End-to-End Session Data Protection in Network Nodes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security architectures implement data security protection in a hop-by-hop manner, leading to potential data leakage and resource wastage due to repeated encryption and decryption processes during data transmission.
Innovation Solution
A method and system for end-to-end data protection, where a first device obtains a security policy and key to protect session data, which is then sent to a second device configured to restore the data using the same key and policy, ensuring continuous security throughout the transmission process without the need for intermediate encryption and decryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data security protection is performed in a hop-by-hop manner between each intermediate node, then security protection coverage is improved, but resource waste occurs due to repeated encryption and decryption
Solution Approach 1:
The patent segments the security protection function by introducing separate security processing units at the terminal devices that handle encryption and decryption independently from the intermediate nodes. This allows end-to-end security while intermediate nodes only perform transparent data forwarding, eliminating repeated encryption/decryption operations and reducing resource waste.
Solution Approach 2:
The patent introduces security context information as an intermediary mechanism that enables terminal devices to establish secure communication directly without requiring intermediate nodes to perform security processing. The security context is transparently forwarded through intermediate nodes, allowing end-to-end protection while maintaining network routing functionality.
2Reliability
If security protection is performed at each intermediate node, then data security is improved, but data leakage risk increases due to multiple decryption points
Solution Approach 1:
The patent extracts the security processing function from intermediate nodes and concentrates it at terminal devices. By removing decryption capabilities from intermediate nodes and keeping only encryption/decryption at endpoints, the system maintains security protection while eliminating multiple decryption points that could lead to data leakage.
Solution Approach 2:
Instead of having intermediate nodes perform security processing (traditional approach), the patent inverts the architecture by having terminal devices perform all security operations. This reversal ensures that data remains encrypted throughout the transmission path and is only decrypted at the destination, fundamentally reducing data leakage risk at intermediate nodes.
3Reliability
If multiple encryption and decryption operations are performed during data transmission, then security protection is improved, but transmission efficiency deteriorates
Solution Approach 1:
The patent merges the security processing operations at the network level by eliminating redundant encryption and decryption at intermediate nodes. The security context information is consolidated and transparently forwarded, allowing terminal devices to perform security operations once rather than multiple times, thereby improving transmission efficiency while maintaining security protection.
Data Source
AI summary
A security implementation method includes obtaining, by a first device, a security policy of a session and at least one key, and sending, by the first device, protected data to a second device, where the protected data is obtained by protecting security of session data of the session using the at least one key based on the security policy of the session, and the second device is configured to restore the protected data using the at least one key based on the security policy to obtain the session data, where when the first device is a terminal device, the second device is an access network node or a user plane node, or when the first device is an access network node or a user plane node, the second device is a terminal device.


