Per-User Network Policy Mapping via Access Point Group Association

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems apply inconsistent network policies to user devices based on their connection methods, whether directly or indirectly connected to a cellular network, leading to inconsistent policy application across devices used by the same user.

Innovation Solution

An Access Point (AP) configures mappings of cellular network connections to local access network groups and associates user devices with identifiers based on their authorization, enabling consistent network policies to be applied on a per-user basis regardless of the connection method.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network policies are applied based on connection method (direct cellular vs. indirect Wi-Fi), then device-specific policies can be implemented, but inconsistency occurs when the same user uses multiple devices with different connection methods

Engineering Contradiction:
Improvenetwork policy applicationVSAvoidpolicy consistency
Core Design Contradiction:
Adaptability or versatilityVSStability of the object's composition

Solution Approach 1:

The patent introduces an intermediary mechanism (user profile/subscription identifier) that mediates between the access network and user devices. This intermediary stores user-specific policy information and ensures consistent policy application across different connection methods by translating device-specific connection parameters into user-based policy decisions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements a universal user profile structure that can accommodate multiple connection methods (cellular, Wi-Fi, etc.) under a single policy framework. The user profile serves multiple functions: identifying the user, storing subscription information, and enforcing policies consistently across diverse access technologies and devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If separate network connections are configured for different user devices, then device-specific connectivity can be managed, but system complexity increases

Engineering Contradiction:
Improvedevice connectivity managementVSAvoidnetwork configuration
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent merges multiple device-specific connection configurations into a unified user-based management structure. Instead of managing separate policies for each device-connection pair, the system combines these into a single user profile that automatically applies appropriate policies regardless of which device or connection method is used.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system segments network management into two distinct layers: user-level policy management (handled by the user profile and subscription information) and connection-level implementation (handled by the access network). This segmentation allows complex policies to be defined at the user level while simplifying the actual connection management at the network level.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11711691B2Applying network policies on a per-user basis
Publication Date: 2023.07.25 CISCO TECHNOLOGY INC
  • US11711691B2 patent drawing
  • US11711691B2 patent drawing
  • US11711691B2 patent drawing

AI summary

In one example, an Access Point (AP) configures a first mapping of a first cellular network connection to a first local access network group, and further configures a second mapping of a second cellular network connection to a second local access network group. The AP determines whether a user device is authorized to use the first cellular network connection or the second cellular network connection. If the user device is authorized to use the first cellular network connection, the AP associates, for the user device, a first user device identifier with the first local access network group. If the user device is authorized to use the second cellular network connection, the AP associates, for the user device, a second user device identifier with the second local access network group.