Communication Device Security Policy Automation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication devices using IPsec struggle with setting detailed security policies, especially for unskilled users when connecting to new networks, as they require manual configuration of encryption methods and keys for each device, which can be complex and prone to errors.
Innovation Solution
A communication system with a first and second communication device, where the first device stores a first security policy for specific communication targets and a second security policy for all other communications, allowing automatic encryption and decryption processes based on stored keys, eliminating the need for users to set policies for each connection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If detailed security policies are manually configured for each communication device, then communication security is improved, but ease of operation deteriorates
Solution Approach 1:
The system performs preliminary actions by automatically generating security policies and configuring encryption keys before communication begins. The communication device autonomously creates security policies for other devices in the network, eliminating the need for manual pre-configuration by users.
Solution Approach 2:
The communication device serves itself by automatically generating and managing security policies without external intervention. The device independently configures encryption methods and keys for communicating with other devices, making the system self-sufficient in security management.
2Reliability
If security policies are configured for every communication target, then encryption security is improved, but device complexity increases
Solution Approach 1:
The system implements a universal security policy generation mechanism that can automatically create appropriate security policies for any communication target in the network. The same device autonomously handles security configuration for multiple different communication partners using a unified approach.
Solution Approach 2:
The communication device acts as an intermediary that automatically mediates security policy creation between communication parties. Instead of requiring direct manual configuration between each pair of devices, the system autonomously establishes security policies as an intermediate step in the communication setup.
3Reliability
If manual security policy setting is required for new network connections, then security control is improved, but loss of time increases
Solution Approach 1:
The system performs preliminary security policy generation and encryption key configuration automatically before communication begins. This preliminary automated action eliminates the time-consuming manual setup process while ensuring security controls are in place from the start of communication.
Solution Approach 2:
The communication device autonomously handles the entire security setup process including policy generation and key configuration without requiring user intervention. This self-service capability dramatically reduces the time needed to establish secure communication while maintaining proper security controls.
Data Source
AI summary
A first communication device includes a security policy storing unit that store a security policy and a default policy applied to communication to which the security policy is not applied, a communication unit that performs communication, and a communication control unit that performs an encryption process and a decryption process according to the default policy when the communication does not correspond to the target of the policy. A second communication device includes an input and output receiving processing unit that receives an input of an encryption key of the default policy of the first communication device, a communication control unit that generates a policy including an encryption method of the default policy and the input encryption key and performs an encryption process and a decryption process in communication with the first communication device according to the policy, and a communication unit that performs communication of a communication packet.


