Network Access Token Policy Enforcement in Cellular Gateways

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for downlink traffic policy enforcement in cellular communication networks, such as the TFT/SDF approach, incur overhead and latency due to extensive packet inspections and table lookups, making them inefficient and not scalable for increasing numbers of application services.

Innovation Solution

A method involving a gateway device that detects triggers to obtain and send network access tokens in control-plane signaling, facilitating the validation and mapping of downlink data packets using these tokens, thereby reducing the need for extensive packet inspections and table lookups.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If packet inspections and table lookups are used for downlink traffic policy enforcement, then policy control accuracy is improved, but processing overhead and latency increase

Engineering Contradiction:
Improvepolicy control accuracyVSAvoidprocessing latency
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-establishing binding relationships between application identifiers and QoS parameters in the control plane before user data arrives. The gateway device derives and stores these bindings in advance, so when downlink traffic arrives, the gateway can directly match application identifiers to pre-stored QoS parameters without performing real-time packet inspection or table lookups, thus reducing processing latency while maintaining policy control accuracy

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts the policy enforcement function from the user plane data path and relocates it to the control plane. By separating control signaling from user data transmission, the system performs policy setup and parameter binding in the control plane, allowing the user plane to simply forward traffic based on pre-established rules, thereby eliminating the need for complex real-time packet inspections and reducing processing overhead

Inventive Principle:
Principle #2Taking out (Extraction)

2Measurement precision

If extensive packet inspections are performed for each downlink data packet, then policy enforcement accuracy is improved, but processing resources and memory usage increase

Engineering Contradiction:
Improvepolicy enforcement accuracyVSAvoidprocessing resources
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system performs preliminary action by pre-computing and storing the binding relationships between application identifiers and QoS parameters in the control plane. This allows the gateway device to perform simple identifier matching rather than extensive packet inspections, significantly reducing processing resources and memory usage while maintaining policy enforcement accuracy

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by creating and storing copies of QoS parameter bindings in the control plane before user data arrives. Instead of inspecting each packet against original policy rules, the gateway device uses these pre-copied bindings for rapid matching, reducing the computational complexity and resource consumption of policy enforcement

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If traditional TFT/SDF approaches are used for traffic mapping, then comprehensive policy control is achieved, but scalability decreases with increasing application services

Engineering Contradiction:
Improvepolicy control comprehensivenessVSAvoidsystem scalability
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent extracts the complex policy control logic from the user plane and places it in the control plane. The control plane handles application identifier to QoS parameter binding setup, while the user plane only performs simple identifier matching. This separation allows the system to scale efficiently as it can pre-process policy rules in the control plane without increasing user plane processing complexity, even as the number of application services increases

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If downlink traffic policy enforcement is performed at the gateway device, then network security is improved, but processing overhead increases

Engineering Contradiction:
Improvenetwork securityVSAvoidgateway processing overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the heavy lifting of policy rule processing from the gateway device's user plane and relocates it to the control plane. The gateway device only needs to perform simple application identifier matching against pre-stored bindings, while the control plane handles complex policy interpretation and parameter derivation. This maintains network security through centralized control while significantly reducing gateway processing overhead and device complexity

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11290382B2Efficient policy enforcement for downlink traffic using network access tokens—control-plane approach
Publication Date: 2022.03.29 QUALCOMM INC
  • US11290382B2 patent drawing
  • US11290382B2 patent drawing
  • US11290382B2 patent drawing

AI summary

A gateway device detects a trigger associated with a device and, in response, identifies an application service associated with the device, obtains a traffic network policy associated with the application service, and obtains a network access token based on the traffic network policy. The network access token facilitates validating and/or mapping a downlink data packet obtained at the gateway device in user-plane traffic that is destined for the device. The network access token is sent to an entity in control-plane signaling. Subsequently, the gateway device obtains a downlink data packet including the network access token. The gateway device verifies the network access token and/or maps the downlink data packet to the device using data obtained from the network access token. The network access token may be removed from the downlink data packet before the downlink data packet is sent to the device according to the mapping.