Dynamic Cryptography Engine for Small Cell Security Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Small cell networks face challenges in dynamically updating security attributes, such as encryption algorithms, due to the use of fixed, pre-shared keys, which can lead to compromised data security when existing methods become outdated or compromised, and inability to adjust security levels based on customer needs.

Innovation Solution

Incorporating a cryptography engine embedded in a secure element within the small cell, coupled with a cryptography multi-access edge compute (MEC) engine and trusted security manager (TSM) nodes, allowing for dynamic reconfiguration of security attributes without increasing vulnerability, enabling the use of new security methods and adjusting security levels as needed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If fixed, pre-shared keys are used for security, then initial security is established, but the system cannot dynamically update security attributes when methods become outdated or compromised

Engineering Contradiction:
Improveability to dynamically update security attributesVSAvoiddata security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements dynamic cryptography by enabling small cells to transition from static, pre-shared keys to dynamic security attributes. The system allows real-time updates of encryption algorithms and keys through secure communication channels between the small cell, TSM nodes, and cryptography MEC engines, ensuring security attributes can adapt when vulnerabilities are discovered or new cryptographic methods are developed.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces intermediary components including TSM (Trusted Security Manager) nodes and cryptography MEC (Multi-access Edge Compute) engines that mediate between the small cell and the network. These intermediaries enable secure distribution and updating of cryptographic attributes without requiring direct modification of the small cell's core security infrastructure, thus maintaining reliability while enabling adaptability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If high-level encryption is always used, then data security is maximized, but resource utilization increases

Engineering Contradiction:
Improvedata securityVSAvoidresource utilization
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent enables dynamic adjustment of security levels by allowing the small cell to receive and implement updated security attributes that can vary in computational intensity. The system can transition between different encryption algorithms and key lengths based on current security requirements and resource availability, optimizing the balance between security and resource consumption rather than maintaining constant high-level encryption.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements parameter changes in security attributes including encryption algorithm selection, key length, and security protocol versions. The small cell can dynamically adjust these cryptographic parameters based on received updates from TSM nodes and cryptography MEC engines, allowing optimization of resource utilization while maintaining adequate security levels for different operational contexts.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11805408B2Systems and methods for dynamic cryptography for small cells
Publication Date: 2023.10.31 VERIZON PATENT & LICENSING INC
  • US11805408B2 patent drawing
  • US11805408B2 patent drawing
  • US11805408B2 patent drawing

AI summary

A device within a small cell may establish a first secure communication channel between the device and a network device based on a first type of encryption. The device within the small cell may transmit data between the small cell and a core network via the first secure communication channel. The device within the small cell may receive information associated with a second type of encryption, wherein the second type of encryption is different from the first type of encryption. The device within the small cell may terminate the first secure communication channel. The device within the small cell may establish a second secure communication channel between the device and the network device based on the information associated with the second type of encryption. The device within the small cell may transmit further data between the small cell and the core network via the second secure communication channel.