Communication Security Module for Decoupled Trustworthiness Services
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile communication networks face challenges in security management, with conventional authentication methods tightly coupled to communication functions, requiring complex updates and lacking standardized security capabilities, leading to potential security risks and inefficiencies.
Innovation Solution
A dedicated communication security apparatus is introduced to handle trustworthiness services, independent of the communication apparatus, implementing security algorithms and protocols to enhance security, allowing for flexible and standardized security management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security functions are tightly coupled with communication modules (USIM and ME), then authentication and security services can be provided, but security function update and upgrade require modification to configurations involving heavy workload and complex operations
Solution Approach 1:
The patent segments the security function from the communication function by introducing a dedicated security module (separate from USIM and ME). This security module independently handles authentication and security services, allowing security functions to be updated without modifying communication module configurations, thus reducing workload and complexity while maintaining high security levels.
Solution Approach 2:
The patent extracts the security function from the integrated USIM-ME system and places it in a separate dedicated security module. This extraction enables independent management and updating of security functions without affecting communication modules, resolving the contradiction between maintaining security reliability and reducing configuration complexity.
2Ease of manufacture
If existing communication standards provide only basic encryption, integrity protection, authentication, and authorization, then implementation is straightforward, but additional security capabilities require discretionary design by operators or manufacturers, leading to inconsistent security levels
Solution Approach 1:
The patent implements a universal security module that provides standardized security services including encryption, integrity protection, authentication, and authorization. This universal module can be deployed across different operators and equipment manufacturers, ensuring consistent security capabilities and levels while maintaining ease of implementation through standardized interfaces and protocols.
3Ease of operation
If authentication parameters are processed by communication modules (ME and USIM), then authentication can be performed, but weak security protection in some user device environments creates risks in the authentication process
Solution Approach 1:
The patent introduces a dedicated security module as an intermediary between the communication module and the authentication process. This security module securely handles authentication parameters and processes, providing strong security protection while maintaining authentication functionality. The security module acts as a trusted intermediary that isolates sensitive authentication operations from potentially insecure communication module environments.
Data Source
Figure 1A
Figure 1B~1D
Figure 1E~1G
AI summary
The present disclosure provides a communication method, a communication apparatus, a computer-readable storage medium, and a computer program product. The communication method includes: A communication security apparatus obtains a trustworthiness service request for a terminal, determines a security algorithm for the trustworthiness service request according to a trustworthiness policy, executes the security algorithm to obtain a trustworthiness service execution result, and sends a trustworthiness service response including the trustworthiness service execution result. In this manner, a security function can be effectively decoupled from a communication function, facilitating independent evolution and flexible deployment of a security capability.