Access Regulating Device for Compromised Terminal Restriction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing number of machine-to-machine (M2M) communication devices in communication networks poses a significant security threat due to potential hacking, which can lead to compromised communication terminals, resulting in unwanted data transfer and network congestion.

Innovation Solution

An access regulating device that uses processing circuitry to identify potentially compromised communication terminals, analyze indications of compromise, and implement communication restrictions, such as barring or limiting network access, to prevent harmful data transfer and congestion.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If communication terminals are allowed unrestricted access to the network, then network utilization and communication efficiency are improved, but network security deteriorates due to potential hacking and compromised terminals

Engineering Contradiction:
Improvenetwork utilizationVSAvoidnetwork security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by implementing an analysis unit that proactively identifies potentially compromised communication terminals before they can cause harm. The system analyzes indicators such as abnormal communication patterns, unauthorized access attempts, or suspicious data transmissions, and preemptively applies communication restrictions to prevent security incidents from occurring

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an access regulating device as an intermediary between communication terminals and the network. This mediator monitors terminal behavior, analyzes compromise indicators, and selectively applies restrictions to suspicious terminals while allowing legitimate terminals unrestricted access, thus balancing security with network utilization

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If communication restrictions are applied to potentially compromised terminals, then network security is improved, but communication efficiency deteriorates due to limited access

Engineering Contradiction:
Improvenetwork securityVSAvoidcommunication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by implementing differential access control where communication restrictions are applied selectively only to potentially compromised terminals rather than uniformly to all terminals. The analysis unit identifies specific terminals exhibiting suspicious behavior and applies restrictions only to those terminals, while legitimate terminals continue to enjoy full network access, thus minimizing the impact on overall communication efficiency

Inventive Principle:
Principle #3Local quality

3Measurement precision

If monitoring and analysis of all communication terminals is performed, then detection precision is improved, but device complexity increases

Engineering Contradiction:
Improvedetection precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies partial action by implementing targeted monitoring that focuses analysis resources on terminals exhibiting specific suspicious behaviors or indicators of compromise. Rather than continuously analyzing all terminals equally, the system applies communication restrictions and intensified monitoring only when specific threshold conditions are met, thus reducing overall system complexity while maintaining high detection precision for compromised terminals

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP3725117B1Regulation of communication terminal access to a communication network
Publication Date: 2023.07.19 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP3725117B1 patent drawingFigure 1
  • EP3725117B1 patent drawingFigure 2~5
  • EP3725117B1 patent drawingFigure 6~7

AI summary

An access regulating device (22) for a communication terminal (10) using a communication network (12) obtains an indication (I) that the communication terminal (10) is a potentially compromised communication terminal, analyses the indication (I), selects type of communication restriction based on the analysis, where a first type of communication restriction comprises barring the communication terminal (10) from using the communication network (12) and a second type of communication restriction comprises limiting the use of the communication network (12) by the communication terminal (10), and informs (B1,B2; Q) at least one network node (16, 18; 24) responsible for handling communication restrictions of the type selected for the communication terminal (10) in order for the communication network (12) to effectuate the communication restriction.