Security Agents in Access Terminals for Next-Gen Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Next-generation communication networks face inefficiencies in security mechanisms, particularly in layered approaches that are not resource-efficient and do not effectively prevent malicious traffic, especially in IP-based networks providing voice, video, and multimedia services.

Innovation Solution

Implementing security agents in access terminal devices and network elements to authenticate and enforce security policies, ensuring that devices running adequate security agents can communicate securely by preventing malicious traffic through network registration and continuous monitoring.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If layered security mechanisms are implemented at link layer, network layer, and application layer, then security coverage is improved, but network resource efficiency deteriorates

Engineering Contradiction:
Improvesecurity coverageVSAvoidnetwork resource efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements security checks at the access point before traffic enters the network core. Security agents in access terminal devices perform preliminary authentication and traffic filtering, preventing malicious traffic from consuming network resources. This preliminary action maintains comprehensive security coverage while improving network resource efficiency by blocking threats before they propagate through multiple network layers.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If comprehensive security checks are performed at multiple points in the end-to-end path, then security reliability is improved, but service latency increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidservice latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Security authentication and traffic filtering are performed in advance at the access point before traffic enters the core network. Security agents continuously monitor and filter traffic at the device level, preventing malicious traffic from reaching multiple inspection points. This preliminary security action maintains high security reliability while minimizing service latency by avoiding repeated security checks throughout the transmission path.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If security agents are implemented in access terminal devices, then prevention of malicious traffic is improved, but device complexity increases

Engineering Contradiction:
Improvemalicious traffic preventionVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security agent in the access terminal device performs multiple functions including authentication, traffic filtering, and continuous monitoring. By consolidating these security functions into a single multi-functional component, the patent improves malicious traffic prevention capability while minimizing the increase in device complexity compared to implementing separate dedicated security mechanisms for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8327435B2Techniques for managing security in next generation communication networks
Publication Date: 2012.12.04 CELLCO PARTNERSHIP INC
  • US8327435B2 patent drawing
  • US8327435B2 patent drawing
  • US8327435B2 patent drawing

AI summary

Disclosed techniques provide enhanced security for a communications network. Access terminal devices intended for operation via the network are expected to have security agent functionality, e.g. in the form security agent software loaded into or otherwise enabled on each of the access terminal devices. Registration procedures include verification that such an agent is present/enabled on an access terminal and that the agent currently implemented on the terminal device provides adequate security for the communications network against malicious traffic from that device.