Secure Service Network Gateway Architecture

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Internet-based information exchange networks lack secure, reliable, and cost-effective solutions for sharing sensitive information in real-time across diverse participants, due to inadequate security, authentication, and authorization mechanisms, leading to inefficiencies and increased costs.

Innovation Solution

A secure service network (SSN) is established using a service layer on top of existing or new IP network infrastructure, providing full encryption, authentication, authorization, and participant privacy, enabling trusted connections and secure data sharing across trusted and untrusted networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If Internet-based information exchange networks are used, then information sharing flexibility and reach are improved, but security, reliability, and privacy protection deteriorate

Engineering Contradiction:
Improveinformation sharing flexibilityVSAvoidsecurity and reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a service layer with gateways (participant gateway, domain gateway, global gateway) that act as intermediaries between participants and the IP network infrastructure. These gateways provide authentication, authorization, and encryption services, enabling secure information exchange while maintaining Internet-based flexibility and reach.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network into multiple layers: the underlying IP network infrastructure layer and the service layer with security functions. This segmentation allows the flexible Internet infrastructure to remain intact while adding security capabilities at the service layer through gateways and service definitions.

Inventive Principle:
Principle #1Segmentation

2Reliability

If traditional point-to-point network connections are used, then security and privacy are improved, but device complexity and cost increase

Engineering Contradiction:
Improvesecurity and privacyVSAvoidnetwork complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal service layer that can serve multiple participants and domains through standardized service definitions and gateways. This multi-functional approach allows secure information exchange among diverse participants without requiring dedicated point-to-point connections for each relationship, reducing overall network complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges security functions (authentication, authorization, encryption) into a shared service layer that serves multiple participants. This consolidation eliminates the need for separate security infrastructure for each participant relationship, reducing device complexity and cost while maintaining security and privacy.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If service layer with authentication and authorization is added, then security and reliability are improved, but device complexity increases

Engineering Contradiction:
Improveauthentication and authorizationVSAvoidservice infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where participants can autonomously define services, set access policies, and manage their own authentication credentials through the gateway interface. This self-service approach reduces the operational complexity of managing security infrastructure while maintaining strong authentication and authorization capabilities.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent uses parameter-based service definitions that allow flexible configuration of security attributes (authentication methods, authorization levels, encryption types) without changing the underlying service infrastructure architecture. This parameterization approach enables adaptive security configurations while maintaining infrastructure simplicity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8719562B2Secure service network and user gateway
Publication Date: 2014.05.06 WMR E PIN
  • US8719562B2 patent drawing
  • US8719562B2 patent drawing
  • US8719562B2 patent drawing

AI summary

A secure service network (SSN) comprising an IP network infrastructure wherein the access of one participant to another participant in the network is controlled by a secure service gateway (SSG) in which a point of origination universal identifier (PoUID) represents a unique identifier for the participant within a participant's internal network domain and the interconnection of the SSGs within the SSN as a precondition of access creates a bilaterally secure peer to peer service connection. Participants in the network are service providers, service requesters, or both. A global secure service gateway (GSSG) may be interconnected in the SSN to provide a central access authority and management services.