Wireless Network Authentication for Rogue Mobile Applications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile device applications can exhibit rogue behavior, leading to undesirable impacts on wireless networks, such as denial of service attacks, by consuming excessive resources, and existing methods lack effective mechanisms to proactively manage and restrict access to rogue applications.

Innovation Solution

A wireless network system assigns unique identities to mobile device applications, authenticates them, and identifies rogue applications, then blocks or disables them to prevent resource consumption, using a database to maintain lists of approved and disapproved applications, and instructing terminals to restrict or terminate disapproved applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If mobile device applications are allowed to access wireless network resources without authentication, then network access availability is improved, but network security deteriorates due to rogue applications consuming excessive resources

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork access availability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements preliminary authentication of mobile device applications before granting network access. The network operator apparatus authenticates applications in advance by verifying authentication information (such as digital certificates or security tokens) before the applications can access network resources. This preliminary action prevents rogue applications from consuming network resources while maintaining availability for legitimate applications.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If authentication mechanisms are implemented to prevent rogue applications, then network security is improved, but system complexity increases due to additional authentication infrastructure

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary authentication control mechanism where the network operator apparatus acts as a mediator between mobile device applications and network resources. The authentication control point verifies application credentials and makes authorization decisions, simplifying the overall system architecture by centralizing security functions rather than distributing complex authentication logic across multiple components.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If rogue applications are blocked after identification, then network resource protection is improved, but response time increases due to detection and blocking procedures

Engineering Contradiction:
Improvenetwork resource protectionVSAvoidapplication blocking response time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs authentication verification before applications can access network resources, rather than detecting and blocking rogue applications after they have already consumed resources. This preliminary authentication action prevents rogue applications from causing harm in the first place, eliminating the need for time-consuming detection and blocking procedures while maintaining continuous network resource protection.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2574089B1Authentication procedures for managing mobile device applications
Publication Date: 2020.04.29 BLACKBERRY LTD
  • EP2574089B1 patent drawingFigure 1
  • EP2574089B1 patent drawingFigure 2
  • EP2574089B1 patent drawingFigure 3

AI summary

Methods, systems, and computer programs for managing mobile device applications are described. In some aspects, a mobile device application is prevented from accessing resources of a wireless network. For example, a wireless network operator system can determine that one or more mobile device applications are disapproved for use in the wireless network. In some implementations, the wireless network operator denies the disapproved mobile device applications access to the wireless network resources. In some implementations, mobile devices disable access to the wireless network by the disapproved mobile device applications.