GPRS Security Enforcement via APN Restrictions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack a satisfactory mechanism to ensure secure remote access to corporate networks, particularly when user equipment has multiple active Primary PDP Contexts, as they can act as routers for packet connections, exposing security loopholes and risking unauthorized access, especially in scenarios involving GPRS and other access methods.

Innovation Solution

A system that provides network-based security mechanisms by using gateway packet data nodes and packet data support nodes to enforce security indications, allowing only secure connections through security markings and APN restrictions, ensuring that user equipment does not act as a router between connections and preventing unauthorized access, even during roaming or when multiple access networks are used.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple Primary PDP Contexts are allowed to be active simultaneously, then user equipment can establish multiple connections for diverse access needs, but security is compromised as user equipment may act as a router for packets between connections

Engineering Contradiction:
Improveconnection diversityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a security enforcement mechanism as an intermediary component that sits between the user equipment and the network. This mechanism monitors and controls packet routing decisions, preventing user equipment from acting as a router between different PDP contexts while still allowing multiple connections to be established. The intermediary enforces security policies without blocking legitimate multi-connection functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements feedback mechanisms where the network continuously monitors the behavior of user equipment with multiple active PDP contexts. When potential security violations are detected (such as routing packets between different contexts), the network sends feedback signals to correct the behavior or terminate the problematic connection. This feedback loop enables the system to maintain security while preserving connection diversity.

Inventive Principle:
Principle #23Feedback

2Object-affected harmful factors

If network-based security mechanisms are implemented to control access, then security is improved, but system complexity increases due to additional configuration and enforcement requirements

Engineering Contradiction:
Improveunauthorized accessVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent segments the security enforcement function into distinct components: a security policy management part that defines access control rules, an enforcement part that implements the policies at the network border, and a monitoring part that tracks compliance. This segmentation allows each component to be optimized independently and simplifies the overall system architecture compared to a monolithic security solution.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent designs the security enforcement mechanism to serve multiple functions: it controls access to corporate networks, monitors packet routing behavior, enforces security policies, and provides audit capabilities. By making the system multi-functional, the patent reduces the need for separate dedicated security components, thereby managing complexity while improving security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Object-affected harmful factors

If access control restrictions are imposed on PDP contexts, then unauthorized access is prevented, but legitimate access may be blocked if restrictions are too stringent

Engineering Contradiction:
Improveunauthorized accessVSAvoidaccess availability
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent implements dynamic access control policies that can adapt to the specific needs of different users, contexts, and time periods. Rather than using static binary allow/denied rules, the system dynamically evaluates access requests based on current conditions such as user identity, destination network, packet characteristics, and temporal information. This dynamic approach prevents unauthorized access while maintaining ease of operation for legitimate users.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameters of access control from simple binary decisions to multi-dimensional evaluation criteria. The system considers multiple parameters simultaneously: user authentication status, destination network type, packet header characteristics, routing path, and temporal context. By changing from single-parameter to multi-parameter decision-making, the system achieves both security and operational ease.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS7949769B2Arrangements and methods relating to security in networks supporting communication of packet data
Publication Date: 2011.05.24 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US7949769B2 patent drawing
  • US7949769B2 patent drawing
  • US7949769B2 patent drawing

AI summary

The present invention relates to a system nodes and a method for enhancing security of end user station access to Internet and intranet(s), e.g. of corporate access, over access network access points, with gateway packet data nodes and packet data support nodes. It further includes security indication providing means for providing an (corporate) access point with a security criterium indication (defining security) and for distributing said security indication to a packet data support node. A security enforcement mechanism is provided in the packet data support node, the security enforcement mechanism at least providing for preventing all other traffic not fulfilling the security criterium conflicting the security indicated access point when there is a connection requiring security over the security indicated access point, at least until the last packet of the security indicated access point connection has been sent.