IP Library › Granted Patent US 11,363,459
Granted Patent B2
US 11,363,459 · App. 17/517,656 · Granted Jun 14, 2022

Integrating CBRS-enabled devices and intent-based networking

Inventors: Rajesh S. Pazhyannur (Fremont, CA); Arun G. Khanna (Sunnyvale, CA); Anand Oswal (Pleasanton, CA)
Assignee: CISCO TECHNOLOGY, INC.
H04W12/06H04L63/0853H04W8/183H04W12/40H04W48/18
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,363,459
App. No.
17/517,656
Granted
Jun 14, 2022
Kind
B2
Abstract

Systems and methods are provided for receiving, at an enterprise network, first authentication data of a citizens broadband radio service (CBRS)-enabled device, receiving, at the enterprise network, second authentication data of the CBRS-enabled device, the first authentication data of the CBRS-enabled device being a different type of authentication data than the second authentication data of the CBRS-enabled device, determining a class of the CBRS-enabled device based on the first authentication data and the second authentication data of the CBRS-enabled device, determining a network segment for the CBRS-enabled device based on the class of the CBRS-enabled device, and providing access to the CBRS-enabled device based on the determining of the network segment for the CBRS-enabled device.

Claims (42)

1. A computer-implemented method comprising:

receiving, at an enterprise network, first authentication data of a citizens broadband radio service (CBRS)-enabled device, the first authentication data comprising an International Mobile Subscriber Identity (IMSI) of the CBRS-enabled device;

receiving, at the enterprise network, second authentication data of the CBRS-enabled device, the first authentication data of the CBRS-enabled device being a different type of authentication data than the second authentication data of the CBRS-enabled device;

validating the first authentication data and the second authentication data, including looking up the first authentication data against a whitelist of authorized IMSI identifiers;

responsive to validating the first and second authentication data, determining a class of the CBRS-enabled device based on the first authentication data of the CBRS-enabled device;

determining a network segment for the CBRS-enabled device based on the class of the CBRS-enabled device; and

providing access to the CBRS-enabled device based on the determining of the network segment for the CBRS-enabled device.

2. The method of claim 1 wherein the second authentication data of the CBRS-enabled device is based on a key of a subscriber identity module (SIM) of the CBRS-enabled device or SIM-based authentication software of the CBRS-enabled device.

3. The method of claim 1 , further comprising assigning a virtual routing and forwarding (VRF) to the CBRS-enabled device based on the network segment determined for the CBRS-enabled device.

4. The method of claim 1 , further comprising receiving a user intent at the enterprise network relating to a Wi-Fi network or a cellular network.

5. The method of claim 4 , further comprising translating the user intent into a network policy.

6. The method of claim 5 , further comprising providing the network policy to the Wi-Fi network or the cellular network to be implemented by the Wi-Fi network or the cellular network.

7. The method of claim 5 , wherein the policy is operative to block network traffic associated with a particular application or website.

8. A system comprising:

one or more processors; and

at least one computer-readable storage medium having stored therein instructions which, when executed by the one or more processors, cause the system to:

receive, at an enterprise network, first authentication data of a citizens broadband radio service (CBRS)-enabled device, the first authentication data comprising an International Mobile Subscriber Identity (IMSI) of the CBRS-enabled device;

receive, at the enterprise network, second authentication data of the CBRS-enabled device, the first authentication data of the CBRS-enabled device being a different type of authentication data than the second authentication data of the CBRS-enabled device;

validate the first authentication data and the second authentication data, including looking up the first authentication data against a whitelist of authorized IMSI identifiers;

responsive to validating the first and second authentication data, determine a class of the CBRS-enabled device based on the first authentication data of the CBRS-enabled device;

determine a network segment for the CBRS-enabled device based on the class of the CBRS-enabled device; and

provide access to the CBRS-enabled device based on the determining of the network segment for the CBRS-enabled device.

9. The system of claim 8 , wherein the second authentication data of the CBRS-enabled device is based on a key of a subscriber identity module (SIM) of the CBRS-enabled device or SIM-based authentication software of the CBRS-enabled device.

10. The system of claim 8 , wherein the instructions which, when executed by the one or more processors, cause the system to assign a virtual routing and forwarding (VRF) to the CBRS-enabled device based on the network segment determined for the CBRS-enabled device.

11. The system of claim 8 , wherein the instructions, when executed by the one or more processors, cause the system to receive a user intent at the enterprise network relating to a Wi-Fi network or a cellular network.

12. The system of claim 11 , further comprising translating the user intent into a network policy.

13. The system of claim 12 , wherein the instructions which, when executed by the one or more processors, cause the system to provide the network policy to the Wi-Fi network or the cellular network to be implemented by the Wi-Fi network or the cellular network.

14. The system of claim 12 wherein the policy is operative to block network traffic associated with a particular application or website.

15. A non-transitory computer-readable storage medium comprising:

instructions stored on the non-transitory computer-readable storage medium, the instructions, when executed by one or more processors, cause the one or more processors to:

receive, at an enterprise network, first authentication data of a citizens broadband radio service (CBRS)-enabled device, the first authentication data comprising an International Mobile Subscriber Identity (IMSI) of the CBRS-enabled device;

receive, at the enterprise network, second authentication data of the CBRS-enabled device, the first authentication data of the CBRS-enabled device being a different type of authentication data than the second authentication data of the CBRS-enabled device;

validate the first authentication data and the second authentication data, including looking up the first authentication data against a whitelist of authorized IMSI identifiers;

responsive to validating the first and second authentication data, determine a class of the CBRS-enabled device based on the first authentication data of the CBRS-enabled device;

determine a network segment for the CBRS-enabled device based on the class of the CBRS-enabled device; and

provide access to the CBRS-enabled device based on the determining of the network segment for the CBRS-enabled device.

16. The non-transitory computer-readable storage medium of claim 15 , wherein the second authentication data of the CBRS-enabled device is based on a key of a subscriber identity module (SIM) of the CBRS-enabled device or SIM-based authentication software of the CBRS-enabled device.

17. The non-transitory computer-readable storage medium of claim 15 , wherein the instructions which, when executed by the one or more processors, cause the one or more processors to assign a virtual routing and forwarding (VRF) to the CBRS-enabled device based on the network segment determined for the CBRS-enabled device.

18. The non-transitory computer-readable storage medium of claim 15 , wherein the instructions, when executed by the one or more processors, cause the one or more processors to receive a user intent at the enterprise network relating to a Wi-Fi network or a cellular network.

19. The non-transitory computer-readable storage medium of claim 18 , further comprising translating the user intent into a network policy.

20. The non-transitory computer-readable storage medium of claim 19 , wherein the instructions, when executed by the one or more processors, cause the one or more processors to provide the network policy to the Wi-Fi network or the cellular network to be implemented by the Wi-Fi network or the cellular network.

21. The non-transitory computer-readable storage medium of claim 19 , wherein the policy is operative to block network traffic associated with a particular application or website.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 2, 2021
From: PAZHYANNUR, RAJESH S.; KHANNA, ARUN G.; OSWAL, ANAND
To: CISCO TECHNOLOGY, INC.
Reel/Frame 058000/0626 →
Continuity (5)
Continuation 17460065 · Aug 27, 2021
Continuation 16936562 · Jul 23, 2020
Provisional Application 62916783 · Oct 17, 2019
Provisional Application 62916725 · Oct 17, 2019
Related Publication 20220060894A1 · Feb 24, 2022
Cited By (6)
US 12,367,726 US 12,511,966 US 12,620,281 US 12,621,664 US 12,633,185 US 12,651,500