M2M Service Layer Sessions Across Multiple Hops for E2E Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional M2M service layer architectures lack support for end-to-end (E2E) sessions, leading to overhead and complexity in managing sessions, preventing network services from providing value-added functionalities like data aggregation and analytics, and are unsuitable for unmanned devices.
Innovation Solution
Implement mechanisms to support E2E M2M service layer sessions that span multiple service layer hops, enabling the M2M service layer to participate in end-to-end security, quality of service, and negotiation of settings through session endpoint and management functions, allowing trusted intermediaries to encrypt/decrypt and compress/decompress data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If conventional application sessions are used, then applications can establish and manage sessions themselves, but this adds extra overhead and complexity to applications
Solution Approach 1:
The patent introduces an intermediary service layer between applications and the communication network that handles session establishment, management, and termination. This service layer acts as a mediator that absorbs the complexity of session management operations, allowing applications to communicate without directly managing sessions themselves, thereby reducing application complexity while maintaining ease of operation.
2Reliability
If end-to-end security services are implemented, then secure communication is achieved, but existing architectures lack support for this functionality
Solution Approach 1:
The patent designs a service layer architecture that provides universal support for multiple functions including end-to-end security services, quality of service functionality, and session management. By making the service layer multi-functional and adaptable, it can accommodate various security protocols and communication requirements without requiring architecture changes, thus achieving both security and versatility.
3Reliability
If end-to-end quality of service functionality is implemented, then latency and bandwidth guarantees are achieved, but existing architectures lack support for this
Solution Approach 1:
The patent implements a dynamic service layer that can adapt to different quality of service requirements in real-time. The architecture allows for dynamic negotiation and adjustment of latency and bandwidth parameters based on current network conditions and application needs, enabling flexible quality of service support without rigid architectural constraints.
4Reliability
If end-to-end negotiation of settings is implemented, then optimal communication parameters are achieved, but existing architectures lack support for this
Solution Approach 1:
The patent implements preliminary negotiation of communication settings during session establishment, where parameters such as compression algorithms, encryption methods, and quality of service levels are agreed upon in advance. This preliminary action optimizes subsequent communication efficiency while the architecture supports flexible negotiation through standardized service layer interfaces.
5Productivity
If trusted intermediaries can process encrypted data, then value-added services like data aggregation and analytics are enabled, but this requires end-to-end session support
Solution Approach 1:
The patent introduces trusted intermediary nodes within the service layer that can decrypt, process, and re-encrypt data while maintaining end-to-end security. These intermediaries act as secure enclaves that enable value-added services like data aggregation and analytics without compromising the security of the overall communication path, thus enabling productivity enhancement with controlled complexity.
Data Source
AI summary
Mechanisms support machine-to-machine service layer sessions that can span multiple service layer hops where a machine-to-machine service layer hop is a direct machine-to-machine service layer communication session between two machine-to-machine service layer instances or between a machine-to-machine service layer instance and a machine-to-machine application. Mechanisms are also disclosed that illustrate machine-to-machine session establishment procedures for oneM2M Session Management Service supporting multiple resources.


