Application Filtering Apparatus for Dynamic PSI Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In conventional mobile communication systems, the Serving-CSCF (S-CSCF) lacks the ability to manage and perform access control using dynamically created Public Service Identity (PSI) information, leading to potential unauthorized access to application servers.

Innovation Solution

An application filtering apparatus is introduced, coupled to a network with terminal devices and a server managing subscriber information, which obtains subscriber data and dynamically allocated identifiers to control service access, preventing invalid application identifier usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the S-CSCF uses conventional access control methods with static subscriber information, then the system structure remains simple, but the system cannot perform access control using dynamically created PSI information

Engineering Contradiction:
Improveaccess control capabilityVSAvoidS-CSCF structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The S-CSCF performs preliminary actions by obtaining and storing PSI filter information (including dynamically created PSI) in advance from the HSS before actual service access occurs. This preliminary preparation enables the S-CSCF to quickly validate access requests against pre-stored filter criteria without complex real-time processing during access attempts.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces PSI filter information as an intermediary element that mediates between the HSS and the access control function. This filter information acts as a pre-processed validation rule set that simplifies the S-CSCF's access control logic, allowing it to efficiently match incoming requests against stored filters without requiring complex dynamic PSI generation and validation capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the S-CSCF processes Initial Filter Criteria upon first SIP request as in conventional systems, then the processing flow remains simple, but it cannot judge whether to activate an AS based on dynamically created PSI

Engineering Contradiction:
Improveaccess control accuracyVSAvoidfilter processing capability
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary action by pre-obtaining and storing complete PSI filter information (including dynamically created PSI and associated filter criteria) from the HSS during location registration, before any service access requests are processed. This advance preparation ensures that all necessary validation rules are available when access control decisions must be made.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The S-CSCF uses feedback mechanisms by continuously comparing incoming SIP requests against stored PSI filter criteria and using the match results to determine AS activation. The system learns from each access attempt and maintains an updated state of which filters are active and which ASes should be activated based on the accumulated filter matching feedback.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If dynamically created PSI is used for service activation, then service flexibility is improved, but the risk of unauthorized access increases without proper management

Engineering Contradiction:
Improveservice activation flexibilityVSAvoidunauthorized access risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary action by pre-obtaining and storing complete PSI filter information (including dynamically created PSI and associated filter criteria) from the HSS during location registration, before any service access requests are processed. This advance preparation ensures that all necessary validation rules are available when access control decisions must be made.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces PSI filter information as an intermediary element that mediates between the HSS and the access control function. This filter information acts as a pre-processed validation rule set that simplifies the S-CSCF's access control logic, allowing it to efficiently match incoming requests against stored filters without requiring complex dynamic PSI generation and validation capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7773983B2Application filtering apparatus, system and method
Publication Date: 2010.08.10 HITACHI LTD
  • US7773983B2 patent drawing
  • US7773983B2 patent drawing
  • US7773983B2 patent drawing

AI summary

Provided is an application filtering apparatus for controlling session, which is coupled to a network which is coupled to a plurality of terminal devices, a first server for managing subscriber information of the terminal devices, and a second server for providing a service to the terminal devices, the application filtering apparatus comprising: an interface coupled to the network; a processor coupled to the memory; and a memory coupled to the processor, wherein the application filtering apparatus is configured to: obtain the subscriber information from the first server; obtain, when one of the terminal devices sends a session control message to the second server, an identifier of the terminal device that has sent from the received session control message; and send, based on the obtained subscriber information and the obtained identifier of the terminal device, an instruction to control the service to the second server via the interface.