US2022239701A1PendingUtilityA1

Control access to domains, servers, and content

Assignee: AT & T IP I LPPriority: Feb 27, 2020Filed: Apr 14, 2022Published: Jul 28, 2022
Est. expiryFeb 27, 2040(~13.6 yrs left)· nominal 20-yr term from priority
H04L 63/0876H04L 63/20H04L 63/0263H04L 63/10
61
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A system to control access to domains, servers, or content, among other things. There may be individualized or global policies. Policy servers or other devices may interface with databases, DNS servers, firewalls, programmable virtualized routers, or dynamic host configuration protocol servers, among other devices to dynamically update various policy enforcement elements.

Claims

exact text as granted — not AI-modified
What is claimed: 
     
         1 . An apparatus comprising:
 a processing system including a processor; and   a memory that stores executable instructions that, when executed by the processing system, facilitate performance of operations, the operations comprising:   receiving, by a virtual network function associated with the apparatus, a policy that includes information associated with accessing a device on a first network;   receiving, by the virtual network function, a request to access the device;   determining, by the virtual network function, to restrict access to the device;   updating, by the virtual network function, the policy with access restriction data for the device, resulting in an updated policy; and   causing, by the virtual network function, the updated policy to be transmitted to a second network different from the first network, wherein the virtual network function comprises a virtual router.   
     
     
         2 . The apparatus of  claim 1 , wherein the determining to restrict the access to the device is in accordance with the policy. 
     
     
         3 . The apparatus of  claim 1 , wherein, based on a previous location of a mobile device, the policy was received from a different network. 
     
     
         4 . The apparatus of  claim 1 , wherein the updated policy is associated with a restriction of a domain name. 
     
     
         5 . The apparatus of  claim 1 , wherein the updated policy is associated with a restriction of a network identifier. 
     
     
         6 . The apparatus of  claim 1 , wherein the updated policy is associated with a restriction of a protocol. 
     
     
         7 . The apparatus of  claim 1 , wherein the updated policy is associated with a restriction of a data packet content. 
     
     
         8 . The apparatus of  claim 1 , wherein the updated policy is implemented in the second network based on thresholds relating to processing or memory resources being satisfied. 
     
     
         9 . A method comprising:
 obtaining, by a virtual router, a policy that includes information associated with accessing a device on a first network;   obtaining, by the virtual router, a request to access the device;   determining, by the virtual router, to restrict access to the device;   updating, by the virtual router, the policy with access restriction data for the device, resulting in an updated policy; and   providing, by the virtual router, the updated policy to a second network different from the first network.   
     
     
         10 . The method of  claim 9 , wherein the determining to restrict the access to the device is in accordance with the policy. 
     
     
         11 . The method of  claim 9 , wherein, based on a previous location of a mobile device, the policy was obtained from a different network. 
     
     
         12 . The method of  claim 9 , wherein the updated policy is associated with a restriction of a domain name. 
     
     
         13 . The method of  claim 9 , wherein the updated policy is associated with a restriction of a network identifier. 
     
     
         14 . The method of  claim 9 , wherein the updated policy is associated with a restriction of a protocol. 
     
     
         15 . The method of  claim 9 , wherein the updated policy is associated with a restriction of a data packet content. 
     
     
         16 . The method of  claim 9 , wherein the updated policy is implemented in the second network based on thresholds relating to processing or memory resources being satisfied. 
     
     
         17 . A non-transitory machine-readable medium, comprising executable instructions that, when executed by a processing system including a processor, facilitate performance of operations, the operations comprising:
 receiving, by a Dynamic Host Configuration Protocol (DHCP) server associated with the processing system, a policy that includes information associated with accessing a device on a first network;   receiving, by the DHCP server, a request to access the device;   determining, by the DHCP server, to restrict access to the device;   updating, by the DHCP server, the policy with access restriction data for the device, resulting in an updated policy; and   causing, by the DHCP server, the updated policy to be transmitted to a second network different from the first network.   
     
     
         18 . The non-transitory machine-readable medium of  claim 17 , wherein the determining to restrict the access to the device is in accordance with the policy. 
     
     
         19 . The non-transitory machine-readable medium of  claim 17 , wherein, based on a previous location of a mobile device, the policy was received from a different network. 
     
     
         20 . The non-transitory machine-readable medium of  claim 17 , wherein the updated policy is implemented in the second network based on thresholds relating to processing or memory resources being satisfied.

Join the waitlist — get patent alerts

Track US2022239701A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.