compatibility, then the communication speed is improved, but the security reliability deteriorates

Engineering Contradiction:
Improvecommunication speedVSAvoidsecurity reliability
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent applies preliminary action by conducting capability negotiation in a preliminary phase before actual data transmission begins. The client and server exchange capability information packets to verify protocol compatibility and establish security features in advance. This ensures that when data transmission occurs, both devices are already aligned on the correct protocol standard, maintaining high communication speed while ensuring security reliability.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9246949B2Secure capability negotiation between a client and server
Publication Date: 2016.01.26 MICROSOFT TECHNOLOGY LICENSING LLC
  • US9246949B2 patent drawing
  • US9246949B2 patent drawing
  • US9246949B2 patent drawing

AI summary

Embodiments of the present disclosure provide for establishing an authenticated session between a client computing device and a remote computing device. In certain embodiments, a connection is established between the client computing device and the remote computing device. Once the connection is established, the client computing device sends a number of requests to the client computing device including a negotiate request, a setup request, and a validation request. In response to the requests, the client computing device receives a number of responses from the remote computing device including a negotiate response, setup response and a validation response. Once the responses have been received, a determination is made as to whether information contained in the validation response matches information contained in the negotiate response. If the information matches, an authenticated session is established between the remote computing device and the client computing device.