Cloud-Based Private Area Network for Cellular Device Grouping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Public cellular networks do not provide a mechanism for devices to determine if they are associated with the same user or account, leading to strict security policies that prevent devices from trusting each other and lacking the functionality of private or home gateways.
Innovation Solution
A cloud-based private area network is implemented by a wireless carrier that uses identification information to group devices by customer account, creating a customer-specific gateway that enables secure communication and provides functions like network address translation, DHCP, and firewall control, allowing devices to detect and communicate securely over a WAN.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If public IP addresses are assigned randomly and periodically in a public cell network, then network security is improved, but device trust and communication functionality deteriorate
Solution Approach 1:
The patent segments the public network into account-based virtual subnets by creating a mapping between customer accounts and virtual subnets. This allows devices from the same account to be logically grouped together while maintaining security isolation from other accounts, resolving the contradiction between network security and device trust.
Solution Approach 2:
The patent introduces a cloud-based gateway as an intermediary that mediates between devices on the public network. The gateway maintains the account-to-virtual-subnet mapping and enables devices to discover and communicate with each other through the gateway, providing trust mechanisms without requiring direct peer-to-peer communication.
2Reliability
If strict security policies are implemented to prevent device trust, then network security is improved, but communication functionality and usability deteriorate
Solution Approach 1:
The patent applies local quality by creating account-specific virtual subnets that provide localized trust and communication functionality. Within each virtual subnet, devices can trust each other and access gateway functions, while the overall network maintains security isolation between different accounts.
Solution Approach 2:
The patent implements universality by providing a multi-functional cloud-based gateway that performs various functions typically found in private gateways (DHCP, NAT, firewall, etc.) within the virtual subnet context. This allows the system to provide both security and rich communication functionality.
3Ease of operation
If cloud-based account-based virtual subnets are created, then device trust and communication are improved, but network complexity increases
Solution Approach 1:
The patent uses copying by creating virtual subnets as logical copies of traditional private networks within the public network infrastructure. These virtual subnets replicate the functionality of private gateways and networks without requiring physical deployment, simplifying the architecture while enabling account-based isolation.
Solution Approach 2:
The patent applies parameter changes by transforming the network identification parameters from simple public IP addresses to account-based virtual subnet identifiers. This parameter transformation enables the system to maintain security while providing account-specific communication functionality through changes in how addresses and networks are identified and managed.
Data Source
AI summary
Examples of the present disclosure describe systems and methods for implementing a cloud-based private area network. In aspects, various customer devices may be connected to a cloud-based carrier or wireless carrier. The carrier may use identification information associated with each customer device to group devices by, for example, customer account. For each customer account, the carrier may create and/or assign a customer-specific gateway. The customer gateway may enable devices identified as associated with an account to detect and communicate securely with each other over a cloud-based private area network. Additionally, each customer gateway may provide several functions typically found in private or home gateways and local area networks (LANs) to the devices associated with an account.


