Stateful Security Redundancy in Communication Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Communication systems face challenges in providing secure and redundant security mechanisms, particularly in ensuring seamless failover and synchronization of secure channel state information across security nodes in redundancy domains, which is crucial for maintaining uninterrupted secure communications.

Innovation Solution

The implementation of a security node within a redundancy domain that determines its administrative and runtime roles based on configuration information and interaction with other nodes, performs synchronization of secure channel state information, and directs traffic to an active security node using activity election protocols and activity-aware routing, ensuring that backup nodes can seamlessly take over in case of failures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If backup security nodes are configured to provide redundancy, then reliability of secure communications is improved, but complexity of synchronizing secure channel state information between nodes increases

Engineering Contradiction:
Improvereliability of secure communicationsVSAvoidcomplexity of synchronizing secure channel state information
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The synchronization process is segmented into selective synchronization of critical state information rather than full state synchronization. The patent segments the secure channel state information into essential components that need to be synchronized between active and backup nodes, reducing the complexity while maintaining reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by pre-configuring backup nodes with security policies and pre-establishing synchronization mechanisms before failures occur. This preliminary preparation reduces the complexity of real-time synchronization during failover events while ensuring high reliability.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If activity election protocols are implemented to determine active and backup roles, then seamless failover is enabled, but overhead of role determination and traffic attraction processes increases

Engineering Contradiction:
Improveseamless failover capabilityVSAvoidoverhead of role determination and traffic attraction
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements dynamic role determination where security nodes can transition between active and backup roles based on real-time conditions. The activity election protocol dynamically assigns roles using metrics such as node availability, performance, and configuration, enabling seamless failover while minimizing overhead through efficient dynamic decision-making.

Inventive Principle:
Principle #15Dynamics

3Reliability

If backup nodes synchronize secure channel state information, then uninterrupted secure communications are maintained, but computational resources consumed by synchronization processes increases

Engineering Contradiction:
Improveuninterrupted secure communicationsVSAvoidcomputational resources for synchronization
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The synchronization mechanism applies local quality by synchronizing only the essential state information locally needed for failover at each backup node, rather than synchronizing all possible data. This selective approach maintains uninterrupted communications while reducing computational resource consumption.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes synchronization parameters dynamically based on network conditions, synchronizing state information at different frequencies and depths depending on the operational context. This parameter adjustment maintains communication reliability while optimizing computational resource usage.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11997104B2Security redundancy
Publication Date: 2024.05.28 NOKIA SOLUTIONS & NETWORKS OY
  • US11997104B2 patent drawing
  • US11997104B2 patent drawing
  • US11997104B2 patent drawing

AI summary

Various example embodiments for supporting security in a communication system are presented. Various example embodiments for supporting security in a communication system may be configured to support stateful security redundancy in the communication system. Various example embodiments for supporting stateful security redundancy in a communication system may be configured to support stateful security redundancy for a set of client devices based on a set of security nodes arranged in a security redundancy architecture. Various example embodiments for supporting stateful security redundancy for a set of client devices based on a set of security nodes arranged in a security redundancy architecture may be configured to support stateful security redundancy for a client device based on a security redundancy domain including an active security node and one or more standby security nodes.