Application Layer Secure Session Protocol for Data Integrity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for secure data transmission in network technology lack comprehensive integrity and confidentiality protection, particularly at the application level, and are vulnerable to man-in-the-middle attacks due to the absence of a secure session concept across transport and application levels.

Innovation Solution

A method that combines intermediate components using cryptographic information to establish a secure session protocol, allowing for a single authentication and reducing the number of data connections, while using hybrid cryptographic methods to ensure integrity and confidentiality, and extending the MMS data format to encapsulate cryptographic information for secure data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional authentication methods are used at the application level, then device identity can be verified, but the system remains vulnerable to man-in-the-middle attacks due to lack of session continuity protection

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidman-in-the-middle attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent establishes a secure session concept at the application level before data transmission begins. Authentication is performed preliminarily using cryptographic methods (digital signatures, certificates) to verify device identities, and session continuity is maintained throughout the communication process, preventing attackers from injecting themselves into the communication stream.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces cryptographic session management as an intermediary layer between the application layer and transport layer. This intermediary establishes secure contexts that bind communication sessions to authenticated identities, creating a protective barrier against man-in-the-middle attacks without requiring changes to existing transport security mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple data connections are established for secure communication across intermediate components, then security is improved, but system complexity and authentication overhead increase

Engineering Contradiction:
Improvesecurity protectionVSAvoiddata connection management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple data connections that pass through intermediate components into a single logical secure session at the application level. By establishing one authentication context that spans across multiple transport connections, the system maintains security while reducing the complexity of managing separate authentications for each connection hop.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The secure session concept designed in the patent serves multiple functions simultaneously: it provides authentication, maintains session continuity, protects against man-in-the-middle attacks, and works across heterogeneous networks and intermediate components. This universal approach eliminates the need for separate security mechanisms for each connection type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If transport level security (TLS) is used to protect data connections, then confidentiality is improved, but application level integrity protection and session continuity are not ensured

Engineering Contradiction:
Improveconfidentiality protectionVSAvoidintegrity protection at application level
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments security protection into two distinct layers: transport level confidentiality (handled by TLS) and application level integrity with session continuity (handled by the new secure session concept). This segmentation allows each layer to specialize in its strength without compromising the other, ensuring both confidentiality and integrity throughout the communication process.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds another dimension to security by introducing application-level session management that operates independently of transport layer security. This additional dimension provides integrity protection and session continuity verification that complements the confidentiality protection already provided by TLS at the transport level.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentEP2494759B1Method and device for securely transmitting data
Publication Date: 2019.05.08 SIEMENS AG
  • EP2494759B1 patent drawingFigure 1
  • EP2494759B1 patent drawingFigure 2
  • EP2494759B1 patent drawingFigure 3~5

AI summary

The invention relates to a method and device (1) for securely transmitting data (D). To this end, a session concept is described, which uses cryptographic methods at the application level. While in conventional methods point-to-point connections can only be sufficiently secured at the transport level, according to the technical teaching provided integrity protection and confidentiality protection of data can now also be implemented at the application level. The method and the device (1) for securely transmitting data (D) are used in network technology.