Secure Transmission Proxy for Unified Certificate Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current BSS service systems face high networking costs and maintenance workloads due to the need for multiple security certificates and separate certificate publication by each service server, which complicates security verification and performance in high-traffic environments.

Innovation Solution

A secure transmission proxy apparatus that decrypts and verifies service requests, performs protocol conversion, and publishes a unified security certificate, reducing the need for multiple certificates and simplifying permission verification across service servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If each business support system publishes a separate security certificate to clients, then communication security between client and service server is ensured, but networking costs increase and device capacity must be expanded

Engineering Contradiction:
Improvecommunication securityVSAvoidnetworking complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a security server as an intermediary between clients and business support systems. The security server publishes a unified security certificate to clients, while the business support systems authenticate each other with the security server using their respective private keys. This mediator approach maintains communication security while eliminating the need for each service system to publish separate certificates to clients.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent merges multiple separate certificate publication functions into a single unified security certificate published by the security server. Instead of each business support system maintaining and publishing its own certificate, the security server combines these authentication functions into one centralized certificate that clients use to communicate securely with any business support system.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If each service system server publishes a certificate for security verification, then service security is maintained, but maintenance workload and reconstruction difficulty increase

Engineering Contradiction:
Improveservice securityVSAvoidmaintenance ease
Core Design Contradiction:
ReliabilityVSEase of repair

Solution Approach 1:

The security server acts as an intermediary that centralizes certificate management and security verification. When a service system needs maintenance or reconstruction, the security server handles the authentication and certificate validation, isolating the complexity from individual service systems. This allows service systems to be maintained or reconstructed without affecting the overall security architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the security verification function from individual business support systems and places it in the security server. By taking out the certificate management and verification responsibilities from each service system, the maintenance workload is significantly reduced, as the security server handles all authentication operations centrally.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If multiple security certificates are used for different business support systems, then access security to multiple systems is ensured, but client workload and reconstruction complexity increase

Engineering Contradiction:
Improveaccess securityVSAvoidclient operation ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent creates a universal security certificate published by the security server that can be used by clients to access multiple different business support systems. This single multi-functional certificate replaces the need for clients to manage multiple separate certificates, while still ensuring secure access to each individual business support system through the security server's verification mechanism.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3166283B1Business access method, system and device
Publication Date: 2019.11.13 HUAWEI TECH CO LTD
  • EP3166283B1 patent drawingFigure 1~2
  • EP3166283B1 patent drawingFigure 3~5
  • EP3166283B1 patent drawingFigure 6~7

AI summary

Embodiments of the present invention provide a service access method and an apparatus, and relate to the field of communications technologies. A secure transmission proxy apparatus performs verification and management on service permission, which reduces networking costs of a service server side and workload of reconstruction and maintenance of the service server side, and enhances communication security. A solution includes: decrypting, by a secure transmission proxy apparatus, a service request message sent by a client, where the service request message includes a service type; performing verification on service permission of a decrypted service request message according to the service type; performing protocol conversion on the decrypted service request message if the service permission verification succeeds; and sending a service request message obtained after the protocol conversion to a service server side, so that the service server side executes a corresponding service according to the service request message obtained after the protocol conversion.