Universal Gateway for Policy-Aware Traffic Forwarding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current enterprise deployments face complexity and inconsistency in managing security and traffic forwarding policies across 5G, Wi-Fi, and wired/Ethernet devices due to separate gateways and dashboards, leading to potential human errors and increased complexity.
Innovation Solution
A universal gateway system is deployed to act as a single point of control for policy-aware traffic forwarding, enforcing uniform security and traffic management policies across multiple types of network traffic, including 5G, Wi-Fi, and wired/Ethernet, by integrating user plane functions and universal interworking functions to interwork non-5G traffic and connect with 5G core networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If separate gateways are used for Wi-Fi and 5G, then each device can be managed independently, but device complexity and provisioning complexity increase
Solution Approach 1:
The patent combines multiple separate gateways (Wi-Fi gateway and 5G gateway) into a single universal gateway that handles both Wi-Fi and 5G traffic. This consolidation reduces the number of devices from two to one, simplifying the network architecture while maintaining the ability to independently manage different device types through a unified interface and single provisioning endpoint.
Solution Approach 2:
The universal gateway is designed to perform multiple functions by supporting both Wi-Fi and 5G access types simultaneously. It can authenticate, authorize, and manage traffic for different access types through a single device, eliminating the need for separate specialized gateways while preserving adaptability to various device types.
2Productivity
If separate gateways enforce policies independently, then each gateway can optimize for its specific traffic type, but policy consistency deteriorates
Solution Approach 1:
By merging policy enforcement functions into a single universal gateway, the system ensures that all access types (Wi-Fi and 5G) are subject to the same centralized policy rules. This eliminates inconsistencies that arise from separate gateways interpreting or applying policies differently, while maintaining efficient enforcement through unified processing.
Solution Approach 2:
The universal gateway applies universal policy enforcement mechanisms that work across multiple access types simultaneously. It maintains a single policy configuration that is consistently applied to both Wi-Fi and 5G traffic, ensuring reliability and consistency while preserving the efficiency needed for different traffic types through adaptive processing.
3Adaptability or versatility
If multiple separate gateways are deployed, then coverage for different access types is improved, but system complexity increases
Solution Approach 1:
The patent merges multiple access type handlers into a single universal gateway platform. This single gateway provides a unified dashboard and interface for managing both Wi-Fi and 5G clients, reducing the number of administrative interfaces from two to one while maintaining comprehensive support for multiple access types through integrated functionality.
Solution Approach 2:
The universal gateway is designed as a multi-functional platform that natively supports multiple access types (Wi-Fi, 5G, and potentially others) within a single device architecture. This approach maintains adaptability to various access types while reducing overall system complexity by eliminating redundant gateway instances and simplifying the network topology.
Data Source
AI summary
Example methods and systems for policy-aware traffic forwarding for multiple types of network traffic are described. In one example, a computer system may extract identification information associated with a first client, wherein the first client is associated with a first type of network traffic and obtain a first policy associated with the first client. In response to detecting first network traffic of the first type from the first client, the computer system may (a) interwork the first network traffic into a data plane entity associated with the second type of network traffic, and (b) forward the first network traffic via the data plane entity according to the first policy. In response to detecting second network traffic of the second type from a second client, the computer system may forward the second network traffic via the data plane entity according to a second policy associated with the second client.


