MPLS Network Tethered Device Authorization via Intermediate Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The integration of secure mode systems with Multi-Protocol Label Switching (MPLS) networks to provide secure access to tethering devices is inefficient and ineffective, as existing methods fail to properly authorize and isolate unauthorized tethered communication devices, posing security threats.
Innovation Solution
A communication network architecture that processes intermediate and end-point security data to authorize devices, using secure mode systems to generate and transfer security data, including shared secret keys and random numbers, to determine authorization and isolate unauthorized tethered devices, ensuring secure data transfer sessions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If tethered devices are allowed to communicate through end-point devices on MPLS networks, then network functionality and device connectivity are improved, but security risks and unauthorized access increase
Solution Approach 1:
The system performs preliminary security verification by checking tethering data against authorized device lists before allowing any data transfer. The network verifies end-point device authorization and tethered device legitimacy in advance, preventing unauthorized devices from accessing the network. This preliminary action ensures that security checks are completed before data transfer begins, resolving the contradiction by enabling connectivity only for pre-authorized devices.
Solution Approach 2:
The patent introduces an intermediary verification mechanism where the network acts as a mediator between end-point devices and tethered devices. The system intercepts and verifies tethering data through intermediate access nodes, checking against authorized device lists maintained by the network. This intermediary layer enables legitimate tethered devices to communicate while blocking unauthorized ones, thus improving connectivity without compromising security.
2Reliability
If security verification processes are implemented for tethered devices, then network security is improved, but processing time and system complexity increase
Solution Approach 1:
The system performs security verification in advance by maintaining pre-configured lists of authorized end-point devices and their permitted tethered devices. When a tethering request occurs, the system simply checks whether the device appears in the authorized list rather than performing complex real-time analysis. This preliminary preparation of authorization lists significantly reduces processing time while maintaining high security standards.
Solution Approach 2:
The network system automatically verifies tethering data against its authorized device lists without requiring manual intervention or complex external validation processes. The intermediate access nodes and network automatically perform the verification and make authorization decisions based on pre-configured policies, reducing both processing time and operational complexity while maintaining reliable security checks.
3Object-affected harmful factors
If unauthorized tethered devices are isolated from the network, then security threats are reduced, but legitimate device connectivity may be affected
Solution Approach 1:
The network acts as an intermediary that intelligently distinguishes between authorized and unauthorized tethered devices. By verifying tethering data against maintained lists of authorized devices, the system can selectively isolate only unauthorized devices while allowing legitimate devices to communicate freely. This intermediary verification process ensures that security isolation does not mistakenly block legitimate connectivity, resolving the contradiction between threat reduction and connectivity preservation.
Solution Approach 2:
The system applies different treatment to different devices based on their authorization status. Authorized end-point devices and their permitted tethered devices receive full network access, while unauthorized devices are isolated. This localized quality control, applied at each network node through verification of tethering data, ensures that security measures are precisely targeted at threats without affecting legitimate device connectivity.
Data Source
AI summary
A communication network processes intermediate security data from intermediate access nodes on a communication path between a network access node and an end-point device to determine if the intermediate access nodes are authorized. If the intermediate access nodes are authorized, then the network processes end-point security data from the end-point device to determine if the end-point device is authorized. If the end-point device is authorized, then the network processes end-point tethering data from the end-point device to determine if any tethered communication devices are coupled to the end-point device. If the end-point device is not coupled to any tethered communication devices, then the network authorizes a data transfer session for the end-point device over the communication path. If the end-point device is coupled to a tethered communication device, then the network denies authorization for the data transfer session over the communication path for the end-point device.


