Network Access Control Module for Dynamic IP Traffic Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network access control mechanisms in telecommunications systems are limited in managing IP traffic and Network Address Translation (NAT) within User Equipment (UE), especially in pre-provisioning and dynamically controlling network access for IP-based applications, which can lead to security breaches and unauthorized access.

Innovation Solution

The implementation of a system and method that utilizes a subscriber module in UE to store and manage control parameters for network access control, including NAT, filtering, and Quality of Service (QoS) settings, allowing operators to remotely configure and update these parameters to restrict access to specific applications and services based on predefined policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If NAT and filtering functions are implemented in UE to manage local IP sub-network, then network security and address management are improved, but device complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a Network Access Control (NAC) module as an intermediary component within the UE that specifically handles NAT and filtering functions. This modular approach isolates the complexity to a dedicated subsystem while maintaining overall network security, rather than distributing complex control logic across the entire device architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The UE architecture is segmented into distinct functional modules including the NAC module for address translation and filtering, the application layer for IP-based services, and the network interface. This segmentation allows each module to perform its specific function independently, managing complexity through functional decomposition.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If control parameters are stored locally in UE, then network access control flexibility is improved, but remote management capability deteriorates

Engineering Contradiction:
Improvenetwork access control flexibilityVSAvoidremote management capability
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The control parameters stored in the UE are designed to be dynamically updateable. The NAC module can receive remote provisioning commands to modify its filtering rules and NAT configurations without requiring physical access to the device. This dynamic characteristic allows the system to maintain local flexibility while enabling remote management through wireless updates.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback mechanisms where the NAC module reports its current configuration state and operational status to remote management systems. This allows operators to monitor and adjust control parameters remotely while maintaining the flexibility of local enforcement, creating a closed-loop management system.

Inventive Principle:
Principle #23Feedback

3Reliability

If firewall application is installed to prevent malicious application access, then network security is improved, but device complexity and user operation difficulty increase

Engineering Contradiction:
Improvenetwork securityVSAvoiduser operation difficulty
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The NAC module operates autonomously to enforce network access control policies without requiring direct user intervention. It automatically monitors IP traffic, applies filtering rules, and blocks malicious applications based on pre-configured parameters. This self-service capability maintains high security while minimizing user operational burden.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Control parameters and filtering rules are pre-configured in the NAC module before network operations begin. This preliminary configuration allows the firewall functionality to operate immediately upon deployment, preventing malicious access from the outset without requiring users to manually configure security settings or respond to security events.

Inventive Principle:
Principle #10Preliminary action

4Productivity

If NAT is used to map multiple local addresses to single routable IP, then network address management is improved, but loss of information about internal network structure occurs

Engineering Contradiction:
Improvenetwork address management efficiencyVSAvoidinternal network structure information
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent replaces traditional NAT address mapping with a more sophisticated NAC-based approach that maintains detailed information about internal network structures. Instead of simple one-to-one or many-to-one address translation, the system uses structured control parameters that preserve knowledge of local IP sub-network topology, enabling both efficient address management and internal network awareness.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS8923308B2Network access control
Publication Date: 2014.12.30 LENOVO INNOVATIONS LTD (HONG KONG)
  • US8923308B2 patent drawing
  • US8923308B2 patent drawing
  • US8923308B2 patent drawing

AI summary

The invention provides for telecommunications user equipment including network access control means operative responsive to control parameters and further including a subscriber module accessible remote from the user equipment and arranged to store the said control parameters for use by the said access control means, and wherein the subscriber module can comprise a mobile equipment offering gateway functionality such as between a public access network and a local IP link.