Selective Access Control for Mobile IP Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computing devices that rely on internet connectivity for application access face limitations when users lack a valid data plan or exceed usage limits, restricting access to web-based applications and services.

Innovation Solution

Implementing a system that translates requests for managed and unmanaged services to corresponding IP addresses, allowing access to essential services like email and storage even without a valid data plan by routing requests through a multiprotocol label switching (MPLS) platform and content filter, while blocking non-essential services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional access control methods are used, then network security is maintained, but users cannot access critical services when data plan is invalid or expired

Engineering Contradiction:
Improveservice accessibilityVSAvoidunauthorized access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments network services into two categories: essential services (email, storage, contacts) and non-essential services (web browsing, applications). This segmentation allows differential access control where essential services remain accessible even with invalid data plans, while non-essential services require valid data plans. The segmentation is implemented through domain classification in the access control system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary access control system positioned between the user device and network services. This intermediary translates service requests and applies classification rules to determine whether to permit or deny access based on data plan validity and service type. The intermediary enables selective access control without requiring changes to the underlying network infrastructure or service providers.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If access is restricted to services requiring valid data plans, then network provider revenue is protected, but device functionality is limited when connectivity is unavailable

Engineering Contradiction:
Improvedevice functionalityVSAvoiddata plan consumption
Core Design Contradiction:
Adaptability or versatilityVSLoss of energy

Solution Approach 1:

The patent applies partial action by providing limited network access for essential services without requiring a valid data plan. Instead of fully restricting all services or fully enabling all services, the system partially enables access to critical services (email, storage, contacts) while maintaining restrictions on non-essential services. This partial access maintains basic device functionality without consuming data plan resources.

Inventive Principle:
Principle #16Partial or excessive action

3Ease of operation

If users must maintain continuous Internet connection, then access to web-based applications is ensured, but user mobility and flexibility are reduced

Engineering Contradiction:
Improveuser accessibilityVSAvoidnetwork management
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements self-service by automatically classifying service requests and applying access control rules without requiring user intervention. The access control system autonomously determines whether to permit or deny access based on the service type and data plan status. Users simply request services normally, and the system handles the complexity of access control transparently, maintaining ease of operation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10057300B2Selective access control to mobile IP network
Publication Date: 2018.08.21 WIRELESS MANAGEMENT SOLUTIONS LLC
  • US10057300B2 patent drawing
  • US10057300B2 patent drawing
  • US10057300B2 patent drawing

AI summary

Systems and methods are described for managing access of a computing device to services over a mobile network where requests for managed or unmanaged services are translated to corresponding IP addresses sent to the computing device and corresponding requests sent to the translated IP addresses are permitted if the computing device has a valid data plan for using the mobile network, are denied if the computing device does not have a valid data plan and the request corresponds to the first address, and are permitted even if the computing device does not have a valid data plan if the request corresponds to the second address.