Resource Directory Security Information Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The setup of secured connections between nodes, such as in IoT devices, often results in increased latency and resource consumption due to negotiation of security protocols and parameters, which is particularly problematic for resource-constrained devices.

Innovation Solution

A resource directory is used to store and manage security information, allowing nodes to retrieve and utilize the security capabilities and preferences of a server node before connection setup, thereby reducing the need for negotiation during connection establishment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security protocol negotiation is performed during connection setup between client and server nodes, then security capabilities and preferences can be agreed upon, but latency and resource consumption increase significantly

Engineering Contradiction:
Improvesecurity connection establishmentVSAvoidconnection setup latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by having server nodes publish their security capabilities and preferences in advance to a resource directory before any client connections are established. This allows clients to retrieve pre-configured security information without needing to negotiate during the connection setup process, thereby reducing latency while maintaining security reliability.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If security protocol negotiation is performed during connection setup, then secure communication can be established, but power and processing resources are consumed

Engineering Contradiction:
Improvesecured connectionVSAvoidnode power consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

Security capability information is published in advance by server nodes to the resource directory, eliminating the need for energy-consuming negotiation protocols during connection setup. Clients can directly use the pre-published security information to establish secured connections, significantly reducing power consumption for resource-constrained devices.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If security capability negotiation is performed during connection setup, then compatible security protocols can be agreed upon, but memory and processing resources are consumed

Engineering Contradiction:
Improveprotocol compatibilityVSAvoidnode resource consumption
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent resolves device complexity by having server nodes pre-publish their supported security protocols and capabilities to the resource directory. Clients retrieve this information before connection establishment, eliminating the need for complex real-time negotiation algorithms and reducing memory and processing requirements during connection setup.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The resource directory acts as an intermediary between client and server nodes, storing and managing security capability information. This intermediary eliminates the need for direct negotiation between clients and servers, simplifying the connection setup process and reducing computational complexity for resource-constrained devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11916970B2Security information exchange between a client and a server
Publication Date: 2024.02.27 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US11916970B2 patent drawing
  • US11916970B2 patent drawing
  • US11916970B2 patent drawing

AI summary

A server node is configured to assume a server role in a particular message exchange with a client node. The server node registers, with a resource directory node, security information (e.g., security capabilities and/or security preferences) of the server node. The server node may also register information about a resource that the server node hosts. The client node determines, from the resource directory node, the security information (e.g., security capabilities and/or security preferences) of the server node. The client node then sets up a secured connection with the server node using the determined security information (e.g., security capabilities and/or security preferences).