ETLS Tunneling for Secure WLAN Data Traffic
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Public wireless local area networks (WLANs) lack secure point-to-point (P2P) L2 links, exposing user traffic to security attacks as they connect to the internet, especially since many networks do not comply with 3GPP TS 23.402 requirements and lack IEEE 802.1x authentication, leading to potential monetary losses and identity theft.
Innovation Solution
Implementing Transport Layer Security (TLS) natively over Ethernet to establish a secure P2P L2 link, known as ETLS, which encrypts signaling and data traffic within TLS type Ethernet frames, providing layer 2 encryption across the public WLAN, even after initial login, using TLS handshakes and encapsulating data and signaling messages.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If public WLAN networks allow direct internet access without IEEE 802.1x authentication, then ease of operation is improved, but security is worsened exposing users to attacks and data theft
Solution Approach 1:
The patent establishes a secure tunnel connection before any data transmission occurs. The TLS tunnel is set up in advance between the UE and TWAG, creating a protected communication channel prior to internet access, thereby preventing security attacks while maintaining ease of operation
Solution Approach 2:
The patent introduces an intermediate encryption layer (TLS tunnel) between the UE and the network. This intermediary mechanism encrypts all traffic at layer 2, acting as a mediator that protects user data while allowing seamless internet access without requiring users to understand or configure security settings
2Object-affected harmful factors
If IEEE 802.1x authentication is implemented for secure access, then security is improved, but device complexity and network compatibility are worsened
Solution Approach 1:
The patent implements TLS tunneling that replicates the security functionality of IEEE 802.1x authentication but using different, more compatible protocols. Instead of requiring complex 802.1x implementation, the system uses standard TLS protocols to achieve equivalent security outcomes with simpler device requirements
Solution Approach 2:
The patent changes the authentication approach from IEEE 802.1x to TLS-based authentication. By altering the protocol parameters and using widely-supported TLS instead of less-common 802.1x, the system maintains strong security while improving compatibility with diverse devices and networks
3Ease of operation
If encryption is applied only during login phase, then ease of operation is improved, but security is worsened as traffic remains exposed after authentication
Solution Approach 1:
The patent maintains continuous encryption throughout the entire communication session, not just during login. The TLS tunnel remains active for all subsequent data transmissions, ensuring uninterrupted security protection while requiring no additional user actions to maintain encryption
Data Source
AI summary
This specification presents a method and apparatus to establish a transport layer security, TLS, tunnel over Ethernet, ETLS tunnel between two endpoints (UE and WAG) and to transport UE traffic encapsulated and encrypted in a proposed TLS type Ethernet frame for all applications, thus providing secure layer 2 connectivity over public wireless local area networks, WLAN, for all UE traffic and overcome the security vulnerability of the traditional HTTP login mechanism over the public WLAN. The UE uses the TLS handshake protocol which may include negotiating ETLS capabilities extension that comprises wireless control protocol for establishing a packet data connection and tunneled authentication protocol for UE authentication and full Ethernet protection for encrypting Ethernet frames of different types.


