Wireless Secure Server Mediator for Mobile Enterprise Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication systems face challenges in delivering secure, convenient, and efficient enterprise communication services to mobile users over converged networks, particularly for multimodal and multimedia applications, due to inadequate security and resource limitations in mobile devices.

Innovation Solution

A wireless secure server is introduced between the mobile client device and the enterprise application, generating push content and managing user and device profiles, while separating authentication and service content generation from content access, utilizing WAP protocol for secure and efficient communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If direct access through enterprise firewall is provided for authenticated users, then convenience of service access is improved, but security level deteriorates

Engineering Contradiction:
Improveconvenience of service accessVSAvoidsecurity level
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a firewall server as an intermediary component between mobile clients and enterprise applications. This server acts as a mediator that receives service requests from authenticated users, validates them, and forwards appropriate requests to the enterprise firewall while blocking direct access attempts. This resolves the contradiction by maintaining convenience for authenticated users while preventing security breaches through the intermediary's controlled access mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If enterprise application is separated from wireless secure server via firewall, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the system into distinct functional components: mobile clients, wireless secure server, enterprise firewall, and enterprise applications. Each component has a specific security function, with the firewall server acting as a dedicated security gateway. This segmentation improves security by isolating components while managing complexity through clear definition of each segment's responsibility and interface protocols.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The firewall server serves as an intermediary layer between the enterprise applications (inside firewall) and wireless clients (outside firewall). It handles authentication, request filtering, and secure communication protocols, thereby improving security while managing system complexity by centralizing security functions in a single intermediary component rather than distributing complexity across all components.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If push content is generated and delivered to mobile device, then service notification efficiency is improved, but wireless network resource consumption increases

Engineering Contradiction:
Improveservice notification efficiencyVSAvoidwireless network resource consumption
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The patent implements periodic polling where the mobile client periodically requests status updates from the wireless secure server. Instead of continuous real-time pushing that would consume excessive network resources, the system uses periodic checks at predetermined intervals. This maintains notification efficiency by ensuring clients receive updates when changes occur while reducing overall network resource consumption compared to continuous monitoring.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The mobile client autonomously manages its own notification subscriptions and status checks. The client initiates periodic status requests, receives push notifications when services are activated or modified, and automatically updates its local configuration. This self-service approach improves notification efficiency by ensuring clients actively monitor their services while reducing network resource consumption by eliminating the need for server-initiated continuous pushing to all clients.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7925717B2Secure interaction between a mobile client device and an enterprise application in a communication system
Publication Date: 2011.04.12 PULSELINK SYSTEMS LLC
  • US7925717B2 patent drawing
  • US7925717B2 patent drawing
  • US7925717B2 patent drawing

AI summary

Techniques are disclosed for controlling interaction between an enterprise application and a mobile client device in a communication system. Push content is generated in a wireless secure server or other type of server, responsive to information received in the wireless secure server from the enterprise application. The push content is deliverable from the wireless secure server to the mobile client device over a wireless network. The wireless secure server receives from the mobile client device, responsive to the push content, a request for additional information identifiable at least in part by the push content. The additional information is deliverable from the server to the mobile client device over the wireless network.