Gateway IP Address Allocation for Secure Tunneling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In Fixed Mobile Convergence networks, particularly when using DSL networks as a non-3GPP IP Access, there are challenges with IP address selection and security, including the risk of man-in-the-middle attacks due to insecure residential networks, where applications struggle to choose between local and global IP addresses, and trusted networks lack adequate security measures.
Innovation Solution
A method and gateway node that allocate a single IP address for both inner and outer IPsec tunnel usage, ensuring secure communication by establishing an IPsec tunnel between a gateway node and a terminal device, using Internet Key Exchange protocol, and configuring security policies to differentiate between local and global communications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a terminal device is allocated multiple IP addresses (local and global) for communication through a residential network, then the device can communicate both locally and globally, but applications face difficulty in selecting the appropriate IP address and the system becomes vulnerable to man-in-the-middle attacks
Solution Approach 1:
The patent merges the local and global IP address functions into a single IP address that operates in both contexts. The gateway node allocates one IP address to the terminal device, and this same address is used for both local network communication and global network communication through the IPsec tunnel, eliminating the need for applications to select between multiple addresses.
Solution Approach 2:
The gateway node acts as an intermediary that handles the complexity of address management. It allocates a single IP address to the terminal device and manages the IPsec tunnel configuration, shielding applications from the complexity of multi-address management while maintaining both local and global communication capabilities.
2Productivity
If residential networks are used for Fixed Mobile Convergence access, then network resource utilization is improved, but security is compromised due to the risk of man-in-the-middle attacks
Solution Approach 1:
The patent applies preliminary anti-action by establishing security measures before communication occurs. The gateway node and terminal device perform mutual authentication using shared secrets before any data transmission, and set up encrypted IPsec tunnels in advance to prevent man-in-the-middle attacks before they can occur.
Solution Approach 2:
The patent converts the inherent security weakness of residential networks into a benefit by implementing mandatory authentication and encryption mechanisms. The very act of going through rigorous authentication and tunnel establishment processes transforms the previously insecure environment into a secure communication channel.
3Ease of operation
If separate IP addresses are used for local and global communication, then address routing is simplified, but the system becomes vulnerable to security attacks and applications face selection issues
Solution Approach 1:
The patent combines the routing functions for local and global communication into a single IP address system. The gateway node configures the terminal device to use one IP address for both types of communication, with the IPsec tunnel handling the routing differentiation transparently, thereby maintaining routing simplicity while enhancing security.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method of providing secure access to a remote communication network via a local communication network for a terminal device. A gateway node located outside the local communication network allocates an IP address to the terminal device. The gateway node subsequently receives a request to establish a secure tunnel between the gateway node and the terminal device. It identifies the terminal device as the same terminal device to which an IP address is allocated, and allocates the same IP address for use by the terminal device as both an inner IP address and an outer IP address for packets sent via the secure tunnel. This ensures that there are no issues as described above in selecting the IP address for use in the secure tunnel, and reduces the risk of a successful man-in-the-middle attack.