Dual-Point Access Control for Movable Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network mobility support and access control technologies do not effectively utilize radio resources, leading to inefficiencies in large-scale deployments, particularly in commercial applications where unknown devices connect to networks, potentially affecting the quality of service for legitimate subscribers.
Innovation Solution
Implementing access control enforcement points at both the mobile router and the mobility anchoring agent, filtering downlink and uplink packets before they cross the air interface, thereby preventing unauthorized access and conserving radio resources. This involves a mobility-anchoring agent, such as a Home Agent or Forwarding Agent, interconnected with the mobile router through a bi-directional tunnel, using lightweight protocols like PANA, PPP, or IEEE 802.1X for authentication and authorization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If access control enforcement points are implemented at both mobile router and mobility anchoring agent, then unauthorized access is prevented and radio resources are conserved, but device complexity increases
Solution Approach 1:
The access control function is segmented into two separate enforcement points: one at the mobile router and another at the mobility anchoring agent. This segmentation allows each enforcement point to handle specific aspects of access control (uplink at mobile router, downlink at mobility anchoring agent), improving overall reliability while distributing the complexity across multiple components rather than concentrating it in a single device.
Solution Approach 2:
The mobility anchoring agent acts as an intermediary between the external network and the mobile network, providing an additional layer of access control. This intermediary enforces downlink access control policies before packets are forwarded to mobile routers, preventing unauthorized access without requiring complex control logic at the mobile router itself.
2Productivity
If packets are filtered before crossing the air interface, then radio resources are optimized and unauthorized access is blocked, but processing time and system complexity increase
Solution Approach 1:
Access control filtering is performed as a preliminary action before packets cross the air interface. The mobility anchoring agent filters downlink packets before they are transmitted over the radio interface, and the mobile router filters uplink packets before transmission. This preliminary filtering prevents unauthorized packets from consuming radio resources in the first place, optimizing radio resource utilization despite the additional processing time required.
3Reliability
If multiple access control enforcement points are deployed, then network security is improved, but network complexity and configuration difficulty increase
Solution Approach 1:
The network security function is segmented into two distinct enforcement points with clearly defined roles: the mobile router handles uplink access control, and the mobility anchoring agent handles downlink access control. This segmentation simplifies configuration by assigning specific security policies to each enforcement point based on their location and function, making it easier to manage and maintain network security despite the presence of multiple enforcement points.
Data Source
AI summary
The invention relates to access control for a movable network (15) managed by a mobile router (10), wherein said mobile route is interconnected through a bi-directional link (40) with a mobility anchoring agent (20) that anchors the network mobility for the mobile router. According to the invention, access control enforcement points (11, 21) are located at both the mobile router (10) and the mobility anchoring agent (20). Access control is exercised at the mobility agent (20) to filter downlink packets to the mobile router (10) and access control is exercised at the mobile router (10) to filter uplink packets to the mobility anchoring agent (20). In this way, unauthorized packets, both uplink and downlink, do not have to cross the air interface before being filtered away, thereby preventing waste of valuable radio resources. The access control modules are typically provisioned with access control filter information, preferably by means of a hierarchical provisioning structure.


