US2017331690A1PendingUtilityA1

Applying network policies to devices based on their current access network

Assignee: IBOSS INCPriority: May 12, 2016Filed: May 12, 2016Published: Nov 16, 2017
Est. expiryMay 12, 2036(~9.8 yrs left)· nominal 20-yr term from priority
H04L 43/10H04L 67/10H04L 61/2514H04L 41/0893H04L 41/0894H04L 67/34H04L 67/52
55
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Methods and systems are described for managing device access to a particular network from various access networks. One example method includes receiving a message, associated with a source address, from a device over a particular network. A current access network for the device is determined based at least in part on the source address of the message. Based on this determination, a network policy for the particular network is applied to the device.

Claims

exact text as granted — not AI-modified
1 . A computer-implemented method executed by one or more processors for applying network policies to devices based on their current access network, the method comprising:
 receiving a message from a device over a particular network, the message associated with a source address;   determining a current access network for the device based at least in part on the source address, wherein the current access network is external to the particular network, and the message received from the device on the particular network is transmitted by the device over the current access network; and   applying a network policy for the particular network to the device based on the determined current access network.   
     
     
         2 . The method of  claim 1 , wherein the message from the device is received by a server at an access network separate from the current access network of the device. 
     
     
         3 . The method of  claim 1 , wherein the network over which the message is received from the device is the Internet. 
     
     
         4 . The method of  claim 1 , further comprising identifying one or more known access networks each identified by a particular source address range, wherein the known access networks includes the current access network, and wherein determining the current access network of the device includes determining that the source address associated with the received message is included in the particular source address range associated with the current access network. 
     
     
         5 . The method of  claim 4 , wherein the particular source address range includes a subnet mask. 
     
     
         6 . The method of  claim 1 , wherein the current access network is associated with a network provider that operates the current access network. 
     
     
         7 . The method of  claim 1 , wherein assigning the network policy to the device includes assigning a maximum bandwidth usage parameter to the device. 
     
     
         8 . The method of  claim 1 , wherein assigning the network policy to the device includes restricting access to one or more network resources. 
     
     
         9 . The method of  claim 1 , wherein assigning the network policy to the device includes permitting access to one or more network resources. 
     
     
         10 . The method of  claim 1 , wherein the received message is a heartbeat message. 
     
     
         11 . The method of  claim 1 , wherein the received message is a request for a proxy automatic configuration (PAC) script. 
     
     
         12 . A non-transitory, computer-readable medium storing instructions operable when executed to cause at least one processor to perform operations comprising:
 receiving a message from a device over a particular network, the message associated with a source address;   determining a current access network for the device based at least in part on the source address, wherein the current access network is external to the particular network, and the message received from the device on the particular network is transmitted by the device over the current access network; and   applying a network policy for the particular network to the device based on the determined current access network.   
     
     
         13 . The computer-readable medium of  claim 12 , wherein the message from the device is received by a server at an access network separate from the current access network of the device. 
     
     
         14 . The computer-readable medium of  claim 12 , wherein the network over which the message is received from the device is the Internet. 
     
     
         15 . The computer-readable medium of  claim 12 , further comprising identifying one or more known access networks each identified by a particular source address range, wherein the known access networks includes the current access network, and wherein determining the current access network of the device includes determining that the source address associated with the received message is included in the particular source address range associated with the current access network. 
     
     
         16 . The computer-readable medium of  claim 15 , wherein the particular source address range includes a subnet mask. 
     
     
         17 . The computer-readable medium of  claim 12 , wherein the current access network is associated with a network provider that operates the current access network. 
     
     
         18 . The computer-readable medium of  claim 12 , wherein assigning the network policy to the device includes assigning a maximum bandwidth usage parameter to the device. 
     
     
         19 . The computer-readable medium of  claim 12 , wherein assigning the network policy to the device includes restricting access to one or more network resources. 
     
     
         20 . A system for applying network policies to devices based on their current access network comprising:
 memory for storing data; and   one or more processors operable to perform operations comprising:
 receiving a message from a device over a particular network, the message associated with a source address; 
 determining a current access network for the device based at least in part on the source address, wherein the current access network is external to the particular network, and the message received from the device on the particular network is transmitted by the device over the current access network; and 
 applying a network policy for the particular network to the device based on the determined current access network.

Join the waitlist — get patent alerts

Track US2017331690A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.