Mobile Router Access Control for Visitor Nodes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile network technologies fail to effectively implement access control based on security policies for visitor nodes within a mobile personal area network, allowing unauthorized access to home networks.

Innovation Solution

A mobile network managing apparatus that includes access request reception, determination, home network communication, and security network communication means to identify and manage visitor nodes, utilizing a security managing apparatus for access control, and storing information to differentiate between home and visitor nodes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a bi-directional tunnel is established between the mobile router and home agent for network mobility, then seamless connectivity is maintained, but security policy enforcement is bypassed

Engineering Contradiction:
Improvenetwork mobilityVSAvoidsecurity policy enforcement
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a policy enforcement module as an intermediary component within the mobile router that intercepts and inspects packets before they are tunneled through the home agent. This mediator ensures security policies are enforced even though the tunnel bypasses the traditional DMZ architecture, resolving the contradiction between maintaining mobility and enforcing security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If visitor nodes are authorized to access the home network, then network functionality is enhanced, but unauthorized access risk increases

Engineering Contradiction:
Improvenetwork access functionalityVSAvoidunauthorized access risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary authentication and authorization mechanisms that verify visitor nodes before granting access to the home network. Security policies are pre-configured and enforced at the mobile router level, ensuring that only authorized visitor nodes can access specific resources, thus enhancing functionality while mitigating unauthorized access risks.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If security policies are enforced at the DMZ policy server, then access control is implemented, but visitor node traffic bypasses the policy server

Engineering Contradiction:
Improveaccess controlVSAvoidnetwork architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security policy enforcement functionality from the remote DMZ policy server and embeds it directly within the mobile router. This local enforcement mechanism ensures that all visitor node traffic passing through the mobile router is subject to security policies, eliminating the bypass issue while maintaining access control reliability.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If the mobile IP proxy acts as surrogate home agent, then secure communication is established, but access control of visitor nodes is not implemented

Engineering Contradiction:
Improvesecure communicationVSAvoidvisitor node access control
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges the functions of the mobile IP proxy, home agent, and security policy enforcement into a single integrated mobile router system. This consolidation ensures that secure communication and visitor node access control are implemented together in a unified architecture, eliminating the operational gaps present in separate proxy-agent systems.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP1966970B1Mobile network managing apparatus and mobile information managing apparatus for controlling access requests
Publication Date: 2017.06.14 PANASONIC INTELLECTUAL PROPERTY CORP OF AMERICA
  • EP1966970B1 patent drawingFigure 1
  • EP1966970B1 patent drawingFigure 2
  • EP1966970B1 patent drawingFigure 3

AI summary

Disclosed is a technique capable of proper execution of access control based on various security policies set by a home user with regards to a packet sent from a visitor node. According to the technique, a MR (Mobile Router) 10 which manages a mobile PAN 30 determines whether a sender of a packet from a communication terminal connected to the mobile PAN is a home user's node which is allowed direct access into a home network or a visitor node (VN 31), and forwards the packet from the home user's node to an HA 20 while forwarding the packet from the visitor node to a policy server 36 located in a DMZ 35. This allows the policy server to perform access control on every packet from a visitor node which attempts to gain access into the home network based on a security policy 36a.