Secure Mobile Communication Relay with Baseband Firewall

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile communication relays in indoor environments are vulnerable to security breaches, particularly with the shift to wireless digital data services, as they lack robust security measures to protect against unauthorized data transmission and malicious code infiltration via smartphones.

Innovation Solution

A secure mobile communication relay system equipped with a baseband processing unit, control unit, storage unit, and firewall function unit that analyzes and filters mobile communication signals based on predefined security policies, allowing or rejecting data transmission and terminating services if security policies are violated.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a mobile communication relay is deployed in an indoor environment to provide mobile communication service, then signal coverage in shadow areas is improved, but security vulnerability increases due to lack of robust security measures

Engineering Contradiction:
Improvesignal coverageVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the security function from the general signal relaying function by introducing a dedicated firewall function unit. This unit operates independently to analyze packet data and enforce security policies, while the baseband processing unit continues to handle signal modulation and demodulation. This segmentation allows the relay to maintain signal coverage capabilities while adding robust security measures.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The firewall function unit acts as an intermediary between the baseband processing unit and the network. It intercepts packet data flowing through the relay, performs security analysis against stored security policies, and determines whether to permit or reject data transmission. This intermediary approach enables security enforcement without disrupting the core signal relaying function.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If firewall security analysis is performed on all packet data, then security protection is improved, but communication overhead and processing time increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidcommunication overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies partial action by having the firewall function unit selectively analyze packet data based on security policies rather than uniformly processing all data. The control unit directs packet data to the firewall function unit only when security policy violation is suspected or when configured to do so, as indicated by firewall selection information stored in the storage unit. This approach provides security protection where needed while minimizing unnecessary processing overhead.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The firewall function unit autonomously determines whether packet data violates security policies by comparing against security policies stored in the storage unit. The control unit operates based on firewall selection information to provide packet data to the firewall function unit or external firewall equipment, enabling the system to self-manage security analysis without requiring constant external intervention, thus reducing communication overhead.

Inventive Principle:
Principle #25Self-service

3Reliability

If security policies are strictly enforced to block malicious codes, then security reliability is improved, but legitimate data transmission may be rejected increasing loss of information

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidlegitimate data transmission
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent implements feedback through the control unit, which receives analysis results from the firewall function unit and adjusts its behavior accordingly. When the firewall function unit determines that packet data does not violate security policies, the control unit permits relay of the data. When violations are detected, the control unit rejects the data and can transmit service option negotiation rejection signals or PDP context deactivation request signals to the terminal. This feedback mechanism ensures that legitimate data transmission is preserved while malicious codes are blocked.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9537828B2Secure mobile communication relay having firewall function
Publication Date: 2017.01.03 JUN YOUNG OK
  • US9537828B2 patent drawing
  • US9537828B2 patent drawing
  • US9537828B2 patent drawing

AI summary

The secure mobile communication relay of the present invention may comprise: a baseband processing unit for the baseband modulation/demodulation of the mobile communication signal transmitted between a terminal and a mobile communication network base station so as to extract baseband data; a control unit for analyzing the baseband data and permitting or rejecting the relay of the baseband data based on the result of a determination of whether or not a set security policy has been violated; a storage unit for storing information for setting the security policy; and a firewall function unit for determining, based on the instructions of the control unit, whether or not the packet data included in the baseband data violates the security policy.