Terminal Device Communication Control for Unauthorized Flow Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Smartphones and similar terminal devices lack a general-purpose means to recognize and control ongoing communications, leading to user-unintended communication, where applications can transmit user information without authorization.
Innovation Solution
A terminal device with a communication control mechanism that detects new flows and sends notifications to an instruction information giving means, which determines whether to permit communication, directing the flow through a designated access network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If applications are installed to provide communication functionality, then communication capability is improved, but unauthorized transmission of user information may occur
Solution Approach 1:
The system establishes a feedback mechanism where the control unit receives notifications from the flow table about new communication flows, determines whether to permit them, and sends control messages back to the flow table. This closed-loop feedback enables dynamic control of communication flows to prevent unauthorized transmissions while maintaining legitimate communication capabilities.
Solution Approach 2:
The control unit acts as an intermediary between the flow table (packet forwarding unit) and the communication flows. It intercepts flow establishment requests, determines whether to permit them based on security policies, and only allows authorized flows to be established in the flow table, thereby mediating between communication needs and security requirements.
2Measurement precision
If flow entries are set per packet flow to control communication, then communication control precision is improved, but system complexity increases
Solution Approach 1:
The flow table automatically manages flow entries by receiving control messages from the control unit, adding or deleting flow entries as instructed. This self-service mechanism reduces the burden on the control unit to manually manage each flow entry, simplifying the overall system while maintaining precise per-flow control capabilities.
Solution Approach 2:
The system separates communication control functions into distinct components: the flow table handles packet forwarding decisions based on flow entries, while the control unit handles flow permission determination. This segmentation allows each component to specialize in its function, improving control precision without proportionally increasing overall system complexity.
Data Source
AI summary
To provide a terminal device capable of preventing user-unintended communication from being made. A communication control means 91 controls a packet transfer means for transmitting a packet. An instruction information giving means 92 gives instruction information indicating an instruction for the communication control means 91 to the communication control means 91. The communication control means 91 sends a flow detection notification that it detected a new flow to the instruction information giving means 92 when detecting the new flow. The instruction information giving means 92 determines whether to permit the flow to be communicated when receiving the flow detection notification. When determining to permit communication, the instruction information giving means 92 then gives instruction information for instructing to transmit a packet of the flow in a path as an access network designated by the instruction information giving means 92 to the communication control means 91.


