Gateway IP Address Allocation for Secure Tunneling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In Fixed Mobile Convergence networks, particularly when using DSL networks as a non-3GPP IP Access, there are challenges with IP address selection and security, including the risk of man-in-the-middle attacks due to insecure residential networks, where applications struggle to choose between local and global IP addresses, and trusted networks lack adequate security measures.

Innovation Solution

A method and gateway node that allocate a single IP address for both inner and outer IPsec tunnel usage, ensuring secure communication by establishing an IPsec tunnel between a gateway node and a terminal device, using Internet Key Exchange protocol, and configuring security policies to differentiate between local and global communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a terminal device is allocated multiple IP addresses (local and global) for communication through a residential network, then the device can communicate both locally and globally, but applications face difficulty in selecting the appropriate IP address and the system becomes vulnerable to man-in-the-middle attacks

Engineering Contradiction:
Improvecommunication capabilityVSAvoidIP address management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges the local and global IP address functions into a single IP address that operates in both contexts. The gateway node allocates one IP address to the terminal device, and this same address is used for both local network communication and global network communication through the IPsec tunnel, eliminating the need for applications to select between multiple addresses.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The gateway node acts as an intermediary that handles the complexity of address management. It allocates a single IP address to the terminal device and manages the IPsec tunnel configuration, shielding applications from the complexity of multi-address management while maintaining both local and global communication capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If residential networks are used for Fixed Mobile Convergence access, then network resource utilization is improved, but security is compromised due to the risk of man-in-the-middle attacks

Engineering Contradiction:
Improvenetwork resource utilizationVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary anti-action by establishing security measures before communication occurs. The gateway node and terminal device perform mutual authentication using shared secrets before any data transmission, and set up encrypted IPsec tunnels in advance to prevent man-in-the-middle attacks before they can occur.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent converts the inherent security weakness of residential networks into a benefit by implementing mandatory authentication and encryption mechanisms. The very act of going through rigorous authentication and tunnel establishment processes transforms the previously insecure environment into a secure communication channel.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

3Ease of operation

If separate IP addresses are used for local and global communication, then address routing is simplified, but the system becomes vulnerable to security attacks and applications face selection issues

Engineering Contradiction:
Improveaddress routingVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent combines the routing functions for local and global communication into a single IP address system. The gateway node configures the terminal device to use one IP address for both types of communication, with the IPsec tunnel handling the routing differentiation transparently, thereby maintaining routing simplicity while enhancing security.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP2347560B1Secure access in a communication network
Publication Date: 2014.08.27 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP2347560B1 patent drawingFigure 1
  • EP2347560B1 patent drawingFigure 2
  • EP2347560B1 patent drawingFigure 3

AI summary

A method of providing secure access to a remote communication network via a local communication network for a terminal device. A gateway node located outside the local communication network allocates an IP address to the terminal device. The gateway node subsequently receives a request to establish a secure tunnel between the gateway node and the terminal device. It identifies the terminal device as the same terminal device to which an IP address is allocated, and allocates the same IP address for use by the terminal device as both an inner IP address and an outer IP address for packets sent via the secure tunnel. This ensures that there are no issues as described above in selecting the IP address for use in the secure tunnel, and reduces the risk of a successful man-in-the-middle attack.