Network Policy Management for Foreground Applications
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network policy management systems in wireless communication systems restrict foreground applications based on per-application unique identifiers, preventing access to restricted networks without allowing permitted applications to access unrestricted networks.
Innovation Solution
A method and system that discover networks, determine if they are restricted, apply restricted network rules, and adjust network scores to prioritize connections to unrestricted networks, using a per-provider subscription management object (PPS-MO) to set access permissions for applications, allowing permitted applications to access restricted networks while blocking prohibited ones.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If network policies are enforced only to background applications on a per application basis using application unique identifier, then background applications can be restricted from accessing restricted networks, but foreground applications cannot be selectively permitted to access restricted networks while maintaining network restrictions
Solution Approach 1:
The patent segments network policy management by application type (foreground vs. background) and access permission level. It introduces separate policy enforcement mechanisms for different application categories, allowing foreground applications to be evaluated individually against network policies while background applications are managed as a group. This segmentation enables selective permission granting without overwhelming complexity.
Solution Approach 2:
The patent implements dynamic network policy enforcement that adapts based on application foreground status. The system dynamically evaluates foreground applications against network policies in real-time, while background applications receive static policy treatment. This dynamic approach allows the system to adjust access control granularity based on operational context, improving flexibility without proportionally increasing complexity.
2Reliability
If an application is restricted from accessing the network using per application unique identifier, then the application is prevented from accessing any network, but permitted applications cannot access unrestricted networks simultaneously
Solution Approach 1:
The patent applies local quality by implementing different access control policies for different networks based on their restriction status. Restricted networks receive strict policy enforcement evaluated against application credentials, while unrestricted networks allow broader access. This localized policy application ensures reliable access control where needed while maintaining versatility for open networks.
Solution Approach 2:
The patent performs preliminary evaluation of application credentials and network policies before establishing connections. The system pre-assesses whether foreground applications meet the criteria for accessing restricted networks based on their unique identifiers and policy rules. This preliminary action ensures reliable access control decisions are made before connection attempts, preventing unauthorized access while allowing permitted applications to proceed.
3Reliability
If network policies restrict foreground applications from accessing restricted networks, then network security is maintained, but application functionality is limited when no alternative networks are available
Solution Approach 1:
The patent introduces an intermediary network policy evaluation mechanism that sits between applications and restricted networks. This intermediary assesses application credentials, determines policy compliance, and mediates access decisions. It maintains security by enforcing policies while preserving application functionality by allowing compliant applications to access restricted networks, thus ensuring operational continuity without compromising security.
Solution Approach 2:
The patent implements feedback mechanisms where the system continuously monitors application network access attempts and policy compliance. When foreground applications are evaluated against network policies, the system provides feedback on access permissions based on credential verification. This feedback loop ensures security rules are maintained while enabling permitted applications to operate continuously across appropriate networks.
Data Source
AI summary
A system and method for managing a network policy of an application on a client includes discovering, by the client, a first network, determining if the first network is a restricted network, applying a restricted network rule to the client when the first network is a restricted network, lowering a network score of the first network when the first network is a restricted network, and associating with the first network.

