D2D Service Restriction via Access Class Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In device-to-device communication, there is a risk of security hazards and unsatisfied security requirements due to lack of security confidentiality awareness when manually restricting services, leading to high costs and low efficiency.

Innovation Solution

A method where a first terminal receives a service restriction instruction from a second terminal, obtains access class information, determines the correctness of the service restriction authority based on this information, and restricts functions accordingly, ensuring secure service restriction.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual service restriction is implemented, then service control can be performed, but security hazards occur due to lack of security confidentiality awareness and high cost with low efficiency

Engineering Contradiction:
Improveservice restriction securityVSAvoidservice restriction efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The terminal automatically performs service restriction operations based on received instructions without requiring manual user intervention. The terminal autonomously executes the restriction of functions such as camera, microphone, or location services according to the service restriction instruction, eliminating the need for users to manually configure security settings while ensuring consistent security policy enforcement.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

A service restriction instruction message is introduced as an intermediary carrier that transmits security control information from one terminal to another. This message includes the service type identifier and function identifier, serving as a standardized interface that enables automated security enforcement without requiring direct user interaction or complex security configuration procedures.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If automated service restriction is implemented, then efficiency is improved, but security authority verification is required to prevent unauthorized restrictions

Engineering Contradiction:
Improveservice restriction efficiencyVSAvoidsecurity verification complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system changes the parameter of authority verification from complex multi-factor authentication to simple access class information comparison. By encoding security authority levels in access class parameters within the instruction message, the system enables automated verification through parameter matching rather than complex security protocols, maintaining security while improving efficiency.

Inventive Principle:
Principle #35Parameter changes

3Extent of automation

If service restriction instructions are transmitted between terminals, then automated control is achieved, but information security risks increase without proper verification

Engineering Contradiction:
Improveservice restriction automationVSAvoidinformation security risk
Core Design Contradiction:
Extent of automationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary verification of the service restriction instruction's authenticity and authority before executing the restriction. By validating the instruction message format, service type identifier, and function identifier against authorized parameters in advance, the system prevents unauthorized or malicious restrictions from being executed, ensuring security before the actual service restriction occurs.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11375435B2Device-to-device service restriction method and storage medium
Publication Date: 2022.06.28 ZTE CORP
  • US11375435B2 patent drawing
  • US11375435B2 patent drawing

AI summary

The present disclosure provides a device-to-device service restriction method and a computer readable storage medium. The method includes: receiving a service restriction instruction sent by a second terminal; obtaining access class information of the second terminal; determining whether a service restriction authority of the second terminal is correct according to the access class information; restricting a function of an application program of a first terminal according to the service restriction instruction in response to that the service restriction authority is correct. In certain embodiments of the present disclosure, a function of the first terminal is restricted by using the service restriction. In a scenario where a service of a terminal needs to be restricted, the information security of a security zone is guaranteed and user experience is improved.