Mobile Application Identity Authentication for Wireless Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile device applications lack effective security measures to manage access to wireless network resources, leading to potential rogue applications consuming network resources and causing denial of service attacks or other disruptions.

Innovation Solution

A wireless network system assigns unique identities to mobile device applications, authenticates them, and identifies rogue applications, blocking or disabling them to prevent resource consumption, using a database to maintain lists of approved and disapproved applications, and instructing terminals or application stores to restrict or terminate disapproved applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If mobile device applications are allowed to access wireless network resources without authentication, then network accessibility and ease of operation are improved, but network security and reliability deteriorate due to rogue applications consuming resources and causing denial of service attacks

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary authentication of mobile device applications before granting network access. The network assigns unique identities to applications and authenticates them in advance, maintaining a database of approved and disapproved applications. This preliminary action prevents rogue applications from accessing network resources while allowing legitimate applications to operate freely.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication mechanism between the mobile device application and the wireless network. The network acts as a mediator that verifies application identities against a database of approved applications, allowing or blocking access based on authentication results. This intermediary layer maintains security without preventing legitimate access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication and access control mechanisms are implemented for mobile device applications, then network security is improved, but device complexity and system overhead increase

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The mobile device application performs self-authentication by presenting its unique identity to the network. The application itself is responsible for providing authentication credentials, and the network simply verifies these credentials against its database. This self-service approach reduces the need for complex client-side security infrastructure while maintaining strong authentication.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements a universal authentication framework that handles multiple application types and network access scenarios through a single identity assignment and verification mechanism. The same authentication process applies to all applications regardless of their specific function or the type of network resource they seek to access, simplifying the overall system architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Loss of energy

If rogue applications are blocked after identification, then network resource protection is improved, but loss of time occurs due to the identification and blocking process

Engineering Contradiction:
Improvenetwork resource protectionVSAvoididentification and blocking time
Core Design Contradiction:
Loss of energyVSLoss of time

Solution Approach 1:

The system performs preliminary authentication and identification of applications before they can access network resources. By checking application identities against the database of approved applications in advance, the system prevents rogue applications from consuming network resources in the first place, rather than having to detect and block them after resource consumption begins.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The network maintains a database of approved and disapproved applications that serves as feedback information. When an application requests network access, the system queries this database to determine whether to allow or block access. This feedback mechanism enables rapid decision-making without requiring complex real-time analysis of application behavior.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3651500B1Managing mobile device applications in a wireless network
Publication Date: 2023.09.20 BLACKBERRY LTD
  • EP3651500B1 patent drawingFigure 1
  • EP3651500B1 patent drawingFigure 2
  • EP3651500B1 patent drawingFigure 3

AI summary

A method for managing mobile device applications on a mobile device, the method comprising receiving, at a mobile device, information identifying a mobile device application, the information indicating that the mobile device application is disapproved for communication in a wireless network and indicating a reason for disabling access to the wireless network, the information received from a wireless network operator system associated with the wireless network and disabling access to the wireless network by the mobile device application at the mobile device.