Security Communication Apparatus Adaptive Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security communication apparatuses can impede efficient communication by performing unnecessary processing and failing to meet throughput demands, particularly in VPN communication and real-time streaming applications, due to redundant encryption and buffering, and require advanced knowledge for network parameter settings.

Innovation Solution

A security communication apparatus with a judging unit to determine if data needs encryption, a receiving unit to process data, and a converting unit to encrypt or decrypt data accordingly, ensuring efficient communication by optimizing processing based on application properties and parameters.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the security communication apparatus performs encryption processing for all communication data, then communication security is ensured, but communication efficiency deteriorates and throughput is reduced

Engineering Contradiction:
Improvecommunication securityVSAvoidcommunication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The security communication apparatus changes the encryption parameter from 'always encrypt' to 'encrypt only when necessary'. The judging unit determines whether encryption is needed based on communication data characteristics and application type, then the converting unit applies encryption only to data that requires it, thereby maintaining security where needed while improving overall communication efficiency

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

Instead of applying encryption to all communication data (excessive action), the system applies encryption only to the necessary portion of data (partial action). The judging unit identifies which data packets require encryption based on their characteristics, and the converting unit processes only those specific packets, avoiding unnecessary encryption overhead

Inventive Principle:
Principle #16Partial or excessive action

2Stability of the object's composition

If the security communication apparatus performs buffering processing, then data transmission stability is improved, but communication delay increases

Engineering Contradiction:
Improvedata transmission stabilityVSAvoidcommunication delay
Core Design Contradiction:
Stability of the object's compositionVSLoss of time

Solution Approach 1:

The system changes the buffering parameter from 'buffer all data' to 'buffer only when necessary'. The judging unit determines whether buffering is needed based on data characteristics and application requirements, then the converting unit applies buffering only to data that benefits from it, thereby maintaining transmission stability where needed while minimizing delay

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

Instead of buffering all communication data (excessive action), the system buffers only the necessary portion (partial action). The judging unit identifies which data packets benefit from buffering based on their characteristics, and the converting unit applies buffering only to those packets, avoiding unnecessary delay

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If the communication apparatus performs encryption at the application level, then data security is enhanced, but redundant encryption occurs with VPN encryption

Engineering Contradiction:
Improvedata securityVSAvoidencryption processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system changes the encryption approach from 'double encryption' to 'single encryption'. The judging unit determines whether the communication data already has encryption protection, and if so, skips the VPN encryption step. This parameter change prevents redundant encryption while maintaining security, reducing processing complexity

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system extracts the encryption function from the security communication apparatus when the application-level encryption is already present. The judging unit detects existing encryption and removes the redundant VPN encryption step, allowing the data to pass through without duplicate encryption processing

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8856915B2Security communication apparatus and security communication method
Publication Date: 2014.10.07 CANON KK
  • US8856915B2 patent drawing
  • US8856915B2 patent drawing
  • US8856915B2 patent drawing

AI summary

A negotiation unit, of a logical network control apparatus connected to a LAN, judges settings of processing to be performed on communication data by a network connection apparatus, from properties of an application to be used in communication, and decides parameters to be used for a VPN connection. The VPN connection is performed using the determined parameters.