Security Policy Server for Mobile Stations in Packet-Switched Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 3G cellular systems lack adequate security measures, particularly for mobile stations, as they are prone to various attacks such as denial of service, viruses, spam, and session hijacking, with existing solutions failing to provide flexible and tailored security that meets individual user needs.

Innovation Solution

A method and system that involves a security policy server managing security profiles for mobile stations, allowing for customizable security settings based on individual, group, or default profiles, which are enforced across network nodes to provide tailored security protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If packet-switched IP-based communications are used in 3G systems, then network efficiency and data packet routing flexibility are improved, but security vulnerabilities increase due to shared infrastructure and lack of dedicated channels

Engineering Contradiction:
Improvenetwork efficiencyVSAvoidsecurity vulnerabilities
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments security protection into separate security profiles (default, group, individual) that can be independently configured and applied. Each profile contains specific security rules and parameters that divide the complex security management into manageable segments, allowing targeted protection without affecting the entire network infrastructure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a security system control module as an intermediary between the packet-switched network and mobile stations. This intermediary component receives security profiles from the policy server and enforces them at network nodes, mediating between the need for efficient IP-based routing and the requirement for security protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If existing security solutions are applied to 3G networks, then basic security coverage is provided, but flexibility and adaptability to individual user needs are insufficient

Engineering Contradiction:
Improvesecurity coverageVSAvoidflexibility to user needs
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements local quality by providing different security profile types (default, group, individual) that can be customized according to specific user needs. Each mobile station can have its security settings tailored to its particular requirements, allowing high adaptability while maintaining reliable security coverage through the hierarchical profile structure.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent introduces dynamic security profile management where security settings can be updated and modified based on changing user needs, network conditions, and threat levels. The control module dynamically retrieves and applies appropriate security profiles, enabling the system to adapt to individual user requirements while maintaining consistent security protection.

Inventive Principle:
Principle #15Dynamics

3Object-affected harmful factors

If comprehensive security protection is implemented for mobile stations, then protection against various attacks is improved, but network infrastructure complexity increases

Engineering Contradiction:
Improveprotection against attacksVSAvoidnetwork infrastructure complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent achieves universality by designing a multi-functional security system control module that handles multiple security tasks through a unified architecture. The module performs security profile retrieval, enforcement, and management across different network nodes, providing comprehensive attack protection without proportionally increasing infrastructure complexity through consolidation of functions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses copying by replicating security profiles across multiple network nodes rather than implementing complex centralized control. Security rules are copied to appropriate nodes (SGSN, GGSN, gateway routers) where they can be independently enforced, distributing the security function and reducing the complexity burden on any single infrastructure component.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS7418253B2Method, security system control module and policy server for providing security in a packet-switched telecommunications system
Publication Date: 2008.08.26 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US7418253B2 patent drawing
  • US7418253B2 patent drawing
  • US7418253B2 patent drawing

AI summary

A method, security system control module and policy server for providing security for Mobile Stations (MSs) in a Packet-Switched Telecommunications System. When an MS accesses the system, its identity is sent to a security system control module that retrieves a security profile associated with the MS. A policy server of the security system control module stores individual security profiles, default security profiles and group security profiles for registered subscribers. Security settings associated with the MS security profile are returned from the policy server to a mobile security manager of the control module, which then determines if they should be propagated in the system. When no previous network access was made in a given time period by an MS having similar security settings, i.e. belongs to the same group security profile, the settings are propagated in the system in order to be enforced, for providing security protection for the MS.