Mobile Site Communication Gateway for Core Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The security of a core network system is compromised when servers at a site providing mobile communication services are cracked, despite the presence of firewalls, due to direct communication with mobile terminals.

Innovation Solution

A communication system with a site antenna and processors executes signal, relay, and firewall processes in an intermediate segment, including a first firewall to detect anomalies and manage virtual processes, enhancing security by managing application services through a management process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If servers at a site directly communicate with mobile terminals, then service provision is enabled, but security of the core network system deteriorates when servers are cracked

Engineering Contradiction:
Improveservice provisionVSAvoidsecurity of core network system
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a gateway device as an intermediary component between the server and mobile terminal. This gateway device includes a firewall function that filters and controls communication packets, allowing legitimate service communication while blocking malicious access. The gateway acts as a mediator that enables service provision while protecting the server and core network system from security threats.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a firewall is installed to protect the core network system, then security is improved, but communication efficiency deteriorates due to additional filtering processes

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The gateway device performs preliminary filtering and validation of communication packets before they reach the server or core network system. By pre-processing and filtering packets at the gateway level, the system reduces the burden on downstream components and prevents malicious traffic from consuming core network resources, thereby maintaining security while minimizing efficiency loss.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If direct connection between site servers and Internet is established, then service accessibility is improved, but vulnerability to external attacks increases

Engineering Contradiction:
Improveservice accessibilityVSAvoidvulnerability to external attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The gateway device serves as an intermediary between the Internet and site servers, enabling service accessibility while protecting against external attacks. The gateway's firewall function monitors and controls incoming traffic from the Internet, allowing legitimate service requests while blocking malicious attacks, thus resolving the contradiction between accessibility and vulnerability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12495079B2Communication management for location connected to mobile communication network
Publication Date: 2025.12.09 RAKUTEN MOBILE INC
  • US12495079B2 patent drawing
  • US12495079B2 patent drawing
  • US12495079B2 patent drawing

AI summary

To increase security when a communication system of a communication operator communicates to and from a server at a site, the communication system executes an application process in an intermediate segment (Step S206), executes a signal process of acquiring upstream data from a signal from a communication terminal via a site antenna (Step S201), executes a relay process of relaying communication between the communication terminal and the application process in an internal network which is communicable to and from a core network system (Step S202), detects an anomaly in communication between the internal network and the intermediate segment (Step S203), and manages the signal process, the relay process, and a virtual process unit of the application process under the control of the communication operator (Step S208).