Block Mode Tunnel Authentication via Layer 2 Token Exchange
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network access control methods fail to maintain authentication and authorization when users employ block mode tunnels, leading to security vulnerabilities and loss of access control.
Innovation Solution
The solution involves periodic authentication token exchange at the OSI model Layer 2 level between the source terminal and the firewall, ensuring continuous authentication even during block tunnel mode communication, using an authentication protocol entity and application programs to maintain a secure communication channel.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a block mode tunnel is used to establish secure communication, then security is improved, but access control authorization is lost
Solution Approach 1:
The patent segments the authentication process into two distinct modes: initial authentication phase and tunnel maintenance phase. During initial authentication, the system operates in basic mode allowing direct communication between terminal and portal. After successful authentication, it transitions to tunnel mode where the tunneling protocol handles maintenance communications. This segmentation allows secure block mode tunnel to be used for authentication token delivery while maintaining access control authorization.
Solution Approach 2:
The patent introduces the tunneling protocol as an intermediary layer between the terminal and the authentication portal. This intermediary enables the delivery of authentication tokens through the block mode tunnel without requiring direct communication paths, thus maintaining both security and access control authorization simultaneously.
2Reliability
If block mode tunnel is enforced for security, then security guarantee is improved, but communication between user and operator is blocked
Solution Approach 1:
The patent implements dynamic communication mode switching. The system adapts its communication path based on the authentication phase: using direct basic mode communication during initial authentication setup, then dynamically switching to tunnel mode for subsequent authentication token deliveries. This dynamic adaptation ensures authentication tokens can be delivered securely through the block mode tunnel while maintaining security guarantees.
Solution Approach 2:
The patent performs preliminary authentication setup in basic mode before enforcing block mode tunnel. During this preliminary phase, the terminal and portal establish the tunnel connection and configure authentication parameters. This preliminary action ensures that the block mode tunnel is properly established and configured before authentication tokens begin to be delivered through it, preventing communication blockage.
Data Source
AI summary
Disclosed is a method and system for controlling access of a source terminal to a network that includes, in particular, a firewall and an authentication portal that maintains the firewall during an access request originating from the source terminal and which permits access when periodically and subsequently provided with a valid authentication token. The source terminal can also communicate in tunnel mode with the destination terminal of the network via a block mode tunnel. Authentication tokens are periodically supplied on the OSI Layer 2 level so that the tokens continue to be provided during a block tunnel mode communication. A network operator can maintain access control using a captive portal paradigm even when a user chooses to use a block mode tunnel.


