Secure Communication During Network Transitions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

When a mobile device transitions from one network to another, existing secure communication systems often require re-establishment of cryptography keys, disrupting the secure data transmission and being non-transparent to the user, which can lead to interruptions in secure communication.

Innovation Solution

A method that maintains secure communication by processing signaling information from the mobile device, using a unique identifier to authenticate and associate a unique key for decryption, allowing seamless transition between networks without re-establishing cryptography keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If new cryptography keys are established when transitioning networks, then security is maintained, but communication continuity is disrupted and user experience deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication continuity
Core Design Contradiction:
ReliabilityVSDuration of action of moving object

Solution Approach 1:

The system performs preliminary actions by establishing and storing the unique identifier and unique key association at the endpoint before network transition occurs. When the mobile device transitions to a new network, the pre-established unique key enables immediate secure communication without requiring key renegotiation, thus maintaining communication continuity while preserving security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The unique identifier acts as an intermediary element that bridges the mobile device and endpoint across different networks. Instead of establishing new cryptographic keys during transition, the system uses the pre-shared unique identifier to retrieve and reuse the existing unique key association at the endpoint, enabling seamless network transition while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptography keys are re-established during network transition, then security is ensured, but transition transparency is lost and user awareness is triggered

Engineering Contradiction:
ImprovesecurityVSAvoidtransition transparency
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The endpoint performs self-service by automatically retrieving the unique key association using the unique identifier from the incoming signaling information. This self-service mechanism eliminates the need for manual key exchange or user intervention during network transition, making the process transparent to the user while maintaining security through automated key retrieval and verification.

Inventive Principle:
Principle #25Self-service

3Duration of action of moving object

If secure communication is maintained without key renegotiation, then communication continuity is preserved, but the complexity of key management increases

Engineering Contradiction:
Improvecommunication continuityVSAvoidkey management complexity
Core Design Contradiction:
Duration of action of moving objectVSDevice complexity

Solution Approach 1:

The system extracts the essential authentication element (unique identifier) from the complex key management process. By separating the identifier function from the cryptographic key function, the system enables simple identifier-based key retrieval at the endpoint, reducing key management complexity while maintaining communication continuity across network transitions.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8477941B1Maintaining secure communication while transitioning networks
Publication Date: 2013.07.02 T MOBILE INNOVATIONS LLC
  • US8477941B1 patent drawing
  • US8477941B1 patent drawing
  • US8477941B1 patent drawing

AI summary

A method and medium are provided for maintaining a secure communication of a media stream as a mobile device transitions from a first network a second network. A request is received from the mobile device to initiate a secure communication with an end point. The endpoint stores a unique identifier of the mobile device and a unique key that is usable to decrypt any securely communicated data received from the mobile device. Data is securely communicated from the mobile device to the end point. The mobile device communicates a second request to securely communicate as it transitions from the first network to the second network. A source identifier is determined from the second request to identify the mobile device as the source. The unique key, previously associated with the mobile device, is utilized to decrypt any data received from the mobile device.