GPRS Security Enforcement via APN Restrictions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems lack a satisfactory mechanism to ensure secure remote access to corporate networks, particularly when user equipment has multiple active Primary PDP Contexts, as they can act as routers for packet connections, exposing security loopholes and risking unauthorized access, especially in scenarios involving GPRS and other access methods.
Innovation Solution
A system that provides network-based security mechanisms by using gateway packet data nodes and packet data support nodes to enforce security indications, allowing only secure connections through security markings and APN restrictions, ensuring that user equipment does not act as a router between connections and preventing unauthorized access, even during roaming or when multiple access networks are used.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple Primary PDP Contexts are allowed to be active simultaneously, then user equipment can establish multiple connections for diverse access needs, but security is compromised as user equipment may act as a router for packets between connections
Solution Approach 1:
The patent introduces a security enforcement mechanism as an intermediary component that sits between the user equipment and the network. This mechanism monitors and controls packet routing decisions, preventing user equipment from acting as a router between different PDP contexts while still allowing multiple connections to be established. The intermediary enforces security policies without blocking legitimate multi-connection functionality.
Solution Approach 2:
The patent implements feedback mechanisms where the network continuously monitors the behavior of user equipment with multiple active PDP contexts. When potential security violations are detected (such as routing packets between different contexts), the network sends feedback signals to correct the behavior or terminate the problematic connection. This feedback loop enables the system to maintain security while preserving connection diversity.
2Object-affected harmful factors
If network-based security mechanisms are implemented to control access, then security is improved, but system complexity increases due to additional configuration and enforcement requirements
Solution Approach 1:
The patent segments the security enforcement function into distinct components: a security policy management part that defines access control rules, an enforcement part that implements the policies at the network border, and a monitoring part that tracks compliance. This segmentation allows each component to be optimized independently and simplifies the overall system architecture compared to a monolithic security solution.
Solution Approach 2:
The patent designs the security enforcement mechanism to serve multiple functions: it controls access to corporate networks, monitors packet routing behavior, enforces security policies, and provides audit capabilities. By making the system multi-functional, the patent reduces the need for separate dedicated security components, thereby managing complexity while improving security.
3Object-affected harmful factors
If access control restrictions are imposed on PDP contexts, then unauthorized access is prevented, but legitimate access may be blocked if restrictions are too stringent
Solution Approach 1:
The patent implements dynamic access control policies that can adapt to the specific needs of different users, contexts, and time periods. Rather than using static binary allow/denied rules, the system dynamically evaluates access requests based on current conditions such as user identity, destination network, packet characteristics, and temporal information. This dynamic approach prevents unauthorized access while maintaining ease of operation for legitimate users.
Solution Approach 2:
The patent changes the parameters of access control from simple binary decisions to multi-dimensional evaluation criteria. The system considers multiple parameters simultaneously: user authentication status, destination network type, packet header characteristics, routing path, and temporal context. By changing from single-parameter to multi-parameter decision-making, the system achieves both security and operational ease.
Data Source
AI summary
The present invention relates to a system nodes and a method for enhancing security of end user station access to Internet and intranet(s), e.g. of corporate access, over access network access points, with gateway packet data nodes and packet data support nodes. It further includes security indication providing means for providing an (corporate) access point with a security criterium indication (defining security) and for distributing said security indication to a packet data support node. A security enforcement mechanism is provided in the packet data support node, the security enforcement mechanism at least providing for preventing all other traffic not fulfilling the security criterium conflicting the security indicated access point when there is a connection requiring security over the security indicated access point, at least until the last packet of the security indicated access point connection has been sent.


