Independent Security Modules for Communication Node Maintenance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current communication systems face challenges in deploying and maintaining security functions due to their complexity and the need for individual modifications across multiple network functions, leading to high maintenance costs and difficulty in upgrading security capabilities in response to network vulnerabilities.
Innovation Solution
Implementing an independent security function in communication nodes through a first module that executes security services based on request messages, enabling standardized procedures for security function deployment, modularization, and flexible maintenance, with security parameters processed within the module rather than the communication node.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the security function is set as a function of each communication node, then the security function can be provided for different communication services, but the operation becomes complex and requires heavy workload
Solution Approach 1:
The patent segments the security function from the communication node by introducing a dedicated security function module that operates independently. This module can be deployed separately from communication nodes and provides security services through standardized interfaces, thereby reducing the operational complexity at each node while maintaining security coverage across the network.
Solution Approach 2:
The patent introduces a security function module as an intermediary between communication nodes and security services. This intermediary module handles security operations centrally, allowing communication nodes to simply invoke security services without implementing complex security functions locally, thus reducing node operation complexity.
2Reliability
If the security function is set on each NF, then security services can be provided, but modification on security protocol involves multiple NFs leading to complex deployment and high maintenance costs
Solution Approach 1:
The patent merges the security function into a single centralized module that can serve multiple communication nodes and network functions. This consolidation eliminates the need to modify multiple NFs individually, simplifying deployment and reducing maintenance costs while maintaining comprehensive security service provision.
Solution Approach 2:
The security function module is designed with universal functionality to serve multiple communication nodes and support various security protocols through a single standardized interface. This multi-functionality allows one module to replace multiple node-specific security implementations, thereby simplifying deployment across the network.
3Reliability
If security capabilities are embedded in different network functions, then security services can be provided for each function, but quick upgrade of security capabilities becomes challenging when network vulnerabilities are exploited
Solution Approach 1:
The patent implements a dynamic security function module that can be quickly updated and redeployed without affecting individual communication nodes. The modular design allows security capabilities to be upgraded centrally and propagated dynamically across the network, enabling rapid response to new vulnerabilities while maintaining comprehensive security coverage.
Data Source
AI summary
This application provides a communication method. The method includes: A first module executes a first security service based on a first request message received from a requester, where the first request message is used to request one or more trusted services, the requester includes a first node or a second node, the first module is a module serving the first node, and the second module is a module serving the second node; and the first module sends a first feedback message to the requester, where the first feedback message is used to feed back an execution result of the first security service to the requester.


