End-to-End Voice Encryption Portal

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless voice and data transmissions are vulnerable to eavesdropping and interception, as existing encryption methods only secure the RF link between a digital device and a base station, leaving communications unencrypted beyond the base station, posing a risk for sensitive information.

Innovation Solution

A method and system for end-to-end encryption of voice and data communications using a portal that registers digital devices, provides encryption keys, sets up secure sessions, and re-encrypts messages between devices, employing the Advanced Encryption Standard (AES) and optional header modulation, without requiring new hardware or excessive network resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If end-to-end encryption is implemented for voice and data communications, then security against eavesdropping is improved, but device complexity and software requirements increase

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a portal server as an intermediary that handles key management, session establishment, and coordination between communicating devices. This mediator approach allows end-to-end encryption to be implemented without requiring complex local implementation on each device, as the portal server manages the cryptographic complexity centrally while devices only need to perform simpler encryption/decryption operations with keys provided by the portal.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements automatic session establishment, key exchange, and encryption/decryption processes without requiring user intervention. The portal server automatically manages session keys, establishes secure channels, and handles the cryptographic operations, making the security mechanism transparent to users while maintaining strong encryption protection.

Inventive Principle:
Principle #25Self-service

2Ease of manufacture

If software-based encryption is deployed to existing devices, then ease of manufacture and deployment are improved, but security vulnerability to interception remains

Engineering Contradiction:
Improveease of deploymentVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary key exchange and session establishment through the portal server before actual voice or data transmission begins. Encryption keys are pre-negotiated and distributed by the portal, and secure sessions are established in advance, ensuring that when communication occurs, the encryption is already in place and cannot be easily intercepted or compromised during the transmission process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent employs dynamic parameter changes including varying encryption keys for different sessions, changing cryptographic parameters based on communication requirements, and adapting encryption strength. The system uses different key pairs for different communication sessions and can adjust encryption parameters to balance security requirements with performance constraints.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9674163B1Method for payload encryption of digital voice or data communications
Publication Date: 2017.06.06 SECUREANT
  • US9674163B1 patent drawing
  • US9674163B1 patent drawing
  • US9674163B1 patent drawing

AI summary

A security platform or network for transmitting end-to-end encrypted voice or data communications between at least a first digital device and a second device is disclosed. The network includes a network portal for registering the first digital device and the second device. The portal provides the first digital device and second device with at least first and second keys and receives requests from each device to communicate with each other. The portal searches for and receives authorization from the called device to set up a secure session with the calling device. The portal receives encrypted messages from the devices, decrypts the encrypted messages with the keys provided to the devices, and re-encrypts the received messages. The portal sends the re-encrypted messages to the other device. Accordingly, the devices are capable of securely communicating with each other by encrypting and decrypting the messages sent to and received from the portal. The intent is to provide a commercially feasible approach to protect sensitive information that is not government classified, with potential users including (a) Individuals—for protecting private information and conversations; (b) Companies—for protecting proprietary/sensitive information; and (c) Government—for protecting SBU conversations and information.