Secure Connection Interface for Encrypted Data Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for securing data transmissions over unsecured media, such as powerline and WiFi, are complex and vulnerable to interception, especially for users without a technical background, as they require personal computers and insecure key exchange processes.

Innovation Solution

A dedicated secure connection interface is provided for electronic devices to exchange security information, which is then used to encrypt data transmissions over an unsecure medium through a separate data connection interface, preventing interception and enabling secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a personal computer and special software are used to configure devices and generate encryption keys, then security key generation capability is improved, but device complexity and ease of operation deteriorate due to requiring additional hardware and software installation

Engineering Contradiction:
Improvesecurity key generationVSAvoidsetup process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security key generation and exchange functionality from the personal computer environment and embeds it directly into the electronic devices themselves. Each device now contains its own secure key generation capability through dedicated security modules, eliminating the external dependency on PCs and special software while maintaining strong encryption standards.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a dedicated secure connection interface as an intermediary channel specifically for exchanging security information between devices. This separate interface acts as a secure mediator that enables direct peer-to-peer key exchange without requiring personal computers, thereby simplifying the setup process while maintaining security reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If WPS mechanism with button press is used for connection setup, then ease of operation is improved, but security deteriorates because key exchange occurs over unsecure medium allowing man-in-the-middle attacks

Engineering Contradiction:
Improveconnection setupVSAvoidkey exchange security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the communication channels by separating security information exchange from payload data transmission. The dedicated secure connection interface handles only security-related communications (key exchange, authentication), while the regular data interface handles payload transmission. This segmentation ensures that even if the data channel is compromised, the security channel remains protected, preventing man-in-the-middle attacks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The dedicated secure connection interface serves as a secure intermediary channel that mediates all security-critical communications between devices. This separate mediation layer ensures that encryption keys and security credentials are exchanged through a protected pathway independent of the unsecure data transmission medium, thereby maintaining security while preserving ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If the same connection interface is used for both security information exchange and payload data transmission, then device complexity is reduced, but security deteriorates because the interface cannot be dedicated to secure key exchange

Engineering Contradiction:
Improveconnection interfaceVSAvoidencryption security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent applies segmentation by dividing the connection functionality into two distinct interfaces: a dedicated secure connection interface for security information exchange and a regular data connection interface for payload transmission. This physical and functional segmentation ensures that security operations occur on a dedicated channel that cannot be compromised by attacks on the data channel, thereby enhancing encryption security while maintaining manageable device complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by assigning different security characteristics to different connection interfaces. The dedicated secure connection interface is specifically designed and configured for high-security operations with enhanced protection measures, while the data interface handles general-purpose communication. This localized quality enhancement ensures that security-critical functions receive appropriate security treatment without unnecessarily complicating the entire system.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8677127B2Method and apparatus for secure setup of an encrypted connection between two communication devices
Publication Date: 2014.03.18 MAXLINEAR INC
  • US8677127B2 patent drawing
  • US8677127B2 patent drawing
  • US8677127B2 patent drawing

AI summary

An electronic device includes a first connection interface and a second connection interface. The first connection interface is operable to exchange security information with another electronic device for use in encrypting data transmissions with the other electronic device. The first connection interface is inoperable to communicate payload data encrypted using the security information. The second connection interface is different than the first connection interface and operable to securely communicate payload data with the other electronic device over an unsecure medium in accordance with the security information exchanged via the first connection interface.