Security Policy Server for Mobile Stations in Packet-Switched Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current 3G cellular systems lack adequate security measures, particularly for mobile stations, as they are prone to various attacks such as denial of service, viruses, spam, and session hijacking, with existing solutions failing to provide flexible and tailored security that meets individual user needs.
Innovation Solution
A method and system that involves a security policy server managing security profiles for mobile stations, allowing for customizable security settings based on individual, group, or default profiles, which are enforced across network nodes to provide tailored security protection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If packet-switched IP-based communications are used in 3G systems, then network efficiency and data packet routing flexibility are improved, but security vulnerabilities increase due to shared infrastructure and lack of dedicated channels
Solution Approach 1:
The patent segments security protection into separate security profiles (default, group, individual) that can be independently configured and applied. Each profile contains specific security rules and parameters that divide the complex security management into manageable segments, allowing targeted protection without affecting the entire network infrastructure.
Solution Approach 2:
The patent introduces a security system control module as an intermediary between the packet-switched network and mobile stations. This intermediary component receives security profiles from the policy server and enforces them at network nodes, mediating between the need for efficient IP-based routing and the requirement for security protection.
2Reliability
If existing security solutions are applied to 3G networks, then basic security coverage is provided, but flexibility and adaptability to individual user needs are insufficient
Solution Approach 1:
The patent implements local quality by providing different security profile types (default, group, individual) that can be customized according to specific user needs. Each mobile station can have its security settings tailored to its particular requirements, allowing high adaptability while maintaining reliable security coverage through the hierarchical profile structure.
Solution Approach 2:
The patent introduces dynamic security profile management where security settings can be updated and modified based on changing user needs, network conditions, and threat levels. The control module dynamically retrieves and applies appropriate security profiles, enabling the system to adapt to individual user requirements while maintaining consistent security protection.
3Object-affected harmful factors
If comprehensive security protection is implemented for mobile stations, then protection against various attacks is improved, but network infrastructure complexity increases
Solution Approach 1:
The patent achieves universality by designing a multi-functional security system control module that handles multiple security tasks through a unified architecture. The module performs security profile retrieval, enforcement, and management across different network nodes, providing comprehensive attack protection without proportionally increasing infrastructure complexity through consolidation of functions.
Solution Approach 2:
The patent uses copying by replicating security profiles across multiple network nodes rather than implementing complex centralized control. Security rules are copied to appropriate nodes (SGSN, GGSN, gateway routers) where they can be independently enforced, distributing the security function and reducing the complexity burden on any single infrastructure component.
Data Source
AI summary
A method, security system control module and policy server for providing security for Mobile Stations (MSs) in a Packet-Switched Telecommunications System. When an MS accesses the system, its identity is sent to a security system control module that retrieves a security profile associated with the MS. A policy server of the security system control module stores individual security profiles, default security profiles and group security profiles for registered subscribers. Security settings associated with the MS security profile are returned from the policy server to a mobile security manager of the control module, which then determines if they should be propagated in the system. When no previous network access was made in a given time period by an MS having similar security settings, i.e. belongs to the same group security profile, the settings are propagated in the system in order to be enforced, for providing security protection for the MS.


