Adapting Terminal Authorization via Encrypted Test Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security protocols for authentication and key agreement in network systems face challenges due to the support of weak cipher suites, which are difficult to configure and manage, especially in large-scale Internet-of-things scenarios, leading to potential incorrect configurations and security risks.

Innovation Solution

An apparatus and method for adapting authorization information in terminals by conducting test communication using an encryption protocol, allowing for the checking and adaptation of encryption protocol configurations to ensure compliance with predefined policies, and outputting warnings for non-secure options, thereby enabling secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If nodes use fixed or configurable guidelines for authentication and key agreement, then security is improved by preventing weak cipher suites, but device complexity increases due to manual configuration requirements on multiple nodes

Engineering Contradiction:
ImprovesecurityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A central policy server is introduced as an intermediary that manages and distributes authorization policies to multiple nodes. The policy server receives authorization information from an external entity and automatically configures the policy database, eliminating the need for manual configuration on each node while maintaining security requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Nodes automatically obtain and apply authorization policies from the central policy server without requiring manual intervention. The system enables self-configuration where nodes query the policy server for their authorization rules and automatically update their local policy databases, reducing configuration complexity while maintaining security.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual configuration of authorization policies is performed on each node, then security control is improved, but time consumption increases significantly in large-scale networks

Engineering Contradiction:
Improvesecurity controlVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The configuration management function is merged into a centralized policy server that handles all nodes. Instead of configuring each node individually, the policy server consolidates authorization policy management, allowing single-point configuration that automatically propagates to all nodes in the network.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

Authorization policies are pre-configured and stored in the policy server's database before nodes need them. When nodes join the network or require authorization updates, they automatically retrieve pre-prepared policies from the server, eliminating the need for time-consuming on-demand configuration.

Inventive Principle:
Principle #10Preliminary action

3Manufacturing precision

If each node is configured individually with authorization policies, then security precision is improved, but ease of operation deteriorates due to lack of standardized interfaces

Engineering Contradiction:
Improveconfiguration precisionVSAvoidconfiguration ease
Core Design Contradiction:
Manufacturing precisionVSEase of operation

Solution Approach 1:

The policy server provides a universal interface for managing authorization policies across all node types. It handles diverse node inputs and formats by translating them into a standardized internal representation, allowing precise policy configuration through a single standardized interface regardless of the specific node type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The policy server acts as an intermediary that standardizes communication between external configuration sources and diverse nodes. It receives authorization information in various formats, processes it through a standardized policy language, and distributes it to nodes, ensuring configuration precision while simplifying operation through interface standardization.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11159492B2Apparatus and method for adapting authorization information for a terminal
Publication Date: 2021.10.26 SIEMENS AG
  • US11159492B2 patent drawing
  • US11159492B2 patent drawing

AI summary

An apparatus for adapting authorization information for a terminal is provided. The apparatus has a communication unit for communicating with the terminal, the communication unit being configured to carry out the communication as a test communication using an encryption protocol, a checking unit for checking a configuration of the encryption protocol on the terminal, and a control unit for adapting the authorization information for the terminal on the basis of a result of the check. A corresponding method for adapting authorization information for a terminal is also proposed. The proposed apparatus makes it possible to check the options supported by a terminal in an encryption protocol. In this case, the check can be carried out, in particular, using an encrypted communication connection which could not be monitored by a firewall.