Service Management Gateway for Private Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing multiple geographically distributed private network sites for entities is challenging due to the difficulty in separately and independently implementing and managing these sites, which requires manual effort and lacks centralized control for security and privacy.

Innovation Solution

A service management gateway that determines and provisions service profiles for authorized user equipment (UEs) across multiple private network sites, providing centralized control over access, quality of service, and security, and automatically reconciles profile data, detects malicious activity, and blacklists unauthorized UEs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple private network sites are managed separately and independently, then each site can be customized for specific local needs, but the complexity of management increases significantly and centralized security control is lost

Engineering Contradiction:
Improvelocal customization capabilityVSAvoidmanagement complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system segments network management into two layers: a centralized service management gateway that handles security policies, authentication, and high-level configuration, and distributed network sites that handle local service delivery and basic operations. This segmentation allows local customization at site level while maintaining centralized security control, resolving the contradiction between adaptability and management complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The service management gateway acts as an intermediary between the centralized management system and distributed network sites. It receives service profiles from the management system, translates them into site-specific configurations, and distributes them to appropriate network sites. This intermediary enables local sites to be customized independently while maintaining overall system coherence and centralized security policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If centralized control is implemented across all network sites, then security and privacy are enhanced, but the ability to independently manage and customize individual sites is reduced

Engineering Contradiction:
Improvesecurity controlVSAvoidindependent site management capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system implements local quality by allowing each network site to have site-specific service profiles and configurations tailored to local requirements, while the service management gateway enforces centralized security policies and authentication mechanisms. This enables security control at the gateway level while maintaining independent management capability at the site level.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The service management gateway dynamically adjusts service profiles based on security requirements and site-specific needs. It can modify access permissions, service parameters, and security policies in real-time without requiring manual reconfiguration of individual sites, thus maintaining both centralized security control and site independence.

Inventive Principle:
Principle #15Dynamics

3Ease of operation

If manual configuration is used for each network site, then detailed control over local settings is achieved, but the time and effort required for deployment and updates increases

Engineering Contradiction:
Improvelocal configuration controlVSAvoiddeployment time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system performs preliminary action by pre-configuring service profiles at the service management gateway with all necessary security policies, authentication parameters, and service settings. These pre-configured profiles are then automatically distributed to network sites, eliminating the need for manual configuration at each site and significantly reducing deployment time while maintaining detailed local control.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Network sites automatically receive and apply service profiles from the service management gateway without requiring manual intervention. The gateway pushes configurations to sites, and sites self-configure based on received profiles, reducing both deployment time and ongoing management effort while maintaining full configurability.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20240089846A1Systems and methods for private network management
Publication Date: 2024.03.14 VERIZON PATENT & LICENSING INC
  • US20240089846A1 patent drawing
  • US20240089846A1 patent drawing
  • US20240089846A1 patent drawing

AI summary

One or more computing devices, systems, and/or methods for managing security associated with applications are provided. In an example, service allocation information associated with a plurality of private network sites of a private network associated with an entity may be received. Based upon the service allocation information, service profiles associated with a first user equipment (UE) may be determined. The service profiles include a first service profile of wireless communication services accessible to the first UE via a first private network site of the plurality of private network sites and a second service profile of wireless communication services accessible to the first UE via a second private network site of the plurality of private network sites. The first service profile, associated with the first UE, is transmitted to the first private network site. The second service profile, associated with the first UE, is transmitted to the second private network site.