IP Library › Granted Patent US 11,418,596
Granted Patent B2
US 11,418,596 · App. 16/856,135 · Granted Aug 16, 2022

Proximity routing policy enforcement for trans-border internet of things data governance compliance

Inventors: Winnie Chau (Hong Kong, HK); John Philip Mulligan (Island South, HK); Shashi Gowda (Lantau Island, HK)
Assignees: AT&T Global Network Services Hong Kong LTD; AT&T Mobility II LLC
H04L67/12G16Y40/10G16Y40/20G16Y40/35H04L45/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,418,596
App. No.
16/856,135
Granted
Aug 16, 2022
Kind
B2
Abstract

The concepts and technologies disclosed herein are directed to proximity routing policy enforcement for trans-border Internet of Things (“IoT”) data governance compliance. A network gateway can receive, from a data source device, a device registration message comprising a device registration header. The network gateway can determine, based upon the device registration header and a data governance policy, whether the data source device is permitted to access a data governance zone. In response to determining that the data source device is permitted to access the data governance zone, the network gateway can determine, based upon a further data governance policy, at least one gateway of a plurality of gateways operating in the data governance zone to which the device registration message is to be forwarded. The network gateway can forward the registration message to the at least one gateway so that the at least one gateway is enabled for device operation.

Claims (34)

1. A network gateway comprising:

a processor; and

a memory comprising instructions that, when executed by the processor, cause the processor to perform operations comprising

receiving, from a data source device, a device registration message comprising a device registration header,

determining, based upon the device registration header and a data governance policy, whether the data source device is permitted to access a data governance zone,

in response to determining that the data source device is permitted to access the data governance zone, determining, based upon a further data governance policy, at least one gateway of a plurality of gateways operating in the data governance zone to which the device registration message is to be forwarded, wherein the plurality of gateways comprises a home device gateway and a home third party gateway,

forwarding the device registration message to the at least one gateway so that the at least one gateway is enabled for device operation, and

receiving, from the data source device, a data message comprising a plurality of data segments comprising a first data segment associated with a network owner, a second data segment associated with a device owner, and a third data segment associated with a third party owner, wherein the network gateway is associated with the network owner, the home device gateway is associated with the device owner, and the home third party gateway is associated with the third party owner.

2. The network gateway of claim 1 , wherein the device registration header comprises a plurality of data fields that uniquely identify the data source device, a network location of the data source device, and a network to which the data source device is connected.

3. The network gateway of claim 2 , wherein the data governance zone comprises a home data governance zone.

4. The network gateway of claim 3 , wherein determining, based upon the device registration header and the data governance policy, whether the data source device is permitted to access the data governance zone comprises determining, based upon the device registration header and the data governance policy, whether the data source device is permitted to access the home data governance zone; and wherein the operations further comprise, in response to determining, based upon the device registration header and the data governance policy, that the data source device is not permitted to access the home data governance zone, generating a registration redirect message to inform the data source device of a visited network gateway to which the device registration message should be redirected, wherein the visited network gateway is associated with a visited data governance zone.

5. The network gateway of claim 4 , wherein the operations further comprise receiving, from the visited network gateway, a transaction identifier that uniquely identifies the data message sent by the data source device and received by the visited network gateway.

6. A method comprising:

receiving, by a network gateway comprising a processor, from a data source device, a device registration message comprising a device registration header;

determining, by the network gateway, based upon the device registration header and a data governance policy, whether the data source device is permitted to access a data governance zone;

in response to determining that the data source device is permitted to access the data governance zone, determining, by the network gateway, based upon a further data governance policy, at least one gateway of a plurality of gateways operating in the data governance zone to which the device registration message is to be forwarded, wherein the plurality of gateways comprises a home device gateway and a home third party gateway,

forwarding, by the network gateway, the device registration message to the at least one gateway so that the at least one gateway is enabled for device operation, and

receiving, from the data source device, a data message comprising a plurality of data segments comprising a first data segment associated with a network owner, a second data segment associated with a device owner, and a third data segment associated with a third party owner, wherein the network gateway is associated with the network owner, the home device gateway is associated with the device owner, and the home third party gateway is associated with the third party owner.

7. The method of claim 6 , wherein the device registration header comprises a plurality of data fields that uniquely identify the data source device, a network location of the data source device, and a network to which the data source device is connected.

8. The method of claim 7 , wherein the data governance zone comprises a home data governance zone.

9. The method of claim 8 , wherein determining, by the network gateway, based upon the device registration header and the data governance policy, whether the data source device is permitted to access the data governance zone comprises determining, by the network gateway, based upon the device registration header and the data governance policy, whether the data source device is permitted to access the home data governance zone; and wherein the method further comprises, in response to determining, based upon the device registration header and the data governance policy, that the data source device is not permitted to access the home data governance zone, generating, by the network gateway, a registration redirect message to inform the data source device of a visited network gateway to which the device registration message should be redirected, wherein the visited network gateway is associated with a visited data governance zone.

10. The method of claim 9 , further comprising receiving, by the network gateway, from the visited network gateway, a transaction identifier that uniquely identifies the data message sent by the data source device and received by the visited network gateway.

11. The method of claim 6 , wherein the data source device comprises an IoT device.

12. The method of claim 6 , wherein the data source device comprises a combination of an IoT device and an asset.

13. A computer-readable storage medium comprising computer-executable instructions that, when executed, cause a processor of a network gateway to perform operations comprising:

receiving, from a data source device, a device registration message comprising a device registration header;

determining, based upon the device registration header and a data governance policy, whether the data source device is permitted to access a data governance zone;

in response to determining that the data source device is permitted to access the data governance zone, determining, based upon a further data governance policy, at least one gateway of a plurality of gateways operating in the data governance zone to which the device registration message is to be forwarded, wherein the plurality of gateways comprises a home device gateway and a home third party gateway;

forwarding the device registration message to the at least one gateway so that the at least one gateway is enabled for device operation; and

receiving, from the data source device, a data message comprising a plurality of data segments comprising a first data segment associated with a network owner, a second data segment associated with a device owner, and a third data segment associated with a third party owner, wherein the network gateway is associated with the network owner, the home device gateway is associated with the device owner, and the home third party gateway is associated with the third party owner.

14. The computer-readable storage medium of claim 13 , wherein the device registration header comprises a plurality of data fields that uniquely identify the data source device, a network location of the data source device, and a network to which the data source device is connected.

15. The computer-readable storage medium of claim 14 , wherein the data governance zone comprises a home data governance zone.

16. The computer-readable storage medium of claim 15 , wherein determining, based upon the device registration header and the data governance policy, whether the data source device is permitted to access the data governance zone comprises determining, based upon the device registration header and the data governance policy, whether the data source device is permitted to access the home data governance zone; and wherein the operations further comprise, in response to determining, based upon the device registration header and the data governance policy, that the data source device is not permitted to access the home data governance zone, generating a registration redirect message to inform the data source device of a visited network gateway to which the device registration message should be redirected, wherein the visited network gateway is associated with a visited data governance zone.

17. The computer-readable storage medium of claim 16 , wherein the operations further comprise receiving, from the visited network gateway, a transaction identifier that uniquely identifies the data message received by the visited network gateway.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 7, 2022
From: GOWDA, SHASHI
To: AT&T MOBILITY II LLC
Reel/Frame 058908/0238 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 7, 2022
From: CHAU, WINNIE; MULLIGAN, JOHN PHILIP
To: AT&T GLOBAL NETWORK SERVICES HONG KONG LTD
Reel/Frame 058908/0335 →
Continuity (1)
Related Publication 20210337027A1 · Oct 28, 2021