Independent Security Modules for Communication Node Maintenance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current communication systems face challenges in deploying and maintaining security functions due to their complexity and the need for individual modifications across multiple network functions, leading to high maintenance costs and difficulty in upgrading security capabilities in response to network vulnerabilities.

Innovation Solution

Implementing an independent security function in communication nodes through a first module that executes security services based on request messages, enabling standardized procedures for security function deployment, modularization, and flexible maintenance, with security parameters processed within the module rather than the communication node.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the security function is set as a function of each communication node, then the security function can be provided for different communication services, but the operation becomes complex and requires heavy workload

Engineering Contradiction:
Improvesecurity function provisionVSAvoidoperation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security function from the communication node by introducing a dedicated security function module that operates independently. This module can be deployed separately from communication nodes and provides security services through standardized interfaces, thereby reducing the operational complexity at each node while maintaining security coverage across the network.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a security function module as an intermediary between communication nodes and security services. This intermediary module handles security operations centrally, allowing communication nodes to simply invoke security services without implementing complex security functions locally, thus reducing node operation complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the security function is set on each NF, then security services can be provided, but modification on security protocol involves multiple NFs leading to complex deployment and high maintenance costs

Engineering Contradiction:
Improvesecurity service provisionVSAvoiddeployment ease
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent merges the security function into a single centralized module that can serve multiple communication nodes and network functions. This consolidation eliminates the need to modify multiple NFs individually, simplifying deployment and reducing maintenance costs while maintaining comprehensive security service provision.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security function module is designed with universal functionality to serve multiple communication nodes and support various security protocols through a single standardized interface. This multi-functionality allows one module to replace multiple node-specific security implementations, thereby simplifying deployment across the network.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If security capabilities are embedded in different network functions, then security services can be provided for each function, but quick upgrade of security capabilities becomes challenging when network vulnerabilities are exploited

Engineering Contradiction:
Improvesecurity service coverageVSAvoidsecurity upgrade speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements a dynamic security function module that can be quickly updated and redeployed without affecting individual communication nodes. The modular design allows security capabilities to be upgraded centrally and propagated dynamically across the network, enabling rapid response to new vulnerabilities while maintaining comprehensive security coverage.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20250260724A1Communication method and apparatus
Publication Date: 2025.08.14 HUAWEI TECH CO LTD
  • US20250260724A1 patent drawing
  • US20250260724A1 patent drawing
  • US20250260724A1 patent drawing

AI summary

This application provides a communication method. The method includes: A first module executes a first security service based on a first request message received from a requester, where the first request message is used to request one or more trusted services, the requester includes a first node or a second node, the first module is a module serving the first node, and the second module is a module serving the second node; and the first module sends a first feedback message to the requester, where the first feedback message is used to feed back an execution result of the first security service to the requester.