Cyber control plane for universal physical space
Abstract
A cyber control plane for universal physical space is provided. A method can include establishing, by a device comprising a processor, control of a physical space within a geographic area by a control system for the physical space; in response to the establishing, generating, by the device, an authorization policy that regulates access to a wireless communication network within the physical space based on network access rules provided by the control system; and denying, by the device, access to resources of the wireless communication network within the physical space to a mobile application according to the authorization policy.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method, comprising:
defining, by a device comprising a processor, a physical space within a geographic area associated with a base station that is part of a communication network, wherein the physical space occupies less than all of the geographic area; establishing, by the device, control of the physical space by a control system for the physical space; denying, by the device according to an authorization policy defined by the control system, access to resources enabled via the base station to a mobile application within the physical space; and granting, by the device, the access to the resources enabled via the base station to the mobile application within a portion of the geographic area that is outside the physical space.
2 . The method of claim 1 , wherein the defining comprises:
defining, by the device, the physical space within a three-dimensional point cloud of the geographic area.
3 . The method of claim 2 , further comprising:
receiving, by the device, local point cloud information relating to local point clouds maintained by respective mobile applications, comprising the mobile application; and constructing, by the device, the three-dimensional point cloud of the geographic area based on the local point cloud information.
4 . The method of claim 2 , further comprising:
requesting, by the device, mapping information from a mobile device operating in the geographic area; and updating, by the device, the three-dimensional point cloud of the geographic area based on the mapping information.
5 . The method of claim 1 , wherein the authorization policy defines a group of permitted devices associated with the mobile application, and wherein the granting of the access comprises:
granting the access to the resources enabled via the base station to the mobile application as executing on a mobile device within the physical space in response to determining that the mobile device is one of the group of permitted devices.
6 . The method of claim 1 , wherein the authorization policy defines a permitted time range associated with the mobile application, wherein the granting of the access comprises:
granting the access to the resources enabled via the base station to the mobile application within the physical space at first times within the permitted time range, and wherein the denying of the access comprises: denying the access to the resources enabled via the base station to the mobile application within the physical space at second times outside of the permitted time range.
7 . The method of claim 1 , further comprising:
transmitting, by the device, a notification of the authorization policy to a mobile device in response to determining that the mobile application is executing on the mobile device and further in response to the mobile device moving to within a threshold distance of the physical space.
8 . The method of claim 7 , wherein transmitting the notification comprises blocking display of a representation of the physical space within the mobile application at the mobile device.
9 . The method of claim 1 , wherein the mobile application is an application selected from a group of applications, the group of applications comprising an augmented reality application, a service robot control application, and an unmanned aerial vehicle control application.
10 . A system, comprising:
a processor; and a memory that stores executable instructions that, when executed by the processor, facilitate performance of operations, the operations comprising:
defining a physical space within a geographic area associated with access point equipment that is part of a communication network, wherein the physical space occupies less than all of the geographic area;
initiating control of the physical space by a steward system for the physical space;
prohibiting, according to an access control policy defined by the steward system, access to resources enabled via the access point equipment to a mobile application as within the physical space; and
granting the access to the resources enabled via the access point equipment to the mobile application within a sub-area of the geographic area that is outside of the physical space.
11 . The system of claim 10 , wherein the operations further comprise:
defining the physical space within a three-dimensional point cloud of the geographic area.
12 . The system of claim 11 , wherein the operations further comprise:
receiving point cloud information associated with local point clouds maintained by respective mobile applications, comprising the mobile application; and generating the three-dimensional point cloud of the geographic area based on the point cloud information.
13 . The system of claim 11 , wherein the operations further comprise:
requesting mapping information from a user equipment operating in the geographic area; and updating the three-dimensional point cloud of the geographic area based on the mapping information.
14 . The system of claim 10 , wherein the access control policy defines a group of permitted devices associated with the mobile application, and wherein the granting of the access comprises:
granting access to the resources enabled via the access point equipment to the mobile application as executing on a user equipment within the physical space in response to determining that the user equipment is one of the group of permitted devices.
15 . The system of claim 10 , wherein the access control policy defines a permitted time range for the mobile application, and wherein the granting of the access comprises:
granting the access to the resources enabled via the access point equipment to the mobile application within the physical space at first times within the permitted time range, and wherein the denying of the access comprises: denying the access to the resources enabled via the access point equipment to the mobile application within the physical space at second times outside of the permitted time range.
16 . A non-transitory machine-readable medium, comprising executable instructions that, when executed by a processor, facilitate performance of operations, comprising:
defining a first section of a geographic area associated with network equipment comprising a base station, wherein the first section of the geographic area comprises less than all of the geographic area; facilitating establishment of control of the first section of the geographic area by a controlling entity; blocking, according to a network access policy defined by the controlling entity, access to communication network resources enabled via the network equipment to a mobile application within the first section of the geographic area; and granting access to the communication network resources enabled via the network equipment to the mobile application within a second section of the geographic area that is wholly outside the first section.
17 . The non-transitory machine-readable medium of claim 16 , wherein the operations further comprise:
defining the first section of the geographic area within a three-dimensional point cloud of the geographic area.
18 . The non-transitory machine-readable medium of claim 17 , wherein the operations further comprise:
receiving point cloud information associated with local point clouds of the geographic area as maintained by respective mobile applications, comprising the mobile application; and generating the three-dimensional point cloud of the geographic area based on the point cloud information.
19 . The non-transitory machine-readable medium of claim 16 , wherein the network access policy defines a group of permitted devices associated with the mobile application, and wherein the granting of the access comprises:
granting the access to the communication network resources enabled via the network equipment to the mobile application as executing on user equipment within the first section of the geographic area in response to determining that the user equipment is one of the group of permitted devices.
20 . The non-transitory machine-readable medium of claim 16 , wherein the network access policy defines a permitted timeframe for the mobile application, and wherein the granting of the access comprises:
granting the access to the communication network resources enabled via the network equipment to the mobile application within the first section of the geographic area at first times within the permitted timeframe, and wherein the blocking of the access comprises: blocking the access to the communication network resources enabled via the network equipment to the mobile application within the first section of the geographic area at second times outside of the permitted timeframe.Join the waitlist — get patent alerts
Track US2022053410A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.