Private Network Enclaves With Closed SIM Session Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication systems are vulnerable to security risks due to potential attack surfaces in local internet service providers and public communication networks, which can lead to data breaches and infiltration by malware, phishing, and other attacks.
Innovation Solution
Establishing a secure communication session using a closed SIM or eSIM that is logically separate from an open SIM, enabling communication through a private network that bypasses public networks, with provisions for disabling all other functionalities and applications during the session.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If communication is routed through public networks and local internet service providers, then communication accessibility and connectivity are improved, but security vulnerability and exposure to attacks increase
Solution Approach 1:
The system segments communication into two distinct modes: public network communication for general accessibility and private network communication for secure transactions. The device maintains separate network interfaces and communication channels, allowing users to switch between public and private networks based on security requirements. This segmentation enables the system to achieve both broad accessibility through public networks and enhanced security through isolated private network paths.
Solution Approach 2:
The patent introduces a private network as an intermediary layer between communicating devices. Instead of direct public network communication, data is routed through a dedicated private network infrastructure that acts as a mediator. This intermediary private network isolates sensitive communications from public network threats while maintaining connectivity, effectively reducing security vulnerabilities without compromising accessibility.
2Reliability
If separate private network infrastructure is established, then security and privacy are improved, but system complexity and infrastructure requirements increase
Solution Approach 1:
The system implements multi-functionality by enabling devices to operate on both public and private networks using the same hardware infrastructure. The communication device includes integrated circuitry that can dynamically switch between network modes, and the system supports multiple communication protocols simultaneously. This universality allows the system to maintain security through private networks while avoiding the need for entirely separate dedicated hardware, thereby reducing overall system complexity.
Solution Approach 2:
The system employs dynamic network switching capabilities that allow seamless transition between public and private network modes. The communication device can dynamically select the appropriate network path based on security requirements, data type, and communication partner. This dynamic behavior enables the system to adapt to changing security needs without requiring complex manual configuration or multiple static network setups, thereby managing system complexity effectively.
3Reliability
If all other functionalities are disabled during secure session, then security is improved, but ease of operation and user convenience decrease
Solution Approach 1:
The system applies local quality by selectively disabling only those functionalities that pose security risks during private network communication, while maintaining other essential functions. Instead of a blanket disablement of all features, the system precisely controls which applications and network interfaces are active during secure sessions. This targeted approach ensures security is enhanced without unnecessarily compromising user convenience and operational ease.
Solution Approach 2:
The system implements periodic switching between secure and normal operational modes. During private network communication sessions, security-enhancing restrictions are temporarily applied, and after the session concludes, normal functionalities are restored. This periodic alternation between restricted and unrestricted modes allows the system to maintain high security during critical communication periods while preserving user convenience during non-critical periods, effectively balancing security and ease of operation.
Data Source
AI summary
A method and system for enabling secure communication sessions is provided. A request from a first device is sent to a second device that relates to establishing a communication session between the first device and the second device. Each of the devices have an open SIM. The first device also has a closed SIM. An indication of a determination that the second device has a closed SIM is received, where the open and closed SIMs of the devices logically separate and distinct from each other. A communication session is established when the determination is received that the second device has the second device closed SIM. The communication session is established between the closed communication SIMs where the first device open SIM is disabled. Instead of using multiple SIMs, a split VPN tunnel can be used with a single SIM.


