Transport Layer Proxy for Secure Mobile Termination

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for secure mobile terminating connections, relying on static IPv4 addresses and access control lists (ACLs, are inefficient, resource-intensive, and prone to security vulnerabilities due to high operational overhead and the need for frequent updates, which can lead to unauthorized access and resource waste.

Innovation Solution

Implementing a transport layer approach using a transport layer proxy in the mobile packet core, where mobile devices are identified by persistent domain names, and secure protocols like TLS are mandated, with access certificates checked to ensure secure connections, reducing reliance on public IP addresses and eliminating the need for frequent ACL updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static IPv4 addresses and access control lists (ACLs) are used for secure mobile terminating connections, then network security is maintained, but operational overhead increases and resource consumption increases

Engineering Contradiction:
Improvenetwork securityVSAvoidoperational overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a transport layer proxy as an intermediary component between the mobile device and the network. This proxy handles security functions including TLS termination, certificate verification, and authorization checks, thereby maintaining network security while reducing the operational overhead on core network elements. The proxy acts as a mediator that offloads complex security management tasks from the traditional ACL-based system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent fundamentally changes the security approach by transitioning from static IPv4 address-based ACLs to dynamic TLS certificate-based authentication. This parameter change involves using cryptographic certificates and public key infrastructure (PKI) instead of simple IP address filtering, enabling more efficient and scalable security management with reduced operational overhead for updates and maintenance.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If static IPv4 addresses and ACLs are used for secure mobile terminating connections, then access control is implemented, but frequent updates are required leading to resource waste and security vulnerabilities

Engineering Contradiction:
Improveaccess controlVSAvoidtime for frequent updates
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-configuring the transport layer proxy with authorization rules and certificate validation parameters before security events occur. The proxy is pre-provisioned with the ability to verify certificates and make authorization decisions, eliminating the need for frequent real-time updates to ACLs. This preliminary configuration enables rapid, automated security decisions without time-consuming manual interventions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements self-service through automated certificate verification and dynamic authorization decision-making at the transport layer proxy. The proxy autonomously validates certificates, checks authorization rules, and makes access decisions without requiring manual ACL updates. This self-service capability reduces the time loss associated with frequent manual security policy updates while maintaining robust access control.

Inventive Principle:
Principle #25Self-service

3Reliability

If transport layer proxy with TLS and access certificates is implemented, then security is improved and operational overhead is reduced, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The transport layer proxy serves as an intermediary that centralizes complex security functions including TLS termination, certificate verification, and authorization checking. By concentrating these complex operations in a single dedicated component rather than distributing them throughout the network, the system improves security while managing complexity in a controlled manner. The proxy shields the rest of the network from the complexity of certificate-based authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical system of manual ACL configuration and IP address-based filtering with an automated cryptographic system using TLS and certificates. This substitution eliminates the need for manual rule updates and simplifies security management despite the underlying cryptographic complexity. The automated certificate-based authentication system replaces cumbersome manual ACL maintenance with more efficient machine-to-machine verification.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20230209615A1Transport layer approach to secure mobile termination
Publication Date: 2023.06.29 AT&T INTELLECTUAL PROPERTY I L P
  • US20230209615A1 patent drawing
  • US20230209615A1 patent drawing
  • US20230209615A1 patent drawing

AI summary

A method performed by a processing system includes receiving a request from a first user endpoint device to establish a mobile terminating connection to a second user endpoint device, determining whether an access certificate that is associated with the second user endpoint device has been received from the first user endpoint device, terminating the mobile terminating connection at the processing system when the access certificate is determined to be received from the first user endpoint device, identifying a private Internet Protocol address that is associated with the second user endpoint device when the access certificate is determined to be received from the first user endpoint device, and establishing a connection from the processing system to the second user endpoint device, separate from the mobile terminating connection from the first user endpoint device to the processing system, using the private internet protocol address of the second user endpoint device.