Communication Security Modules for Adaptive Trustworthiness Policies
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication network security technologies struggle to dynamically adapt to changing user security requirements across different service scenarios, as they rely on network-initiated security policy negotiations that fail to account for user-specific needs.
Innovation Solution
Deploy independent security function modules on communication nodes to enable security policy negotiations based on user-specific trustworthiness requirements and capabilities, allowing for flexible and timely generation of security policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If network side initiates security policy negotiation based on capability lists, then security policy can be generated, but it cannot adapt to changing user security requirements in different service scenarios
Solution Approach 1:
The patent transforms the static security policy generation approach into a dynamic one by enabling users to actively trigger security policy negotiation when their security requirements change. The system continuously adapts security policies based on real-time user needs and service scenarios, rather than relying on fixed capability lists established during initial registration.
Solution Approach 2:
The patent introduces a feedback mechanism where users can actively indicate changes in their security requirements, and the network responds by initiating new security policy negotiations. This closed-loop feedback ensures that security policies remain aligned with current user needs and service contexts.
2Reliability
If user passively uses original security policy, then communication continues without interruption, but security requirement changes are not addressed
Solution Approach 1:
The patent enables users to take active control over their security requirements by allowing them to trigger security policy negotiation independently. Instead of passively accepting network-initiated policies, users can self-initiate the negotiation process when their security needs change, making the system more responsive to user demands.
3Adaptability or versatility
If independent security function modules are deployed on communication nodes, then security policy can be generated based on user-specific requirements, but device complexity increases
Solution Approach 1:
The patent implements a universal security function module that can be deployed on various communication nodes (access nodes, core network nodes, etc.) and performs multiple functions including capability list management, security policy generation, and negotiation coordination. This multi-functional approach avoids the need for separate dedicated modules for each function, thereby limiting the increase in device complexity.
4Ease of manufacture
If security policy negotiation is initiated by network side, then security policy can be generated based on capability lists, but communication delay increases when user security requirements change
Solution Approach 1:
The patent employs preliminary action by having the network side pre-prepare and store capability lists of communication entities before actual security policy negotiation is needed. When a user triggers a security policy negotiation, the network can quickly retrieve relevant capability information and initiate the negotiation process without delay, significantly reducing the response time compared to real-time capability discovery.
Data Source
AI summary
This application provides a communication method. The method includes: A first security module generates a security policy based on a trustworthiness requirement statement of a first node and/or a network global trustworthiness policy of the first node and a trustworthiness requirement statement of a second node and/or the network global trustworthiness policy of the second node, where the first security module is a security module serving the first node, and the second security module is a security module serving the second node; and the first security module sends the security policy to the second security module, where the security policy is used for secure communication between the first node and the second node.


