Communication Security Modules for Adaptive Trustworthiness Policies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication network security technologies struggle to dynamically adapt to changing user security requirements across different service scenarios, as they rely on network-initiated security policy negotiations that fail to account for user-specific needs.

Innovation Solution

Deploy independent security function modules on communication nodes to enable security policy negotiations based on user-specific trustworthiness requirements and capabilities, allowing for flexible and timely generation of security policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network side initiates security policy negotiation based on capability lists, then security policy can be generated, but it cannot adapt to changing user security requirements in different service scenarios

Engineering Contradiction:
Improveadaptability to changing user security requirementsVSAvoidsecurity policy effectiveness
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent transforms the static security policy generation approach into a dynamic one by enabling users to actively trigger security policy negotiation when their security requirements change. The system continuously adapts security policies based on real-time user needs and service scenarios, rather than relying on fixed capability lists established during initial registration.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces a feedback mechanism where users can actively indicate changes in their security requirements, and the network responds by initiating new security policy negotiations. This closed-loop feedback ensures that security policies remain aligned with current user needs and service contexts.

Inventive Principle:
Principle #23Feedback

2Reliability

If user passively uses original security policy, then communication continues without interruption, but security requirement changes are not addressed

Engineering Contradiction:
Improvecommunication continuityVSAvoidresponse to security requirement changes
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent enables users to take active control over their security requirements by allowing them to trigger security policy negotiation independently. Instead of passively accepting network-initiated policies, users can self-initiate the negotiation process when their security needs change, making the system more responsive to user demands.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If independent security function modules are deployed on communication nodes, then security policy can be generated based on user-specific requirements, but device complexity increases

Engineering Contradiction:
Improveuser-specific security policy generationVSAvoidsecurity module deployment
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal security function module that can be deployed on various communication nodes (access nodes, core network nodes, etc.) and performs multiple functions including capability list management, security policy generation, and negotiation coordination. This multi-functional approach avoids the need for separate dedicated modules for each function, thereby limiting the increase in device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Ease of manufacture

If security policy negotiation is initiated by network side, then security policy can be generated based on capability lists, but communication delay increases when user security requirements change

Engineering Contradiction:
Improvesecurity policy generation capabilityVSAvoidresponse time for security policy updates
Core Design Contradiction:
Ease of manufactureVSLoss of time

Solution Approach 1:

The patent employs preliminary action by having the network side pre-prepare and store capability lists of communication entities before actual security policy negotiation is needed. When a user triggers a security policy negotiation, the network can quickly retrieve relevant capability information and initiate the negotiation process without delay, significantly reducing the response time compared to real-time capability discovery.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250274493A1Communication method and apparatus
Publication Date: 2025.08.28 HUAWEI TECH CO LTD
  • US20250274493A1 patent drawing
  • US20250274493A1 patent drawing
  • US20250274493A1 patent drawing

AI summary

This application provides a communication method. The method includes: A first security module generates a security policy based on a trustworthiness requirement statement of a first node and/or a network global trustworthiness policy of the first node and a trustworthiness requirement statement of a second node and/or the network global trustworthiness policy of the second node, where the first security module is a security module serving the first node, and the second security module is a security module serving the second node; and the first security module sends the security policy to the second security module, where the security policy is used for secure communication between the first node and the second node.