Clientless SASE Network Connectivity Using MNO Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
SASE implementations relying on software clients for remote access become inefficient and impractical with the increasing demands of mobile access and IoT endpoints, as they struggle to determine trustworthiness of devices without clients.
Innovation Solution
Utilizing Mobile Network Operator (MNO) authentication as a proxy of trust, where SIM-based identifiers are used to establish IP address-to-tenant mappings within the SASE domain, enabling client-less access by mapping access IDs and IP addresses to ensure secure network connectivity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If software clients are installed on devices to enable remote access to SASE, then authentication capability is provided, but device complexity and operational burden increase
Solution Approach 1:
The patent extracts the authentication function from the device-side software client and relocates it to the network-side SASE gateway. The gateway performs authentication using MNO credentials (IMSI, IMEI, or subscription-based identifiers) received in routing decisions, eliminating the need for devices to install and maintain SASE clients while preserving reliable authentication capability.
Solution Approach 2:
The patent introduces MNO credentials (IMSI, IMEI, or subscription identifiers) as intermediary trust anchors between the device and SASE gateway. These credentials serve as a mediator that enables authentication without requiring direct software client installation on the device, allowing the gateway to verify device identity using existing MNO authentication mechanisms.
2Reliability
If client-based access control is used in SASE, then authentication is enabled, but scalability to mobile access and IoT endpoints deteriorates
Solution Approach 1:
The patent makes the SASE gateway universally applicable to diverse access scenarios by using MNO credentials as a universal authentication mechanism. The gateway can authenticate any device (mobile phones, tablets, IoT sensors) using their existing MNO identifiers without requiring device-specific software clients, thereby achieving both reliable authentication and broad adaptability.
Solution Approach 2:
The patent inverts the traditional authentication paradigm by moving authentication from the device side to the network side. Instead of devices presenting credentials to a server, the SASE gateway proactively retrieves and verifies MNO credentials for devices based on routing decisions, enabling scalable access control for mobile and IoT devices without client installation.
3Ease of operation
If MNO authentication is used as proxy of trust, then device trust determination is simplified, but network security control complexity increases
Solution Approach 1:
The patent applies preliminary action by having the SASE gateway retrieve and store MNO authentication credentials in advance during device registration or initial connection. This pre-retrieved credential information is then readily available for rapid authentication decisions during normal traffic routing, simplifying trust determination without requiring complex real-time verification processes.
Solution Approach 2:
The patent enables self-service authentication where the SASE gateway autonomously retrieves and verifies MNO credentials without requiring manual intervention or complex security control processes. The gateway independently performs authentication using stored MNO credential information, reducing operational complexity while maintaining strong security control.
Data Source
AI summary
Methods and systems for providing network connectivity are disclosed. In an embodiment, a method for providing network connectivity involves receiving from a Mobile Network Operator (MNO) an access ID, an IP address, and an Access Point Name (APN) at a SASE domain, wherein the access ID, the IP address, and the APN correspond to a wireless device, updating IP address-to-tenant mappings at the SASE domain in response to the access ID, the IP address, and the APN, and forwarding traffic received at the SASE domain from the wireless device via the MNO according to the updated IP address-to-tenant mappings.


