Tethering Communication Flow Control for Security and Accounting
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge is to control and restrict communication of a different apparatus using a tethering function provided by a communication terminal, particularly in scenarios where the owners differ, leading to issues with fee-based service accounting and security.
Innovation Solution
A communication terminal equipped with a communication flow control unit that performs permission or blocking of communication for the different apparatus based on attribute information, communication destination, and network interface information, according to a pre-stored control policy, ensuring secure and authorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If tethering function is provided to different apparatus, then communication accessibility is improved, but security and accounting control deteriorate
Solution Approach 1:
The patent segments communication control into two levels: the communication terminal performs flow identification and classification of tethered apparatus traffic, while the communication control apparatus executes policy-based permission or blocking decisions. This segmentation allows the terminal to maintain accessibility while the control apparatus enforces security and accounting rules.
Solution Approach 2:
The communication control apparatus acts as an intermediary between the tethered apparatus and the network. It receives flow identification information from the terminal, applies control policies, and makes authorization decisions. This intermediary role enables security control without directly interfering with the terminal's tethering function.
2Reliability
If communication control is implemented for tethered apparatus, then security is improved, but device complexity increases
Solution Approach 1:
The patent extracts the complex control logic from the communication terminal and places it in a separate communication control apparatus. The terminal only needs to perform relatively simple flow identification and information transmission, while the control apparatus handles the complex policy evaluation and decision-making processes.
Solution Approach 2:
The terminal performs partial control actions (flow identification and classification) without implementing the full control logic. The remaining control functions are executed by the communication control apparatus, allowing the terminal to remain relatively simple while still contributing to security control.
3Reliability
If flow identification is performed at terminal, then accounting control is improved, but processing load on terminal increases
Solution Approach 1:
The terminal performs only the necessary minimum for flow identification (extracting flow identification information and transmitting it to the control apparatus) rather than implementing complete accounting control locally. This partial action reduces the terminal's processing load while still enabling accounting control through the control apparatus.
Data Source
AI summary
Provided a communication terminal configured to provide a tethering function controls permission of communication of a different apparatus using the tethering function provided by the communication terminal, based on at least one of attribute information of the different apparatus, a communication destination of the different apparatus, and information on an interface of a network to which the communication terminal is connected, in accordance with a control policy stored in a storage unit in advance.


