Secure Device-Assisted Traffic Control for WWAN Service Integrity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mass market digital communications networks face capacity constraints due to increasing user demands for high-bandwidth applications, leading to degraded network service experiences and increased costs for service providers.
Innovation Solution
Implementing a secure execution environment with hardware-based partition techniques, such as secure memory, modems, and buses, to protect device-assisted services, ensuring secure communication and control through encrypted links and protected execution partitions to enhance service measurement and control integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If network capacity is increased to meet growing digital networking demand, then user service capacity is improved, but network costs increase and service provider profits decrease
Solution Approach 1:
The patent implements device-assisted service measurement and control where the user device itself performs service measurement and control functions rather than relying entirely on network infrastructure. The device includes a service measurement component that autonomously measures service usage and a service control component that enforces service policies locally, enabling the device to self-manage service control tasks and reducing the need for network capacity expansion
Solution Approach 2:
The patent extracts service measurement and control functionality from the network infrastructure and relocates it to the user device. By taking out these functions from the network side and implementing them in the device's secure execution environment, the network burden is reduced while maintaining service measurement and control capabilities
2Reliability
If service measurement and control functions are implemented in the device, then service control integrity is improved, but device security requirements increase
Solution Approach 1:
The patent segments the device execution environment into a secure execution environment and a non-secure execution environment. Service measurement and control functions are placed in the secure environment with protected memory spaces and execution contexts, isolating them from potentially malicious code in the non-secure environment. This segmentation prevents malware from compromising service control integrity while allowing the device to run untrusted applications
Solution Approach 2:
The patent introduces a secure execution environment as an intermediary layer between the device's application execution and the service measurement/control functions. This intermediary provides a trusted execution context that mediates access to service control resources, ensuring that even if the device is compromised at the application level, the core service measurement and control functions remain protected
Data Source
AI summary
There is provided a wireless end-user device that includes a wireless wide area network (WWAN) modem to communicate Internet data with a WWAN, and one or more processors configured to pass, using an operating system packet network stack, Internet data packet traffic, including Internet data, between the WWAN modem and one or more applications being executed by the one or more processors, classify, using the application identification agent, each of individual flows of the Internet data packet traffic passing through the operating system packet network stack according to the one or more applications associated with each of the individual flows, measure, using a service measurement agent, for each of the classified individual flows, an amount of the Internet data packet traffic associated with each of the one or more applications, and apply, using a policy control agent, application-specific traffic policy controls to each of the classified individual flows.


