Group Policy Access Control for Cellular Modem Proximity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless cellular networks lack effective support for managing multiple devices connected to a single user, leading to challenges in preventing abuse such as device sharing or lending, especially when these devices access general internet services, and there is a need for reliable charging models that balance operator revenue and user acceptance.

Innovation Solution

A method and apparatus in a wireless telecommunication network that determines if a mobile device is associated with other devices and controls network access based on defined policies, including geographic proximity, aggregate bitrate, and data usage, to enforce usage restrictions and prevent abuse by limiting or preventing access when policies are breached.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple devices are allowed to connect to the network under a single user subscription, then device versatility and user convenience are improved, but the risk of subscription abuse (lending/selling devices) increases

Engineering Contradiction:
Improvedevice connectivityVSAvoidsubscription security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system continuously monitors the physical proximity of multiple devices associated with a single user by measuring signal strength or distance metrics. When devices move beyond a threshold distance from each other or from the user's registered location, the system detects this deviation and responds by revoking network access for the suspicious device, thereby preventing subscription abuse while allowing legitimate multi-device usage.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an intermediary verification mechanism that acts as a mediator between the network and multiple user devices. This intermediary system validates the legitimacy of each device's connection by checking proximity relationships, serving as a trust intermediary that enables multi-device connectivity without compromising subscription security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If geographic proximity verification is implemented to prevent device sharing, then subscription security is improved, but system complexity increases

Engineering Contradiction:
Improveabuse preventionVSAvoidnetwork management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex proximity verification logic from the core network infrastructure and implements it as a separate, modular function. By isolating the geographic verification mechanism into a dedicated component that handles only distance calculation and threshold comparison, the system achieves effective abuse prevention while minimizing the complexity burden on the overall network management architecture.

Inventive Principle:
Principle #2Taking out (Extraction)

3Difficulty of detecting and measuring

If real-time monitoring of device proximity is performed, then abuse detection capability is improved, but network overhead and processing requirements increase

Engineering Contradiction:
Improveabuse detectionVSAvoidnetwork processing load
Core Design Contradiction:
Difficulty of detecting and measuringVSUse of energy by moving object

Solution Approach 1:

Instead of continuously monitoring all devices at maximum precision, the system implements partial monitoring by checking proximity only when triggered by specific events such as connection attempts, location updates, or suspicious activity patterns. This event-driven approach provides sufficient abuse detection capability while significantly reducing the overall processing load and energy consumption of the network system.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9084175B2Access control according to a policy defined for a group of associated electronic devices comprising a cellular modem
Publication Date: 2015.07.14 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US9084175B2 patent drawing
  • US9084175B2 patent drawing
  • US9084175B2 patent drawing

AI summary

Access to a telecommunications network can be controlled according to a policy defined for a plurality of user equipment devices associated with the same user. When two user equipment devices are allowed to operate in parallel under the same subscription, the policy may define a distance between the user equipment devices. When the actual distance between the user equipment devices conforms with the distance defined in the policy, one or more network nodes serving one of the user equipment devices can be assigned to replace a network node serving the other user equipment device to prevent abuse of the end user's subscription or to optimize performance, so as to consolidate service.