Voice Data Security via IPsec Protocol Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Secure voice data transmission between high-security networks through a lower-security transit network is compromised as existing methods fail to adequately process and secure voice data, leading to potential security flaws and uncontrolled data transmission across layers.

Innovation Solution

Implementing an IPsec processing protocol that routes and encodes voice data using a distinct protocol like SVHP, adding a header for encoding and removing it for decoding, ensuring secure transmission through the transit network while maintaining integrity and confidentiality.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If voice data is transmitted without IPsec protocol processing, then transmission efficiency is improved, but security is compromised as data transits in clear form

Engineering Contradiction:
Improvetransmission efficiencyVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces an intermediary security device positioned between the secure network and the transit network. This device acts as a mediator that selectively applies IPsec protocols to different data types: voice data is processed through a dedicated protocol path while other data receives standard IPsec encryption, thus maintaining security without unnecessarily compromising transmission efficiency

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If a single IPsec protocol is used for all data, then device complexity is reduced, but voice data security is compromised due to protocol incompatibility

Engineering Contradiction:
Improveprotocol processing complexityVSAvoidvoice data security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the data processing path into two distinct protocols: a dedicated protocol for voice data that preserves its security characteristics, and standard IPsec protocols for other data types. The security device is divided into multiple processing modules that can independently handle different data types through appropriate protocol selection

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different security processing qualities to different data types based on their specific requirements. Voice data receives specialized protocol handling tailored to its security and transmission needs, while other data receives standard IPsec processing, thus optimizing both security and device complexity management

Inventive Principle:
Principle #3Local quality

3Speed

If voice data is routed through the network layer without protocol encoding, then processing speed is improved, but security control is lost across layers

Engineering Contradiction:
Improveprocessing speedVSAvoidsecurity control
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent implements preliminary action by pre-configuring the security device with multiple protocol processing paths and pre-establishing security policies for different data types. This allows the device to quickly route voice data through the appropriate protocol without requiring complex real-time decisions, thus maintaining both processing speed and security control

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2901652B1Method for securing a voice data transmission channel and related security device
Publication Date: 2017.07.19 THALES SA
  • EP2901652B1 patent drawingFigure 1~2
  • EP2901652B1 patent drawingFigure 3
  • EP2901652B1 patent drawingFigure 4~5

AI summary

The invention relates to a method for securing a channel for data transmission between a starting network (N1) and a destination network (N3) via a transit network (N2) having a lower security level, the data including a first set of data including voice data and a set of second data. When the data is transmitted from the starting network to the transit network, the method comprises the following steps: switching (102) the second set of data to a step of encryption according to at least one IPsec protocol in order to obtain encrypted data, and transmitting (114) the encrypted data to the transit network; and switching (102) the first set of data to a step of encoding according to the IPsec processing protocol in order to obtain encoded data, and transmitting (114) the encoded data to the transit network.