Communication Security Modules for Independent Service Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication network security technologies are closely coupled with communication functions, making it difficult to independently update and maintain security capabilities, leading to challenges in quickly upgrading security when vulnerabilities are identified.

Innovation Solution

A communication method and apparatus that decouples security functions from communication functions, enabling independent deployment and maintenance of security modules through a first security module that executes security services based on request messages and provides feedback, allowing for standardized and modularized security procedures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Use of energy by moving object

If security functions are closely coupled with communication functions, then effective utilization of network resources is achieved, but independent update and maintenance of security capabilities becomes difficult

Engineering Contradiction:
Improvenetwork resource utilizationVSAvoidsecurity capability maintenance
Core Design Contradiction:
Use of energy by moving objectVSEase of repair

Solution Approach 1:

The patent segments the security function from the communication function by introducing a security capability management module that independently manages security capabilities. This allows security functions to be separately updated and maintained while remaining integrated with communication functions through standardized interfaces, resolving the contradiction between resource utilization and maintenance ease.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts security capabilities as independent, reusable components that can be managed separately from communication functions. The security capability management module can select and apply appropriate security capabilities based on communication scenarios, achieving both tight integration for resource efficiency and independent manageability for ease of maintenance.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If security protocols are modified to address vulnerabilities, then security performance is improved, but the complexity of coordinating multiple network functions increases

Engineering Contradiction:
Improvesecurity performanceVSAvoidnetwork function coordination
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates universal security capability interfaces that can be applied across multiple network functions and scenarios. When security vulnerabilities are identified and protocols are modified, the changes are made in centralized security capability modules rather than in each individual network function, reducing coordination complexity while improving security performance.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If security capabilities are embedded in different network functions, then specific security needs are met, but quick upgrade of security capabilities becomes challenging

Engineering Contradiction:
Improvesecurity capability customizationVSAvoidsecurity upgrade speed
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent prepares security capabilities as pre-defined, standardized components that can be quickly selected and deployed. The security capability management module maintains a repository of security capabilities that can be rapidly activated or updated based on emerging threats, enabling both customized security solutions and fast deployment without requiring extensive reconfiguration of individual network functions.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250260726A1Communication method and apparatus
Publication Date: 2025.08.14 HUAWEI TECH CO LTD
  • US20250260726A1 patent drawing
  • US20250260726A1 patent drawing
  • US20250260726A1 patent drawing

AI summary

A communication method is described where a first security module executes a first security service or managing the first security module based on a first request message received from a requester, wherein the first security service is usable to call a security capability, the requester comprises a first node, a second node, or a second security module, the first security module serves the first node, and the second security module serves the second node. The first security module sends a first feedback message to the requester, wherein the first feedback message is usable to feed back, to the requester, an execution result of the first security service or a management result of the first security module.