Secure Communications Manager for Dynamic Network Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security methods fail to establish secure communications in dynamic environments with heterogeneous security capabilities, where devices with and without secure elements interact, lacking ad-hoc access management and secure channel setup without advanced setup operations.

Innovation Solution

A secure-communications-management method where a managed device, without a secure element, relies on a manager device with a secure element to authenticate and authorize third-party devices, setting up secure channels based on the third-party device's security capabilities, using unique identification data or direct encryption when necessary.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a managed device without a secure element attempts to communicate with third-party devices, then communication flexibility is improved, but security reliability deteriorates because the device lacks inherent security capabilities

Engineering Contradiction:
Improvecommunication flexibilityVSAvoidsecurity reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a manager device as an intermediary that provides security services to managed devices lacking secure elements. The manager device authenticates third-party devices and establishes secure communication channels, allowing managed devices to communicate flexibly without having inherent security capabilities. This mediator approach resolves the contradiction by externalizing security functions while maintaining communication adaptability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If secure communication channels are established using traditional methods requiring all devices to have secure elements, then security reliability is improved, but device compatibility deteriorates in heterogeneous networks

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal security management system where the manager device can serve multiple types of managed devices with different security capabilities. The system accommodates both devices with secure elements and those without, providing appropriate authentication and channel establishment methods for each. This multi-functional approach maintains security reliability while achieving broad device compatibility in heterogeneous networks.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If advanced setup operations are required to establish secure channels, then security reliability is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements automatic authentication and secure channel establishment processes where the manager device handles security negotiations without requiring manual configuration. The system automatically detects device capabilities, selects appropriate authentication methods, and establishes secure channels through programmed operations. This self-service approach maintains security reliability while dramatically improving ease of operation by eliminating complex manual setup procedures.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2741465B1Method and device for managing secure communications in dynamic network environments
Publication Date: 2021.03.17 ORANGE SA
  • EP2741465B1 patent drawingFigure 1A~2
  • EP2741465B1 patent drawingFigure 3
  • EP2741465B1 patent drawingFigure 4~5

AI summary

In a dynamic network environment secure communications are managed using a securecommunications-manager device that has a secure element, and a method, which controls the security policy applied by managed communications devices. A managed communications device does not communicate with third party communications devices that have not been authorized by its associated manager. A managed communications device delegates the authentication of third party devices to its associated manager device. The intervention of the secure-communications-manager device that possesses a secure element is necessary for the setting up of a secure communications channel for accessing to at least a service provided by the managed device from a third party device.