Secure Device Data Record Processing Agents for Wireless Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless and wireline access networks face capacity constraints due to increasing user demands for high-bandwidth applications, leading to degraded network service experiences and rising service provider costs.

Innovation Solution

Implementation of a secure device data record (DDR) processing system within wireless communication devices, which monitors and reports service usage securely, using a processor configured with a secure execution environment to generate and manage DDRs, ensuring compliance with access policies and detecting malicious activity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If network capacity is increased to meet growing digital networking demand, then user capacity constraint is reduced, but service provider costs increase

Engineering Contradiction:
Improvenetwork capacityVSAvoidservice provider costs
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The system implements self-service through automated service usage monitoring and billing processes. The service provider system automatically tracks resource consumption, generates usage records, and processes billing without requiring manual intervention, thereby reducing operational costs while maintaining high network capacity

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system employs feedback mechanisms by continuously monitoring service usage and providing real-time information about resource consumption patterns. This enables dynamic resource allocation and optimization, allowing the network to efficiently manage capacity while controlling costs through data-driven decisions

Inventive Principle:
Principle #23Feedback

2Reliability

If secure execution environment is implemented for DDR processing, then device-based access policies are secured, but device complexity increases

Engineering Contradiction:
Improveaccess policy securityVSAvoiddevice structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the device architecture by implementing a dedicated secure execution environment that is separated from the main processor operations. This secure enclave is specifically designed for DDR processing and access control functions, isolating critical security operations from the rest of the system to enhance security without significantly complicating the overall device structure

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure execution environment acts as an intermediary between the processor and the access policy enforcement mechanisms. It serves as a trusted mediator that verifies and enforces access policies without requiring the main processor to directly handle security-critical operations, thereby simplifying the integration of security features into the existing device architecture

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11665186B2Communications device with secure data path processing agents
Publication Date: 2023.05.30 HEADWATER RESEARCH LLC
  • US11665186B2 patent drawing
  • US11665186B2 patent drawing
  • US11665186B2 patent drawing

AI summary

Secure device data records (DDRs) are provided. In some embodiments, a system for secure DDRs includes a processor of a wireless communication device for wireless communication with a wireless network, in which the processor is configured with a secure execution environment, and in which the secure execution environment is configured to: monitor service usage of the wireless communication device with the wireless network; and generate a plurality of device data records of the monitored service usage of the wireless communication device with the wireless network, in which each device data record is associated with a unique sequence order identifier; and a memory coupled to the processor and configured to provide the processor with instructions. In some embodiments, the secure execution environment is located in an application processor, in a modem processor, and/or in a subscriber identity module (SIM).