Mobile Security Gateway Seamless Network Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users of cellular mobile devices face the challenge of having to re-authenticate when transitioning from a cellular service provider network to an enterprise network's wireless access point, which discourages them from using the more cost-effective wireless network and increases IT burdens.
Innovation Solution
A mobile security gateway (MSG) is deployed in the public network to publish authentication information and security status of mobile devices to an enterprise security database, allowing seamless authentication and access to the enterprise network without re-authentication when switching from cellular to wireless access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users access the enterprise network via cellular service provider network, then network access is available, but users must re-authenticate when transitioning to wireless access points, increasing authentication complexity and reducing ease of operation
Solution Approach 1:
The patent implements preliminary authentication via the cellular service provider network before wireless access point connection. The authentication credentials obtained through cellular access are stored and automatically reused when the device connects to wireless access points, eliminating the need for re-authentication and simplifying the user experience.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism that bridges cellular network authentication and wireless access point authentication. This intermediary system allows credentials obtained from cellular providers to be recognized and accepted by enterprise wireless access points, resolving the authentication complexity between different network types.
2Reliability
If users re-authenticate at wireless access points, then security policies are enforced, but IT burdens increase and costs rise
Solution Approach 1:
The patent merges the authentication processes of cellular service provider networks and enterprise wireless access points into a unified system. By integrating credential verification across both network types, the system enforces security policies once through cellular authentication while automatically applying the same security enforcement at wireless access points, reducing IT management complexity.
Solution Approach 2:
The patent creates a universal authentication framework where a single authentication credential obtained through cellular access can be used across multiple network types including both cellular data services and wireless access points. This multi-functional authentication approach maintains security policy enforcement while reducing the need for separate authentication systems.
3Reliability
If cellular networks are used for enterprise access, then network availability is maintained, but reliance on expensive cellular data services increases
Solution Approach 1:
The patent implements a dynamic network selection mechanism that automatically transitions device connectivity from cellular data services to wireless access points after successful authentication. The system dynamically switches between network types based on availability and cost considerations, maintaining network access reliability while optimizing data transmission costs by preferring wireless access over cellular data.
Data Source
AI summary
In general, techniques are described for provisioning layer two access in computer networks. A network device located in a public network comprising an interface and a control unit may implement the techniques. The interface establishes a session with a mobile device. The control unit requests security state data identifying a security state of the mobile device via the established session. The interface receives a mobile device identifier and the security state data from the mobile device via the session. The mobile device identifier identifies the mobile device. The control unit publishes the security state information to a database such that the security state information is associated with the mobile device identifier.


