Session slicing of mirrored packets
US-12184680-B2 · Dec 31, 2024 · US
US9325737B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-9325737-B2 |
| Application number | US-76981407-A |
| Country | US |
| Kind code | B2 |
| Filing date | Jun 28, 2007 |
| Priority date | Jun 28, 2007 |
| Publication date | Apr 26, 2016 |
| Grant date | Apr 26, 2016 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A method and wireless device select a set of secure network connections ( 230 ) between a wireless device ( 108 ) in a wireless communication system and a target destination system ( 238 ). A first security assessment ( 708 ) associated with each of a plurality of base station connections associated with respective each of a plurality of base stations ( 116 ) available for wireless communications with the wireless device ( 108 ) is performed. A second security assessment ( 716 ) associated with each of a plurality of subsequent network connections available between the plurality of base stations ( 116 ) and a target destination system ( 238 ) is performed. A set of base station connections from the plurality of base station connections are prioritized according to predetermined security criteria associated with the wireless device ( 108 ). A set of subsequent network connections from the plurality of subsequent network connections ( 230 ) are prioritized according to predetermined security criteria associated with the wireless device ( 108 ).
Opening claim text (preview).
What is claimed is: 1. A method of selecting a set of secure network connections between a wireless device in a wireless communication system and a target destination system, the method comprising: determining a security level requirement for a wireless device; performing a first security assessment for each of a plurality of base stations available for wireless communications with the wireless device, wherein each base station has an associated security level, wherein the first security assessment provides results of how close the security level of each base station matches the security level requirement for the wireless device, wherein one of the base stations in the plurality is selected based on the results of the first security assessment; performing a second security assessment for each of a plurality of network paths from the wireless device to a target destination system via the selected base station, wherein each network path has an associated security level that is determined based on security information for at least one network component included in the network path, wherein the second security assessment provides results of whether any of the network paths has a security level that meets the security level requirement for the wireless device and is, thereby, selectable to enable communications between the wireless device and the target destination system. 2. The method of claim 1 : wherein the first security assessment is performed with at least one of: a wireless device, at least one of the plurality of base stations, an internal information processing system operated by a service provider of the wireless communication system, and an external information processing system operated by a third party service provider; and wherein the second security assessment is performed with at least one of: the wireless device, at least one of the plurality of base stations, an internal information processing system operated by a service provider of the wireless communication system, and an external information processing system operated by a third party service provider. 3. The method of claim 1 , further comprising: determining, in response to performing the second security assessment, that the security level of each network path fails to meet the security level requirement for the wireless device, wherein a second one of the base stations in the plurality is selected based on the results of the first security assessment; and performing a subsequent second security assessment for each of a plurality of network paths from the wireless device to the target destination system via the selected second base station, wherein each network path has an associated security level that is determined based on security information for at least one network component included in the network path, wherein the subsequent second security assessment provides results of whether any of the network paths has a security level that meets the security level requirement for the wireless device and is, thereby, selectable to enable communications between the wireless device and the target destination system. 4. The method of claim 1 , further comprising: selecting, based on the results of the security assessment, a network path of the plurality of network paths, which has a security level that meets the security level requirement for the wireless device; and communicating with the target destination system via the selected base station and the selected network path. 5. The method of claim 1 , further comprising: receiving a respective over-the-air message from each base station in the plurality of base stations, the respective over-the-air message comprising security information associated with each base station that is used to determine the associated security level for each base station. 6. The method of claim 1 , wherein performing the first security assessment further comprises: associating a priority level with each base station in the plurality of base stations based on the associated security level of each base station in order to prioritize the plurality of base stations based on how close the security level of each base station matches the security level requirement for the wireless device; and selecting the base station based on the priority level. 7. The method of claim 1 , wherein performing the second security assessment further comprises: connecting with the selected base station; and associating a priority level with each network path in the plurality of network paths in order to prioritize the network connections based on whether any of the network paths has a security level that meets the security level requirement for the wireless device. 8. The method of claim 1 further comprising: transmitting a request to an information processing system for security information associated with the plurality of base stations to determine the security level of each base station, wherein the information processing system is one of: an internal information processing system operated by a service provider of the wireless communication system or an external information processing system operated by a third party service provider; and receiving the security information from the information processing system, wherein the security information comprises at least one of: the security levels associated with each base station in the plurality of base stations, a candidate list comprising priority levels associated with the plurality of base stations, the security levels associated with each network path in the plurality of network paths, or a candidate list comprising priority levels associated with the plurality of network paths. 9. The method of claim 1 further comprising: receiving a request from the wireless device for security information associated with at least one of the plurality of base stations or the plurality of network paths between the selected and the target destination system, wherein the first and second security assessments are performed in response to receiving the request. 10. The method of claim 9 , further comprising: transmitting, to the wireless device, at least one of a prioritized list of base stations or a prioritized list of network paths, wherein each prioritized list is based at least in part on the security level associated with each base station and the security level associated with each network path. 11. A wireless device comprising: a memory; a processor communicatively coupled to the memory; a transceiver communicatively coupled to the memory and the processor; and a security monitor service manager, communicatively coupled to the memory, the processor, and the transceiver, wherein the security monitor service manager is adapted to: determine a security level requirement for a wireless device perform a first security assessment for each of a plurality of base stations available for wireless communications with the wireless device, wherein each base station has an associated security level, wherein the first security assessment provides results of how close the security level of each base station matches the security level requirement for the wireless device, wherein one of the base stations in the plurality is selected based on the results of the first security assessment; perform a second security assessment for each of a plurality of network paths from the wireless device to a target destination system via the selected base station, wherein each network path has an associated security level that is determined based on security information for at least one network component included in the network path, wherein the second security assessment provides results of whether
for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.