Wireless Device Connection Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for efficient control of connectivity to wireless networks in devices such as smartphones and tablets, particularly in managing connections to private and public WLANs and peer-to-peer networks, ensuring secure and authorized access while allowing flexibility in personal and work modes of operation.

Innovation Solution

A wireless device receives communication policies that include allowable service provider identifiers and device types, storing them in memory and allowing connections based on matches during operation in specific modes (work or personal) to ensure secure and authorized network access, while allowing flexibility in peer-to-peer connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the wireless device allows connections to any wireless network for flexibility, then ease of operation is improved, but security and compliance with IT policies deteriorate

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system dynamically adjusts connection policies based on operational mode. In work mode, the device enforces strict IT policy compliance by matching service provider identifiers against authorized lists. In personal mode, the device relaxes restrictions to allow connections to any network. This dynamic switching resolves the contradiction by adapting security levels to operational context.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameter of network access restrictions based on operational mode. When switching from personal mode to work mode, the device loads authorized service provider identifiers from IT policies and enforce matching rules. This parameter change enables the device to maintain security compliance while preserving user flexibility when needed.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If the wireless device enforces strict IT policy compliance for network connections, then security is improved, but adaptability to different network environments deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidadaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The connection policy enforcement dynamically switches between strict compliance mode (work mode) and flexible mode (personal mode). In work mode, the device strictly matches service provider identifiers against authorized lists from IT policies. In personal mode, the device disables this matching requirement, allowing connections to any network. This dynamic behavior resolves the contradiction between security and adaptability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the policy enforcement parameter based on operational mode. When in work mode, the device enables identifier matching against authorized lists. When in personal mode, the device disables this restriction. This parameter change allows the device to maintain security when required while adapting to different network environments when flexibility is needed.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If the wireless device stores and checks multiple service provider identifiers against IT policies, then security compliance is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity complianceVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts only the necessary authorization information (authorized service provider identifiers) from complete IT policies and stores it locally in the device. This extracted data is sufficient for connection decisions, eliminating the need to maintain and process entire policy documents. This extraction reduces device complexity while maintaining security compliance capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The device performs preliminary action by pre-loading authorized service provider identifiers from IT policies into local storage before they are needed for connection decisions. This preliminary preparation eliminates the need for real-time policy retrieval and complex processing during connection attempts, simplifying the device's operational complexity while ensuring security compliance.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9167512B2Methods and apparatus for use in controlling connections to wireless networks
Publication Date: 2015.10.20 MALIKIE INNOVATIONS LTD
  • US9167512B2 patent drawing
  • US9167512B2 patent drawing
  • US9167512B2 patent drawing

AI summary

In one illustrative example, a wireless device receives a communication policy from a private network. The communication policy includes allowable service provider identifiers (e.g. domain names, realms) corresponding to allowable service providers. The wireless device stores these identifiers in its memory. When roaming, the wireless device encounters a wireless network (“hotspot”) and receives via the wireless network one or more reachable service provider identifiers corresponding to one or more reachable service providers. In a work mode of operation, the wireless device allows a connection to the wireless network based on a match between one of the allowable and reachable service provider identifiers, but otherwise disallows the connection. The communication policy may additionally or alternatively include device types for P2P networks, and/or allowable private network identifiers (e.g. ESSIDs), and/or allowable hotspot aggregator service identifiers or names, for use in the work mode.