Cloud-Based Private Area Network for Cellular Device Grouping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Public cellular networks do not provide a mechanism for devices to determine if they are associated with the same user or account, leading to strict security policies that prevent devices from trusting each other and lacking the functionality of private or home gateways.

Innovation Solution

A cloud-based private area network is implemented by a wireless carrier that uses identification information to group devices by customer account, creating a customer-specific gateway that enables secure communication and provides functions like network address translation, DHCP, and firewall control, allowing devices to detect and communicate securely over a WAN.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If public IP addresses are assigned randomly and periodically in a public cell network, then network security is improved, but device trust and communication functionality deteriorate

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice trust and communication
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the public network into account-based virtual subnets by creating a mapping between customer accounts and virtual subnets. This allows devices from the same account to be logically grouped together while maintaining security isolation from other accounts, resolving the contradiction between network security and device trust.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a cloud-based gateway as an intermediary that mediates between devices on the public network. The gateway maintains the account-to-virtual-subnet mapping and enables devices to discover and communicate with each other through the gateway, providing trust mechanisms without requiring direct peer-to-peer communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If strict security policies are implemented to prevent device trust, then network security is improved, but communication functionality and usability deteriorate

Engineering Contradiction:
Improvenetwork securityVSAvoidcommunication functionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by creating account-specific virtual subnets that provide localized trust and communication functionality. Within each virtual subnet, devices can trust each other and access gateway functions, while the overall network maintains security isolation between different accounts.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements universality by providing a multi-functional cloud-based gateway that performs various functions typically found in private gateways (DHCP, NAT, firewall, etc.) within the virtual subnet context. This allows the system to provide both security and rich communication functionality.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If cloud-based account-based virtual subnets are created, then device trust and communication are improved, but network complexity increases

Engineering Contradiction:
Improvedevice trust and communicationVSAvoidnetwork architecture
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent uses copying by creating virtual subnets as logical copies of traditional private networks within the public network infrastructure. These virtual subnets replicate the functionality of private gateways and networks without requiring physical deployment, simplifying the architecture while enabling account-based isolation.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent applies parameter changes by transforming the network identification parameters from simple public IP addresses to account-based virtual subnet identifiers. This parameter transformation enables the system to maintain security while providing account-specific communication functionality through changes in how addresses and networks are identified and managed.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11736444B2Cloud-based private area network
Publication Date: 2023.08.22 NAGRASTAR LLC
  • US11736444B2 patent drawing
  • US11736444B2 patent drawing
  • US11736444B2 patent drawing

AI summary

Examples of the present disclosure describe systems and methods for implementing a cloud-based private area network. In aspects, various customer devices may be connected to a cloud-based carrier or wireless carrier. The carrier may use identification information associated with each customer device to group devices by, for example, customer account. For each customer account, the carrier may create and/or assign a customer-specific gateway. The customer gateway may enable devices identified as associated with an account to detect and communicate securely with each other over a cloud-based private area network. Additionally, each customer gateway may provide several functions typically found in private or home gateways and local area networks (LANs) to the devices associated with an account.