DHCP-Based Remote Node Mode Switching for Secure Telecom Availability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Secure telecommunications networks face high availability issues due to severe failures of security gateways or certificate handling problems, leading to disruptions in radio services and management access, with existing redundancy and switch-over mechanisms being insufficient to prevent security breaches.

Innovation Solution

A method that switches remote nodes from secure communication tunnels to non-security communication mode using DHCP protocol messages, including a request and response with a one-time password, allowing operator-controlled bypass of security gateways during failures, thereby maintaining radio service without compromising security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If redundancy of security gateways is provided, then availability is improved, but the risk of severe failures of the security gateway cluster remains

Engineering Contradiction:
ImproveavailabilityVSAvoidrisk of severe failures
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary mechanism (DHCP-based switch-over procedure with one-time password verification) that enables remote nodes to safely transition between secure and non-secure communication modes. This intermediary control mechanism allows the network to maintain availability during security gateway failures while preserving security through operator-controlled verification, resolving the contradiction between redundancy and failure risk.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If automatic switch back to non-security communication is allowed, then availability is improved, but security is compromised due to man-in-the-middle opportunities

Engineering Contradiction:
ImproveavailabilityVSAvoidsecurity breaches
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements a feedback mechanism where the network operator receives verification requests (one-time passwords) before allowing switch-over to non-secure communication. This feedback loop ensures that automatic failover only occurs with operator authorization, maintaining security while enabling availability. The operator's verification decision directly controls whether the switch-over proceeds, preventing unauthorized security bypasses.

Inventive Principle:
Principle #23Feedback

3Reliability

If security gateway failures occur, then radio service is disrupted, but manual site visits are required for restoration

Engineering Contradiction:
Improveservice continuityVSAvoidmanual intervention requirement
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent enables self-service restoration by allowing remote nodes to automatically detect security gateway failures and initiate switch-over to non-secure communication modes without requiring manual site visits. The nodes autonomously perform availability detection, verify credentials through DHCP messages, and execute switch-over procedures independently, eliminating the need for operator presence while maintaining service continuity.

Inventive Principle:
Principle #25Self-service

4Object-affected harmful factors

If secure communication tunnels are used for all remote nodes, then security is improved, but availability decreases during gateway failures

Engineering Contradiction:
Improvesecurity protectionVSAvoidavailability during failures
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent makes the communication mode dynamic by allowing remote nodes to switch between secure and non-secure communication modes based on real-time availability conditions. Instead of being locked into a single mode, the system dynamically adapts its security level according to gateway status, enabling nodes to maintain availability during failures while preserving security during normal operation through operator-controlled mode switching.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9451457B2Method to enhance high availability in a secure telecommunications network, and telecommunications network comprising a plurality of remote nodes
Publication Date: 2016.09.20 DEUTSCHE TELEKOM AG
  • US9451457B2 patent drawing
  • US9451457B2 patent drawing
  • US9451457B2 patent drawing

AI summary

A method for enhancing high availability in a secure telecommunications network includes: switching from a first operational mode to a second operational mode based on an exchange of at least a first message and a second message between at least one specific remote node of the plurality of remote nodes and one or a plurality of further network nodes using Dynamic Host Configuration Protocol (DHCP). The first message includes a request from the at least one specific remote node of the plurality of remote nodes and the second message includes an answer to the first message by a network management node. The second message includes a one-time password.