Service Integrity Adaptation for Secure Network Interchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In service-oriented architectures, existing technologies fail to effectively protect the integrity of services provided across multiple devices and networks, as they primarily focus on individual device integrity rather than service-specific integrity, which is semantically insignificant in such scenarios.

Innovation Solution

A method and system that compute and transmit service-specific integrity information across networks, using a management unit to assess and encrypt the integrity status of components, ensuring that only this information is shared, thereby adapting access rules and preventing direct access to individual device integrity from external networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If service-specific integrity information is transmitted across networks, then the integrity and confidentiality of service data are improved, but the complexity of the system increases due to the need for management units and access rule adaptation mechanisms

Engineering Contradiction:
Improveservice integrityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A management unit is introduced as an intermediary component that collects integrity information from multiple components, processes it, and generates service-specific integrity information. This mediator abstracts the complexity from the data interchange process, allowing networks to exchange only the necessary aggregated integrity data without direct access to individual component details, thus improving reliability while managing system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If access rules are adapted based on service-specific integrity information, then the security of data interchange is improved, but the difficulty of operation increases due to the need for continuous integrity monitoring and rule adjustment

Engineering Contradiction:
Improvesecurity protectionVSAvoidoperation simplicity
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system implements self-service mechanisms where the management unit automatically collects integrity information from components, evaluates it against predefined criteria, and generates updated access rules without requiring manual intervention. The components themselves provide integrity data through standardized interfaces, and the system automatically adapts access rules based on the aggregated service-specific integrity information, reducing operational complexity while maintaining high security.

Inventive Principle:
Principle #25Self-service

3Loss of information

If individual device integrity information is protected from external access, then the confidentiality of internal system information is improved, but the measurement precision of service integrity decreases

Engineering Contradiction:
Improveinformation confidentialityVSAvoidintegrity assessment accuracy
Core Design Contradiction:
Loss of informationVSMeasurement precision

Solution Approach 1:

The management unit merges integrity information from multiple individual components into a single service-specific integrity information item. By combining the integrity data of all components involved in a service into one aggregated representation, the system protects individual device information from external access while maintaining precise measurement of the overall service integrity. The aggregation process preserves the essential integrity characteristics needed for assessment without exposing sensitive individual component details.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10084821B2Adaptation of access rules for a data interchange between a first network and a second network
Publication Date: 2018.09.25 SIEMENS AG
  • US10084821B2 patent drawing
  • US10084821B2 patent drawing
  • US10084821B2 patent drawing

AI summary

Adapting access rules for a data interchange between a first network and a second network by the second network is provided based on a service-specific integrity information item of the first network, wherein the first network processes data for carrying out a service and the service defines multiple components. A respective integrity status is transmitted for each of the components by each respective component via a communication link within the first network to a management unit of the first network. The service-specific integrity information item is computed based on each respective integrity status by the management unit. The service-specific integrity information item is transmitted by a network access point of the first network to a receiver in the second network for adapting the access rules. Access by the receiver to each respective integrity status is prevented.