IP Library Granted Patent US 10,749,837
Granted Patent B2
US 10,749,837 · App. 16/193,375 · Granted Aug 18, 2020

Network access control based on profile type

Inventors: Salvador Mendoza (Issaquah, WA); Suliman Albasheir (Issaquah, WA)
Assignee: T-Mobile USA, Inc.
H04L61/15H04L41/0893H04L45/745H04L63/101H04L63/102H04L12/4633H04L12/66H04L45/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,749,837
App. No.
16/193,375
Granted
Aug 18, 2020
Kind
B2
Abstract

In some examples, a telecommunications-network packet gateway can receive, from a terminal via a packet tunnel, a lookup request for a network address associated with a server name. The packet gateway can determine a profile identifier associated with the packet tunnel and retrieve, from a policy server, an associated profile type. The packet gateway can then select a nameserver associated with the profile type, and forward the lookup request to the nameserver. The nameserver can store a name list. Upon receiving a request, the nameserver can determine whether the server name is included in the name list and, in response, send a reply. In some examples, the packet gateway receives a request from the terminal for content, determines a profile type, selects a destination server associated with the profile type, and forwards the request to the destination server.

Claims (68)

1. A method, comprising, by a packet gateway of a telecommunications network:

receiving, from a terminal via a packet tunnel, a lookup request for a network address associated with a server name;

determining a profile identifier associated with the packet tunnel;

retrieving, from a policy server, a profile type associated with the profile identifier;

selecting a first nameserver of a plurality of nameservers, wherein the first nameserver is associated with the profile type; and

forwarding the lookup request to the first nameserver.

2. The method according to claim 1 , further comprising:

receiving a request packet comprising a port number; and

determining that the request packet comprises the lookup request based on the port number matching a predetermined value.

3. The method according to claim 1 , further comprising, after forwarding the lookup request, performing the following operations in order:

receiving a reply from the first nameserver;

forwarding the reply to the terminal via the packet tunnel;

receiving a traffic packet from the terminal via the packet tunnel, the traffic packet comprising a destination address and a port number;

determining that the port number does not match a predetermined value associated with name lookup; and

in response, forwarding the traffic packet based at least in part on the destination address.

4. The method according to claim 3 , wherein the traffic packet comprises encrypted data.

5. The method according to claim 3 , wherein the traffic packet lacks a cleartext indication of a destination server name.

6. The method according to claim 1 , further comprising retrieving the profile type from the policy server in a Diameter information element (IE).

7. The method according to claim 1 , wherein:

the packet gateway comprises at least one of a General Packet Radio Service (GPRS) Gateway GPRS Support Node (GGSN), a Long Term Evolution (LTE) Packet Data Network Gateway (PGW), or a fifth-generation User Plane Function (UPF);

the packet tunnel comprises a GPRS Tunneling Protocol (GTP) tunnel;

the policy server comprises at least one of an LTE Policy and Charging Rules Function (PCRF) or a fifth-generation Policy Control Function (PCF); and

the nameserver comprises a Domain Name System (DNS) server.

8. A system comprising:

a first nameserver storing a first name list and configured to perform first operations comprising:

receiving a first request comprising a first network name;

determining whether the first network name is included in the first name list; and

in response, sending a first reply; and

a packet gateway configured to perform second operations comprising:

receiving, from a terminal, a lookup request for a network address associated with a server name;

determining a profile type associated with the terminal;

selecting a destination nameserver of a plurality of nameservers, wherein the destination nameserver is associated with the profile type and the plurality of nameservers comprises the first nameserver; and

forwarding the lookup request to the destination nameserver.

9. The system according to claim 8 , wherein the second operations comprise:

determining that the profile type is a first predetermined profile type;

in response, selecting the first nameserver as the destination nameserver; and

forwarding the lookup request to the destination nameserver as the first request.

10. The system according to claim 8 , wherein the second operations comprise:

receiving a request packet comprising a port number; and

determining that the request packet comprises the lookup request based on the port number matching a predetermined value.

11. The system according to claim 8 , the second operations further comprising retrieving, from a policy server, the profile type associated with the terminal.

12. The system according to claim 11 , further comprising the policy server.

13. The system according to claim 8 , wherein the first operations comprise:

determining that the first network name is not included in the first name list; and

in response, sending the first reply comprising error information.

14. The system according to claim 8 , wherein the first operations comprise:

determining that the first network name is included in the first name list; and

in response, sending the first reply comprising error information.

15. The system according to claim 8 , wherein:

the plurality of nameservers comprises a second nameserver; and

the system further comprises the second nameserver storing a second name list and configured to perform third operations comprising:

receiving a second request comprising a second network name;

determining whether the second network name is included in the second name list; and

in response, sending a second reply.

16. A system comprising:

a packet gateway configured to perform first operations comprising:

receiving, from a terminal, a request for content;

determining a profile type associated with the terminal;

selecting a destination server of a plurality of servers, wherein the destination server is associated with the profile type and the plurality of servers comprises a first server; and

forwarding the request for content to the destination server.

17. The system according to claim 16 , the first operations further comprising retrieving, from a policy server, the profile type associated with the terminal.

18. The system according to claim 16 , the first operations further comprising:

receiving the request for content via a packet tunnel; and

determining the profile type as a type associated with the packet tunnel.

19. The system according to claim 16 , the first operations further comprising selecting the destination server by:

determining that the destination server is a first server in response to the profile type being associated with the first server; and

determining that the destination server is a second server of the plurality of servers in response to the profile type not being associated with the first server, wherein the packet gateway is communicatively connectable with the second server via a public data network.

20. The system according to claim 19 , wherein the first server is closer to the packet gateway with respect to a predetermined distance metric than is the second server.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Aug 23, 2022
From: DEUTSCHE BANK TRUST COMPANY AMERICAS
To: IBSV LLC; LAYER3 TV, LLC; PUSHSPRING, LLC; T-MOBILE CENTRAL LLC; T-MOBILE USA, INC.; ASSURANCE WIRELESS USA, L.P.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; SPRINTCOM LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM LLC
Reel/Frame 062595/0001 →
SECURITY AGREEMENT Recorded Apr 2, 2020
From: T-MOBILE USA, INC.; ISBV LLC; T-MOBILE CENTRAL LLC; LAYER3 TV, INC.; PUSHSPRING, INC.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; CLEARWIRE LEGACY LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM L.P.; ASSURANCE WIRELESS USA, L.P.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS
Reel/Frame 053182/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 19, 2018
From: MENDOZA, SALVADOR; ALBASHEIR, SULIMAN
To: T-MOBILE USA, INC.
Reel/Frame 047543/0634 →
Continuity (1)
Related Publication 20200162382A1 · May 21, 2020
Cited By (1)
US 12,549,508