Automated Whitelist Management for Enterprise Small Cell Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In enterprise small cell network environments, existing technologies face challenges in differentiating between public and enterprise access, managing whitelists for authorized users, and accommodating 'bring your own device' (BYOD) scenarios, leading to security concerns and performance issues due to unauthorized access.

Innovation Solution

An automated whitelist management system that associates user credentials with International Mobile Subscriber Identity (IMSI) using Extensible Authentication Protocol (EAP) messaging, allowing enterprises to autonomously manage femtocell or small cell whitelists, integrating with WiFi networks for differentiated service provision and secure access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If automated whitelist management is implemented to differentiate public and enterprise access, then network security is improved, but system complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an Identity Services Engine (ISE) as an intermediary component that automatically manages whitelist provisioning between the wireless network and enterprise directories (Active Directory, LDAP). The ISE intercepts authentication requests, retrieves user credentials from directory services, and automatically provisions whitelists for authorized users, eliminating manual configuration complexity while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service automation where the whitelist provisioning process serves itself by automatically detecting when new users are added to enterprise directories and provisioning their access rights without manual intervention. The ISE continuously monitors directory services and automatically updates whitelists, making the system self-maintaining and reducing operational complexity.

Inventive Principle:
Principle #25Self-service

2Productivity

If manual whitelist management is used, then system complexity is reduced, but productivity and ability to accommodate employee changes deteriorates

Engineering Contradiction:
Improvewhitelist provisioning speedVSAvoidmanagement complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by pre-provisioning user credentials and access rights in advance through automated directory integration. When users are added to enterprise directories, the ISE proactively retrieves their credentials and provisions whitelists before they attempt network access, eliminating delays and manual configuration steps.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback loops where the ISE monitors directory service changes in real-time and automatically responds by updating whitelists. This feedback mechanism ensures that whitelist provisioning keeps pace with employee changes without manual intervention, maintaining high productivity while adapting to dynamic organizational structures.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If differentiated service provision is implemented for enterprise users, then service quality is improved, but device complexity increases

Engineering Contradiction:
Improveservice differentiation capabilityVSAvoidnetwork configuration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by providing differentiated service treatments to different user groups based on their enterprise credentials. The ISE identifies specific user categories (employees, contractors, visitors) and applies appropriate service policies, QoS parameters, and access rights to each group locally, enabling versatile service differentiation without requiring complex global network reconfiguration.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9219816B2System and method for automated whitelist management in an enterprise small cell network environment
Publication Date: 2015.12.22 CISCO TECHNOLOGY INC
  • US9219816B2 patent drawing
  • US9219816B2 patent drawing
  • US9219816B2 patent drawing

AI summary

A method is provided in one embodiment and includes receiving a network address associated with a wireless device at a first network element in which the network address identifies the wireless device on a first network, and receiving user credentials from a directory service associated with a second network. The user credentials identify a user associated with the wireless device on the second network. The method further includes associating the user credentials with the network address, and communicating a request message to a second network element. The request message includes a request for a user identifier identifying the user on a third network. The method further includes receiving a response message from the second network element including the user identifier, associating the user credentials with the user identifier, and storing the association of the user credentials and the user identifier in a whitelist.