Trusted Device Control Messages via Secure Sessions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Large enterprises face significant challenges in securing inter-device communications, particularly in networks where communications are exposed and vulnerable to breaches, as existing security measures are often inadequate in managing and monitoring a fleet of devices across multiple locations.
Innovation Solution
Implementing a secure protocol for trusted control messages that utilize custom encryption and a Secure Input/Output Module (SIOM) to establish secure sessions between devices, ensuring that event and command data are encrypted and validated, mitigating Man-In-The-Middle attacks and enabling efficient monitoring and management of endpoint devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If standard network communication protocols are used for inter-device communications, then device connectivity and data transmission are enabled, but security vulnerabilities expose the system to breaches and hacking
Solution Approach 1:
The patent introduces a secure communication module as an intermediary component that sits between standard network protocols and the communication interface. This module implements encryption, authentication, and secure session management to protect data transmissions while maintaining compatibility with standard networking infrastructure.
Solution Approach 2:
The system dynamically changes communication parameters such as encryption keys, session tokens, and security protocols based on the communication context. This allows the system to adapt security levels according to the sensitivity of data being transmitted and the trustworthiness of communication partners.
2Reliability
If encryption is implemented to protect data transmissions, then security is improved, but processing overhead and communication latency increase
Solution Approach 1:
The system performs preliminary actions by establishing secure sessions and exchanging cryptographic keys before actual data transmission begins. This allows encryption contexts to be pre-configured and cached, reducing the computational overhead during active communication phases.
Solution Approach 2:
Once a secure session is established, the encryption context remains active and reusable for multiple data transmissions. This continuous secure context eliminates the need to repeatedly perform expensive cryptographic handshakes, maintaining both security and performance during sustained communication.
3Reliability
If secure sessions are established between all devices, then communication security is enhanced, but device complexity and management overhead increase
Solution Approach 1:
The patent segments the security management function into a dedicated secure communication module that operates independently from application logic. This modular approach encapsulates the complexity of session management, authentication, and key handling within a standardized interface that simplifies integration across diverse devices.
Solution Approach 2:
The secure communication module implements a universal protocol that handles multiple security functions (authentication, encryption, session management) through a single standardized interface. This multi-functional approach eliminates the need for device-specific security implementations and simplifies fleet-wide management.
Data Source
AI summary
Two endpoint devices communicate with one another in a secure session using a secure protocol. Trusted control messages are passed upstream from one of the endpoint devices through one or more additional secure sessions to a centralized managing server. Additionally, trusted control messages are passed downstream from the centralized manager server through secure sessions to one or more of the endpoint devices. Each endpoint device is integrated into a terminal device.


