IP Library › Granted Patent US 11,863,986
Granted Patent B2
US 11,863,986 · App. 17/646,403 · Granted Jan 2, 2024

Mobility and access control across tenant boundaries in a multitenant private communication system

Inventors: Chad Trank (Queen Creek, AZ); David G. Wiatrowski (Woodstock, IL)
Assignee: MOTOROLA SOLUTIONS, INC.
H04W12/082H04W8/26H04W12/086H04W48/02H04W76/10H04W84/045
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,863,986
App. No.
17/646,403
Granted
Jan 2, 2024
Kind
B2
Abstract

A multitenant private communication system and a method for providing mobility and access control across tenant boundaries in the multitenant private communication system. The method includes receiving a first connection request from a user device for connection to first network infrastructure of a first tenant and establishing a connection between the user device and a first private sub-network of the first tenant through the first network infrastructure. The method further includes receiving a second connection request from the user device for connection to second network infrastructure of a second tenant of the multitenant private communication system and determining whether the second network infrastructure is a guest network infrastructure of the user device. The method also includes establishing a connection between the user device and the first private sub-network through the second network infrastructure when the second network infrastructure is the guest network infrastructure of the user device.

Claims (57)

1. A multitenant private communication system comprising:

a first tenant including a first network infrastructure, a first private sub-network, and a user device, the first network infrastructure being a resident network infrastructure of the user device and the first private sub-network being private for members of the first tenant;

a second tenant including a second network infrastructure; and

a data center communicating with the first tenant and the second tenant and including an electronic processor configured to

receive a first connection request from the user device for connection to the first network infrastructure,

establish a connection between the user device and the first private sub-network through the first network infrastructure;

receive a second connection request from the user device for connection to the second network infrastructure;

determine whether the second network infrastructure is a guest network infrastructure of the user device;

establish a connection between the user device and the first private sub-network through the second network infrastructure when the second network infrastructure is the guest network infrastructure of the user device; and

reject a connection between the user device and the second network infrastructure when the second network infrastructure is not the guest network infrastructure of the user device.

2. The system of claim 1 , wherein the first tenant includes a first plurality of user devices as members of the first tenant, wherein the user device is one of the first plurality of user devices, wherein the electronic processor is further configured to

define an access point name (APN) for the first private sub-network; and

set the APN as a default APN of the first plurality of user devices.

3. The system of claim 2 , wherein the user device is a first user device, the system further comprising:

a shared private sub-network private for the members of the first tenant and the second tenant,

wherein the electronic processor is further configured to

receive a third connection request from a second user device for connection to the first network infrastructure, the first network infrastructure being the resident network infrastructure of the second user device;

establish a connection between the second user device and the shared private sub-network through the first network infrastructure;

receive a fourth connection request from a third user device for connection to the second network infrastructure, the first network infrastructure being the resident network infrastructure of the third user device; and

establish a connection between the third user device and the shared private sub-network through the second network infrastructure.

4. The system of claim 3 , wherein the first tenant includes a second plurality of user devices as members of the first tenant, wherein the second tenant includes a third plurality of user devices as members of the second tenant, wherein the second user device and the third user device are one of the second plurality of user devices, wherein the electronic processor is further configured to

define a shared access point name (APN) for the shared private sub-network;

set the shared APN as a default APN of the second plurality of user devices and the third plurality of user devices.

5. The system of claim 1 , wherein the first network infrastructure includes one or more selected from the group consisting of a base station, a serving gateway (SGW), and a packet data network gateway (PGW) of the first tenant.

6. The system of claim 1 , wherein the first tenant and the second tenant share a public land mobile network identifier (PLMNID), wherein the first tenant is assigned a first tracking area code and the second tenant is assigned a second tracking area code.

7. The system of claim 6 , wherein the user device is assigned a user profile including a regional subscription zone code (RSZC), wherein the electronic processor is further configured to

store, in a memory of the data center, an access control database including a plurality of tracking area codes, each tracking area code mapped to mapped to one or more RSZCs, wherein determining that the second network infrastructure is the guest network infrastructure of the user device includes determining that the RSZC of the user profile is mapped to the second tracking area code in the access control database.

8. The system of claim 1 , further comprising:

a tenant internet protocol security (IPsec) tunnel directly connecting the first network infrastructure and the second network infrastructure,

wherein, to establish the connection between the user device and the first private sub-network through the second network infrastructure, the electronic processor is configured to route traffic between the user device and the first private sub-network through the tenant IPsec tunnel.

9. A method for providing mobility and access control across tenant boundaries in a multitenant private communication system, the method comprising:

receiving a first connection request from a user device for connection to first network infrastructure of a first tenant of the multitenant private communication system, the first network infrastructure being a resident network infrastructure of the user device;

establishing a connection between the user device and a first private sub-network of the first tenant through the first network infrastructure, the first private sub-network being private for members of the first tenant;

receiving a second connection request from the user device for connection to second network infrastructure of a second tenant of the multitenant private communication system;

determining whether the second network infrastructure is a guest network infrastructure of the user device;

establishing a connection between the user device and the first private sub-network through the second network infrastructure when the second network infrastructure is the guest network infrastructure of the user device; and

rejecting a connection between the user device and the second network infrastructure when the second network infrastructure is not the guest network infrastructure of the user device.

10. The method of claim 9 , further comprising:

defining an access point name (APN) for the first private sub-network; and

setting the APN as a default APN of a first plurality of user devices of the first tenant, wherein the user device is one of the first plurality of user devices.

11. The method of claim 10 , wherein the user device is a first user device, further comprising:

receiving a third connection request from a second user device for connection to the first network infrastructure, the first network infrastructure being the resident network infrastructure of the second user device;

establishing a connection between the second user device and a shared private sub-network of the first tenant and the second tenant through the first network infrastructure;

receiving a fourth connection request from a third user device for connection to the second network infrastructure, the first network infrastructure being the resident network infrastructure of the third user device; and

establishing a connection between the third user device and the shared private sub-network through the second network infrastructure.

12. The method of claim 11 , further comprising:

defining a shared access point name (APN) for the shared private sub-network;

setting the shared APN as a default APN of a second plurality of user devices of the first tenant, wherein the second user device and the third user device are one of the second plurality of user devices; and

setting the shared APN as a default APN of a third plurality of user devices of the second tenant.

13. The method of claim 9 , wherein the first network infrastructure includes one or more of a base station, a serving gateway (SGW), and a packet data network gateway (PGW) of the first tenant.

14. The method of claim 9 , wherein the first tenant and the second tenant share a public land mobile network identifier (PLMNID), wherein the first tenant is assigned a first tracking area code and the second tenant is assigned a second tracking area code.

15. The method of claim 14 , further comprising:

assigning a user profile including a regional subscription zone code (RSZC) to the user device

storing an access control database including a plurality of tracking area codes, each tracking area code mapped to mapped to one or more RSZCs, wherein determining that the second network infrastructure is the guest network infrastructure of the user device includes determining that the RSZC of the user profile is mapped to the second tracking area code in the access control database.

16. The method of claim 9 , further comprising

providing a tenant internet protocol security (IPsec) tunnel directly connecting the first network infrastructure and the second network infrastructure; and

routing traffic between the user device and the first private sub-network through the tenant IPsec tunnel.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 29, 2021
From: TRANK, CHAD; WIATROWSKI, DAVID G.
To: MOTOROLA SOLUTIONS, INC.
Reel/Frame 058502/0012 →
Continuity (1)
Related Publication 20230209349A1 · Jun 29, 2023