Block Mode Tunnel Authentication via Layer 2 Token Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network access control methods fail to maintain authentication and authorization when users employ block mode tunnels, leading to security vulnerabilities and loss of access control.

Innovation Solution

The solution involves periodic authentication token exchange at the OSI model Layer 2 level between the source terminal and the firewall, ensuring continuous authentication even during block tunnel mode communication, using an authentication protocol entity and application programs to maintain a secure communication channel.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a block mode tunnel is used to establish secure communication, then security is improved, but access control authorization is lost

Engineering Contradiction:
ImprovesecurityVSAvoidaccess control authorization
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the authentication process into two distinct modes: initial authentication phase and tunnel maintenance phase. During initial authentication, the system operates in basic mode allowing direct communication between terminal and portal. After successful authentication, it transitions to tunnel mode where the tunneling protocol handles maintenance communications. This segmentation allows secure block mode tunnel to be used for authentication token delivery while maintaining access control authorization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces the tunneling protocol as an intermediary layer between the terminal and the authentication portal. This intermediary enables the delivery of authentication tokens through the block mode tunnel without requiring direct communication paths, thus maintaining both security and access control authorization simultaneously.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If block mode tunnel is enforced for security, then security guarantee is improved, but communication between user and operator is blocked

Engineering Contradiction:
Improvesecurity guaranteeVSAvoidauthentication token delivery
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent implements dynamic communication mode switching. The system adapts its communication path based on the authentication phase: using direct basic mode communication during initial authentication setup, then dynamically switching to tunnel mode for subsequent authentication token deliveries. This dynamic adaptation ensures authentication tokens can be delivered securely through the block mode tunnel while maintaining security guarantees.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent performs preliminary authentication setup in basic mode before enforcing block mode tunnel. During this preliminary phase, the terminal and portal establish the tunnel connection and configure authentication parameters. This preliminary action ensures that the block mode tunnel is properly established and configured before authentication tokens begin to be delivered through it, preventing communication blockage.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7730527B2Procedure for controlling access to a source terminal network using a block mode tunnel and computer programs for its implementation
Publication Date: 2010.06.01 ORANGE SA
  • US7730527B2 patent drawing
  • US7730527B2 patent drawing
  • US7730527B2 patent drawing

AI summary

Disclosed is a method and system for controlling access of a source terminal to a network that includes, in particular, a firewall and an authentication portal that maintains the firewall during an access request originating from the source terminal and which permits access when periodically and subsequently provided with a valid authentication token. The source terminal can also communicate in tunnel mode with the destination terminal of the network via a block mode tunnel. Authentication tokens are periodically supplied on the OSI Layer 2 level so that the tokens continue to be provided during a block tunnel mode communication. A network operator can maintain access control using a captive portal paradigm even when a user chooses to use a block mode tunnel.