Secure Communication Between User Equipment and Private Network
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing IPsec VPN schemes face challenges such as uncertainty in IP address-based pre-shared key definition, complex configuration requirements, difficulty in professional parameter negotiation, and increased costs due to treating IPsec clients as part of the home network, leading to poor extensibility and security concerns in secure communication between external user equipment and private networks.
Innovation Solution
A method and apparatus that generate a security parameters index (SPI) value using pre-stored root keys and agreed algorithms to encrypt and authenticate data, simplifying key generation and authentication, and encapsulating encrypted data into packets for secure communication, ensuring only authorized access to private networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If IPsec VPN technology is used to encrypt data and allow communication traffics to pass through the Internet securely, then security of communication is improved, but device complexity and configuration complexity increase
Solution Approach 1:
The patent extracts the complex IPsec configuration requirements and parameter negotiation procedures from the access process, separating them into a pre-configured authentication phase using simple username/password credentials. This allows the complex security parameters to be pre-negotiated and stored, while the actual access process remains simple for users.
Solution Approach 2:
The patent implements preliminary authentication and key exchange before actual data transmission. The complex IPsec parameters, encryption keys, and security associations are pre-established during an initial authentication phase, so that subsequent communication can proceed without repeating complex negotiations.
2Reliability
If IPsec client end is treated as a part of home network, then network security is improved, but extensibility deteriorates due to complex attributes configuration
Solution Approach 1:
The patent creates a universal access mechanism that works across different network types and devices. By using standard username/password authentication instead of device-specific IPsec configurations, the system achieves multi-functionality that accommodates various user equipment types while maintaining security through centralized credential verification.
3Ease of operation
If pre-shared key is defined based on IP address, then authentication is simplified, but reliability deteriorates due to IP address uncertainty
Solution Approach 1:
The patent introduces an intermediary authentication server that mediates between the user equipment and the home network. Instead of direct IP-address-based authentication, the authentication server verifies credentials and establishes security associations, providing reliable authentication even when IP addresses change or are uncertain.
Data Source
AI summary
It is an object of the present invention to provide a new technical solution of supporting special secure communication between user equipment which is located in an external network and an private network the user equipment belongs to. Specifically, transmitted data is encrypted/decrypted and authenticated by using pre-stored root keys corresponding to specific private networks and the agreed encryption/decryption and authentication algorithm at the user equipment and an access device. The manner of generating the encryption/decryption keys and authentication key is simplified, and the complexity of the access device at the private network end is reduced on the premise of not degrading the security grade. The technical solution of the present invention is highly flexible and extensible and can achieve better user experience.


