DHCP-Based Remote Node Mode Switching for Secure Telecom Availability
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Secure telecommunications networks face high availability issues due to severe failures of security gateways or certificate handling problems, leading to disruptions in radio services and management access, with existing redundancy and switch-over mechanisms being insufficient to prevent security breaches.
Innovation Solution
A method that switches remote nodes from secure communication tunnels to non-security communication mode using DHCP protocol messages, including a request and response with a one-time password, allowing operator-controlled bypass of security gateways during failures, thereby maintaining radio service without compromising security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If redundancy of security gateways is provided, then availability is improved, but the risk of severe failures of the security gateway cluster remains
Solution Approach 1:
The patent introduces an intermediary mechanism (DHCP-based switch-over procedure with one-time password verification) that enables remote nodes to safely transition between secure and non-secure communication modes. This intermediary control mechanism allows the network to maintain availability during security gateway failures while preserving security through operator-controlled verification, resolving the contradiction between redundancy and failure risk.
2Reliability
If automatic switch back to non-security communication is allowed, then availability is improved, but security is compromised due to man-in-the-middle opportunities
Solution Approach 1:
The patent implements a feedback mechanism where the network operator receives verification requests (one-time passwords) before allowing switch-over to non-secure communication. This feedback loop ensures that automatic failover only occurs with operator authorization, maintaining security while enabling availability. The operator's verification decision directly controls whether the switch-over proceeds, preventing unauthorized security bypasses.
3Reliability
If security gateway failures occur, then radio service is disrupted, but manual site visits are required for restoration
Solution Approach 1:
The patent enables self-service restoration by allowing remote nodes to automatically detect security gateway failures and initiate switch-over to non-secure communication modes without requiring manual site visits. The nodes autonomously perform availability detection, verify credentials through DHCP messages, and execute switch-over procedures independently, eliminating the need for operator presence while maintaining service continuity.
4Object-affected harmful factors
If secure communication tunnels are used for all remote nodes, then security is improved, but availability decreases during gateway failures
Solution Approach 1:
The patent makes the communication mode dynamic by allowing remote nodes to switch between secure and non-secure communication modes based on real-time availability conditions. Instead of being locked into a single mode, the system dynamically adapts its security level according to gateway status, enabling nodes to maintain availability during failures while preserving security during normal operation through operator-controlled mode switching.
Data Source
AI summary
A method for enhancing high availability in a secure telecommunications network includes: switching from a first operational mode to a second operational mode based on an exchange of at least a first message and a second message between at least one specific remote node of the plurality of remote nodes and one or a plurality of further network nodes using Dynamic Host Configuration Protocol (DHCP). The first message includes a request from the at least one specific remote node of the plurality of remote nodes and the second message includes an answer to the first message by a network management node. The second message includes a one-time password.


