IoT Device APN Verification for Service Restriction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless communication systems lack effective mechanisms to restrict IoT devices to specific services, leading to potential unauthorized communications across unsupported networks, which can compromise security and network resource allocation.

Innovation Solution

Implementing a method where IoT devices obtain APN information, determine if it matches authorized APNs, and prohibit communications if there is a mismatch, ensuring that devices only connect to networks that support the indicated services by using access point name (APN) information during network discovery and provisioning procedures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If IoT devices are allowed to communicate across multiple networks without restriction, then network versatility and connectivity are improved, but security and unauthorized access risks worsen

Engineering Contradiction:
Improvenetwork connectivityVSAvoidunauthorized access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements service-based restriction mechanisms during network discovery and provisioning procedures before actual communications occur. The IoT device determines its services and restricts network access based on service compatibility during the initial connection phase, preventing unauthorized communications before they can compromise security.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If IoT devices are restricted to specific services through APN verification, then security and network resource allocation are improved, but device complexity and provisioning overhead worsen

Engineering Contradiction:
ImprovesecurityVSAvoidprovisioning overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent enables IoT devices to autonomously determine their own services and perform self-verification against available APNs without requiring complex external provisioning infrastructure. The device independently obtains APN information, determines service compatibility, and restricts communications based on matching criteria, reducing the need for manual configuration and external verification systems.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements a feedback mechanism where the IoT device receives APN information from network entities, compares it against its authorized services, and adjusts its communication behavior accordingly. The device obtains service information, verifies APN compatibility, and provides feedback by either establishing or prohibiting communications based on the verification result.

Inventive Principle:
Principle #23Feedback

3Object-affected harmful factors

If APN verification is performed during network discovery, then unauthorized communications are prevented, but network discovery time and provisioning duration worsen

Engineering Contradiction:
Improveunauthorized communicationsVSAvoidnetwork discovery time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The patent performs service determination and APN verification during the initial network discovery and provisioning phase, before any actual data communications occur. By establishing service-based restrictions upfront during network attachment procedures, the system prevents unauthorized communications from occurring in the first place, rather than requiring ongoing verification that would extend communication time.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10849059B2Techniques for verifying service-based wireless communications
Publication Date: 2020.11.24 QUALCOMM INC
  • US10849059B2 patent drawing
  • US10849059B2 patent drawing
  • US10849059B2 patent drawing

AI summary

Aspects described herein relate to obtaining, by a device, access point name (APN) information corresponding to a network entity, the APN information indicating one or more available APNs, determining whether at least one APN of the one or more available APNs indicated in the obtained APN information matches authorized APN information stored in the device, and prohibiting communications for the device that correspond to the at least one APN based at least in part on the determination that the at least one APN is not indicated in the authorized APN information.