Dynamic Firewall Role Provisioning for Mobile Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless communication networks face security issues such as Botnet, DDOS, and Malware due to the increasing number of user devices, which existing technologies have not adequately addressed without significant hardware investments.

Innovation Solution

A dynamic provisioning system where a central server creates a local network group and selects a user device to act as a firewall, using short-range wireless communication to enhance security, reduce network congestion, and lower power consumption by routing communication through the provisioned firewall device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network security infrastructure is used, then network security can be provided, but substantial hardware investment is required

Engineering Contradiction:
Improvenetwork securityVSAvoidhardware investment
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

User devices provision themselves with firewall roles dynamically. The system allows devices to autonomously determine their own security needs and select appropriate firewall roles without requiring centralized hardware deployment or manual configuration, thereby eliminating substantial hardware investment while maintaining network security

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Firewall roles are dynamically assigned and reassigned based on real-time network conditions, device capabilities, and security threats. This dynamic provisioning allows the network to adapt its security infrastructure flexibly without requiring fixed hardware installations, reducing capital expenditure while maintaining reliable security protection

Inventive Principle:
Principle #15Dynamics

2Productivity

If more user devices are added to the network, then network coverage and connectivity are improved, but security risks and network congestion increase

Engineering Contradiction:
Improvenetwork connectivityVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The network is segmented into multiple local network groups, each with its own provisioned firewall device. This segmentation isolates security threats within specific groups, preventing lateral movement of attacks across the entire network, thereby maintaining high connectivity while reducing security risks through localized containment

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Provisioned firewall devices act as intermediaries between user devices and external networks. These firewalls filter and control traffic flows, blocking malicious packets while allowing legitimate communications, thus enabling expanded network coverage without proportionally increasing security risks

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If centralized firewall processing is used, then network security is maintained, but network congestion and power consumption increase

Engineering Contradiction:
Improvenetwork securityVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

Firewall processing is distributed to local user devices within each network group rather than centralized. Each provisioned device performs security functions locally for its own group, reducing the energy burden on any single device and minimizing network traffic congestion while maintaining comprehensive security coverage

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically selects and rotates firewall roles among different user devices based on their current power status, processing capabilities, and network conditions. This dynamic distribution prevents any single device from excessive power consumption and reduces overall network congestion by balancing the security processing load across multiple participants

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10257165B2Dynamic provisioning of a firewall role to user devices
Publication Date: 2019.04.09 T MOBILE US INC
  • US10257165B2 patent drawing
  • US10257165B2 patent drawing
  • US10257165B2 patent drawing

AI summary

A system and method of providing security service to a mobile traffic network are provided. A local network group comprising a plurality of user devices that are subscribed to the security service is created. One of the plurality of the user devices is selected to act as a firewall for the plurality of user devices of the local network group. The selected user device is provisioned to act as a firewall for the local network group. A message is sent to the plurally of user devices of the local network group to route communication through the selected user device via a short range wireless communication technology.