Service Provider Security Device for Cellular Graphics Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing service provider technologies in cellular networks are limited in their ability to provide effective security services, including data integrity, quality of service, and security for graphics data, due to the inability to securely track and validate traffic originating from or transmitted to endpoint devices.

Innovation Solution

A security device is deployed within the service provider's network to monitor and encrypt digital fingerprints of graphics data packets, embedding unique service provider information, allowing for validation and tracking of data packets, and enabling security actions such as blocking or alerting based on predefined rules or machine learning patterns.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If service providers deploy traditional security technologies in cellular networks, then basic network security is maintained, but the ability to effectively track and validate graphics data packets is insufficient

Engineering Contradiction:
Improvedata integrityVSAvoidsecurity device complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security device is divided into distinct functional modules: a fingerprint generation module that creates unique identifiers for graphics data packets, an embedding module that inserts these fingerprints into packet headers, and a validation module that verifies packet authenticity. This segmentation allows each component to perform its specific function efficiently without requiring the entire system to be overly complex.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces digital fingerprints as an intermediary element between the service provider's security system and the graphics data packets. These fingerprints serve as verifiable markers that enable tracking and validation without requiring direct complex interaction between the security device and every packet, thereby simplifying the overall system architecture while maintaining reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If service providers monitor and track all network traffic, then security and tracking capability is improved, but network processing overhead and complexity increase

Engineering Contradiction:
Improvetracking capabilityVSAvoidnetwork processing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Instead of applying uniform monitoring and tracking to all network traffic, the security device applies fingerprinting specifically to graphics data packets, which constitute a substantial portion of cellular network traffic. This localized approach allows the system to maintain enhanced tracking capability for high-value traffic while avoiding the processing overhead of applying the same level of scrutiny to all packets, thereby preserving network productivity.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9906366B1Service provider based security in a wireless network
Publication Date: 2018.02.27 AT&T MOBILITY II LLC
  • US9906366B1 patent drawing
  • US9906366B1 patent drawing
  • US9906366B1 patent drawing

AI summary

A service provider based security system of a cellular network includes a security device that is deployed in the cellular network. The security device receives and monitors cellular network traffic to identify a data packet of the cellular network traffic that is associated with a graphics protocol. Responsively, the security device creates a digital fingerprint using unique service provider specific information and/or a portion of the data packet. The security device encrypts the digital fingerprint. Further, the encrypted digital fingerprint is embedded in a header of the identified data packet and/or stored in a database coupled to the security device for further access by authorized users. Additionally, the security device determines a security action that is to be executed in association with the identified data packet.