Trusted Intermediary Server for Secure Packet Network Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current secure communication systems over public networks, such as the Internet, lack adequate security measures to protect data confidentiality and user anonymity, and are often expensive and difficult for widespread adoption due to the need for specialized hardware and complex user configurations.

Innovation Solution

A method and apparatus utilizing a trusted intermediary server to facilitate secure communication over packet-based networks by encrypting data and employing authentication protocols, such as HMAC and RSA, to ensure data integrity and anonymity, while allowing secure communication without requiring users to open private ports or expose their IP addresses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If data is transmitted over public packet-based networks, then communication availability and speed are improved, but security and confidentiality are compromised

Engineering Contradiction:
Improvecommunication speedVSAvoidsecurity risks
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a trusted intermediary server that acts as a mediator between communicating parties. The server establishes separate encrypted connections with each party and facilitates data exchange without exposing either party's direct network identity. This intermediary approach enables secure communication over public networks by adding a layer of trust and protection against eavesdropping and identity exposure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates virtual copies of communication channels through the intermediary server. Instead of direct peer-to-peer connections, the server establishes separate connection copies - one with each party - allowing data to be transmitted through the public network while maintaining security. The server copies and forwards encrypted data packets between parties without revealing their actual network addresses to each other.

Inventive Principle:
Principle #26Copying

2Object-affected harmful factors

If traditional encryption mechanisms are implemented, then data confidentiality is improved, but ease of operation deteriorates due to complex configurations

Engineering Contradiction:
Improvedata confidentialityVSAvoiduser configuration complexity
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The trusted intermediary server automatically performs encryption key management, connection establishment, and authentication processes without requiring user intervention. The server self-manages the complex cryptographic operations, including generating and distributing encryption keys, establishing secure channels, and verifying participant identities. Users simply initiate communication through the server interface without needing to understand or configure the underlying security mechanisms.

Inventive Principle:
Principle #25Self-service

3Reliability

If specialized hardware is used for secure communication, then security is improved, but cost and device complexity increase

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidhardware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces specialized cryptographic hardware with software-based security implementations running on standard computers and servers. Instead of requiring dedicated hardware security modules or specialized communication devices, the security functions are implemented through software applications that utilize standard network interfaces and processing capabilities. This substitution maintains security reliability while eliminating the need for complex specialized hardware.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS8850200B1Method and apparatus for secure communications through a trusted intermediary server
Publication Date: 2014.09.30 SYNECTIC DESIGN
  • US8850200B1 patent drawing
  • US8850200B1 patent drawing
  • US8850200B1 patent drawing

AI summary

A method and apparatus for a trusted intermediary server to assist with the secure exchange of data across a communications network, and in particular a packet-based network, such as the public Internet or an intranet. Communications are routed between private ports of the clients through the trusted intermediary server, with the private key transfer supported by a second type of communication medium. Although the trusted intermediary server negotiates the connection and is involved in the process, the communicants can perform their own key agreement and authentication for protecting data routed through the system.