Intermediary Device Service Optimization via Key Negotiation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Intermediary devices in communication networks cannot provide service optimization for user equipment and network servers due to their inability to decrypt ciphertext.

Innovation Solution

A service processing method and apparatus that utilizes a key management function entity to negotiate and obtain a first key, allowing the intermediary device to decrypt ciphertext transmitted between user equipment and network servers, thereby enabling service optimization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If an intermediary device is disposed between user equipment and network server to forward data, then data transmission reliability is improved, but the intermediary device cannot decrypt ciphertext and thus cannot provide service optimization

Engineering Contradiction:
Improvedata transmission reliabilityVSAvoidservice optimization capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

A key management function entity is introduced as a mediator between the user equipment, network server, and intermediary device. This entity facilitates key negotiation and distribution, enabling the intermediary device to obtain decryption keys without compromising the security architecture. The key management function entity acts as a trusted third party that coordinates key exchange between multiple devices, resolving the contradiction by allowing the intermediary to decrypt ciphertext while maintaining data transmission reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If encryption is used to protect data privacy, then data security is improved, but intermediary devices cannot decrypt ciphertext to provide service optimization functions

Engineering Contradiction:
Improvedata privacy protectionVSAvoidservice optimization functionality
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system performs preliminary key negotiation and key distribution before data encryption occurs. The key management function entity establishes secure communication channels and distributes decryption keys to the intermediary device in advance. This preliminary action enables the intermediary to decrypt and process ciphertext for service optimization while the user equipment and network server maintain encryption for data privacy protection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Different parts of the system have different security requirements. The user equipment and network server maintain strong encryption for data privacy, while the intermediary device receives decrypted keys locally to provide service optimization functions. This local quality approach allows each component to operate with appropriate security levels - encryption for privacy protection and decryption for service optimization - without compromising either function.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If decryption keys are shared with intermediary devices to enable service optimization, then service optimization capability is improved, but security risks increase due to key exposure

Engineering Contradiction:
Improveservice optimization capabilityVSAvoidsecurity reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The key management function entity serves as a secure intermediary that handles key distribution to the intermediary device. This mediator architecture allows the intermediary to obtain decryption keys for service optimization while the key management function entity maintains control over key security. The trusted third party facilitates key exchange through secure channels, reducing the security risks associated with direct key sharing between user equipment, network server, and intermediary devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3462666B1Service processing method and device
Publication Date: 2023.05.31 HUAWEI TECH CO LTD
  • EP3462666B1 patent drawingFigure 1~2
  • EP3462666B1 patent drawingFigure 3~4
  • EP3462666B1 patent drawingFigure 5

AI summary

The present invention discloses a service processing method and apparatus, and relates to the communications field. The method includes: receiving trigger information sent by an intermediary device; and assisting, based on the trigger information, the intermediary device in negotiating with UE and a network server, to enable the intermediary device to obtain a first key, where the first key is used by the intermediary device to decrypt ciphertexts sent by the UE and the network server, the ciphertext is obtained after the UE or the network server encrypts service information by using a second key, and the first key is corresponding to the second key. The present invention resolves a problem that an intermediary device cannot provide service optimization for user equipment and a network server because the intermediary device cannot decrypt ciphertext, and achieves an effect of expanding a usage scope of service optimization.