H04L61/503

Port chunk allocation in network address translation

A system and method for providing network and port address translation is provided. A global IP address and a block (chunk) of ports are allocated for each mobile subscriber (MS) on first data connection. Subsequent data connections from the same MS are assigned the same IP address and a new port from this block. The mapping information is communicated, processed, and stored once for the complete block, instead of for every new data connection. This process reduces processing, communication, and storage requirements.

System and method to facilitate network element failure detection and session restoration in a network environment

A method is provided in one example embodiment and may include maintaining, by a Diameter Routing Agent (DRA), an availability status for a plurality of network elements; receiving a request associated with a user equipment (UE) session, wherein a first network element of the plurality of network elements is serving the UE session; determining that the first network element serving the UE session is unavailable; and re-establishing the UE session at a second network element of the plurality of network elements that is available, wherein the re-establishing is performed without terminating the UE session.

Network access control
11129021 · 2021-09-21 · ·

A network controller configured to provide network access to client devices, receives a network access request from a client device. The network access request includes a media access control (MAC) address of the client device and information about a first private key. The network controller sends to a server an authentication request, which includes the MAC address of the client device. The network controller receives an authentication response from the server, which includes a second private key. The network controller determines whether the first private key is the same as the second private key. In response to determining that the first private key is different from the second private key, network access is denied to the client device, and in response to determining that the first private key is the same as the second private key, network access is granted to the client device.

SYSTEM AND METHOD FOR GENERATION OF SIMPLIFIED DOMAIN NAME SERVER RESOLUTION TREES
20210352043 · 2021-11-11 · ·

A system and method for generating and representing a consolidated resolution tree of a network are provided. The method includes receiving a target fully qualified domain name (FQDN); creating at least one tentative equivalence class (TEC) containing all the internet root domain name servers (DNS); processing the at least one TEC to determine respective consolidated edges and vertices; retrieving nameservers from domain registration records; determining whether additional TECs are to be generated for the retrieved nameserver(s); processing all new TECs to determine respective consolidated edges and vertices, when it is determined that new TECs are to be generated; and generating a resolution tree for display based on the consolidated edges and vertices.

Client device address assignment following authentication

Methods and systems are described for assigning the proper internet protocol (IP) address to a client device following authentication of the client device on a network. In particular, at commencement of an authentication procedure of the client device, a role is associated with the client device that denies all DHCP renews/requests. By assigning a role to the client device 103 with a “deny DHCP renew/request” rule at the commencement of an authentication procedure, the systems and methods described herein ensure that a race condition does not allow the client device to renew an IP address in an old segment of the network. Accordingly, the client device may avoid a possibly improper IP address in a segment of the network system in which the client device is no longer associated with or operating on.

Route delivery method and device
11102170 · 2021-08-24 · ·

The application relates to a route delivery method and device. A location information of user equipment UE is received by a control plane network element device. A client IP address used by the control plane network element device to access a third-party server is determined based on the location information by the control plane network element device. An access request message is sent by the control plane network element device to the third-party server carrying the client IP address. A UE IP address assigned by the third-party server to the UE based on the client IP address is received by the control plane network element device. A user plane network element device configured to deliver a route to the UE is determined based on the UE IP address and the location information by the control plane network element device.

NETWORK ACCESS CONTROL
20210195414 · 2021-06-24 ·

A network controller configured to provide network access to client devices, receives a network access request from a client device. The network access request includes a media access control (MAC) address of the client device and information about a first private key. The network controller sends to a server an authentication request, which includes the MAC address of the client device. The network controller receives an authentication response from the server, which includes a second private key. The network controller determines whether the first private key is the same as the second private key. In response to determining that the first private key is different from the second private key, network access is denied to the client device, and in response to determining that the first private key is the same as the second private key, network access is granted to the client device.

Control system having various capabilities

An integrated unitary internet protocol (IP) control system with a rapid spanning tree protocol (RSTP), multi-port high speed switch, supervisor, web display and/or an expansion plant input/output (IO) capabilities. The system may have communication modules associated with encrypted file subsystems integrated with an IO network. A resulting secure IP based communication network may be connected between a software framework and the hardware IO network.

CLIENT DEVICE ADDRESS ASSIGNMENT FOLLOWING AUTHENTICATION
20210160212 · 2021-05-27 ·

Methods and systems are described for assigning the proper internet protocol (IP) address to a client device following authentication of the client device on a network. In particular, at commencement of an authentication procedure of the client device, a role is associated with the client device that denies all DHCP renews/requests. By assigning a role to the client device 103 with a “deny DHCP renew/request” rule at the commencement of an authentication procedure, the systems and methods described herein ensure that a race condition does not allow the client device to renew an IP address in an old segment of the network. Accordingly, the client device may avoid a possibly improper IP address in a segment of the network system in which the client device is no longer associated with or operating on.

Inter-PGW handover architecture
11026276 · 2021-06-01 · ·

A method is disclosed for providing IP access across packet data network gateways (PGWs), comprising: receiving, from a UE, at a coordinating node, an attach request; sending a request to create a first new session to a first PGW; sending a request to create a second new session to a second PGW; receiving, from the first PGW and at the coordinating node, a first request for policies for the UE; receiving, from the second PGW and at the coordinating node, a second request for policies for the UE; opening a first data tunnel from the coordinating node to the first PGW; opening a second data tunnel from the coordinating node to the second PGW without closing the first data tunnel; and opening a data tunnel between the UE and the coordinating node for providing IP access to both the first PGW and the second PGW.