Network security path identification and validation
US-12170668-B2 · Dec 17, 2024 · US
US9749330B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-9749330-B2 |
| Application number | US-201514846096-A |
| Country | US |
| Kind code | B2 |
| Filing date | Sep 4, 2015 |
| Priority date | Jul 2, 2010 |
| Publication date | Aug 29, 2017 |
| Grant date | Aug 29, 2017 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A method and system for data session establishment from a mobile device in a multiple networks scenario, the method including, checking whether an identifier for an first network is on a blacklist on the mobile device; if the first network identifier is not on the blacklist, attempting to establish a data connection with the first network; and if the first network identifier is on the blacklist, establishing a data connection with a second network. The method and system for data session establishment include deriving and maintaining the blacklist.
Opening claim text (preview).
The invention claimed is: 1. A method for data session establishment from a mobile device comprising: checking whether an identifier for a first network is on a blacklist on the mobile device; if the first network identifier is not on the blacklist, attempting to establish a data connection with the first network, said attempting comprising performing authentication with an authentication entity of the first network; if the attempt to establish the data connection is unsuccessful, determining network identifiers of networks associated to the first network, adding the first network identifier and the network identifiers of associated networks to the blacklist, the associated networks having a common authentication entity with the first network; and if the first network identifier is on the blacklist, establishing a data connection with a second network having a different authentication entity, wherein the first network and associated networks are associated based on information stored on the mobile device. 2. The method of claim 1 , wherein the first network is a higher data throughput Radio Access Technology than the second network. 3. The method of claim 1 , wherein the first network is an Evolution Data Only (EVDO) network and the second network is a Code Division Multiple Access (CDMA) 1× network. 4. The method of claim 3 , further comprising adding the EVDO network identifier to the blacklist if the attempt to establish a data connection is unsuccessful. 5. The method of claim 4 , wherein a data connection is established with the CDMA network subsequent to the addition of the EVDO network identifier to the blacklist. 6. The method of claim 4 , wherein the attempting to establish performs an access network (AN) authentication and wherein the attempting to establish is unsuccessful if the AN authentication returns a rejection. 7. The method of claim 4 , wherein the adding the EVDO network identifier further comprises adding EVDO network identifiers for EVDO networks associated with a current EVDO network to the blacklist. 8. The method of claim 1 , wherein the first network identifier is at least one of an EVDO ColorCode, an EVDO subnet identifier, an EVDO bandclass, an EVDO channel number, a Location Area Identifier, an Absolute Radio Frequency Channel Number (ARFCN), a frequency band, a Base Station Identity Code (BSIC), a Public Land Mobile Network Identifier (PLMN ID), an UTRA Absolute Radio Frequency Channel Number (UARFCN), an Evolved Absolute Radio Frequency Channel Number (EARFCN), a system identifier (SID), a network identifier (NID) or a packet zone identifier (PZID). 9. The method of claim 1 , wherein the blacklist further contains a time value associated with the first network identifier, said time value being utilized for the expiration of the first network identifier on the blacklist. 10. The method of claim 1 , further comprising checking whether a radio of the mobile device has been turned off, and if the radio has been turned off clearing the blacklist of all entries. 11. The method of claim 1 , wherein the information stored on the mobile device is received in a broadcast message and stored on the mobile device, or wherein the information stored on the mobile device is provisioned onto the mobile device. 12. A mobile device configured for data session establishment with a network comprising: a communications subsystem; and a processor, wherein the mobile device is configured to: check whether an identifier for a first network is on a blacklist on the mobile device; if the first network identifier is not on the blacklist, attempt to establish a data connection with the first network, the attempt comprising performing authentication with an authentication entity of the first network; if the attempt to establish the data connection is unsuccessful, determine network identifiers of networks associated to the first network, add the first network identifier and the network identifiers of associated networks to the blacklist, the associated networks having a common authentication entity with the first network; and if the first network identifier is on the blacklist, establishing a data connection with a second network having a different authentication entity, wherein the first network and associated networks are associated based on information stored on the mobile device. 13. The mobile device of claim 12 , wherein the first network is a higher data throughput Radio Access Technology than the second network. 14. The mobile device of claim 12 , wherein the first network has a smaller footprint than the second network. 15. The mobile device of claim 12 , wherein the first network is an Evolution Data Only (EVDO) network and the second network is a Code Division Multiple Access (CDMA) network. 16. The mobile device of claim 15 , further configured to add the EVDO network identifier to the blacklist if the attempt to establish a data connection is unsuccessful. 17. The mobile device of claim 16 , wherein a data connection is established with the CDMA network subsequent to the addition of the EVDO network identifier to the blacklist. 18. The mobile device of claim 17 , wherein the adding the EVDO network identifier includes adding EVDO network identifiers for EVDO networks associated with a current EVDO network to the blacklist. 19. The mobile device of claim 12 , wherein the information stored on the mobile device is received in a broadcast message and stored on the mobile device, or wherein the information stored on the mobile device is provisioned onto the mobile device. 20. A non-transitory computer-readable medium having executable code stored thereon for execution by a processor of a mobile device, the executable code comprising instructions for: checking whether an identifier for a first network is on a blacklist on the mobile device; if the first network identifier is not on the blacklist, attempting to establish a data connection with the first network, said attempting comprising performing authentication with an authentication entity of the first network; if the attempt to establish the data connection is unsuccessful, determining network identifiers of networks associated to the first network, adding the first network identifier and the network identifiers of associated networks to the blacklist, the associated networks having a common authentication entity with the first network; and if the first network identifier is on the blacklist, establishing a data connection with a second network having a different authentication entity, wherein the first network and associated networks are associated based on information stored on the mobile device.
Authentication · CPC title
Access control lists [ACL] · CPC title
by using authentication-authorization-accounting [AAA] servers or protocols · CPC title
adapted for operation in multiple networks {or having at least two operational modes}, e.g. multi-mode terminals · CPC title
Setup of application sessions (admission control or resource allocation in data switching networks H04L47/70) · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.