Secure Packet Communications with Diverse Path Key Stream Transmission

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for secure data transmission do not efficiently manage the transport of decryption information, often requiring pre-provisioning of keys and lacking dynamic security measures across diverse networks.

Innovation Solution

The method involves fragmenting and transmitting ciphertext and decryption key streams over diverse paths across different networks, incorporating intentional delays and mis-aligned sequencing to thwart interception, using various encryption algorithms and keys on a per-traffic-flow basis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If decryption keys are pre-provisioned to destination nodes, then secure communication can be established, but administrative burden increases and security is compromised

Engineering Contradiction:
Improvesecure communication establishmentVSAvoidadministrative burden
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary action by pre-generating keystreams and storing them in a keystream database at the source node before communication occurs. This eliminates the need for pre-provisioning keys at destination nodes, reducing administrative burden while maintaining security through dynamic retrieval during communication.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention extracts the keystream generation and storage function from the destination node and relocates it to the source node. The destination node only receives and uses keystreams, eliminating the security risk and administrative complexity of pre-provisioning keys at multiple destination nodes.

Inventive Principle:
Principle #2Taking out (Extraction)

2Adaptability or versatility

If keys are transmitted over the network, then dynamic security is achieved, but interception risk increases

Engineering Contradiction:
Improvedynamic securityVSAvoidinterception risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system segments the keystream transmission by dividing it into multiple frames distributed across different packets. Each packet contains only a portion of the keystream, making interception of complete keystreams difficult. The keystream is reconstructed at the destination by assembling frames from multiple packets.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The invention adds temporal and spatial dimensions to keystream transmission by distributing keystream frames across multiple time intervals and network paths. This multi-dimensional approach obscures the keystream transmission pattern and reduces interception risk while maintaining dynamic security.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Productivity

If keystreams are transmitted in real-time, then communication efficiency is improved, but security is compromised

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary action by pre-generating and storing keystreams in a database before communication occurs. During communication, keystreams are retrieved from the database and transmitted in real-time, achieving both communication efficiency and security through advance preparation combined with dynamic delivery.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention implements dynamics by allowing the system to adapt between pre-generated keystream retrieval and real-time generation based on communication requirements. The keystream database enables flexible, dynamic keystream provisioning that maintains security while supporting efficient real-time communication.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11310078B2Cipher stream based secure packet communications with key stream transmission over diverse paths
Publication Date: 2022.04.19 ROGERS WESLEY
  • US11310078B2 patent drawing
  • US11310078B2 patent drawing
  • US11310078B2 patent drawing

AI summary

Techniques for sending encrypted data includes establishing a plurality of different links between a first node and a different second node. The different links are different physical layer links or different virtual private network (VPN) links or some combination. The method also includes encrypting plaintext using a first value for an encryption parameter to produce ciphertext. Further, the method includes sending a first plurality of messages that indicate the ciphertext using at least one link of the plurality of different links. Still further, the method includes sending a different second plurality of messages that indicate the first value for the encryption parameter using at least one different link of the plurality of different links without introducing a random bit error.