VoIP Security Key Exchange via Segmented Public Key Transmission

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security key exchange methods for VoIP networks require prearranged security keys and involve intermediate parties, making them vulnerable to interception and user authentication challenges.

Innovation Solution

A method where communication devices divide their public keys into two halves and transmit them through different routes, allowing each device to predict and verify the counterpart's public key privately, generating a master key for secure data communication without intermediate party involvement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security keys are prearranged between sender and receiver, then security protection is provided, but key sharing procedures expose personal information to intermediate attackers

Engineering Contradiction:
Improvesecurity protectionVSAvoidexposure to intermediate attackers
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The public key is divided into two separate halves. Each half is transmitted through a different route (signaling route and media route), so that no single intermediate attacker can obtain the complete public key needed to compromise security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a certificate authority that issues certificates containing public key halves. This intermediary enables secure key distribution without requiring direct prearrangement between sender and receiver, eliminating the need for insecure key sharing procedures.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If certificates from public offices are used for banking and payment services, then security is provided, but user authentication becomes complex

Engineering Contradiction:
ImprovesecurityVSAvoiduser authentication
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Users can verify the other party's certificate using the predicted public key generated from the two halves received through different routes. This self-verification mechanism eliminates the need for complex manual authentication procedures while maintaining security.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If public keys are transmitted through a single route, then key exchange is simple, but intermediate attackers can intercept the complete public key

Engineering Contradiction:
Improvekey exchange simplicityVSAvoidinterception by intermediate attackers
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The public key is segmented into two halves transmitted through different routes (signaling route and media route). This segmentation maintains operational simplicity while preventing complete key interception by any single attacker.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a dimensional aspect to key transmission by using two different transmission routes instead of a single path. This multi-dimensional approach ensures that compromising one route does not expose the complete public key.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS8380992B2Device and method for security key exchange and system pertaining to same
Publication Date: 2013.02.19 SAMSUNG ELECTRONICS CO LTD
  • US8380992B2 patent drawing
  • US8380992B2 patent drawing
  • US8380992B2 patent drawing

AI summary

The present invention relates to a device and method that enable a security key to be shared using security key exchange between two terminals, and a system that supports the same. To achieve the above, an in-house generated public key is divided into two, said two public keys that have been divided are delivered to counterpart devices via different pathways, and the two public keys delivered from counterpart devices are used to predict the public key of the counterpart device. In addition, said predicted public key is verified, and said verified public key is used to form a master key. Subsequently, said generated master key is verified, and said master key that has been verified is used to exchange data with the counterpart device.