ETLS Tunneling for Secure WLAN Data Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Public wireless local area networks (WLANs) lack secure point-to-point (P2P) L2 links, exposing user traffic to security attacks as they connect to the internet, especially since many networks do not comply with 3GPP TS 23.402 requirements and lack IEEE 802.1x authentication, leading to potential monetary losses and identity theft.

Innovation Solution

Implementing Transport Layer Security (TLS) natively over Ethernet to establish a secure P2P L2 link, known as ETLS, which encrypts signaling and data traffic within TLS type Ethernet frames, providing layer 2 encryption across the public WLAN, even after initial login, using TLS handshakes and encapsulating data and signaling messages.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If public WLAN networks allow direct internet access without IEEE 802.1x authentication, then ease of operation is improved, but security is worsened exposing users to attacks and data theft

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent establishes a secure tunnel connection before any data transmission occurs. The TLS tunnel is set up in advance between the UE and TWAG, creating a protected communication channel prior to internet access, thereby preventing security attacks while maintaining ease of operation

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediate encryption layer (TLS tunnel) between the UE and the network. This intermediary mechanism encrypts all traffic at layer 2, acting as a mediator that protects user data while allowing seamless internet access without requiring users to understand or configure security settings

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If IEEE 802.1x authentication is implemented for secure access, then security is improved, but device complexity and network compatibility are worsened

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements TLS tunneling that replicates the security functionality of IEEE 802.1x authentication but using different, more compatible protocols. Instead of requiring complex 802.1x implementation, the system uses standard TLS protocols to achieve equivalent security outcomes with simpler device requirements

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent changes the authentication approach from IEEE 802.1x to TLS-based authentication. By altering the protocol parameters and using widely-supported TLS instead of less-common 802.1x, the system maintains strong security while improving compatibility with diverse devices and networks

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If encryption is applied only during login phase, then ease of operation is improved, but security is worsened as traffic remains exposed after authentication

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent maintains continuous encryption throughout the entire communication session, not just during login. The TLS tunnel remains active for all subsequent data transmissions, ensuring uninterrupted security protection while requiring no additional user actions to maintain encryption

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS11388145B2Tunneling data traffic and signaling over secure etls over wireless local area networks
Publication Date: 2022.07.12 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US11388145B2 patent drawing
  • US11388145B2 patent drawing
  • US11388145B2 patent drawing

AI summary

This specification presents a method and apparatus to establish a transport layer security, TLS, tunnel over Ethernet, ETLS tunnel between two endpoints (UE and WAG) and to transport UE traffic encapsulated and encrypted in a proposed TLS type Ethernet frame for all applications, thus providing secure layer 2 connectivity over public wireless local area networks, WLAN, for all UE traffic and overcome the security vulnerability of the traditional HTTP login mechanism over the public WLAN. The UE uses the TLS handshake protocol which may include negotiating ETLS capabilities extension that comprises wireless control protocol for establishing a packet data connection and tunneled authentication protocol for UE authentication and full Ethernet protection for encrypting Ethernet frames of different types.