Secure Mobile Communication Relay with Baseband Firewall
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile communication relays in indoor environments are vulnerable to security breaches, particularly with the shift to wireless digital data services, as they lack robust security measures to protect against unauthorized data transmission and malicious code infiltration via smartphones.
Innovation Solution
A secure mobile communication relay system equipped with a baseband processing unit, control unit, storage unit, and firewall function unit that analyzes and filters mobile communication signals based on predefined security policies, allowing or rejecting data transmission and terminating services if security policies are violated.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a mobile communication relay is deployed in an indoor environment to provide mobile communication service, then signal coverage in shadow areas is improved, but security vulnerability increases due to lack of robust security measures
Solution Approach 1:
The patent segments the security function from the general signal relaying function by introducing a dedicated firewall function unit. This unit operates independently to analyze packet data and enforce security policies, while the baseband processing unit continues to handle signal modulation and demodulation. This segmentation allows the relay to maintain signal coverage capabilities while adding robust security measures.
Solution Approach 2:
The firewall function unit acts as an intermediary between the baseband processing unit and the network. It intercepts packet data flowing through the relay, performs security analysis against stored security policies, and determines whether to permit or reject data transmission. This intermediary approach enables security enforcement without disrupting the core signal relaying function.
2Reliability
If firewall security analysis is performed on all packet data, then security protection is improved, but communication overhead and processing time increase
Solution Approach 1:
The patent applies partial action by having the firewall function unit selectively analyze packet data based on security policies rather than uniformly processing all data. The control unit directs packet data to the firewall function unit only when security policy violation is suspected or when configured to do so, as indicated by firewall selection information stored in the storage unit. This approach provides security protection where needed while minimizing unnecessary processing overhead.
Solution Approach 2:
The firewall function unit autonomously determines whether packet data violates security policies by comparing against security policies stored in the storage unit. The control unit operates based on firewall selection information to provide packet data to the firewall function unit or external firewall equipment, enabling the system to self-manage security analysis without requiring constant external intervention, thus reducing communication overhead.
3Reliability
If security policies are strictly enforced to block malicious codes, then security reliability is improved, but legitimate data transmission may be rejected increasing loss of information
Solution Approach 1:
The patent implements feedback through the control unit, which receives analysis results from the firewall function unit and adjusts its behavior accordingly. When the firewall function unit determines that packet data does not violate security policies, the control unit permits relay of the data. When violations are detected, the control unit rejects the data and can transmit service option negotiation rejection signals or PDP context deactivation request signals to the terminal. This feedback mechanism ensures that legitimate data transmission is preserved while malicious codes are blocked.
Data Source
AI summary
The secure mobile communication relay of the present invention may comprise: a baseband processing unit for the baseband modulation/demodulation of the mobile communication signal transmitted between a terminal and a mobile communication network base station so as to extract baseband data; a control unit for analyzing the baseband data and permitting or rejecting the relay of the baseband data based on the result of a determination of whether or not a set security policy has been violated; a storage unit for storing information for setting the security policy; and a firewall function unit for determining, based on the instructions of the control unit, whether or not the packet data included in the baseband data violates the security policy.


