End-to-End Session Data Protection in Network Nodes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security architectures implement data security protection in a hop-by-hop manner, leading to potential data leakage and resource wastage due to repeated encryption and decryption processes during data transmission.

Innovation Solution

A method and system for end-to-end data protection, where a first device obtains a security policy and key to protect session data, which is then sent to a second device configured to restore the data using the same key and policy, ensuring continuous security throughout the transmission process without the need for intermediate encryption and decryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data security protection is performed in a hop-by-hop manner between each intermediate node, then security protection coverage is improved, but resource waste occurs due to repeated encryption and decryption

Engineering Contradiction:
Improvesecurity protection coverageVSAvoidresource waste
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent segments the security protection function by introducing separate security processing units at the terminal devices that handle encryption and decryption independently from the intermediate nodes. This allows end-to-end security while intermediate nodes only perform transparent data forwarding, eliminating repeated encryption/decryption operations and reducing resource waste.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces security context information as an intermediary mechanism that enables terminal devices to establish secure communication directly without requiring intermediate nodes to perform security processing. The security context is transparently forwarded through intermediate nodes, allowing end-to-end protection while maintaining network routing functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security protection is performed at each intermediate node, then data security is improved, but data leakage risk increases due to multiple decryption points

Engineering Contradiction:
Improvedata securityVSAvoiddata leakage risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the security processing function from intermediate nodes and concentrates it at terminal devices. By removing decryption capabilities from intermediate nodes and keeping only encryption/decryption at endpoints, the system maintains security protection while eliminating multiple decryption points that could lead to data leakage.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of having intermediate nodes perform security processing (traditional approach), the patent inverts the architecture by having terminal devices perform all security operations. This reversal ensures that data remains encrypted throughout the transmission path and is only decrypted at the destination, fundamentally reducing data leakage risk at intermediate nodes.

Inventive Principle:
Principle #13The other way round (Inversion)

3Reliability

If multiple encryption and decryption operations are performed during data transmission, then security protection is improved, but transmission efficiency deteriorates

Engineering Contradiction:
Improvesecurity protectionVSAvoidtransmission efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges the security processing operations at the network level by eliminating redundant encryption and decryption at intermediate nodes. The security context information is consolidated and transparently forwarded, allowing terminal devices to perform security operations once rather than multiple times, thereby improving transmission efficiency while maintaining security protection.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11695742B2Security implementation method, device, and system
Publication Date: 2023.07.04 HUAWEI TECH CO LTD
  • US11695742B2 patent drawing
  • US11695742B2 patent drawing
  • US11695742B2 patent drawing

AI summary

A security implementation method includes obtaining, by a first device, a security policy of a session and at least one key, and sending, by the first device, protected data to a second device, where the protected data is obtained by protecting security of session data of the session using the at least one key based on the security policy of the session, and the second device is configured to restore the protected data using the at least one key based on the security policy to obtain the session data, where when the first device is a terminal device, the second device is an access network node or a user plane node, or when the first device is an access network node or a user plane node, the second device is a terminal device.