Location-Based Service Access Control in Untrusted Wireless Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless communication systems lack effective mechanisms to control access to cellular network services based on the geographic location of a device when connecting through untrusted wireless networks, leading to potential security and regulatory compliance issues.

Innovation Solution

The implementation of methods and apparatus that allow wireless communication devices to provide geographic location information to establish secure tunnels with evolved packet data gateways, enabling selective control over access to services by determining whether to allow or disallow connections to specific access point names based on the device's location, using protocols like IKEv2 and SIP registration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If wireless communication devices connect through untrusted wireless networks to access cellular services, then service availability and connectivity are improved, but security and regulatory compliance are compromised

Engineering Contradiction:
Improveservice availabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements location-specific service access control by determining the geographic location of the wireless communication device and selectively allowing or disallowing access to specific cellular services based on that location. Different services are granted or denied depending on the local geographic context, enabling fine-grained control over service availability while maintaining security requirements for each location

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent introduces an evolved packet data gateway (ePDG) as an intermediary that acts as a trusted network element between the untrusted wireless network and the cellular core network. The ePDG receives location information from the device, determines which services should be accessible based on location policies, and controls the establishment of secure tunnels to appropriate access point names (APNs), thereby mediating security and access control

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If location-based service control is implemented through untrusted networks, then security and regulatory compliance are improved, but system complexity increases

Engineering Contradiction:
Improveregulatory complianceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent enables the wireless communication device to self-report its geographic location information directly to the ePDG without requiring complex location determination infrastructure in the network. The device uses its own positioning capabilities (such as GPS or network-based location) and provides this information autonomously, simplifying the overall system architecture while maintaining location-based control capabilities

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs location-based service access control decisions during the initial secure tunnel establishment phase between the device and the ePDG. By determining whether to allow access to specific APNs before the device attempts to access services, the system preemptively enforces location policies, avoiding the need for complex ongoing service-level access control mechanisms

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10057767B2Methods and apparatus to support location specific control of access to services through untrusted wireless networks
Publication Date: 2018.08.21 APPLE INC
  • US10057767B2 patent drawing
  • US10057767B2 patent drawing
  • US10057767B2 patent drawing

AI summary

Apparatus and methods to support location specific control to allow and/or disallow access to services through untrusted wireless networks by a wireless communication device are disclosed. One or more network elements obtain a location of the wireless communication device and selectively allow and/or disallow access to one or more cellular network services and/or one or more access point names (APNs) based on the location of the wireless communication device when connecting through an untrusted wireless network.