Network Access Token Policy Enforcement in Cellular Gateways
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for downlink traffic policy enforcement in cellular communication networks, such as the TFT/SDF approach, incur overhead and latency due to extensive packet inspections and table lookups, making them inefficient and not scalable for increasing numbers of application services.
Innovation Solution
A method involving a gateway device that detects triggers to obtain and send network access tokens in control-plane signaling, facilitating the validation and mapping of downlink data packets using these tokens, thereby reducing the need for extensive packet inspections and table lookups.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If packet inspections and table lookups are used for downlink traffic policy enforcement, then policy control accuracy is improved, but processing overhead and latency increase
Solution Approach 1:
The patent applies preliminary action by pre-establishing binding relationships between application identifiers and QoS parameters in the control plane before user data arrives. The gateway device derives and stores these bindings in advance, so when downlink traffic arrives, the gateway can directly match application identifiers to pre-stored QoS parameters without performing real-time packet inspection or table lookups, thus reducing processing latency while maintaining policy control accuracy
Solution Approach 2:
The patent extracts the policy enforcement function from the user plane data path and relocates it to the control plane. By separating control signaling from user data transmission, the system performs policy setup and parameter binding in the control plane, allowing the user plane to simply forward traffic based on pre-established rules, thereby eliminating the need for complex real-time packet inspections and reducing processing overhead
2Measurement precision
If extensive packet inspections are performed for each downlink data packet, then policy enforcement accuracy is improved, but processing resources and memory usage increase
Solution Approach 1:
The system performs preliminary action by pre-computing and storing the binding relationships between application identifiers and QoS parameters in the control plane. This allows the gateway device to perform simple identifier matching rather than extensive packet inspections, significantly reducing processing resources and memory usage while maintaining policy enforcement accuracy
Solution Approach 2:
The patent uses copying by creating and storing copies of QoS parameter bindings in the control plane before user data arrives. Instead of inspecting each packet against original policy rules, the gateway device uses these pre-copied bindings for rapid matching, reducing the computational complexity and resource consumption of policy enforcement
3Adaptability or versatility
If traditional TFT/SDF approaches are used for traffic mapping, then comprehensive policy control is achieved, but scalability decreases with increasing application services
Solution Approach 1:
The patent extracts the complex policy control logic from the user plane and places it in the control plane. The control plane handles application identifier to QoS parameter binding setup, while the user plane only performs simple identifier matching. This separation allows the system to scale efficiently as it can pre-process policy rules in the control plane without increasing user plane processing complexity, even as the number of application services increases
4Reliability
If downlink traffic policy enforcement is performed at the gateway device, then network security is improved, but processing overhead increases
Solution Approach 1:
The patent extracts the heavy lifting of policy rule processing from the gateway device's user plane and relocates it to the control plane. The gateway device only needs to perform simple application identifier matching against pre-stored bindings, while the control plane handles complex policy interpretation and parameter derivation. This maintains network security through centralized control while significantly reducing gateway processing overhead and device complexity
Data Source
AI summary
A gateway device detects a trigger associated with a device and, in response, identifies an application service associated with the device, obtains a traffic network policy associated with the application service, and obtains a network access token based on the traffic network policy. The network access token facilitates validating and/or mapping a downlink data packet obtained at the gateway device in user-plane traffic that is destined for the device. The network access token is sent to an entity in control-plane signaling. Subsequently, the gateway device obtains a downlink data packet including the network access token. The gateway device verifies the network access token and/or maps the downlink data packet to the device using data obtained from the network access token. The network access token may be removed from the downlink data packet before the downlink data packet is sent to the device according to the mapping.


