Secured ID Linking for Video Policy Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile networks and video systems face challenges in identifying client devices and subscribers due to differences in identifiers and lack of APIs for discovery, making it difficult to apply policies across network transitions, especially in LTE environments where devices move between WiFi and cellular connections.

Innovation Solution

A system is implemented that creates a secured ID linking request with an encrypted mobile identifier, allowing a mobile video session manager to link subscribers to client devices and apply policies across network transitions by inserting the encrypted identifier into HTTP messages, enabling seamless policy management and resource release.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If different identifiers are used in mobile networks and video systems, then each system can maintain its own identification standards, but it becomes difficult to link subscribers to client devices across network transitions

Engineering Contradiction:
Improveidentifier compatibilityVSAvoidID linking mechanism
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary mapping mechanism that connects video system identifiers (device IDs, account IDs) with mobile network identifiers (IMSI, MSISDN) through a session manager. This mediator translates between different identifier systems, enabling cross-network policy application without requiring direct compatibility between the disparate identifier standards.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates a copy of the video flow identifier and stores it in the mobile network's policy control database (PCRF) along with the corresponding mobile network identifier. This identifier copy enables the mobile network to recognize and apply policies to the video flow using its own identifier system, bridging the gap between the two different identification standards.

Inventive Principle:
Principle #26Copying

2Reliability

If policies are applied to video flows during network transitions, then service quality is maintained, but network resources may be inefficiently utilized when devices switch between WiFi and cellular

Engineering Contradiction:
Improvevideo service qualityVSAvoidnetwork resource utilization
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The session manager continuously monitors the client device's network connection status and provides feedback to the policy control system. When a device transitions from cellular to WiFi or vice versa, the session manager detects this change and triggers appropriate policy updates, ensuring service quality is maintained while allowing network resources to be optimized based on current connection state.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent implements dynamic policy application where video flow policies are activated or deactivated based on the current network connection type. When devices switch between WiFi and cellular networks, the system dynamically adjusts policy enforcement to maintain service quality on cellular while allowing unthrottled traffic on WiFi, optimizing network resource utilization according to real-time conditions.

Inventive Principle:
Principle #15Dynamics

3Reliability

If encrypted identifiers are inserted into HTTP messages, then secure ID linking is achieved, but message processing complexity increases

Engineering Contradiction:
ImproveID linking securityVSAvoidmessage processing
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary encryption of video flow identifiers before inserting them into HTTP messages. The identifier is encrypted using a key derived from the mobile network identifier (IMSI) before the message is transmitted to the session manager. This preliminary security measure ensures that identifier linking remains secure throughout the message processing chain without requiring complex decryption operations at each intermediate step.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10721621B2Updating policy for a video flow during transitions
Publication Date: 2020.07.21 CISCO TECHNOLOGY INC
  • US10721621B2 patent drawing
  • US10721621B2 patent drawing
  • US10721621B2 patent drawing

AI summary

First, an authentication module may receive an identification (ID) linking request, create a secured ID linking request from the ID linking request, and send the secured ID linking request to a packet gateway module located in a packet core of a mobile network. Next, the packet gateway module may insert into the secured ID linking request, an encrypted version of a mobile identifier corresponding to a client device from which the secured ID linking request was received. Next, a mobile video session manager module may receive from the packet gateway module, the secured ID linking request and link a subscriber of a managed video service corresponding to a video identifier to the client device corresponding to the mobile identifier. A policy corresponding to the subscriber of the managed video service may then be applied to flows over the packet core to and from the client device.