Terminal Device Communication Control for Unauthorized Flow Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Smartphones and similar terminal devices lack a general-purpose means to recognize and control ongoing communications, leading to user-unintended communication, where applications can transmit user information without authorization.

Innovation Solution

A terminal device with a communication control mechanism that detects new flows and sends notifications to an instruction information giving means, which determines whether to permit communication, directing the flow through a designated access network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If applications are installed to provide communication functionality, then communication capability is improved, but unauthorized transmission of user information may occur

Engineering Contradiction:
Improvecommunication capabilityVSAvoidunauthorized transmission
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system establishes a feedback mechanism where the control unit receives notifications from the flow table about new communication flows, determines whether to permit them, and sends control messages back to the flow table. This closed-loop feedback enables dynamic control of communication flows to prevent unauthorized transmissions while maintaining legitimate communication capabilities.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The control unit acts as an intermediary between the flow table (packet forwarding unit) and the communication flows. It intercepts flow establishment requests, determines whether to permit them based on security policies, and only allows authorized flows to be established in the flow table, thereby mediating between communication needs and security requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If flow entries are set per packet flow to control communication, then communication control precision is improved, but system complexity increases

Engineering Contradiction:
Improvecommunication control precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The flow table automatically manages flow entries by receiving control messages from the control unit, adding or deleting flow entries as instructed. This self-service mechanism reduces the burden on the control unit to manually manage each flow entry, simplifying the overall system while maintaining precise per-flow control capabilities.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system separates communication control functions into distinct components: the flow table handles packet forwarding decisions based on flow entries, while the control unit handles flow permission determination. This segmentation allows each component to specialize in its function, improving control precision without proportionally increasing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10555217B2Terminal device, terminal-device control method, and terminal-device control program
Publication Date: 2020.02.04 IP WAVE PTE LTD
  • US10555217B2 patent drawing
  • US10555217B2 patent drawing
  • US10555217B2 patent drawing

AI summary

To provide a terminal device capable of preventing user-unintended communication from being made. A communication control means 91 controls a packet transfer means for transmitting a packet. An instruction information giving means 92 gives instruction information indicating an instruction for the communication control means 91 to the communication control means 91. The communication control means 91 sends a flow detection notification that it detected a new flow to the instruction information giving means 92 when detecting the new flow. The instruction information giving means 92 determines whether to permit the flow to be communicated when receiving the flow detection notification. When determining to permit communication, the instruction information giving means 92 then gives instruction information for instructing to transmit a packet of the flow in a path as an access network designated by the instruction information giving means 92 to the communication control means 91.