Security Participant Decrypts Cloud Conferencing Packets

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud conferencing systems lack centralized security for data channels, as the media distribution device cannot decrypt and inspect payload data due to lack of end-to-end keys, compromising security and inability to provide functions like virus scans.

Innovation Solution

Introducing a security participant network device that decrypts and applies security policies to packets before they are distributed, ensuring secure data transmission by receiving end-to-end encryption keys and interacting with the key management device to provide centralized security within the network environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data channels are encrypted for privacy enhancement, then security and privacy are improved, but the ability to inspect and control malicious content is lost

Engineering Contradiction:
Improvedata securityVSAvoidunability to detect malicious content
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The security participant performs decryption and security policy application in advance before media distribution. The encrypted media is first decrypted by the security participant using end-to-end keys, then security policies are applied to the decrypted content, and only after security verification does the media get distributed to other participants. This preliminary security check prevents malicious content from being propagated while maintaining encrypted transmission.

Inventive Principle:
Principle #10Preliminary action

2Object-generated harmful factors

If centralized security inspection is implemented, then ability to block malicious files is improved, but system complexity increases due to additional security participant device

Engineering Contradiction:
Improvemalicious content blockingVSAvoidsystem architecture
Core Design Contradiction:
Object-generated harmful factorsVSDevice complexity

Solution Approach 1:

The security participant device performs multiple functions: it acts as a regular media participant, decrypts encrypted media using end-to-end keys, applies security policies to the decrypted content, and controls media distribution. By consolidating these diverse functions into a single multi-functional component, the system achieves centralized security inspection without proportionally increasing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The security participant serves as an intermediary between the encrypted media stream and the media distribution network. It receives encrypted media, decrypts it using end-to-end keys, applies security policies, and then distributes the verified media to other participants. This intermediary role enables centralized security control while maintaining the existing end-to-end encryption architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-generated harmful factors

If security participant decrypts media using end-to-end keys, then security policy application is improved, but risk of key compromise and security breach increases

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidkey exposure risk
Core Design Contradiction:
Object-generated harmful factorsVSObject-affected harmful factors

Solution Approach 1:

The security participant applies security policies to the decrypted media content before distributing it to other participants. This preliminary security verification acts as a countermeasure against malicious content, ensuring that any potential threats are detected and blocked before they can affect other participants in the conference.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS10230694B2Content inspection in privacy enhanced cloud conferencing
Publication Date: 2019.03.12 CISCO TECHNOLOGY INC
  • US10230694B2 patent drawing
  • US10230694B2 patent drawing
  • US10230694B2 patent drawing

AI summary

A media distribution network device connects to an online collaborative session between a first participant network device, a second participant network device, and a security participant network device. The security participant network device is configured to decrypt packets of the online collaborative session to apply security polices to the packets. An encrypted packet is received at the media distribution network device. The encrypted packet is received from the first participant network device containing data to be distributed as part of the online collaborative session. The encrypted packet is distributed to the security participant network device prior to distributing the encrypted packet to the second participant network device.