Mobile Network Security Proxy for Malicious Data Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile communications networks lack effective security measures to protect subscriber terminal units from various attacks and malicious data transmissions, similar to fixed network-based internet access.

Innovation Solution

A security and filtering device within the mobile communications network provides personalized security services, including real-time data traffic filtering, virus protection, spam filtering, and cost control, with distributed implementation across multiple network nodes, allowing subscribers to adjust settings dynamically and offering proxy-like functionality.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a security and filtering device is implemented in the mobile communications network, then security protection against malicious data and attacks is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security and filtering device is divided into multiple functional components including a filtering component, authentication component, and administrative component. Each component handles specific security functions independently, making the overall system more manageable and easier to implement while maintaining comprehensive security protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security and filtering device provides multiple functions including data filtering, authentication, cost control, and proxy services within a single integrated device. This multi-functionality reduces the need for separate dedicated devices for each security function, thereby managing complexity while enhancing security protection.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If data traffic is filtered and analyzed in real-time, then security against malicious content is improved, but processing time and network latency increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by filtering and analyzing data traffic at the network level before it reaches the subscriber's terminal. Security rules and filtering criteria are pre-configured, allowing rapid real-time processing without requiring complex analysis during data transmission, thus reducing latency while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security and filtering device acts as an intermediary between the network and the subscriber's terminal. It handles security processing centrally, allowing the terminal to operate faster while still benefiting from comprehensive security protection. The intermediary processes data efficiently and forwards it to the destination without significant delay.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If security services are personalized for each subscriber, then security adaptability is improved, but system complexity and management overhead increase

Engineering Contradiction:
Improvesecurity personalizationVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The security settings are made dynamic and adaptable to each subscriber's needs. The administrative component allows subscribers to customize their security preferences, and the system automatically adjusts filtering rules and security parameters in real-time. This dynamic configuration enables high adaptability while managing complexity through automation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes security parameters such as filtering criteria, authentication methods, and data handling rules based on individual subscriber profiles. By parameterizing security settings rather than implementing fixed complex rules for each subscriber, the system achieves personalized security while reducing management overhead through standardized parameter configurations.

Inventive Principle:
Principle #35Parameter changes

4Productivity

If proxy functionality is added to buffer and retrieve data, then performance and data availability are improved, but device complexity and storage requirements increase

Engineering Contradiction:
Improvedata transmission performanceVSAvoiddevice complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The proxy functionality is merged with the existing security and filtering device, combining data buffering, retrieval, and security filtering operations in a single integrated system. This consolidation avoids the need for separate proxy servers and storage systems, thereby improving data availability and transmission performance while managing device complexity through integration.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS7779246B2Content and security proxy in a mobile communications system
Publication Date: 2010.08.17 DEUTSCHE TELEKOM AG
  • US7779246B2 patent drawing
  • US7779246B2 patent drawing

AI summary

A method and device is provided for making available security functions during the transmission of data from and to a subscriber terminal of a mobile communications network. A real-time analysis of the data flow from and to the subscriber terminal is carried out in a device of a network node of the mobile communications network during which data with contents defined beforehand by the subscriber or by a network operator/provider are identified and processed. This results in protecting the terminal and subscriber's devices connected thereto from external attacks.