Dynamic policy exchange
By transmitting permission group mappings between client devices and access points and dynamically adjusting QoS tags, the problem of client devices misusing QoS tags is solved, and optimized traffic classification and resource allocation based on network conditions and application requirements are achieved.
Patent Information
- Application Number
- CN202180018223.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-03-04
- Filing Date
- 2021-03-03
- Publication Date
- 2026-02-27
- Estimated Expiration
- 2041-03-03
AI Technical Summary
Client devices may misuse or unintentionally use expired QoS tags, leading to improper traffic allocation and affecting the rational use of network resources.
By transmitting permission group mappings between client devices and access points, QoS tags are dynamically adjusted to ensure that traffic classification conforms to network policies. This includes the access point dynamically adjusting permission levels based on network conditions and reconfiguring traffic formats on client devices to match optimized QoS levels.
It enables dynamic adjustment of QoS based on network conditions and application requirements, improving the rational allocation and utilization efficiency of network resources and preventing malicious or unintentional traffic misuse.
Smart Images

Figure CN115211158B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The embodiments presented in this disclosure relate generally to the distribution and implementation of Quality of Service (QoS) schemes in wireless networks. More specifically, the embodiments disclosed herein provide client devices with the ability to select between different connections based on current QoS policies prior to establishing a connection with a network, and the ability to update policies while remaining connected to the network. BACKGROUND
[0002] Various wireless networking standards allow devices to classify various types of traffic according to different QoS markers, which indicate how the traffic should be prioritized (e.g., delay-sensitive traffic is prioritized higher than delay-insensitive traffic, identified users are prioritized higher than guest users, retry traffic is prioritized higher than first-attempt transmissions, etc.). Different network controllers can specify different QoS schemes, which set different priorities for traffic indicated with one or more QoS markers, but client devices can misuse these QoS markers, for example, intentionally misusing QoS markers to increase the priority of traffic that should have a lower priority, or unintentionally misusing QoS markers in cases where an outdated traffic distribution scheme is used for the traffic. BRIEF DESCRIPTION OF DRAWINGS
[0003] In order that the above-recited features of the present disclosure can be understood in detail, a more particular description of the disclosure, briefly summarized above, can be had by reference to embodiments, some of which are illustrated in the appended drawings. It is to be noted, however, that the appended drawings illustrate typical embodiments and are therefore not to be considered limiting of its scope, as other equally effective embodiments are considered.
[0004] Figure 1 A network environment according to embodiments of the present disclosure is shown.
[0005] Figure 2 A rights group mapping according to embodiments of the present disclosure is shown.
[0006] Figure 3A And Figure 3B is a flowchart of a method according to embodiments of the present disclosure from the perspective of a client device.
[0007] Figure 4 is a flowchart of a method according to embodiments of the present disclosure from the perspective of an access point.
[0008] Figure 5 Hardware of a computing device according to embodiments of the present disclosure is shown.
[0009] For ease of understanding, the same reference numbers will be used in different drawings to designate the same elements. It is contemplated that elements disclosed in one embodiment can be beneficially utilized on other embodiments without specific recitation. DETAILED DESCRIPTION
[0010] SUMMARY
[0011] One embodiment presented in the disclosure is a method comprising: receiving, at a client device from a first access point (AP), a first permission group mapping that identifies first permission levels for one or more applications executing on the client device; receiving, at the client device from a second AP, a second permission group mapping that identifies second permission levels for the one or more applications; selecting between the first AP and the second AP based on which of the first and second permission group mappings better satisfies needs of the one or more applications; establishing a connection with the selected AP; and applying a quality of service (QoS) marking to traffic sent from the client device to the selected AP based on the permission group mapping corresponding to the selected AP.
[0012] One embodiment presented in the disclosure is a method comprising: mapping, by an access point (AP), a plurality of applications to a set of permission groups for quality of service (QoS) levels in a network; sending the mapping of permission groups to a client device; receiving a packet from the client device that includes a QoS marking; and in response to determining that the QoS marking received from the client device does not match a permission group for the packet, performing a corrective action with respect to the client device.
[0013] One embodiment presented in the disclosure is a computer-readable storage device comprising instructions that, when executed by a processor, perform operations comprising: mapping, by an access point (AP), a plurality of applications to a set of permission groups for quality of service (QoS) levels in a network; sending the mapping of permission groups to a client device; receiving a packet from the client device that includes a QoS marking; and in response to determining that the QoS marking received from the client device does not match a permission group for the packet, disassociating the client device from the network.
[0014] Example Embodiments
[0015] Embodiments of this disclosure provide the distribution and implementation of a Quality of Service (QoS) scheme in a wireless network, which allocates different priority levels of services using application identifiers (AppIDs) based on network conditions and network policies. During negotiation with client devices, an access point (AP) indicates to each client device the permission level assigned to different applications (or data streams within applications), allowing the client devices to choose whether to connect to that AP or to a different AP that provides the desired QoS for one or more specified applications. The permission levels assigned to each application may include various priority levels (e.g., first priority, second priority, best effort, guaranteed minimum rate, etc.) and denial-of-service (e.g., blacklisting / blocking, rate throttling, etc.). In some embodiments, the AP changes the permission levels assigned to different applications based on current network conditions (and may negotiate these permission levels with each client device to set them) and monitors communication from connected client devices to ensure that associated client devices conform to the QoS scheme and that traffic is correctly labeled according to the scheme.
[0016] Figure 1 A network environment 100 according to an embodiment of the present disclosure is shown. For example... Figure 1 As shown, multiple APs 110a to 110c (collectively referred to as AP 110) serve various client devices 120a to 120e (collectively referred to as client device 120) in an environment 100. Each AP 110a to 110c provides permission group mappings 130a to 130c (collectively referred to as permission group mappings) for: how a given AP 110 handles traffic with associated client device 120; and how several APs 110 in the same network can provide the same or different permission levels to various applications, devices, users, and packet types based on the permission group mappings. In various embodiments, network controller 140 can coordinate the operation of APs 110 in a shared network, either in a separate computing device or in one of the APs 110.
[0017] For example, the first client device 120a can be associated with the first AP 110a and transmit communications to and receive communications from the first AP 110a indicating that QoS markings conform to the first privilege group mapping 130a. In another example, the second AP 110b can authorize the second client device 120b associated with the second AP 110b to mark transmissions according to the second privilege group mapping 130b, which specifies different priority levels than the first privilege group mapping 130a, even though the first AP 110a and the second AP 110b are part of the same network. The privilege group mappings 130 can indicate groups of AppIDs that are blocked by the network or not served by the network, as well as groups of AppIDs that are served by the network at various priority levels. In various embodiments, various APs 110 can set how to prioritize various applications based on local conditions, including but not limited to: the number of client devices 120 associated with a given AP 110, the amount of traffic transmitted to / from the AP 110, the user account of the associated client devices 120, the signal-to-noise ratio (SNR) within the service range of the given AP 110, the packet loss rate, etc.
[0018] In another example, the third AP 110c associated with the third client device 120c and the fourth client device 120d can authorize traffic to conform to a third privilege group mapping 130c, which replaces the fourth privilege group mapping 130d provided earlier. In this example, the third client device 120c receives the third privilege group mapping 130c and configures traffic according to this new third privilege group mapping 130c. In various embodiments, the third client device 120c deletes or overwrites the fourth privilege group mapping 130d. In this example, the fourth client device 120d continues to use the fourth privilege group mapping 130d, even though the third AP 110c authorizes use of the third privilege group mapping 130c; and in response, the third AP 110c disassociates from the fourth client device 140d; disconnecting the connection between them. In some embodiments, the third AP 110c can attempt to resend the updated third privilege group mapping 130c to the fourth client device 120d one or more times before disassociating from the fourth client device 120d. In some embodiments, disassociating from the third AP 110c allows the fourth client device 120d to re-associate with the third AP 110c and receive the third privilege group mapping 130c as part of the association process for proper use after re-association.
[0019] In some embodiments, in addition to one or more re-association attempts and the fourth client device 120d continuing to insist on classifying traffic according to a scheme other than the third permission group mapping 130c authorized by the third AP 110c, the third AP 110c can blacklist (locally or over the network) (i) the fourth client device 120d, (ii) an account associated with the fourth client device 120d, or (iii) an application running on the fourth client device 120d whose traffic does not comply with the third permission group mapping 130c. In other words, when the fourth client device 120d refuses to classify traffic according to the third permission group mapping 130c, the third AP 110c can refuse to associate with the fourth client device 120d. APs 110 can manage blacklists of devices, users, or applications that do not classify traffic according to an authorized permission group mapping 130 to prevent malicious or unauthorized use of network resources.
[0020] In another example, a fifth client device 120e that has not yet associated with any of the APs 110a-c in the environment 100 can receive the currently authorized permission group mappings 130a-c to determine which AP 110 to associate with (e.g., through an 802.11u exchange process). For example, the fifth client device 120e can receive the permission group mappings 130 through GAS-221 (Generic Advertisement Service) queries and responses that do not require active association / connection between the APs 110 and the fifth client device 120e. Thus, the fifth client device 120e can analyze the several permission group mappings 130a-c to determine how to receive the highest QoS based on a priority of a user of the fifth client device 120e. Once the fifth client device 120e determines which of the APs 110a-c to associate with based on the individual permission group mappings 130a-c, the fifth client device 120e can begin an association process with the selected AP 110 and delete / discard the permission group mappings 130 of the non-associated APs 110.
[0021] In some embodiments, the client device 120 evaluates a number of APs 110 based on the priority levels assigned to various traffic types within the permission group mapping 130 and associates with a given AP 110 that provides the most matching permission level to the communication priority of the client device 120. For example, if the client device 120 is attempting to prioritize communications to / from application A, the client device 120 can select an AP 110 whose permission group mapping 130 gives application A the highest priority among the received permission group mappings 130. In another example, if the client device 120 is attempting to use application B, but not prioritize communications to / from application B relative to other applications running on the client device 120, the client device 120 can select an AP 110 that does not blacklist application B or block / stop communications to / from application B.
[0022] In some embodiments, the client device 120 uses the permission group mapping 130 to configure (or reconfigure) how traffic is formed such that the client device 120 receives a higher QoS for traffic according to the permission group mapping of the selected AP 110. For example, consider a video conferencing application that can include video streams, audio streams, and text streams (e.g., for instant messaging between video conference participants). If the streams are identified, the permission group mapping 130 can assign different permissions and / or priority levels to the different streams (e.g., provide greater latency elasticity to audio than video, which is provided greater latency elasticity than text), but if the streams are not identified, the lowest permission level is assigned to data to / from the video conferencing application (e.g., all data is treated as belonging to a text stream unless identified). Thus, the client device 120 can configure traffic to identify different QoS markers for different streams to receive a higher overall QoS according to the permission group mapping 130.
[0023] The APs 110 can include various networking devices configured to provide wireless networks (e.g., IEEE 802.11 or “WiFi” networks, Bluetooth® networks, ZigBee® networks, Z-Wave® networks, Thread® networks, LiFi® networks, etc.), cellular (including generations and their subtypes, such as Long-Term Evolution (LTE) and Fifth Generation New Radio (5G NR)) networks, Citizens Broadband Radio Service (CBRS) networks, proprietary networks, etc. Example hardware that can be included in the APs 110 will be discussed in more detail with respect to FIG. 2. The APs 110 can include various networking devices configured to provide wireless networks (e.g., IEEE 802.11 or “WiFi” networks, Bluetooth® networks, ZigBee® networks, Z-Wave® networks, Thread® networks, LiFi® networks, etc.), cellular (including generations and their subtypes, such as Long-Term Evolution (LTE) and Fifth Generation New Radio (5G NR)) networks, Citizens Broadband Radio Service (CBRS) networks, proprietary networks, etc. Example hardware that can be included in the APs 110 will be discussed in more detail with respect to FIG. 2. Figure 5 The APs 110 can include various networking devices configured to provide wireless networks (e.g., IEEE 802.11 or “WiFi” networks, Bluetooth® networks, ZigBee® networks, Z-Wave® networks, Thread® networks, LiFi® networks, etc.), cellular (including generations and their subtypes, such as Long-Term Evolution (LTE) and Fifth Generation New Radio (5G NR)) networks, Citizens Broadband Radio Service (CBRS) networks, proprietary networks, etc. Example hardware that can be included in the APs 110 will be discussed in more detail with respect to FIG. 2.
[0024] Similarly, the client devices 120 can include any computing device configured to wirelessly connect to one or more APs 110. Example client devices 120 can include, but are not limited to, a smartphone, a feature phone, a tablet computer, a laptop computer, a desktop computer, an Internet of Things (loT) device, and the like. Example hardware that can be included in the client devices 120 will be discussed in relation to FIG. 2. Figure 5 A more detailed discussion is provided.
[0025] Figure 2 A rights group mapping 130 is shown in accordance with an embodiment of the disclosure. The rights group mapping 130 assigns individual priority levels 210 to individual applications based on the AppIDs 220 of the applications. Thus, several such applications can be grouped for individual priority levels 210. The rights group mapping 130 thus defines how a set of rights groups are allocated among individual applications requesting network resources (e.g., bandwidth) on the network.
[0026] As shown, a first group of AppIDs 220a is grouped for a first priority level 210a (e.g., rights granted applications), a second group of AppIDs 220b is grouped for a second priority level 210b (e.g., regular applications), and an nth group of AppIDs 220n is grouped for an nth priority level 210n (e.g., blacklisted applications). Various other categories can be provided to group AppIDs 220 into sets with corresponding priority levels 210 that can vary as network conditions change (e.g., reduced bandwidth applications, time-controlled applications, backup applications, etc.). For example, a first application can have an associated AppID 220 that is associated with a first priority level at a first time and a second priority level at a second time due to an increase / decrease in available bandwidth, an appearance / disappearance of a higher priority application communicating on the network, an appearance / disappearance of a higher priority client device 120 associated with an AP 110, and the like.
[0027] The priority levels 210 can be described by mobile device-provided QoS level descriptors 230 and enterprise-provided QoS level descriptors 240, which are used by the client device 120 and the AP 110, respectively, to handle and prioritize traffic. For example, the client device 120 can create, customize, or adjust the mobile device-provided QoS level descriptors 230 for applications described by the client device 120 to provide communication for the respective applications at known QoS levels (e.g., at a guaranteed bit rate) by various key performance indicators (e.g., data rate, delay / jitter bounds, application category, DSCP or TOS marking, etc.). In another example, the network controller 140 can specify enterprise-provided QoS level descriptors 240 for the AP 110 to handle traffic for a given application, which can be unknown to the client device 120. The enterprise-provided QoS level 240 can be defined based on various key performance indicators (e.g., priority, delay / jitter bounds, application category, etc.) and indicates that the client device 120 map a differentiated services code point (DSCP) value to a traffic identifier (TID) or user priority (UP) for each application to identify how the AP 110 will handle the traffic.
[0028] While Figure 2 While the mobile QoS level descriptors 230 and the enterprise QoS level descriptors 240 are shown separately, a given AppID 220 can be described by one or both of the mobile QoS level descriptors 230 and the QoS level descriptors 240.
[0029] In various embodiments, the QoS level descriptors 230 / 240 can specify different privileges for different content streams (also referred to as data streams) from a single application. For example, a video conferencing application can provide different levels of service for audio, video, and content (e.g., text, metadata, slides / images) related to a presentation such that the most delay-sensitive data is provided a higher priority than less sensitive data.
[0030] In various embodiments, when a client device 120 initiates a communication with an application that is not currently assigned a priority level 210, the client device 120 can negotiate which priority level 210 the application should be assigned. The client device 120 reports the expected demands of the application being negotiated, including various key performance indicators, such as latency, jitter, application type (e.g., enterprise, gaming, productivity, general purpose), relative priority assessment to other applications running on the client device 120, and the like. In some embodiments, the key performance indicators include previous socket read content of the activity level of the application, thus including flow descriptors, minimum and peak data rate values, latency bound information, and jitter bound information (e.g., reported through TSPEC (Traffic Specification)).
[0031] Figure 3A is a flow diagram of a method 300 in the perspective of a client device 120 that is associated with an AP 110 prior to receiving the privilege group mapping 130 according to embodiments of the present disclosure. The method 300 begins at block 310, where the client device 120 associates with the AP 110 to establish a communication session according to a wireless communication standard (e.g., WiFi, Bluetooth, LTE, 5G, or other communication protocol). Once block 310 is complete, the client device 120 and the AP 110 can establish an association / connection and exchange encryption keys through various handshake procedures to begin transmitting data between each other.
[0032] At block 320, the client device 120 receives the privilege group mapping 130 from the AP 110 that was associated in block 310. In various embodiments, the client device 120 can initiate the transfer of the privilege group mapping 130 through an Access Network Query Protocol (ANQP) GAS request that identifies an application running on the client device 120, and the AP 110 returns the privilege level associated with the identified application in an initial response (or in one or more comeback responses). In some embodiments, the client device 120 can receive the full privilege group mapping 130 (identifying the priority levels 210 associated with all AppIDs 220 currently mapped in the network), while in other embodiments, the client device 120 can receive a partial privilege group mapping 130 (identifying the priority levels 210 for the AppIDs 220 identified in the query).
[0033] At block 330, the client device 120 selectively reconfigures traffic according to the permission group mapping 130 of the associated AP 110 to increase the QoS levels available to the client device 120. For example, the client device can initially configure traffic from a given application in a first format according to the permission group mapping 130 that gives a first QoS level, but the permission group mapping 130 provides a second QoS level for the traffic in a second format. Thus, if the second QoS level provides a preferred priority level for the traffic, the client device can reconfigure the traffic from the first format to the second format (e.g., by separately formatting different data streams, by requesting a different encapsulation or datagram format) to take advantage of the second QoS level.
[0034] At block 340, the client device 120 applies QoS markings to uplink traffic to the AP 110 according to the permission group mapping 130 of the AP 110 with which the client device is associated. In various embodiments, the QoS markings are added to packets / frames transmitted from the client device to the AP 110 according to the application, or the particular data format used to send or request data (e.g., in different streams from one application). In various embodiments, the application can apply one or more QoS markings or AppIDs to the traffic, and an operating system or message controller on the client device 120 replaces the original QoS markings applied by the application with the QoS markings based on the permission group mapping 130 provided by the AP 110.
[0035] In various embodiments, the method 300 can repeat from block 320 such that the client device 120 can receive an updated version of the permission group mapping 130 after receiving an earlier permission group mapping 130 while remaining associated with the current AP 110. In various embodiments, the updated version of the permission group mapping 130 can be a complete remapping of the permission levels to different applications, or can be a partial remapping that identifies changes to the permission level assignments relative to the earlier version of the permission group mapping 130 and / or permission level assignments to newly identified applications. Further, as discussed in more detail with respect to Figure 3B As discussed in more detail, the client device 120 can request and / or receive permission group mappings 130 from other APs 110 to determine whether to request a handoff to a different AP 110 based on the permissions assigned in the various permission group mappings 130.
[0036] Figure 3Bis a flowchart of a method 305 from the perspective of a client device that is associated with an AP 110 after receiving the permission group mapping 130, in accordance with embodiments of the present disclosure. In various embodiments, the method 305 can be performed by a client device 120 that is not associated with any AP 110, or a client device 120 that is currently associated with a given AP 110 but is evaluating whether to associate with a different AP 110. The method 305 begins at block 315, where the client device 120 identifies one or more candidate APs 110 with which to associate. These candidate APs 110 can include any of the APs 110 within range of the client device 120, or a selected subset of the APs 110 within range of the client device 120 (e.g., those APs 110 belonging to network A but not those belonging to network B, those APs 110 providing a given signal strength, those APs 110 operating a given communication standard, etc.).
[0037] At block 325, the client device 120 receives the permission group mapping 130 from the candidate APs 110 identified in block 315. In various embodiments, the client device 120 can initiate the transfer of the permission group mapping 130 through an Access Network Query Protocol (ANQP) GAS request that identifies an application running on the client device 120, with the candidate APs 110 returning the permission level associated with the identified application in an initial response (or in one or more reply responses). In some embodiments, the client device 120 can receive a complete permission group mapping 130 that identifies the priority levels 210 associated with all AppIDs 220 currently mapped in the network, while in other embodiments the client device 120 can receive a partial permission group mapping 130 that identifies the priority levels 210 for the AppIDs 220 identified in the query. In some embodiments, the client device 120 can also receive the permission group mapping 130 when it has already associated with a first AP 110a and is attempting to switch to a new AP 110 with a QoS that more closely aligns with the desired QoS, or when it receives updated permission levels from the APs 110.
[0038] At block 335, the client device 120 selects which candidate AP 110 to associate with (or remain associated with) based at least in part on the permission group mappings 130 received in block 325. In various embodiments, the client device 120 identifies the permission group mapping 130 that provides the best service according to the needs and priorities of the client device 120, and selects the AP 110 that provides that permission group mapping 130. For example, a first client device 120a executing a video conferencing application can select to associate with the first AP 110a that provides the highest level of permissions to the video conferencing application and the second highest level of permissions to a gaming application that the first client device 120a is not executing. In contrast, a second client device 120b that is not executing the video conferencing application but is executing the gaming application can select to associate with the second AP 110b that gives the gaming application a higher priority than the first AP 110a. Similarly, a third client device 120c that is executing both the video conferencing application and the gaming application can select to associate with which of the first AP 110a and the second AP 110b in the present example based on user-defined priorities of the two applications.
[0039] When several APs 110 provide permission group mappings 130 that all meet or exceed the requirements of the client device 120, the client device 120 can select the “best” permission group mapping based on prioritizing the following: the priority of remaining associated with the current AP 110, associating with the AP 110 that has the greatest range, associating with the AP 110 that is closest in physical distance to the client device 120, associating with the AP 110 that has the strongest signal, associating with the AP 110 that has the fewest active connections, etc.
[0040] At block 345, the client device 120 associates with the AP 110 selected from block 335 to establish a communication session according to a wireless communication standard (e.g., WiFi, Bluetooth, LTE, 5G, or other communication protocol). Once block 345 is complete, the client device 120 and the AP 110 can establish an association / connection and exchange encryption keys through various handshake procedures to begin transmitting data between each other.
[0041] At block 355, the client device 120 selectively reconfigures traffic according to the permission group mapping 130 of the associated AP 110 to increase the QoS levels available to the client device 120. For example, the client device can initially configure traffic from a given application in a first format according to the permission group mapping 130 that gives a first QoS level, but the permission group mapping 130 also provides a second QoS level in a second format for the traffic. Thus, if the second QoS level provides a preferred priority for the traffic, the client device can reconfigure the traffic from the first format to the second format (e.g., by separately formatting different data streams, by requesting a different encapsulation or datagram format) to take advantage of the second QoS level.
[0042] At block 365, the client device 120 applies QoS markings to uplink traffic to the AP 110 according to the permission group mapping 130 of the AP 110 with which the client device is associated. In various embodiments, the QoS markings are added to packets / frames sent from the client device to the AP 110 according to the application, or the particular data format used to send or request data (e.g., in different streams from one application). In various embodiments, the application can apply one or more QoS markings or AppIDs to the traffic, and an operating system or message controller on the client device 120 replaces the original QoS markings applied by the application with the QoS markings based on the permission group mapping 130 provided by the AP 110.
[0043] In various embodiments, the client device 120 can perform the method 300 and / or the method 305 in response to the associated AP 110 sending an updated permission group mapping 130 to the client device 120. For example, after performing the method 300 or the method 305, the client device 120 can perform the method 300 (starting at block 320) in response to receiving the updated permission group mapping 130 to maintain a connection with the associated AP 110. In another example, after performing the method 300 or the method 305, the client device 120 can perform the method 305 in response to receiving the updated permission group mapping 130 to determine whether to associate with a different AP 110.
[0044] In some embodiments, the AP 110 sends the updated privilege group mapping 130 in response to an update to the privilege group mapping 130 (e.g., in response to changing network conditions or after a predetermined amount of time, identifying a new application and mapping a privilege level to the application). In some embodiments, the AP 110 sends the updated privilege group mapping 130 in response to a client device misclassifying uplink traffic (e.g., using an outdated privilege group mapping 130, or applying QoS markings that do not conform to the updated privilege group mapping 130). In some embodiments, the client device requests the updated privilege group mapping 130 from the associated AP 110 and / or one or more other APs 110 to reevaluate whether to remain associated with the current AP 110.
[0045] Figure 4 is a flowchart of a method 400 from the perspective of an AP 110 according to embodiments of the disclosure. The method 400 can begin at block 410, where the AP 110 (or the network controller 140) maps applications to various privilege levels for accessing network resources, and maps applications into groups with shared privilege levels. In various embodiments, the AP 110 determines the privilege levels to be assigned based on the identity or category of the application, such that similar types of applications receive similar QoS levels. The AP 110 can change the privilege levels assigned to different applications based on current network conditions, including but not limited to: the number of client devices 120 associated with a given AP 110, the amount of traffic sent to / from the AP 110, the user accounts of the associated client devices 120, the SNR within the service range of the given AP 110, reported packet loss rates, etc. The AP 110 can negotiate with the client devices 120 what privilege levels to assign to various applications based on the network settings and connection requirements of new applications, including: latency, jitter, application type (e.g., enterprise, gaming, productivity, general), relative priority assessments to other applications running on the client devices 120, etc. In some embodiments, the key performance indicators include previous socket read content of the activity level of the application, thus including flow descriptors, minimum and peak data rate values, latency bound information, and jitter bound information (e.g., reported through TSPEC).
[0046] At block 420, the AP 110 sends the permission group mapping 130 to the client device 120. In various embodiments, the permission group mapping 130 can be sent to the client device 120 prior to the client device 120 being (potentially) associated with the AP 110, during initialization of the association with the client device 120, or after the client device 120 and AP 110 have established an association. In some embodiments, where the client device 120 and AP 110 have already associated, when the AP 110 sends the permission group mapping 130, the permission group mapping 130 can be an updated permission group mapping 130 that changes one or more permission levels for one or more applications, or adds a newly identified application to one or more permission levels. In some embodiments, the AP 110 can initiate the transfer of the permission group mapping 130 through an ANQP GAS request that identifies an application running on the client device 120, and the AP 110 returns the permission level associated with the identified application in an initial response or in one or more comeback responses. In some embodiments, the client device 120 can receive the full permission group mapping 130 (identifying the priority level 210 associated with all AppIDs 220 currently mapped in the network), while in other embodiments, the client device 120 can receive a partial permission group mapping 130 (identifying the priority level 210 for the AppIDs 220 identified in the query).
[0047] At block 430, the AP 110 receives packets from the associated client device 120. The packets can include a QoS marking of the application sending the packets to the AP 110. In various embodiments, the operating system or message controller on the client device 120 replaces the original QoS marking applied by the application with the QoS marking based on the permission group mapping 130 provided by the AP 110.
[0048] At block 440, the AP 110 determines whether the given client device is using QoS markings in compliance with the permission group mapping 130 on uplink traffic based on the packets received from the given client device according to block 430. The AP 110 can compare the QoS marking and AppID of the requesting application to the permission group mapping 130 to determine whether the client device 120 is marking packets sent to the AP 110 as prescribed by the permission group mapping 130. When the client device 120 has not properly classified traffic according to the permission group mapping 130, the method 400 proceeds to block 450 to determine what corrective action to apply. When the client device 120 has properly classified traffic according to the permission group mapping 130, the method 400 proceeds to block 490.
[0049] At block 450, the AP 110 determines whether a rights group mapping retransmission threshold has been reached for the non-compliant client device 120. For example, the AP 110 can attempt to provide the updated rights group mapping 130 to the client device 120 N times within a given time period before disassociating the client device 120. Thus, if the AP 110 has retransmitted the rights group mapping 130 N or more times and the client device 120 continues to use QoS markers that do not comply with the rights group mapping 130, the method 400 proceeds to block 470, at which the client device 120 is disassociated with the AP 110. Otherwise, when the retransmission threshold is not met (e.g., retransmissions < N), the method 400 proceeds to block 460, at which the AP 110 sends the rights group mapping 130 to the client device 120.
[0050] At block 460, the AP 110 retransmits the rights group mapping 130 to the client device 120 that is using QoS markers that do not comply with the rights group mapping 130. For example, the client device 120 can fail to receive the updated rights group mapping 130 (e.g., due to packet loss, the client device 120 being in sleep mode, lack of transmission from the AP 110) and continue to use the old rights group mapping 130 until the updated rights group mapping 130 is successfully received. After the rights group mapping 130 is sent to the client device 120 that is using QoS markers that do not comply with the rights group mapping 130, the method 400 returns to blocks 430 and 440, at which the AP 110 continues to receive packets from the monitored client device 120 to determine whether the client device 120 is now using the retransmitted rights group mapping 130.
[0051] At block 470, the AP 110 disassociates with the client device 120 that is using QoS markers that do not comply with the rights group mapping 130. In various embodiments, after disassociating with the client device 120, the AP 110 allows the disassociated client device 120 to attempt to reassociate with the AP 110 and receive the rights group mapping 130 one or more times. For example, when the client device 120 is unable to receive and implement the updated rights group mapping 130, the client device 120 can disassociate with the AP 110 and receive the updated rights group mapping 130 at or before reassociation, and then properly apply the updated QoS markers.
[0052] In some embodiments, once the client device 120 has disassociated with the AP 110 at least a threshold number of times within a given time period due to using QoS markers that do not comply with the access group mapping 130, or the behavior of the client device 120 violates a security policy, or the AP 110 determines that the client device 120 is engaging in malicious, rogue behavior, or determines that the client device 120 is not applying the QoS markers specified in the access group mapping 130 correctly, the method 400 optionally proceeds from block 470 to block 480. In block 480, the AP 110 blacklists the client device 120, thereby preventing the client device from reassociating with the AP 110 or another AP 110 in the network for at least a predetermined number of times (e.g., by ignoring or rejecting association requests).
[0053] At block 490, the AP 110 sends queued downlink traffic to the associated client device according to the QoS levels assigned in the access group mapping 130. The AP 110 can indicate in the packets sent to the client device 120 what the QoS marker for the uplink traffic should be, which is done by using an equivalent QoS marker in the downlink traffic. The method 400 can then return to block 430 to continue receiving packets from the client device 120, which mark the uplink traffic according to the access group mapping 130.
[0054] Figure 5 A hardware of a computing device 500 is shown, which can be used in the AP 110, client device 120, or network controller 140 described in the present disclosure. The computing device 500 includes a processor 510, a memory 520, and a communication interface 530. The processor 510 can be any processing element capable of performing the functions described herein. The processor 510 is representative of a single processor, multiple processors, a processor having multiple cores, and combinations thereof. The communication interface 530 facilitates communication between the computing device 500 and other devices. The communication interface 530 is representative of wireless communication antennas and various wired communication ports. The memory 520 can be volatile or non-volatile memory and can include RAM, flash memory, cache, disk drives, and other computer-readable memory storage devices. Although shown as a single entity, the memory 520 can be divided into different memory storage elements, e.g., RAM and one or more hard drives.
[0055] As shown, memory 520 includes various instructions that are executable by processor 510 to provide an operating system 521 for managing various functions of computing device 500, as well as one or more applications 522 for providing various functionality to a user of computing device 500, including one or more of the functionality described in this disclosure. In addition, memory 520 includes one or more permission group mappings 130 for analyzing how traffic transmitted between client device 120 and AP 110 is formatted.
[0056] In this disclosure, reference is made to various embodiments. However, the scope of the present disclosure is not limited to the specifically described embodiments. Rather, any combination of the described features and elements, whether related to different embodiments or not, is contemplated to implement and practice contemplated embodiments. Furthermore, when referring to elements of an embodiment in the form "at least one of A and B," it will be understood that the embodiment includes only elements A, only elements B, and elements both A and B are contemplated. Additionally, while some embodiments disclosed herein can implement advantages over other possible solutions or over the prior art, whether or not a given embodiment implements a particular advantage is not limiting to the scope of the present disclosure. Thus, aspects, features, embodiments, and advantages of the disclosure disclosed herein are merely illustrative and not limiting of the scope of the appended claims, unless expressly recited otherwise in the claims. Likewise, reference to "the invention" is not to be construed as an identification of any one of the disclosed inventions, unless expressly recited otherwise in the claims, and is not to be construed as a limitation on the scope of the disclosure.
[0057] As will be apparent to those of ordinary skill in the art, embodiments disclosed herein can be embodied as a system, a method, or a computer program product. Accordingly, embodiments can take the form of an entirely hardware embodiment, an entirely software embodiment (including firmware, resident software, microcode, etc.) or an embodiment combining software and hardware aspects that can all generally be referred to herein as a "circuit," "module" or "system." Furthermore, embodiments can take the form of a computer program product embodied in one or more computer readable medium(s) having computer readable program code embodied thereon.
[0058] Program code embodied on a computer readable medium can be transmitted using any appropriate medium, including but not limited to wireless, wired, optical fiber cable, RF, etc., or any suitable combination of the foregoing.
[0059] Computer program code for carrying out operations of embodiments of the present disclosure can be written in any combination of one or more programming languages, including an object oriented programming language such as Java, Smalltalk, C++ or the like and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider).
[0060] The computer program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other device to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide processes for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.
[0061] The computer program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other device to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide processes for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.
[0062] The computer program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other device to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide processes for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.
[0063] The flow and block diagrams in the drawings show the architectural, functional, and operational aspects of possible implementations of systems, methods, and computer program products according to various embodiments. In this regard, each block in the flow or block diagrams can represent a module, segment, or portion of code, which comprises one or more executable instructions for implementing the specified logical function(s). It should also be noted that in some alternative implementations, the functions noted in the blocks can occur out of the order noted in the figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently, or the blocks can sometimes be executed in the reverse order, depending on the functionality involved. Such functionality can be executed in response to one or more events, or in response to one or more requests from other components or systems. Also, each block in the block diagrams and / or flow diagrams can represent a combination of segments or portions of code, which can be implemented at either the hardware level or in a combination of hardware and computer instructions.
[0064] In light of the foregoing, the scope of the present disclosure is determined by the appended claims.
Claims
1. A method for communication, comprising: At the client device, a first permission group mapping is received from a first access point (AP), the first permission group mapping identifying a first permission level of one or more applications executing on the client device; The client device receives a second permission group mapping from a second AP, the second permission group mapping identifying a second permission level for the one or more applications; The selection is made between the first AP and the second AP based on which of the first permission group mapping and the second permission group mapping better meets the needs of the one or more applications; Establish a connection with the selected AP; as well as Based on the permission group mapping corresponding to the selected AP, a Quality of Service (QoS) flag is applied to the traffic sent from the client device to the selected AP.
2. The method according to claim 1, further comprising: In response to identifying that a given permission level mapped to a given application is lower than the desired QoS level, a new AP that provides the desired QoS level is identified; Disconnect from the first AP; and Establish a new connection with the new AP.
3. The method according to claim 1 or 2, wherein, The first permission group mapping is received before the client device is associated with the first AP, and the second permission group mapping is received when the client device is not associated with the second AP.
4. The method according to claim 1 or 2, wherein, When the client device is associated with the second AP, it receives the second permission group mapping and replaces the permission group mapping previously provided from the second AP with the second permission group mapping.
5. The method according to claim 1 or 2, further comprising: In response to receiving the first permission group mapping, the client device reconfigures the traffic sent from the client device to the first AP according to the permission group mapping to select a higher QoS category to apply to the traffic.
6. The method according to claim 1 or 2, wherein, The first permission group mapping identifier is the guaranteed bit rate for a given application.
7. The method according to claim 1 or 2, wherein, The operating system of the client device, based on the permission group mapping, replaces the original QoS tag imposed on the traffic by the application with the QoS tag.
8. The method according to claim 1 or 2, wherein, The client device applies a first QoS tag to a first packet type and applies a second QoS tag to a second packet type, wherein the first packet type and the second packet type originate from a single application.
9. A method for communication, comprising: Access points (APs) map multiple applications to a set of permission groups that are based on Quality of Service (QoS) levels within the network. Send the mapping of the permission group to the client device; Receive packets including QoS tags from the client device; as well as In response to determining that the QoS tag received from the client device does not match the permission group for the packet, a corrective action is performed regarding the client device.
10. The method according to claim 9, wherein, The corrective action includes one or more of the following: Disconnect the client device from the network; and The set of permission groups is resent to the client device.
11. The method according to claim 9 or 10, wherein, The group includes a first data stream assigned a first QoS tag and a second data stream assigned a second QoS tag, wherein the QoS tag is determined to be mismatched with the permission group for the group when one or more of the first QoS tag and the second QoS tag do not match the permission group for the first data stream or the second data stream, respectively.
12. The method according to claim 9 or 10, further comprising: Send downlink traffic to the client device in accordance with the QoS flag indication of the permission group assigned to the receiving application running on the client device.
13. The method according to claim 9 or 10, wherein, The set of permission groups is sent before the client device is associated with the AP.
14. The method according to claim 9 or 10, wherein, After the client device is associated with the AP, the set of permission groups is sent to the client device, and the set of permission groups is replaced with the set of permission groups from the earlier version.
15. The method according to claim 9 or 10, further comprising: In response to changes in network conditions, the multiple applications are remapped to the set of permission groups based on the changes in network conditions.
16. The method according to claim 9 or 10, further comprising: In response to the identification of a new application requesting resources on the network, a permission group to be assigned to the new application is negotiated based on the network settings and connection requirements of the new application.
17. A computer-readable storage device including instructions that, when executed by a processor, perform operations including: Access points (APs) map multiple applications to a set of permission groups that are based on Quality of Service (QoS) levels within the network. Send the mapping of the permission group to the client device; Receive packets including QoS tags from the client device; as well as In response to determining that the QoS tag received from the client device does not match the permission group for the packet, the client device is disconnected from the network.
18. The computer-readable storage device according to claim 17, wherein, The group includes a first data stream assigned a first QoS tag and a second data stream assigned a second QoS tag, wherein the QoS tag is determined to be mismatched with the permission group for the group when one or more of the first QoS tag and the second QoS tag do not match the permission group for the first data stream or the second data stream, respectively.
19. The computer-readable storage device according to claim 17 or 18, wherein, The permission group is sent before the client device is associated with the AP.
20. The computer-readable storage device according to claim 17 or 18, wherein, After the client device is associated with the AP, the permission group is sent to the client device, replacing the earlier version of the permission group.
21. A computer-readable storage device comprising instructions that, when executed by a processor, perform the method according to any one of claims 1 to 8.
22. A client device, the client device comprising a processor and a memory, wherein, The processor is configured to operate according to the method of any one of claims 1 to 8.
23. An access point, the access point comprising a processor and a memory, wherein, The processor is configured to operate according to the method of any one of claims 9 to 16.
Citation Information
Patent Citations
Systems and Methods for Differentiated Fast Initial Link Setup
US20140254502A1