Communication Device Security Policy Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication devices using IPsec struggle with setting detailed security policies, especially for unskilled users when connecting to new networks, as they require manual configuration of encryption methods and keys for each device, which can be complex and prone to errors.

Innovation Solution

A communication system with a first and second communication device, where the first device stores a first security policy for specific communication targets and a second security policy for all other communications, allowing automatic encryption and decryption processes based on stored keys, eliminating the need for users to set policies for each connection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If detailed security policies are manually configured for each communication device, then communication security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvecommunication securityVSAvoidease of setting security policy
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by automatically generating security policies and configuring encryption keys before communication begins. The communication device autonomously creates security policies for other devices in the network, eliminating the need for manual pre-configuration by users.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The communication device serves itself by automatically generating and managing security policies without external intervention. The device independently configures encryption methods and keys for communicating with other devices, making the system self-sufficient in security management.

Inventive Principle:
Principle #25Self-service

2Reliability

If security policies are configured for every communication target, then encryption security is improved, but device complexity increases

Engineering Contradiction:
Improveencryption securityVSAvoidcomplexity of security policy configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements a universal security policy generation mechanism that can automatically create appropriate security policies for any communication target in the network. The same device autonomously handles security configuration for multiple different communication partners using a unified approach.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The communication device acts as an intermediary that automatically mediates security policy creation between communication parties. Instead of requiring direct manual configuration between each pair of devices, the system autonomously establishes security policies as an intermediate step in the communication setup.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If manual security policy setting is required for new network connections, then security control is improved, but loss of time increases

Engineering Contradiction:
Improvesecurity controlVSAvoidtime to set up communication
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary security policy generation and encryption key configuration automatically before communication begins. This preliminary automated action eliminates the time-consuming manual setup process while ensuring security controls are in place from the start of communication.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The communication device autonomously handles the entire security setup process including policy generation and key configuration without requiring user intervention. This self-service capability dramatically reduces the time needed to establish secure communication while maintaining proper security controls.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8799638B2Communication system, communication device, and communication method with a security policy for communication between devices
Publication Date: 2014.08.05 SEIKO EPSON CORP
  • US8799638B2 patent drawing
  • US8799638B2 patent drawing
  • US8799638B2 patent drawing

AI summary

A first communication device includes a security policy storing unit that store a security policy and a default policy applied to communication to which the security policy is not applied, a communication unit that performs communication, and a communication control unit that performs an encryption process and a decryption process according to the default policy when the communication does not correspond to the target of the policy. A second communication device includes an input and output receiving processing unit that receives an input of an encryption key of the default policy of the first communication device, a communication control unit that generates a policy including an encryption method of the default policy and the input encryption key and performs an encryption process and a decryption process in communication with the first communication device according to the policy, and a communication unit that performs communication of a communication packet.