Terminal-Generated Service Flow Policy for Downlink Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mobile communications networks face security threats due to evolving network vulnerabilities, particularly in filtering downlink data packets, which can lead to property loss, privacy leakage, and network congestion, and struggle to provide differentiated control for vertical industry applications.
Innovation Solution
A service flow control method and apparatus where a terminal device generates and sends a service flow policy to a routing device, enabling data packet filtering based on specific rules and user-defined criteria, ensuring secure data passage and blocking security threats, with the option to use a security server for enhanced security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a firewall uses locally configured filtering rules to block security threats, then basic security isolation is achieved, but the security protection becomes outdated quickly as network threats evolve rapidly
Solution Approach 1:
The terminal device performs preliminary identification of security threats in downlink data packets and generates service flow policies in advance. When new threats are detected, the terminal device immediately creates updated filtering rules and sends them to the network device, enabling proactive security protection rather than reactive updates.
Solution Approach 2:
The system establishes a feedback loop where the terminal device continuously monitors downlink data packets for security threats, identifies malicious packets, generates updated service flow policies, and sends these policies to the network device. The network device then applies these policies to block future threats, creating a dynamic adaptive security system.
2Reliability
If a firewall filters all downlink data packets using generic rules, then network security is improved, but network congestion occurs due to excessive traffic blocking legitimate applications
Solution Approach 1:
Instead of applying uniform filtering rules to all data packets, the system implements differentiated filtering based on terminal device types and application requirements. The terminal device identifies its specific service flow needs and generates customized service flow policies that allow legitimate applications while blocking only malicious packets, enabling localized optimization of security and throughput.
Solution Approach 2:
The service flow policies are dynamically generated and updated based on real-time identification of security threats and terminal device requirements. The filtering rules adapt to changing network conditions, terminal device states, and emerging threats, allowing the system to maintain high throughput for legitimate traffic while providing robust security protection.
3Device complexity
If a firewall uses fixed filtering rules, then device complexity is reduced, but adaptability to vertical industry applications and differentiated control capabilities are lost
Solution Approach 1:
The terminal device autonomously identifies its own service flow requirements and security threats, generates appropriate service flow policies, and sends these policies to the network device without requiring manual configuration or complex centralized management. This self-service approach simplifies the overall system while enabling high adaptability to different vertical industry applications.
Solution Approach 2:
The terminal device performs preliminary identification of its service flow characteristics and security requirements, generating customized service flow policies in advance. This allows the system to adapt to various vertical industry applications (such as Internet of Vehicles, Internet of Things) without requiring complex pre-configuration or manual rule management for each application type.
Data Source
AI summary
This application discloses a service flow control method and apparatus, to resolve an existing problem of relatively low security. The method includes: generating, by a terminal device, a service flow policy; and sending, by the terminal device, the service flow policy to a routing device, where the service flow policy is used to instruct the routing device to perform data packet filtering on a downlink data packet according to the service flow policy.


