Abstraction Function Module for Mobile Handset Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing use of advanced mobile handsets with IP connectivity poses a security risk as sensitive network information, such as Cell-ID and neighbor lists, can be exploited by unauthorized entities, potentially leading to commercial and security issues, as these interfaces between the control and user planes may inadvertently disclose this information to third parties.

Innovation Solution

An abstraction function module is introduced in the mobile handset to encrypt sensitive network information from the control plane, using an encoding key received from an abstraction server, ensuring that only authorized clients or applications in the user plane can access this information, thereby protecting it from unauthorized disclosure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If interfaces between control plane and user plane are provided to enable information exchange, then functionality and service capability are improved, but security risk increases due to potential unauthorized access to sensitive network information

Engineering Contradiction:
Improveservice capabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

An abstraction function module is introduced as an intermediary between the control plane and user plane. This module receives requests from user plane applications, retrieves sensitive network information from the control plane, encrypts it using encoding keys, and provides the encrypted information to authorized applications. This intermediary mechanism enables service functionality while protecting sensitive information from unauthorized access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The abstraction function module changes the state of network information by applying encryption transformations. Sensitive network information is converted from plaintext to encrypted form using encoding keys retrieved from abstraction servers. This parameter change ensures that only authorized entities with the appropriate decoding capabilities can access the original information, thereby mitigating security risks while maintaining service functionality.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If sensitive network information is encrypted using abstraction function, then security is improved, but device complexity increases due to additional encryption/decryption operations

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The encryption and decryption functionality is extracted from the main handset system and implemented as a separate abstraction function module. This module operates independently to handle encryption/decryption operations, allowing the core handset system to maintain its original simplicity while gaining enhanced security capabilities through the modular abstraction layer.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP2235977B1Abstraction function for mobile handsets
Publication Date: 2018.02.28 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP2235977B1 patent drawingFigure 1~2
  • EP2235977B1 patent drawingFigure 3~5
  • EP2235977B1 patent drawingFigure 6~8

AI summary

Handset (80), computer software and method for protecting sensitive network information, available in the handset (80), from disclosure to an unauthorized server, by using an abstraction function module (200 or 1400), the handset (80) being connected to a network (112). The method includes receiving at the abstraction function module (200 or 1400) an encoding key (KE) from an abstraction server (210); receiving at the abstraction function module (200 or 1400) a request from a client or application (106) for providing the sensitive network information from a control plane module (100 or 1420) of the handset (80), wherein the client or application (106) resides in a user plane module (104 or 1410), which is different from the control plane module (100 or 1420), the sensitive network information is stored in the control plane module (100 or 1420) of the handset (80), and both the control plane module (100 or 1420) and the user plane module (104 or 1410) reside in the handset (80); retrieving by the abstraction function module (200 or 1400) the requested sensitive network information from the control plane module (100 or 1420); encrypting, by the abstraction function module (200 or 1400), the retrieved sensitive network information based on the received encoding key (KE); and providing the encrypted sensitive network information to the client or application (106) in the user plane module (104 or 1410).