Dynamic M2M Access Control via Cached Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Machine-to-Machine (M2M) devices frequently accessing operator networks can abuse radio frequency resources, leading to service availability issues for other devices, as existing methods struggle to enforce guidelines for resource usage in real-time.

Innovation Solution

Implementing a system that determines in real-time whether M2M devices comply with policies by using a cached policy data structure stored in base stations, allowing or rejecting access based on predefined thresholds and security protocols, and detecting policy violations through message analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If M2M devices are allowed to access the operator network freely, then device connectivity and communication capability are improved, but radio frequency resources are abused leading to service availability issues for other devices

Engineering Contradiction:
Improvedevice connectivityVSAvoidservice availability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system dynamically adjusts network access permissions for M2M devices based on real-time policy compliance evaluation. The network device continuously monitors device behavior, compares it against stored policies, and dynamically allows or rejects access requests accordingly, transforming static network access into a dynamic, adaptive process that resolves the contradiction between connectivity and service availability

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements a feedback mechanism where the network device receives compliance information from M2M devices, evaluates it against stored policies, and sends control decisions back to the devices. This closed-loop feedback system enables real-time enforcement of resource usage guidelines, preventing resource abuse while maintaining connectivity for compliant devices

Inventive Principle:
Principle #23Feedback

Solution Approach 3:

The system performs preliminary actions by pre-storing policy rules and compliance criteria in the network device before M2M devices attempt network access. This preliminary preparation enables immediate real-time evaluation of access requests without requiring complex real-time policy retrieval, allowing the system to quickly enforce resource constraints while maintaining device connectivity

Inventive Principle:
Principle #10Preliminary action

2Reliability

If real-time policy compliance determination is implemented, then resource abuse is prevented and service availability is maintained, but system complexity increases due to cached policy data structures and continuous monitoring

Engineering Contradiction:
Improveservice availabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary action by pre-storing policy rules, compliance criteria, and evaluation algorithms in cached policy data structures within the network device before runtime operations. This preliminary preparation eliminates the need for complex real-time policy retrieval and processing, simplifying the real-time compliance determination process while maintaining service availability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses copying by creating cached copies of policy data structures and compliance rules in the network device's local memory. Instead of accessing complex policy management systems in real-time, the network device uses these pre-copied policy structures for immediate compliance evaluation, reducing system complexity while maintaining reliable service availability control

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9450983B2Controlling access to an operator network by non-conforming devices
Publication Date: 2016.09.20 VERIZON PATENT & LICENSING INC
  • US9450983B2 patent drawing
  • US9450983B2 patent drawing
  • US9450983B2 patent drawing

AI summary

A device is configured to receive an alarm message from a particular device that received a radio resource control request from a client device. The alarm message may indicate that a threshold access limit to an operator network is satisfied by the client device or that a particular protocol is being used by the client device. The device may determine a policy associated with the client device. The policy may indicate a policy rule associated with a policy action to be taken if the policy rule is violated. The device may determine the policy rule is violated based on the alarm message received from the particular device. The device may instruct the particular device to perform the policy action, by accepting or rejecting the radio resource control request, based on the policy rule being violated.