Telecommunication Access Control via Device-Specific Evaluation Metrics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security mechanisms in telecommunication systems, particularly in mobile networks, fail to prevent unauthorized access and forwarding of confidential information signals, such as SMS messages used for internet banking, due to lack of interoperability and shared access certificates, allowing malicious users or viruses to initiate transactions from unsecured devices.

Innovation Solution

A method that involves an SMS filter and application filter to restrict access and forwarding of confidential information signals by using a stored evaluation metric to assign access rights based on message content, sender, and receiver information, ensuring that only authorized devices can access and receive sensitive information, while preventing message distribution to unauthorized devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If access certificates are shared across multiple devices to enable interoperability, then device compatibility and functionality are improved, but security is worsened because unauthorized devices can access confidential information

Engineering Contradiction:
ImproveinteroperabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments access rights by introducing device-specific identifiers and evaluation metrics that differentiate authorization levels for each device. Instead of using a single shared certificate, the system divides access control into device-specific permissions, where each device receives tailored access rights based on its identity and the evaluation of confidential information characteristics.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by making access rights device-specific rather than uniform across all devices. Each device receives customized access permissions based on its unique identifier and the specific confidential information being accessed. This allows the second device to have different access levels to different confidential information on the third device, creating localized security zones.

Inventive Principle:
Principle #3Local quality

2Ease of operation

If confidential information is made accessible to multiple devices for user convenience, then ease of operation is improved, but security control is worsened allowing malicious transactions

Engineering Contradiction:
Improveaccess convenienceVSAvoidmalicious transaction risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary evaluation metric that acts as a mediator between the confidential information and accessing devices. This evaluation metric assesses each access request based on device identifiers and information characteristics, providing a security checkpoint that prevents malicious transactions while allowing legitimate access. The intermediary layer filters and controls information flow without preventing convenient access for authorized devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If access control mechanisms are implemented to prevent unauthorized access, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidaccess control complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-establishing device identifiers and evaluation metrics before access requests occur. The system pre-configures security parameters and device identities, so that when access requests are made, the evaluation process is streamlined rather than requiring complex real-time analysis. This preliminary setup reduces the computational complexity during actual access control operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3032448B1Method for authorizing access to information in a telecommunication system
Publication Date: 2020.01.22 IPCOM GMBH & CO KG
  • EP3032448B1 patent drawingFigure 1
  • EP3032448B1 patent drawingFigure 2
  • EP3032448B1 patent drawingFigure 3

AI summary

The present invention suggests a method for restricting the access to confidential information among end devices. After security barriers are implemented between devices in many usage scenarios users are nonetheless enabled to share confidential information, which crosses the established barriers. Therefore a telecommunication system is suggested, which provides means for excluding devices from access to confidential information and furthermore restricts message forwarding in mobile scenarios to prevent message distribution.