Proximity Security Mechanism Selection for Out-of-Coverage Links

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security establishment mechanisms for device-to-device communication, particularly in out-of-coverage scenarios, face challenges in ensuring secure connections without network assistance, leading to potential failures and resource wastage.

Innovation Solution

A method for determining a target security establishment mechanism, either with or without network assistance, based on the network coverage status of the communicating devices, allowing for flexible negotiation and selection of a compatible mechanism to ensure secure connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a security establishment mechanism without network assistance is used, then devices can establish secure connections in out-of-coverage scenarios, but security reliability may be compromised due to lack of network verification

Engineering Contradiction:
Improveability to establish security in out-of-coverage scenariosVSAvoidsecurity establishment reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements dynamic mechanism selection where the security establishment mechanism is adapted based on network coverage conditions. The initiating UE determines whether to use network-assisted or non-network-assisted mechanism dynamically, allowing the system to switch between different security approaches depending on whether the target UE is in coverage, resolving the contradiction between adaptability and reliability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of network assistance involvement based on coverage conditions. By using indication information to signal whether network assistance is available, the system adjusts the security establishment approach accordingly, enabling reliable security establishment in coverage while maintaining adaptability in out-of-coverage scenarios.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If multiple security establishment mechanisms are supported and negotiated, then adaptability to different network conditions is improved, but negotiation overhead and device complexity increase

Engineering Contradiction:
Improvecompatibility across different network conditionsVSAvoidnegotiation process complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent performs preliminary determination of the security establishment mechanism by the initiating UE before the actual security establishment process. By pre-determining the mechanism and indicating it through request message, the system avoids complex back-and-forth negotiations, reducing overhead while maintaining support for multiple mechanisms.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Instead of having both UEs negotiate and decide the mechanism together, the patent inverts the approach by having the initiating UE unilaterally determine and indicate the mechanism. The target UE then accepts or rejects based on its capability, simplifying the negotiation process while maintaining adaptability.

Inventive Principle:
Principle #13The other way round (Inversion)

3Reliability

If security establishment fails due to mechanism incompatibility, then communication security is compromised, but repeated negotiation attempts increase time consumption and resource waste

Engineering Contradiction:
Improvesecurity establishment success rateVSAvoidnegotiation time and resource consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary capability assessment and mechanism determination before attempting security establishment. The initiating UE determines a suitable mechanism based on network conditions and target UE capability, and indicates this in the request message, preventing failed attempts and reducing negotiation iterations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback through the indication information exchange between UEs. The target UE provides feedback on its capability to support the indicated mechanism, allowing the initiating UE to select an appropriate mechanism from the beginning, avoiding repeated failed negotiation attempts and reducing time consumption.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20260025662A1Security establishment method and related apparatus
Publication Date: 2026.01.22 HUAWEI TECH CO LTD
  • US20260025662A1 patent drawing
  • US20260025662A1 patent drawing
  • US20260025662A1 patent drawing

AI summary

A security establishment method and a related apparatus are provided, to select an appropriate security establishment mechanism for a communication apparatus, thereby ensuring communication security. In the method, a first communication apparatus initiating proximity-based service communication determines a target mechanism from a plurality of mechanisms, for example, determines the target mechanism according to a mechanism selection rule, and sends a request message, to request a receiver to perform security establishment with the first communication apparatus by using the target mechanism. A second communication apparatus that receives the request message sends a first message to the first communication apparatus based on a network coverage status, to indicate whether to agree to perform the security establishment with the first communication apparatus by using the target mechanism.