Tiered Security Services for Wireless Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless communication networks fail to adequately support simultaneous connections to multiple networks with differing security levels and enforce end-to-end security and separation, leading to potential outages and data compromises across varying trust zones.

Innovation Solution

The implementation of multiple virtual machines with distinct security profiles on access terminals, validated and managed by the network, which enforces security procedures and segregates communications based on these profiles to ensure end-to-end security and separation across different security tiers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple networks with differing security levels are connected simultaneously, then network connectivity and versatility are improved, but security risk and potential for cross-tier compromises increase

Engineering Contradiction:
Improveability to connect to multiple networksVSAvoidsecurity risk and cross-tier compromise
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the access terminal into multiple virtual machines, each isolated in its own security sandbox. This segmentation allows simultaneous connections to multiple networks with different security levels while preventing compromise propagation between tiers. Each virtual machine operates independently with its own security context, resolving the contradiction between connectivity versatility and security isolation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a security gateway as an intermediary component between the virtual machines and the external networks. This gateway validates authentication credentials, enforces security policies, and mediates communications between different security tiers. The intermediary prevents direct exposure of internal networks to external threats, maintaining security while enabling multi-network connectivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If end-to-end security separation is enforced, then data integrity and security are improved, but device complexity and network configuration requirements increase

Engineering Contradiction:
Improveend-to-end security and separationVSAvoiddevice complexity and network configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where the security gateway automatically validates authentication credentials and enforces security policies without requiring manual configuration of each virtual machine. The system autonomously manages security contexts, allocates resources, and maintains separation between tiers. This automation reduces operational complexity while maintaining robust end-to-end security separation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent dynamically adjusts security parameters such as authentication methods, encryption strengths, and network routing based on the security level of each virtual machine and its associated network. The system changes security parameters adaptively rather than using fixed configurations, reducing complexity by allowing the system to self-optimize security settings based on current operational requirements.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If security validation and enforcement are implemented, then data integrity is improved, but processing time and network latency increase

Engineering Contradiction:
Improvedata integrityVSAvoidprocessing time and network latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs security validation and authentication in advance before establishing network connections and data transmission. The security gateway validates credentials and establishes security contexts preliminarily, so that once connected, data transmission can proceed without repeated security checks. This preliminary action reduces processing time during active communication while maintaining data integrity through pre-enforced security policies.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7895642B1Tiered security services
Publication Date: 2011.02.22 T MOBILE INNOVATIONS LLC
  • US7895642B1 patent drawing
  • US7895642B1 patent drawing
  • US7895642B1 patent drawing

AI summary

A system, a method and computer-readable media for supporting multiple security tiers in a network. A system is provided that includes an access terminal. The access terminal includes multiple virtual machines, which are each associated with a different security profile. The system further includes an access network that validates the virtual machines. The access network also assigns security procedures for use with the various virtual machines by referencing their associated security profiles. The system further includes a core network. The core network also enforces the various security profiles, and references the profiles in the selection of services used in the handling of communications from the virtual machines.