Telecommunications Terminal Unsolicited Content Handling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Telecommunications terminals face challenges in securely receiving unsolicited content from external applications, as it may contain unwanted elements like viruses, and existing methods lack control over information exchange and trustworthiness verification.
Innovation Solution
A two-part process is implemented, where the terminal first verifies the trustworthiness of an address provided in an unsolicited message and only requests and receives the actual content from that address if it is deemed trustworthy, allowing for secure and controlled information exchange.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If the terminal receives unsolicited content from external applications, then the terminal can receive pushed content without user request, but the content may contain unwanted elements such as viruses and cannot be implicitly trusted
Solution Approach 1:
The content delivery process is segmented into two distinct parts: (1) receiving an unsolicited message containing address information, and (2) requesting and receiving actual content from the verified address. This segmentation allows the terminal to separate the trust verification step from the content reception step, enabling secure handling of pushed content while maintaining efficiency.
Solution Approach 2:
The terminal performs preliminary verification of the address information before requesting or receiving the actual content. By verifying the trustworthiness of the address in advance (part 1), the terminal ensures that subsequent content reception (part 2) is secure, thus enabling reliable pushed content delivery without implicit trust.
2Loss of time
If the terminal implicitly trusts pushed content, then content can be received quickly without verification, but malicious content may be executed
Solution Approach 1:
The address information serves as an intermediary between the external application and the content delivery process. The terminal verifies this intermediary (address) before accepting the actual content, creating a trust bridge that eliminates the need for implicit trust while minimizing verification overhead.
Solution Approach 2:
The terminal performs preliminary verification of the address information before requesting or receiving the actual content. By verifying the trustworthiness of the address in advance (part 1), the terminal ensures that subsequent content reception (part 2) is secure, thus enabling reliable pushed content delivery without implicit trust.
3Reliability
If the terminal verifies address information before receiving content, then content trustworthiness is improved, but the process complexity increases
Solution Approach 1:
The verification process is segmented into two manageable parts: (1) receiving and verifying address information from unsolicited messages, and (2) using the verified address to request and receive content. This segmentation simplifies the overall complexity by breaking down the verification process into discrete, manageable steps.
Solution Approach 2:
The terminal autonomously performs the verification of address information and makes decisions about whether to request or receive content based on the verification results. This self-service approach eliminates the need for external verification mechanisms, reducing overall system complexity while maintaining high reliability.
Data Source
AI summary
A method and apparatus are disclosed that enable a telecommunications terminal to securely receive unsolicited content from applications that are external to the terminal. In particular, the present invention enables the terminal to control the interaction with external applications by using a secure, two-task process. In the two-task process of the present invention, the execution of the second task is based on verifying the trustworthiness of address information that is provided in the first task. This is in contrast to a one-task process, in which an untrustworthy server that provides content might hide its own address by substituting a legitimate address.


