IP Library › Granted Patent US 10,666,605
Granted Patent B2
US 10,666,605 · App. 16/182,322 · Granted May 26, 2020

Dynamic security gateway selection

Inventors: Stefano Faccin (San Ysidro, CA); Suli Zhao (San Diego, CA); Amer Catovic (Carlsbad, CA)
Assignee: QUALCOMM Incorporated
H04L61/1511H04L61/2007H04L61/305H04W4/90H04W48/17H04W76/10H04W88/16H04L61/304H04L61/3045H04W84/042
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,666,605
App. No.
16/182,322
Granted
May 26, 2020
Kind
B2
Abstract

In aspects of the disclosure, a method, an apparatus, and a computer program product for wireless communication are provided. In one aspect, the apparatus determines if a connection to a PLMN has been established. In another aspect, the apparatus builds a FQDN based on the determination by attempting to build the FQDN using each of the prioritized FQDNs in order of priority until the FQDN is built, building the FQDN using a PLMN ID of the PLMN if it is determined that the PLMN is found in the list, or building the FQDN based on the wildcard PLMN if it is determined that the list comprises the wildcard PLMN. Further still, the apparatus selects a network security gateway to provide network security and internet working control based on the FQDN.

Claims (121)

1. A method of wireless communication at a user equipment, the method comprising:

connecting to a wireless communication network;

obtaining an internet protocol (IP) address from the wireless communication network;

determining that a connection to a first public land mobile network (PLMN) has been established;

building a fully qualified domain name (FQDN) based on a determination that the connection to the first PLMN has been established and a set of information configured by the user equipment's home public land mobile network (HPLMN), the set of information configured by the user equipment's HPLMN comprising a list of public land mobile networks (PLMNs), the building of the FQDN comprising:

building the FQDN using a PLMN identification (PLMN ID) of the first PLMN when the connection to the first PLMN has been established and the first PLMN is in the list of PLMNs configured by the user equipment's HPLMN; and

selecting a network security gateway based on the FQDN.

2. The method of claim 1 , wherein building the FQDN using the PLMN ID of the first PLMN when the connection to the first PLMN has been established and the first PLMN is in the list of PLMNs configured by the user equipment's HPLMN comprises:

determining if the first PLMN is in the list of PLMNs configured by the user equipment's HPLMN; and

in response to determining that the connection to the first PLMN has been established and determining that the first PLMN is in the list of PLMNs configured by the user equipment's HPLMN, building the FQDN using the PLMN ID of the first PLMN.

3. The method of claim 1 , wherein the list of PLMNs configured by the user equipment's HPLMN comprises a list of visited public land mobile networks (VPLMNs).

4. The method of claim 1 , wherein the list of PLMNs configured by the user equipment's HPLMN comprises a list of visited public land mobile networks (VPLMNs) configured by the user equipment's HPLMN; and

wherein building the FQDN using the PLMN ID of the first PLMN when the connection to the first PLMN has been established and the first PLMN is in the list of PLMNs configured by the user equipment's HPLMN comprises:

determining if the first PLMN is in the list of VPLMNs configured by the user equipment's HPLMN; and

in response to determining that the connection to the first PLMN has been established and determining that the first PLMN is in the list of VPLMNs configured by the user equipment's HPLMN, building the FQDN using the PLMN ID of the first PLMN.

5. The method of claim 1 , further comprising:

by the one or more processors of the user equipment:

receiving, from the user equipment's HPLMN, the list of PLMNs configured by the user equipment's HPLMN.

6. The method of claim 1 , further comprising:

by the one or more processors of the user equipment:

receiving, via an access network discovery and selection function (ANDSF), the list of PLMNs configured by the user equipment's HPLMN.

7. An apparatus for wireless communication, the apparatus comprising:

means for connecting to a wireless communication network;

means for obtaining an internet protocol (IP) address from the wireless communication network;

means for determining that a connection to a first public land mobile network (PLMN) has been established;

means for building a fully qualified domain name (FQDN) based on a determination that the connection to the first PLMN has been established and a set of information configured by the user equipment's home public land mobile network (HPLMN), the set of information configured by the user equipment's HPLMN comprising a list of public land mobile networks (PLMNs), the means for building the FQDN being configured to:

build the FQDN using a PLMN identification (PLMN ID) of the first PLMN when the connection to the first PLMN has been established and the first PLMN is in the list of PLMNs configured by the user equipment's HPLMN; and

means for selecting a network security gateway based on the FQDN.

8. The apparatus of claim 7 , wherein the means for building the FQDN using the PLMN ID of the first PLMN when the connection to the first PLMN has been established and the first PLMN is in the list of PLMNs configured by the user equipment's HPLMN is configured to:

determine if the first PLMN is in the list of PLMNs configured by the user equipment's HPLMN; and

in response to determining that the connection to the first PLMN has been established and determining that the first PLMN is in the list of PLMNs configured by the user equipment's HPLMN, build the FQDN using the PLMN ID of the first PLMN.

9. The apparatus of claim 7 , wherein the list of PLMNs configured by the user equipment's HPLMN comprises a list of visited public land mobile networks (VPLMNs).

10. The apparatus of claim 7 , wherein the list of PLMNs configured by the user equipment's HPLMN comprises a list of visited public land mobile networks (VPLMNs) configured by the user equipment's HPLMN; and

wherein the means for building the FQDN using the PLMN ID of the first PLMN when the connection to the first PLMN has been established and the first PLMN is in the list of PLMNs configured by the user equipment's HPLMN is configured to:

determine if the first PLMN is in the list of VPLMNs configured by the user equipment's HPLMN; and

in response to determining that the connection to the first PLMN has been established and determining that the first PLMN is in the list of VPLMNs configured by the user equipment's HPLMN, build the FQDN using the PLMN ID of the first PLMN.

11. The apparatus of claim 7 , further comprising:

means for receiving, from the user equipment's HPLMN, the list of PLMNs configured by the user equipment's HPLMN.

12. The apparatus of claim 7 , further comprising:

means for receiving, via an access network discovery and selection function (ANDSF), the list of PLMNs configured by the user equipment's HPLMN.

13. An apparatus for wireless communication, the apparatus comprising:

a memory; and

at least one processor coupled to the memory and configured to:

connect to a wireless communication network;

obtain an internet protocol (IP) address from the wireless communication network;

determine that a connection to a first public land mobile network (PLMN) has been established;

build a fully qualified domain name (FQDN) based on a determination that the connection to the first PLMN has been established and a set of information configured by a user equipment's home public land mobile network (HPLMN), the set of information configured by the user equipment's HPLMN comprising a list of public land mobile networks (PLMNs), the building of the FQDN comprising:

building the FQDN using a PLMN identification (PLMN ID) of the first PLMN when the connection to the first PLMN has been established and the first PLMN is in the list of PLMNs configured by the user equipment's HPLMN; and

select a network security gateway based on the FQDN.

14. The apparatus of claim 13 , wherein building the FQDN using the PLMN ID of the first PLMN when the connection to the first PLMN has been established and the first PLMN is in the list of PLMNs configured by the user equipment's HPLMN comprises:

determining if the first PLMN is in the list of PLMNs configured by the user equipment's HPLMN; and

in response to determining that the connection to the first PLMN has been established and determining that the first PLMN is in the list of PLMNs configured by the user equipment's HPLMN, building the FQDN using the PLMN ID of the first PLMN.

15. The apparatus of claim 13 , wherein the list of PLMNs configured by the user equipment's HPLMN comprises a list of visited public land mobile networks (VPLMNs).

16. The apparatus of claim 13 , wherein the list of PLMNs configured by the user equipment's HPLMN comprises a list of visited public land mobile networks (VPLMNs) configured by the user equipment's HPLMN; and

wherein building the FQDN using the PLMN ID of the first PLMN when the connection to the first PLMN has been established and the first PLMN is in the list of PLMNs configured by the user equipment's HPLMN comprises:

determining if the first PLMN is in the list of VPLMNs configured by the user equipment's HPLMN; and

in response to determining that the connection to the first PLMN has been established and determining that the first PLMN is in the list of VPLMNs configured by the user equipment's HPLMN, building the FQDN using the PLMN ID of the first PLMN.

17. The apparatus of claim 13 , wherein the at least one processor is further configured to:

receive, from the user equipment's HPLMN, the list of PLMNs configured by the user equipment's HPLMN.

18. The apparatus of claim 13 , wherein the at least one processor is further configured to:

receive, via an access network discovery and selection function (ANDSF), the list of PLMNs configured by the user equipment's HPLMN.

19. A non-transitory computer-readable medium storing computer executable code for wireless communication, comprising code for:

connecting to a wireless communication network;

obtaining an internet protocol (IP) address from the wireless communication network;

determining that a connection to a first public land mobile network (PLMN) has been established;

building a fully qualified domain name (FQDN) based on a determination that the connection to the first PLMN has been established and a set of information configured by a user equipment's home public land mobile network (HPLMN), the set of information configured by the user equipment's HPLMN comprising a list of public land mobile networks (PLMNs), the building of the FQDN comprising:

building the FQDN using a PLMN identification (PLMN ID) of the first PLMN when the connection to the first PLMN has been established and the first PLMN is in the list of PLMNs configured by the user equipment's HPLMN; and

selecting a network security gateway based on the FQDN.

20. The non-transitory computer-readable medium of claim 19 , wherein building the FQDN using the PLMN ID of the first PLMN when the connection to the first PLMN has been established and the first PLMN is in the list of PLMNs configured by the user equipment's HPLMN comprises:

determining if the first PLMN is in the list of PLMNs configured by the user equipment's HPLMN; and

in response to determining that the connection to the first PLMN has been established and determining that the first PLMN is in the list of PLMNs configured by the user equipment's HPLMN, building the FQDN using the PLMN ID of the first PLMN.

21. The non-transitory computer-readable medium of claim 19 , wherein the list of PLMNs configured by the user equipment's HPLMN comprises a list of visited public land mobile networks (VPLMNs).

22. The non-transitory computer-readable medium of claim 19 , wherein the list of PLMNs configured by the user equipment's HPLMN comprises a list of visited public land mobile networks (VPLMNs) configured by the user equipment's HPLMN; and

wherein building the FQDN using the PLMN ID of the first PLMN when the connection to the first PLMN has been established and the first PLMN is in the list of PLMNs configured by the user equipment's HPLMN comprises:

determining if the first PLMN is in the list of VPLMNs configured by the user equipment's HPLMN; and

in response to determining that the connection to the first PLMN has been established and determining that the first PLMN is in the list of VPLMNs configured by the user equipment's HPLMN, building the FQDN using the PLMN ID of the first PLMN.

23. The non-transitory computer-readable medium of claim 19 , wherein the non-transitory computer-readable medium further comprises code for:

receiving, from the user equipment's HPLMN, the list of PLMNs configured by the user equipment's HPLMN.

24. The non-transitory computer-readable medium of claim 19 , wherein the non-transitory computer-readable medium further comprises code for:

receiving, via an access network discovery and selection function (ANDSF), the list of PLMNs configured by the user equipment's HPLMN.

25. A method of wireless communication, the method comprising:

by one or more processors of a home public land mobile network (HPLMN) of a user equipment:

sending a set of information to the user equipment, the set of information configured by the HPLMN and comprising a list of public land mobile networks (PLMNs), the user equipment being configured to:

connect to a wireless communication network;

obtain an internet protocol (IP) address from the wireless communication network;

determine that a connection to a first public land mobile network (PLMN) has been established;

build a fully qualified domain name (FQDN) based on a determination that the connection to the first PLMN has been established and the set of information configured by the HPLMN comprising the list of PLMNs, the building of the FQDN comprising:

building the FQDN using a PLMN identification (PLMN ID) of the first PLMN when the connection to the first PLMN has been established and the first PLMN is in the list of PLMNs configured by the HPLMN; and

select a network security gateway based on the FQDN.

26. An apparatus for wireless communication, the apparatus comprising:

means for sending a set of information to a user equipment, the set of information configured by the user equipment's home public land mobile network (HPLMN) and comprising a list of public land mobile networks (PLMNs), the user equipment being configured to:

connect to a wireless communication network;

obtain an internet protocol (IP) address from the wireless communication network;

determine that a connection to a first public land mobile network (PLMN) has been established;

build a fully qualified domain name (FQDN) based on a determination that the connection to the first PLMN has been established and the set of information configured by the user equipment's HPLMN comprising the list of PLMNs, the building of the FQDN comprising:

building the FQDN using a PLMN identification (PLMN ID) of the first PLMN when the connection to the first PLMN has been established and the first PLMN is in the list of PLMNs configured by the user equipment's HPLMN; and

select a network security gateway based on the FQDN.

27. An apparatus for wireless communication, the apparatus comprising:

a memory; and

at least one processor coupled to the memory and configured to:

sending a set of information to a user equipment, the set of information configured by the user equipment's home public land mobile network (HPLMN) and comprising a list of public land mobile networks (PLMNs), the user equipment being configured to:

connect to a wireless communication network;

obtain an internet protocol (IP) address from the wireless communication network;

determine that a connection to a first public land mobile network (PLMN) has been established;

build a fully qualified domain name (FQDN) based on a determination that the connection to the first PLMN has been established and the set of information configured by the user equipment's HPLMN comprising the list of PLMNs, the building of the FQDN comprising:

building the FQDN using a PLMN identification (PLMN ID) of the first PLMN when the connection to the first PLMN has been established and the first PLMN is in the list of PLMNs configured by the HPLMN configured by the user equipment's HPLMN; and

select a network security gateway based on the FQDN.

28. A non-transitory computer-readable medium storing computer executable code for wireless communication, comprising code for:

sending a set of information to a user equipment, the set of information configured by the user equipment's home public land mobile network (HPLMN) and comprising a list of public land mobile networks (PLMNs), the user equipment being configured to:

connect to a wireless communication network;

obtain an internet protocol (IP) address from the wireless communication network;

determine that a connection to a first public land mobile network (PLMN) has been established;

build a fully qualified domain name (FQDN) based on a determination that the connection to the first PLMN has been established and the set of information configured by the user equipment's HPLMN comprising the list of PLMNs, the building of the FQDN comprising:

building the FQDN using a PLMN identification (PLMN ID) of the first PLMN when the connection to the first PLMN has been established and the first PLMN is in the list of PLMNs configured by the HPLMN configured by the user equipment's HPLMN; and

select a network security gateway based on the FQDN.

29. The method of claim 1 , wherein the network security gateway comprises an Evolved Packet Data Gateway (EPDG).

30. The apparatus of claim 7 , wherein the network security gateway comprises an Evolved Packet Data Gateway (EPDG).

31. The apparatus of claim 13 , wherein the network security gateway comprises an Evolved Packet Data Gateway (EPDG).

32. The method of claim 25 , wherein the network security gateway comprises an Evolved Packet Data Gateway (EPDG).

33. The apparatus of claim 26 , wherein the network security gateway comprises an Evolved Packet Data Gateway (EPDG).

34. The apparatus of claim 27 , wherein the network security gateway comprises an Evolved Packet Data Gateway (EPDG).

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 6, 2018
From: FACCIN, STEFANO; ZHAO, SULI; CATOVIC, AMER
To: QUALCOMM INCORPORATED
Reel/Frame 047426/0617 →
Continuity (4)
Continuation 15887682 · Feb 2, 2018
Continuation 14969612 · Dec 15, 2015
Provisional Application 62160572 · May 12, 2015
Related Publication 20190075076A1 · Mar 7, 2019