Tiered Security Services for Wireless Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wireless communication networks fail to adequately support simultaneous connections to multiple networks with differing security levels and enforce end-to-end security and separation, leading to potential outages and data compromises across varying trust zones.
Innovation Solution
The implementation of multiple virtual machines with distinct security profiles on access terminals, validated and managed by the network, which enforces security procedures and segregates communications based on these profiles to ensure end-to-end security and separation across different security tiers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple networks with differing security levels are connected simultaneously, then network connectivity and versatility are improved, but security risk and potential for cross-tier compromises increase
Solution Approach 1:
The patent segments the access terminal into multiple virtual machines, each isolated in its own security sandbox. This segmentation allows simultaneous connections to multiple networks with different security levels while preventing compromise propagation between tiers. Each virtual machine operates independently with its own security context, resolving the contradiction between connectivity versatility and security isolation.
Solution Approach 2:
The patent introduces a security gateway as an intermediary component between the virtual machines and the external networks. This gateway validates authentication credentials, enforces security policies, and mediates communications between different security tiers. The intermediary prevents direct exposure of internal networks to external threats, maintaining security while enabling multi-network connectivity.
2Reliability
If end-to-end security separation is enforced, then data integrity and security are improved, but device complexity and network configuration requirements increase
Solution Approach 1:
The patent implements self-service mechanisms where the security gateway automatically validates authentication credentials and enforces security policies without requiring manual configuration of each virtual machine. The system autonomously manages security contexts, allocates resources, and maintains separation between tiers. This automation reduces operational complexity while maintaining robust end-to-end security separation.
Solution Approach 2:
The patent dynamically adjusts security parameters such as authentication methods, encryption strengths, and network routing based on the security level of each virtual machine and its associated network. The system changes security parameters adaptively rather than using fixed configurations, reducing complexity by allowing the system to self-optimize security settings based on current operational requirements.
3Reliability
If security validation and enforcement are implemented, then data integrity is improved, but processing time and network latency increase
Solution Approach 1:
The patent performs security validation and authentication in advance before establishing network connections and data transmission. The security gateway validates credentials and establishes security contexts preliminarily, so that once connected, data transmission can proceed without repeated security checks. This preliminary action reduces processing time during active communication while maintaining data integrity through pre-enforced security policies.
Data Source
AI summary
A system, a method and computer-readable media for supporting multiple security tiers in a network. A system is provided that includes an access terminal. The access terminal includes multiple virtual machines, which are each associated with a different security profile. The system further includes an access network that validates the virtual machines. The access network also assigns security procedures for use with the various virtual machines by referencing their associated security profiles. The system further includes a core network. The core network also enforces the various security profiles, and references the profiles in the selection of services used in the handling of communications from the virtual machines.


