Trusted Server Verification for Mobile Redirection Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile wireless communications devices often experience degraded service quality due to congestion and network failures, necessitating efficient and secure mechanisms for disconnecting from one service provider or host server and connecting to another.

Innovation Solution

A communications system comprising a mobile wireless device, a trusted server, and multiple host servers, where a given host server generates a redirection request for the mobile device to connect to another host server, with the trusted server verifying the request before allowing the connection, enhancing security and load balancing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If host servers and intermediate servers are used to provide connectivity between mobile devices and other devices/servers, then service coverage and connectivity are improved, but server congestion and traffic overload occur leading to degraded quality of service

Engineering Contradiction:
Improveservice coverageVSAvoidquality of service
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a trusted server as an intermediary between the mobile device and host servers. The trusted server receives redirection requests, verifies them against a whitelist of authorized servers, and only then allows the mobile device to connect to verified hosts. This mediator architecture prevents direct connection to potentially malicious or overloaded servers, resolving the contradiction by maintaining service coverage while improving reliability through verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If mobile devices are allowed to disconnect from one service provider and connect to another during network failures or congestion, then service continuity is improved, but security risks increase due to potential connection to unauthorized servers

Engineering Contradiction:
Improveservice continuityVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary verification by maintaining a whitelist of authorized host servers in advance. Before allowing a mobile device to redirect to a new host, the trusted server checks whether the target host exists in the pre-established whitelist. This preliminary action ensures service continuity by enabling redirection while preventing security risks through prior authorization verification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback control through the verification process. When a mobile device requests redirection to a new host, the trusted server provides feedback by either approving or denying the request based on whitelist verification. This feedback mechanism ensures that only connections to authorized servers are permitted, maintaining security while allowing necessary service continuity.

Inventive Principle:
Principle #23Feedback

3Reliability

If redirection requests are verified by a trusted server before allowing connection to new host servers, then security is improved, but system complexity and verification overhead increase

Engineering Contradiction:
Improveconnection securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses a whitelist copy mechanism where the trusted server maintains a copy of authorized host server identifiers. Instead of complex real-time verification protocols, the system simply checks whether the target host's identifier matches an entry in the whitelist copy. This copying approach maintains high security while reducing system complexity by replacing complex verification logic with simple pattern matching.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP2506618B1Communications system including trusted server to verify a redirection request and associated methods
Publication Date: 2019.08.28 BLACKBERRY LTD
  • EP2506618B1 patent drawingFigure 1
  • EP2506618B1 patent drawingFigure 2
  • EP2506618B1 patent drawingFigure 3

AI summary

A communications system 10 includes a mobile wireless communications device 16, a trusted server 28, and a plurality of host servers 12a...12n. A given one of the host servers is in communication with the mobile wireless communications device. The given host server is configured to generate and send a redirection request to the mobile wireless communications device, the redirection request requesting the mobile wireless communications device to communicate with an other one of the host servers. The mobile wireless communications device is configured to send the redirection request to the trusted server, and the trusted server configured to send the redirection request to the mobile wireless communications device based upon verification of the redirection request.