Network Security Domain Discovery via Centralized Master Device
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for discovering security information in networks, particularly in home networks with multiple security domains, are inefficient due to the need for multiple device interactions and the difficulty in distinguishing between security domains.
Innovation Solution
A method involving a first device that sends a broadcast or multicast message to multiple second devices in a network, requesting security domain discovery, and subsequently obtaining and displaying security domain information, including IDs and names, based on responses from participating devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If a new device performs multiple device interactions to discover security domains in the network, then the device can identify security domains, but the joining efficiency is reduced due to the complexity of interactions
Solution Approach 1:
The master device pre-generates and stores security domain information (including security domain IDs and names) in a local database before new devices need to discover them. When a new device joins, it can directly retrieve this pre-prepared information through a simple interaction, avoiding the need for multiple complex discovery interactions and thereby improving joining efficiency while maintaining accurate security domain identification
Solution Approach 2:
The patent introduces a master device as an intermediary that centralizes the storage and management of security domain information. Instead of new devices directly interacting with multiple other devices to discover security domains, they interact only with the master device, which provides the security domain information through a simplified process, thus reducing interaction complexity while ensuring accurate identification
2Adaptability or versatility
If multiple security domains exist in the same network, then the network functionality is enhanced, but the difficulty in distinguishing security domains increases
Solution Approach 1:
The patent assigns unique identifying characteristics (security domain IDs and names) to each security domain within the network. Each security domain has its own distinct local quality markers that enable easy differentiation. The master device stores and manages these unique identifiers, allowing new devices to quickly distinguish between different security domains without confusion, thus maintaining high distinguishability while supporting multiple security domains
Solution Approach 2:
The patent segments the network into distinct security domains, each with its own unique identifier and name. This segmentation approach organizes the network structure clearly, making it easier to manage and distinguish between different security domains. Each domain is treated as an independent entity with its own identification characteristics, enhancing both network functionality and distinguishability
3Ease of operation
If a new device requests the master device to configure security information, then the device can join the network, but the configuration process becomes complex
Solution Approach 1:
The master device automatically retrieves security domain information from its local database and pushes it to new devices without requiring complex manual configuration. The system performs self-service by having the master device proactively provide the necessary security domain information (IDs and names) to joining devices, simplifying the configuration process while maintaining ease of operation for device joining
Data Source
AI summary
Provided is a method for discovering security information. A first device sends a broadcast or multicast message to M second devices in a network where the first device is located, M is an integer greater than or equal to 1, and the broadcast or multicast message contains a request for performing security domain discovery; the first device receives representations of security domain resources fed back by N second devices, wherein N is an integer greater than or equal to 1 and less than or equal to M; the first device obtains L pieces of security domain information on the basis of the representations of the security domain resources fed back by the N second devices, and displays the L pieces of security domain information, L is an integer greater than or equal to 1, and the security domain information comprises a security domain identification (ID) and a security domain name.


