Layered Security for Inmate Wireless Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Correctional facilities face challenges in securing mobile devices issued to inmates, as they can be tampered with or used for unsanctioned activities due to advances in communication technologies, posing security risks through physical alteration, software vulnerabilities, and unauthorized network access.
Innovation Solution
A layered security system is implemented on mobile devices and wireless network infrastructure, comprising hardware barriers, application and OS security measures, wireless intrusion prevention, and access control lists to prevent unsanctioned use, with each layer providing additional protection if previous barriers are bypassed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If mobile devices are issued to inmates for communication, then communication capability is improved, but security risk increases due to potential tampering and unauthorized use
Solution Approach 1:
The security system is divided into multiple independent layers: hardware barrier layer, application layer, operating system layer, and network layer. Each layer provides independent security functions, so if one layer is compromised, other layers continue to provide protection. This segmentation resolves the contradiction by maintaining security (reducing harmful factors) while allowing mobile device communication functionality to operate.
Solution Approach 2:
A hardware barrier is introduced as an intermediary component between the inmate and the mobile device. This physical barrier (such as a locked case or cage) mediates access to the device, preventing direct tampering while still allowing authorized communication functions to proceed when the device is properly accessed through the barrier.
2Object-affected harmful factors
If security measures are increased to prevent tampering, then security risk is reduced, but device complexity increases
Solution Approach 1:
The security system is divided into multiple independent layers: hardware barrier layer, application layer, operating system layer, and network layer. Each layer provides independent security functions, so if one layer is compromised, other layers continue to provide protection. This segmentation resolves the contradiction by maintaining security (reducing harmful factors) while allowing mobile device communication functionality to operate.
Solution Approach 2:
Security is implemented across multiple dimensions rather than a single complex barrier: physical dimension (hardware barrier), software application dimension, operating system dimension, and network communication dimension. This multi-dimensional approach provides comprehensive security without requiring any single component to be overly complex.
3Object-affected harmful factors
If physical access is restricted to prevent hardware tampering, then security is improved, but ease of operation deteriorates
Solution Approach 1:
A hardware barrier is introduced as an intermediary component between the inmate and the mobile device. This physical barrier (such as a locked case or cage) mediates access to the device, preventing direct tampering while still allowing authorized communication functions to proceed when the device is properly accessed through the barrier.
Solution Approach 2:
The hardware barrier is pre-configured with authorized access mechanisms (such as key locks, biometric authentication, or scheduled access codes). This preliminary setup allows legitimate users to access the device easily through pre-arranged methods while preventing unauthorized access and tampering, thus maintaining both security and ease of operation for authorized users.
Data Source
AI summary
A layered security suite is disclosed wherein multiple security barriers that prevent the unsanctioned use of a mobile device issued by a controlled-environment facility. The security barriers are implemented along multiple points within the communication path between the mobile device with outside networks, including on the mobile device, on wireless access points that serve data traffic for the mobile device, and a firewall device that monitors all data coming to and from the wireless access points. The barriers on the mobile device prevent the user from performing unsanctioned application and settings changes, including both software and hardware components, while the barrier on the wireless access point detects and prevents unauthorized connections between mobile devices and unsanctioned wireless access points. The firewall device discards packets with unsanctioned internet addresses. The layers work in concert to prevent all manner of tampering with the mobile device by members of the controlled-environment facility.


