Conditional Limited Service Grant for First Responder Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

During crises or high-demand events, first responders face difficulties accessing communication networks due to high utilization, and existing technologies lack efficient methods for prioritizing and securely granting limited access to communication services.

Innovation Solution

A conditional limited service grant system that uses device verification, including capability attestation, user authentication, and one-time password validation, to prioritize access for first responders through a secure computing device acting as a gatekeeper, ensuring reliable and secure access during crises.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If access to communication networks is granted during high-demand events, then service availability increases, but network overload and service degradation occur

Engineering Contradiction:
Improveservice availabilityVSAvoidnetwork performance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system implements differentiated access policies for different device types during crises. First responder devices receive prioritized access with guaranteed bandwidth and lower latency, while regular user devices experience throttled service. This local quality differentiation resolves the contradiction by ensuring critical services maintain high reliability even when overall network demand is high.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The network gateway acts as an intermediary that verifies device credentials and enforces access policies. It mediates between the overloaded network and requesting devices by filtering and prioritizing traffic based on device type and crisis status, thereby maintaining network performance while providing service availability to authorized devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If access is prioritized for specific devices during crises, then first responder access improves, but security risks increase

Engineering Contradiction:
Improveaccess priorityVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary verification of device credentials and crisis status before granting prioritized access. Devices must present valid authentication credentials and the system verifies their first responder status and active crisis conditions beforehand. This preliminary action ensures that only authorized devices receive priority access, eliminating security risks while maintaining ease of operation for legitimate users.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors and verifies device credentials and crisis status in real-time. If a device's crisis status changes or credentials become invalid, the system immediately revokes prioritized access. This feedback mechanism ensures security is maintained dynamically while allowing ease of operation during valid crisis conditions.

Inventive Principle:
Principle #23Feedback

3Reliability

If multiple verification steps are implemented, then security and access control improve, but system complexity increases

Engineering Contradiction:
Improveaccess controlVSAvoidverification system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The verification system is segmented into distinct modular components: credential verification module, crisis status verification module, and access policy enforcement module. Each module handles a specific verification task independently. This segmentation improves access control reliability through comprehensive verification while managing system complexity by organizing functions into separate, maintainable units.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2847926B1Conditional limited service grant based on device verification
Publication Date: 2019.08.21 INTEL CORP
  • EP2847926B1 patent drawingFigure 1
  • EP2847926B1 patent drawingFigure 2
  • EP2847926B1 patent drawingFigure 3

AI summary

Embodiments of apparatus, computer-implemented methods, systems, devices, and computer-readable media are described herein for accepting capability attestation of a device for determination of whether to grant access to a service during a state of operation. In various embodiments, access to the service sought may be conditionally granted responsive to verification of the capability attested. In various embodiments, during the state of operation, access to the service may be granted on a limited basis.