Dual-Mode Service Access Control via Location Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cellular network technologies, such as UMA, face challenges in authenticating and authorizing dual-mode devices to prevent unauthorized access to broadband networks, leading to revenue loss for service providers and complications with E911 services due to the inability to determine the physical location of handsets.
Innovation Solution
A system that receives an IP data packet from a multi-mode device, determines the geographic location associated with the public originating IP address, and compares it with authorized locations to decide whether to allow unlicensed mobile access, routing data through either unlicensed wireless or cellular networks based on authorization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If UMA technology allows dual-mode devices to connect to unlicensed wireless networks for broadband access, then service versatility and user convenience are improved, but unauthorized access and revenue loss occur because the system cannot validate the physical location of handsets
Solution Approach 1:
The patent introduces an intermediary validation system that acts as a mediator between the UMA network controller and the access point. This intermediary validates the physical location of the handset by checking whether the access point's identifier matches the subscriber's authorized location data, thereby preventing unauthorized access while maintaining service versatility
Solution Approach 2:
The system performs preliminary validation of the access point's identifier before granting UMA service access. By validating the physical location in advance through comparing the access point identifier with authorized location data, the system prevents unauthorized connections before they can occur, rather than detecting them after the fact
2Ease of operation
If the access point is made transparent to UMA technology to simplify connection establishment, then ease of operation is improved, but the ability to determine physical location and prevent fraud is lost
Solution Approach 1:
The patent extracts the validation function from the access point itself and places it in the network controller. The access point remains transparent for connection establishment, while the network controller separately validates the access point identifier against authorized location data, thus maintaining both ease of operation and location detection capability
Solution Approach 2:
An intermediary validation mechanism is introduced that separates the connection establishment function from the location validation function. The access point handles connections transparently while the intermediary validates the physical location by comparing identifiers, thus resolving the contradiction between operational simplicity and detection capability
3Adaptability or versatility
If subscribers can use any access point with IP connection for UMA service, then service accessibility is improved, but E911 location accuracy and billing accuracy deteriorate
Solution Approach 1:
The system performs preliminary validation of the access point identifier against the subscriber's authorized location data before granting service. This ensures that while subscribers can access service at any authorized location, the system maintains accurate location information for E911 and billing purposes by verifying the location in advance
Solution Approach 2:
The system implements feedback by continuously validating the access point identifier against authorized location data and updating the subscriber's location information accordingly. This feedback mechanism ensures location accuracy for E911 and billing while maintaining service accessibility at authorized locations
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A system that facilitates controlling network access comprises a lookup component (108) that determines a geographic location associated with a public originating IP address, wherein the public originating IP address is associated with a request for dual mode services made by a dual mode client (104). A comparison component (114) compares the determined geographic location with a retained geographic location associated with the dual mode client and determines whether to enable dual mode services based at least in part upon the comparison.