Adaptive Network Layer Security for M2M Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing machine-to-machine (M2M) communication security architecture in 3GPP networks faces inefficiencies due to different types of security mechanisms being used in various parts of the system and at different levels, leading to unnecessary resource usage and difficulty in leveraging lower-layer security at the application layer.

Innovation Solution

A method is proposed where nodes determine the security status of the communication path at the network layer level, and if secure, application layer security is skipped, reducing unnecessary security measures and optimizing resource usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If application layer security is always established between UE and MTC Server, then security is ensured, but resource usage and energy consumption increase

Engineering Contradiction:
ImprovesecurityVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements dynamic security mechanism where the system adaptively switches between application layer security and network layer security based on real-time security status assessment. The UE and MTC server determine whether the network path is secure and adjust security measures accordingly, making the security system flexible rather than static.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the security parameter state by introducing security status indicators that reflect the actual security condition of the network path. When the network layer provides sufficient security, the system transitions from requiring application layer security to relying on network layer security, effectively changing the security provisioning state.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If application layer security is always established, then data security is improved, but signaling overhead and system complexity increase

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies partial security measures by establishing application layer security only when necessary, rather than always. The system assesses the security status and applies security measures proportionally to the actual risk, avoiding excessive security implementation when network layer security is already sufficient.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent segments the security mechanism into two independent layers: network layer security and application layer security. This segmentation allows the system to selectively activate only the necessary layer based on security requirements, reducing overall system complexity while maintaining security effectiveness.

Inventive Principle:
Principle #1Segmentation

3Reliability

If different security mechanisms are used at different levels, then security coverage is improved, but resource efficiency deteriorates

Engineering Contradiction:
Improvesecurity coverageVSAvoidresource efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges the decision-making process for security mechanism selection into a unified framework. Instead of independently managing multiple security mechanisms, the system combines network layer security assessment with application layer security decisions, allowing efficient selection of the appropriate security level based on overall system state.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9420001B2Securing data communications in a communications network
Publication Date: 2016.08.16 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US9420001B2 patent drawing
  • US9420001B2 patent drawing
  • US9420001B2 patent drawing

AI summary

A method of securing communications between first node attached to first network and second node attached to second network. At the second node, first and second information is received on whether the respective first and second networks have a secure network layer path to the respective first and second nodes or are known to use a secure network layer path to attached nodes. Third information is received on whether the first network has a secure internal network layer path and, where the first and second networks are different, whether the first network has a secure network layer path to the second network or is known to use a secure network layer path to the second network. The information determines whether the entire path between the first node and the second node is secured at the network layer level, and whether to establish application layer security for communications.