Mobile Router Access Control for Visitor Nodes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile network technologies fail to effectively implement access control based on security policies for visitor nodes within a mobile personal area network, allowing unauthorized access to home networks.
Innovation Solution
A mobile network managing apparatus that includes access request reception, determination, home network communication, and security network communication means to identify and manage visitor nodes, utilizing a security managing apparatus for access control, and storing information to differentiate between home and visitor nodes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a bi-directional tunnel is established between the mobile router and home agent for network mobility, then seamless connectivity is maintained, but security policy enforcement is bypassed
Solution Approach 1:
The patent introduces a policy enforcement module as an intermediary component within the mobile router that intercepts and inspects packets before they are tunneled through the home agent. This mediator ensures security policies are enforced even though the tunnel bypasses the traditional DMZ architecture, resolving the contradiction between maintaining mobility and enforcing security.
2Adaptability or versatility
If visitor nodes are authorized to access the home network, then network functionality is enhanced, but unauthorized access risk increases
Solution Approach 1:
The patent implements preliminary authentication and authorization mechanisms that verify visitor nodes before granting access to the home network. Security policies are pre-configured and enforced at the mobile router level, ensuring that only authorized visitor nodes can access specific resources, thus enhancing functionality while mitigating unauthorized access risks.
3Reliability
If security policies are enforced at the DMZ policy server, then access control is implemented, but visitor node traffic bypasses the policy server
Solution Approach 1:
The patent extracts the security policy enforcement functionality from the remote DMZ policy server and embeds it directly within the mobile router. This local enforcement mechanism ensures that all visitor node traffic passing through the mobile router is subject to security policies, eliminating the bypass issue while maintaining access control reliability.
4Reliability
If the mobile IP proxy acts as surrogate home agent, then secure communication is established, but access control of visitor nodes is not implemented
Solution Approach 1:
The patent merges the functions of the mobile IP proxy, home agent, and security policy enforcement into a single integrated mobile router system. This consolidation ensures that secure communication and visitor node access control are implemented together in a unified architecture, eliminating the operational gaps present in separate proxy-agent systems.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Disclosed is a technique capable of proper execution of access control based on various security policies set by a home user with regards to a packet sent from a visitor node. According to the technique, a MR (Mobile Router) 10 which manages a mobile PAN 30 determines whether a sender of a packet from a communication terminal connected to the mobile PAN is a home user's node which is allowed direct access into a home network or a visitor node (VN 31), and forwards the packet from the home user's node to an HA 20 while forwarding the packet from the visitor node to a policy server 36 located in a DMZ 35. This allows the policy server to perform access control on every packet from a visitor node which attempts to gain access into the home network based on a security policy 36a.