Trusted Service Database Whitelist Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for managing undesired service requests in mobile networks face challenges such as unmanageable blacklists, constant updates, lack of automatic whitelisting, and user inconvenience, particularly due to the vulnerability of mobile devices to malware that can lead to financial risks and incorrect service blocking.
Innovation Solution
A method and system that dynamically maintain a trusted service-information database, allowing only verified legitimate service requests by establishing a secure communication channel for user verification, using a trusted service-information database to filter out malicious requests and update the whitelist interactively, thereby preventing malware-induced service setups.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a blacklist is used to block undesired service requests, then malicious calls can be blocked, but the blacklist becomes very large and unmanageable
Solution Approach 1:
The patent inverts the traditional blacklist approach by implementing a whitelist system. Instead of maintaining a comprehensive list of all malicious services, the network maintains a list of trusted services and automatically allows only those. This inversion fundamentally resolves the management complexity issue while maintaining reliable blocking of malicious requests.
Solution Approach 2:
The system implements automatic whitelist population through user verification. When a user successfully verifies a service request, the service is automatically added to the whitelist without requiring manual operator intervention. This self-service mechanism continuously updates the whitelist, reducing operational burden while maintaining security.
2Reliability
If manual monitoring and updating of service requests is performed, then malicious services can be identified, but substantial network resources are required
Solution Approach 1:
The system shifts the detection burden from network resources to user devices. The terminal performs local analysis of service requests and communicates verification results to the network. This distributes the computational load, reducing network resource requirements while maintaining detection capability.
Solution Approach 2:
The system implements a feedback loop where terminal verification results are communicated back to the network, which then updates the whitelist accordingly. This automated feedback mechanism eliminates the need for continuous manual monitoring and substantial network resources, as the system self-updates based on verified user interactions.
3Reliability
If a filter blocks all suspicious service requests, then malicious calls are prevented, but legitimate services may be incorrectly blocked
Solution Approach 1:
By inverting to a whitelist system, the patent ensures that only pre-verified trusted services are blocked by default, while all other services require user verification rather than automatic blocking. This fundamentally improves ease of operation for legitimate services while maintaining reliability against malicious requests.
Solution Approach 2:
The system introduces user verification as an intermediary step between service request and blocking decision. Instead of direct automatic blocking, the user acts as a mediator to verify legitimate services, preventing incorrect blockages while maintaining security against malicious requests.
4Reliability
If constant search for malicious services is performed to keep blacklist up-to-date, then protection remains effective, but operational burden increases
Solution Approach 1:
The whitelist automatically updates itself through user verification feedback. When users verify services, they are automatically added to the whitelist without requiring operators to manually search for or add them. This self-service mechanism maintains up-to-date protection while eliminating operational burden.
Solution Approach 2:
The system uses feedback from terminal verification results to automatically update the whitelist. This automated feedback-driven update mechanism keeps the service control list current without requiring constant manual searching or operator intervention, resolving both reliability and ease of operation concerns.
Data Source
AI summary
A Method and a system for managing undesired service requests sent from at least one terminal to a network are described, wherein the network comprises a network node for storing trusted service-information. The method comprises the steps of: the network receiving a service request from a terminal, the request comprising service request information; and, sending, preferably via a secure communication channel, a user verification request for requesting the user to verify the service requested by the terminal if at least part of the service request information is not listed in the trusted service-information.


