Hardware Security Device for Multi-Access Host Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing multi-access edge computing networks face challenges in ensuring secure and reliable data exchange due to the deployment of diverse hardware elements, lack of verification for host modules, and inadequate management of encryption levels, leading to difficulties in selecting and deploying secure host modules.

Innovation Solution

A hardware security device is integrated into the network to verify the presence of host modules through challenge-response authentication, determine security levels, and manage encryption, using a system on a chip to ensure secure data processing and key management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a large number of hardware elements are deployed close to end user levels to provide secure data processing, then network security and reliability are improved, but device complexity and deployment difficulty increase

Engineering Contradiction:
Improvenetwork security and reliabilityVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a hardware security device as an intermediary component that mediates between the host module and the security management system. This device verifies the presence and security level of host modules without requiring direct deployment of complex security infrastructure at every end user level, thus improving reliability while managing complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces complex mechanical/deployment-based security verification with a challenge-response authentication mechanism. Instead of physically verifying each hardware element, the system uses cryptographic challenges sent through the network to verify host module security levels, reducing deployment complexity while maintaining security

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If diverse hardware elements from different manufacturers are deployed, then adaptability and versatility are improved, but defining a common security level becomes difficult

Engineering Contradiction:
Improvehardware compatibilityVSAvoidcommon security level
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent creates a universal security verification mechanism that works across different hardware manufacturers and types. The hardware security device uses standardized challenge-response authentication protocols that can verify security levels of host modules regardless of their manufacturer or specific hardware architecture, thus achieving both versatility and common security standards

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent standardizes security verification by changing the verification parameter from hardware-specific physical verification to a unified cryptographic challenge-response mechanism. This allows different hardware elements to be verified using a common security level framework based on cryptographic parameters rather than hardware-specific characteristics

Inventive Principle:
Principle #35Parameter changes

3Device complexity

If existing MEC network architectures are used without additional security verification mechanisms, then device complexity is reduced, but the ability to verify host module presence and security level is lost

Engineering Contradiction:
Improvenetwork architecture simplicityVSAvoidhost module verification capability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements a self-service verification mechanism where the hardware security device actively initiates challenge-response authentication sequences to verify host module presence and security levels. This self-service approach adds verification capability without requiring complex centralized management, as the security device autonomously performs verification tasks

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12363130B2Methods and devices for securing a multiple-access peripheral network
Publication Date: 2025.07.15 ORANGE SA
  • US12363130B2 patent drawing
  • US12363130B2 patent drawing
  • US12363130B2 patent drawing

AI summary

A description is given of a method for securing a multi-access edge computing network, where provision is made for a hardware security device designed to be connected to a host module of the network. The method, implemented by the hardware security device, includes upon reception of a presence request from the host module in the network, verifying whether the presence request comprises data representative of an identifier of the host module, and, if so, sending a presence response to the host module, comprising a signature of the hardware security device.