Secure Multi-Protocol Communication via Selective Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless communication devices face security issues when protocol translation occurs outside the control of the sender or receiver, especially when firewalls are involved, leading to exposure of email messages and failure to satisfy end-to-end security requirements.

Innovation Solution

A method and system for secure communications across multiple protocols, where an encryption key is received and used to encrypt a portion of the communication, while another portion remains unencrypted, allowing secure transmission and conversion between protocols without decrypting the encrypted portion, ensuring end-to-end security through an access device, intermediate server, and application server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If protocol translation takes place outside the control of sender or receiver, then communication between different protocols is enabled, but security is compromised and end-to-end encryption is broken

Engineering Contradiction:
Improveprotocol compatibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The communication data is segmented into encrypted portions and unencrypted portions. The encrypted portions maintain end-to-end security while the unencrypted portions enable protocol translation at intermediate servers. This segmentation allows both security and protocol compatibility to coexist.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An intermediary server is introduced that handles protocol translation for unencrypted portions while encrypted portions pass through unchanged. This intermediary enables protocol compatibility without compromising the security of encrypted data, as the encryption is maintained throughout the transmission path.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption is applied to entire communication, then end-to-end security is maintained, but protocol conversion capability is lost

Engineering Contradiction:
Improveend-to-end securityVSAvoidprotocol conversion
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The communication is divided into encrypted and unencrypted segments. Encrypted segments maintain security requirements, while unencrypted segments allow protocol conversion at intermediate servers. This selective encryption approach resolves the contradiction between security and protocol flexibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different portions of the communication have different encryption qualities. Some portions are encrypted for security, while other portions remain unencrypted to enable protocol translation. This local differentiation allows both security and protocol conversion capabilities to coexist in the same communication system.

Inventive Principle:
Principle #3Local quality

3Reliability

If firewalls are deployed between connectors and servers, then security requirements are satisfied, but protocol translation control is lost

Engineering Contradiction:
Improvesecurity requirementsVSAvoidprotocol translation control
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The communication stream is segmented into encrypted and unencrypted portions that can traverse firewalls independently. The encrypted portions maintain security through firewalls, while unencrypted portions enable controlled protocol translation, allowing both security and operational control to coexist.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7546460B2Secure communications across multiple protocols
Publication Date: 2009.06.09 ORACLE INT CORP
  • US7546460B2 patent drawing
  • US7546460B2 patent drawing
  • US7546460B2 patent drawing

AI summary

Systems, methods, and devices for secure communications across multiple protocols are disclosed. In one embodiment, the method comprises receiving, at an access device, an encryption key. The access device analyzes the communication to determine a portion of the communication to be encrypted and to determine an additional portion of the communication to remain unencrypted by the first encryption process. The method further comprises encrypting the portion of the communication using the first encryption process and the encryption key, and transmitting the communication from the access device.