Secure Session Establishment in Half-Duplex Voice Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional push-to-talk (PTT) systems experience delays in call setup due to the computational intensity of asymmetric key exchange (AKE) methods, which is particularly detrimental in bursty dispatch calls that require rapid communication.

Innovation Solution

Implementing a method where wireless devices generate and cache a shared symmetric Traffic Encryption Key (TEK) via asymmetric key exchange for initial secure communications, allowing for expedited secure call setup by reusing cached TEK in subsequent sessions, thus reducing the need for repeated key negotiations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If asymmetric key exchange (AKE) methods are used to establish secure communications in PTT systems, then security is improved, but call setup time increases due to computational intensity

Engineering Contradiction:
ImprovesecurityVSAvoidcall setup time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by establishing and caching the symmetric TEK during the initial AKE process before actual voice communication begins. This cached TEK is then reused for subsequent secure sessions, eliminating the need to perform the full AKE computational process again during call setup, thus reducing call setup time while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the cryptographic parameter approach by transitioning from using AKE for every session to using a cached symmetric TEK for subsequent sessions. This parameter change involves storing the TEK in memory and reusing it, which fundamentally alters the computational requirements from intensive AKE to lightweight symmetric encryption operations

Inventive Principle:
Principle #35Parameter changes

2Reliability

If repeated asymmetric key exchange is performed for each secure communication session, then security is maintained, but device processing resources are consumed excessively

Engineering Contradiction:
ImprovesecurityVSAvoiddevice processing resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies discarding and recovering by discarding the need for repeated AKE computational processes and recovering the symmetric TEK from the initial exchange. The cached TEK is recovered and reused across multiple sessions, eliminating redundant computational effort while preserving security

Inventive Principle:
Principle #34Discarding and recovering

Solution Approach 2:

The patent performs the computationally intensive AKE process as a preliminary action during the first session, then caches the resulting symmetric TEK for reuse. This preliminary action consolidates the computational burden into a single event rather than repeating it for each session, significantly reducing per-session processing resource consumption

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7747021B2Method and apparatus for fast secure session establishment on half-duplex point-to-point voice cellular network channels
Publication Date: 2010.06.29 GOOGLE TECHNOLOGY HOLDINGS LLC
  • US7747021B2 patent drawing
  • US7747021B2 patent drawing
  • US7747021B2 patent drawing

AI summary

Methods and apparatus are provided for secure communication techniques in a communication system. The system can include a first device which communicates with a second device over a channel. A security association can be established during a first session between the devices via an asymmetric key exchange. The security association comprises a Traffic Encryption Key (TEK) and a first state vector. The TEK comprises a shared, secret symmetric key. The security association is stored in each of the devices for use during a second session between the devices to expedite security association establishment during call set-up of the second session. The security association can be associated with the second device in the first device, and with the first device in the second device. An updated state vector can be generated at the first device. A second session can be established between the first device and the second device by using the TEKs from the first session and the updated state vector. The security association can be used to encrypt voice packets being sent from the first device to the second device. The security association and updated state vector can then be used to decrypt the encrypted voice packets received by the second device from the first device.