Private-Network UE Identity Switching for Policy-Blocked Traffic
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Wireless network providers enforce policies that restrict certain types of traffic or communication sessions, leading to unauthorized or unsupported traffic being rejected, which can disrupt user experience and network efficiency.
Innovation Solution
A system that enables User Equipment (UE) to automatically switch identities to a different network based on policy enforcement, using a policy enforcement system and client to manage UE identities and switch to networks where the traffic is authorized or supported.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If wireless network providers enforce policies to restrict certain types of traffic or communication sessions, then network security and policy compliance are improved, but traffic delivery reliability deteriorates when authorized networks are unavailable
Solution Approach 1:
The system dynamically switches between different network identities (first identity and second identity) based on policy enforcement requirements and network availability. The UE can adapt its network identity in real-time to maintain authorized traffic delivery while complying with network policies, resolving the contradiction between security enforcement and traffic delivery reliability.
Solution Approach 2:
The system changes the network identity parameter (from first identity to second identity) to switch between different network access profiles. This parameter change enables the UE to access different networks that have varying policy enforcement rules, allowing authorized traffic to be delivered even when the primary network rejects it due to policy restrictions.
2Device complexity
If a UE uses a single network identity for communication, then device complexity is reduced, but adaptability to different network policies deteriorates
Solution Approach 1:
The UE is equipped with multiple network identities (first identity and second identity) that serve different network access purposes. The first identity is used for networks with certain policy enforcement levels, while the second identity is used for networks with different policy requirements. This multi-functionality enables the UE to adapt to various network policies without increasing operational complexity for the end user.
Solution Approach 2:
The system introduces an identity selection mechanism that acts as an intermediary between the UE and different networks. Based on network type identification and policy assessment, the system automatically selects the appropriate identity (first or second) to use, shielding the user from complexity while maintaining high adaptability to network policies.
3Reliability
If traffic is rejected by a network due to policy enforcement, then network security is maintained, but communication continuity deteriorates
Solution Approach 1:
Instead of trying to modify the rejected traffic to comply with the rejecting network's policies, the system inverts the approach by switching to a different network identity that accesses a different network with more favorable policy enforcement. This allows the same traffic to be delivered successfully through an alternative network path.
Solution Approach 2:
The system extracts the problematic element (the first identity that is being rejected due to policy enforcement) and replaces it with a different identity (second identity) that has not been subjected to the same policy restrictions. This extraction and replacement strategy maintains communication continuity while respecting the original network's security policies.
Data Source
AI summary
A system described herein may identify traffic associated with a User Equipment (“UE”) that is connected to a first network. The UE may maintain a plurality of UE identities via one or more SIM (“Subscriber Identification Module”) cards, Universal Integrated Circuit Cards (“UICCs”), etc. The system may determine, based on one or more policies, that the traffic is not authorized via the first network. In some situations, the traffic may not be authorized if the first network does not support a type, service, etc. of the traffic. The system may identify a second network, based on the one or more policies, via which the traffic is authorized, and may indicate the second network to the UE. The UE may automatically (e.g., without user intervention) switch to a particular UE identity that is associated with the second network, and may output the traffic via the second network using such UE identity.


