Secure Voice Communication via Direct Key Negotiation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current secure communication technologies are vulnerable to man-in-the-middle attacks as they rely on third-party servers to negotiate encryption keys, which can be compromised, compromising the security of point-to-point voice communications.

Innovation Solution

The system enables direct key negotiation between client devices using a Diffie-Hellman key exchange protocol and validates the encryption key through a voice channel by converting the key fingerprint into natural language phrases, allowing users to manually verify the key's consistency over the communication channel.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If third-party servers are used to negotiate encryption keys, then key negotiation can be facilitated, but security is compromised due to vulnerability to man-in-the-middle attacks

Engineering Contradiction:
Improvekey negotiationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the key negotiation process from the untrusted third-party server environment and performs it directly between the two communicating clients. This eliminates the server's ability to intercept or manipulate the key exchange, resolving the security vulnerability while maintaining ease of operation through automated direct negotiation.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a fingerprint comparison mechanism as an intermediary verification step. The fingerprint of the negotiation key is transmitted through the server and compared by both clients to ensure authenticity. This intermediary verification layer maintains security even when using third-party servers, as the fingerprint comparison detects any tampering.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If direct key negotiation is performed between client devices, then security is improved, but complexity of the communication protocol increases

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication protocol
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent employs a universal Diffie-Hellman key exchange protocol that can operate in multiple modes: direct client-to-client negotiation for high security, or server-mediated negotiation with fingerprint verification for compatibility. This multi-functional approach allows the system to adapt to different security requirements without increasing baseline complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent performs preliminary fingerprint generation and comparison during the key negotiation phase itself, rather than requiring separate verification steps. The fingerprint is generated as part of the key exchange process and verified automatically, embedding the security check within the existing protocol flow to minimize additional complexity.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If encryption keys are validated through manual voice verification, then key security is enhanced, but communication time increases

Engineering Contradiction:
Improvekey securityVSAvoidcommunication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements partial manual verification by having users verify only the fingerprint representation of the key rather than the entire key itself. This partial verification approach provides sufficient security assurance while significantly reducing the time and effort required compared to verifying complete cryptographic keys.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent creates a simplified copy or representation of the encryption key in the form of a fingerprint that can be easily communicated and verified through voice channels. This fingerprint copy retains the essential security verification function while being much more suitable for human verification than the raw cryptographic key material.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11245530B2System and method for secure communication
Publication Date: 2022.02.08 ALIBABA GROUP HOLDING LTD
  • US11245530B2 patent drawing
  • US11245530B2 patent drawing
  • US11245530B2 patent drawing

AI summary

One embodiment described herein provides a system and method for secure point-to-point communication. During operation, the system establishes a voice communication channel between a local client device and a remote client device and obtains an encryption key negotiated between the local client device and the remote client device. The system can then obtain a voice signal generated by a user associated with the local client device based on the encryption key and performs a key-validation operation by sending the voice signal from the local client device to the remote client device using the voice communication channel. In response to a successful validation of the encryption key, the system establishes a secure point-to-point communication channel between the local and remote client devices using the validated encryption key.