Integrated Encryption Transport Device Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network encryption systems are inefficient and costly due to the separation of ownership and management of encryption and transport functionalities between customers and service providers, limiting flexibility and inter-accessibility, which restricts effective network security and management.
Innovation Solution
A method and system that integrates encryption and transport functionalities into a single device, allowing customers and service providers to share access to hardware resources, with restricted access controls and user authentication, enabling flexible ownership and management while maintaining security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption and transport functionalities are separated and owned by different parties (customer and service provider), then security control and service management are maintained separately, but infrastructure cost and system complexity increase significantly
Solution Approach 1:
The patent combines encryption functionality and transport functionality into a single integrated network device. The encryption unit and transport unit share common hardware resources including processor, memory, and communication interfaces, eliminating the need for separate customer-owned encryption devices and provider-owned transport devices. This integration maintains security control while reducing infrastructure complexity and cost.
Solution Approach 2:
The integrated network device performs multiple functions within a single system: encryption, decryption, data transport, and protocol handling. The device can operate in different modes (encrypted transport, unencrypted transport) and serve both customer security requirements and provider service management needs, replacing multiple specialized devices with one multi-functional unit.
2Reliability
If customer-owned encryption devices are used, then customer security requirements are met, but service provider access to transport functions is restricted
Solution Approach 1:
The integrated device segments access rights by functional unit rather than by ownership. The encryption unit maintains customer security control while the transport unit allows service provider access. The processor and memory can execute different instruction sets for different users, providing tailored access levels: customers access encryption functions, providers access transport functions, and both can interact through defined interfaces.
Solution Approach 2:
The integrated device acts as an intermediary between customer security requirements and service provider transport needs. The encryption unit processes data according to customer security policies while the transport unit handles data movement according to service provider routing and delivery requirements. The unified system mediates between these two sets of requirements without requiring separate devices.
3Ease of operation
If service provider-owned transport devices are used, then service management is simplified, but customer access to encryption functions is restricted
Solution Approach 1:
The system segments access rights by functional unit rather than by ownership. The transport unit provides simplified service management for the service provider while the encryption unit provides secure access for the customer. The processor can execute different instruction sets for different users, allowing customers to access encryption functions and service providers to access transport functions within the same integrated device.
4Adaptability or versatility
If separate infrastructure is acquired and maintained by customer and service provider, then functional requirements are met, but cost and efficiency deteriorate
Solution Approach 1:
The patent merges customer encryption functions and service provider transport functions into a single shared infrastructure. Both parties utilize the same hardware resources (processor, memory, communication interfaces) of the integrated network device, eliminating the need for duplicate infrastructure acquisition and maintenance. This shared approach reduces overall system cost while maintaining all required functional capabilities.
Solution Approach 2:
The integrated device provides universal functionality that serves both customer and service provider requirements. The same hardware platform can operate in encrypted transport mode or unencrypted transport mode, can handle multiple protocols, and can serve multiple customers. This multi-functionality eliminates the need for separate specialized infrastructure for each function or user type.
Data Source
AI summary
A network includes encryption devices at customer sites and transport devices provide transport functionality for encrypted data for transmission across networks. A method of controlling access to a first plurality of functions of the encryption devices and access to a second plurality functions of the transport devices is disclosed. The method involves providing a customer with access to at least some of the first plurality of functions and providing a network service provider with access to at least some of the second plurality of functions. The method also involves providing the network service provider with restricted access to a first subset of the first plurality of functions and/or providing the network service provider with restricted access to a second subset of the second plurality of functions. This allows the customer and the service provider to share access to hardware resources such as the encryption devices and the transport devices.


