Wireless Device Connection Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a need for efficient control of connectivity to wireless networks in devices such as smartphones and tablets, particularly in managing connections to private and public WLANs and peer-to-peer networks, ensuring secure and authorized access while allowing flexibility in personal and work modes of operation.
Innovation Solution
A wireless device receives communication policies that include allowable service provider identifiers and device types, storing them in memory and allowing connections based on matches during operation in specific modes (work or personal) to ensure secure and authorized network access, while allowing flexibility in peer-to-peer connections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the wireless device allows connections to any wireless network for flexibility, then ease of operation is improved, but security and compliance with IT policies deteriorate
Solution Approach 1:
The system dynamically adjusts connection policies based on operational mode. In work mode, the device enforces strict IT policy compliance by matching service provider identifiers against authorized lists. In personal mode, the device relaxes restrictions to allow connections to any network. This dynamic switching resolves the contradiction by adapting security levels to operational context.
Solution Approach 2:
The system changes the parameter of network access restrictions based on operational mode. When switching from personal mode to work mode, the device loads authorized service provider identifiers from IT policies and enforce matching rules. This parameter change enables the device to maintain security compliance while preserving user flexibility when needed.
2Reliability
If the wireless device enforces strict IT policy compliance for network connections, then security is improved, but adaptability to different network environments deteriorates
Solution Approach 1:
The connection policy enforcement dynamically switches between strict compliance mode (work mode) and flexible mode (personal mode). In work mode, the device strictly matches service provider identifiers against authorized lists from IT policies. In personal mode, the device disables this matching requirement, allowing connections to any network. This dynamic behavior resolves the contradiction between security and adaptability.
Solution Approach 2:
The system changes the policy enforcement parameter based on operational mode. When in work mode, the device enables identifier matching against authorized lists. When in personal mode, the device disables this restriction. This parameter change allows the device to maintain security when required while adapting to different network environments when flexibility is needed.
3Reliability
If the wireless device stores and checks multiple service provider identifiers against IT policies, then security compliance is improved, but device complexity increases
Solution Approach 1:
The system extracts only the necessary authorization information (authorized service provider identifiers) from complete IT policies and stores it locally in the device. This extracted data is sufficient for connection decisions, eliminating the need to maintain and process entire policy documents. This extraction reduces device complexity while maintaining security compliance capability.
Solution Approach 2:
The device performs preliminary action by pre-loading authorized service provider identifiers from IT policies into local storage before they are needed for connection decisions. This preliminary preparation eliminates the need for real-time policy retrieval and complex processing during connection attempts, simplifying the device's operational complexity while ensuring security compliance.
Data Source
AI summary
In one illustrative example, a wireless device receives a communication policy from a private network. The communication policy includes allowable service provider identifiers (e.g. domain names, realms) corresponding to allowable service providers. The wireless device stores these identifiers in its memory. When roaming, the wireless device encounters a wireless network (“hotspot”) and receives via the wireless network one or more reachable service provider identifiers corresponding to one or more reachable service providers. In a work mode of operation, the wireless device allows a connection to the wireless network based on a match between one of the allowable and reachable service provider identifiers, but otherwise disallows the connection. The communication policy may additionally or alternatively include device types for P2P networks, and/or allowable private network identifiers (e.g. ESSIDs), and/or allowable hotspot aggregator service identifiers or names, for use in the work mode.


