Selective Message Encryption in Distributed Collaborative Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional communication systems are limited in providing flexible and dynamic security for data exchange in distributed networks, as they often require all data to be encrypted or none, and do not allow for granular control over message protection based on the sensitivity of data and trustworthiness of network links, leading to overprotection and inefficiencies.

Innovation Solution

A distributed communication system that enables selective encryption of messages based on endpoint membership, message properties, and network link trustworthiness, allowing encryption to be applied only when necessary, and allowing messages to be flagged as sensitive for later encryption at network nodes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all data is encrypted in conventional communication systems, then security is improved, but processing overhead and message size increase

Engineering Contradiction:
Improvedata securityVSAvoidcommunication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies encryption selectively rather than uniformly to all data. Each message is evaluated individually based on its sensitivity and the trustworthiness of the network link, applying encryption only where necessary. This local quality approach resolves the contradiction by maintaining security for sensitive messages while avoiding the overhead of encrypting all messages.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system performs partial encryption action by encrypting only the portion of data that requires protection. Instead of applying encryption excessively to all messages, the system applies it partially based on message sensitivity assessment and link trust evaluation, thereby maintaining security where needed while improving overall communication efficiency.

Inventive Principle:
Principle #16Partial or excessive action

2Reliability

If security provisions are made for complete end-to-end paths in conventional systems, then security coverage is improved, but configuration complexity and performance degradation increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidsecurity configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the end-to-end communication path into individual message-level decisions. Instead of configuring security for the complete path as a single unit, the system evaluates and applies security provisions to each message independently as it traverses the network. This segmentation reduces configuration complexity while maintaining comprehensive security coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security configuration becomes dynamic rather than static. The system continuously evaluates message sensitivity and link trustworthiness in real-time, adjusting encryption decisions dynamically for each message based on current conditions. This dynamic approach simplifies configuration management while ensuring appropriate security coverage.

Inventive Principle:
Principle #15Dynamics

3Stability of the object's composition

If conventional systems use the least secure link assessment for all messages, then security consistency is improved, but security efficiency deteriorates due to overprotection

Engineering Contradiction:
Improvesecurity policy consistencyVSAvoidbandwidth utilization
Core Design Contradiction:
Stability of the object's compositionVSProductivity

Solution Approach 1:

The patent applies different security treatments to different messages based on their individual characteristics. Instead of uniformly applying the least secure link assessment to all messages, the system evaluates each message's sensitivity and applies encryption selectively. This local quality approach maintains security consistency for sensitive messages while improving bandwidth utilization by avoiding unnecessary encryption of non-sensitive data.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes the security parameter (encryption state) based on message-specific attributes rather than using a fixed parameter for all messages. By evaluating message sensitivity and link trustworthiness, the system dynamically adjusts the encryption parameter, resolving the contradiction between security consistency and bandwidth efficiency.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS7636841B2Systems and methods for secure data exchange in a distributed collaborative application
Publication Date: 2009.12.22 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US7636841B2 patent drawing
  • US7636841B2 patent drawing
  • US7636841B2 patent drawing

AI summary

A collaborative communication system that includes a plurality of endpoints and interconnecting nodes configured to communicate via messages over interconnecting channels. Each of the plurality of endpoints and/or interconnecting nodes can determine whether to apply protection to the messages on a per message basis and/or base on the interconnecting channel being used. Thus, a balance between adequate protection and use of system resources and bandwidth can be maintained.