Mobile Server Wi-Fi Switching via VPN Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users tend to prefer 3G and 4G mobile telecommunications networks over Wi-Fi networks due to security concerns, despite Wi-Fi offering higher throughput at a lower cost, as existing technologies do not effectively manage access point security and capacity for seamless switching.
Innovation Solution
A method controlled by a mobile operating server that determines the availability of authenticated and non-authenticated Wi-Fi access points, instructing devices to connect to Wi-Fi networks based on security and capacity, and initiates a virtual private network (VPN) for secure data transmission, while maintaining downlink communication through the Wi-Fi network and disabling uplink transmission if necessary.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users use 3G and 4G mobile telecommunications networks, then security is improved, but throughput and cost-effectiveness deteriorate
Solution Approach 1:
The patent segments the communication channels into downlink and uplink paths. Downlink traffic routes through unauthenticated Wi-Fi access points for high throughput, while uplink traffic routes through authenticated channels (3G/4G or authenticated Wi-Fi) for security. This segmentation allows simultaneous optimization of throughput and security for different data flows.
Solution Approach 2:
The patent introduces a gateway or network infrastructure as an intermediary that terminates unencrypted downlink traffic from unauthenticated Wi-Fi access points and re-encrypts it before forwarding to the mobile device. This intermediary enables secure communication over untrusted Wi-Fi networks without requiring device authentication at the access point.
2Productivity
If users switch to Wi-Fi networks, then throughput and cost are improved, but security deteriorates
Solution Approach 1:
The patent segments the communication channels into downlink and uplink paths. Downlink traffic routes through unauthenticated Wi-Fi access points for high throughput, while uplink traffic routes through authenticated channels (3G/4G or authenticated Wi-Fi) for security. This segmentation allows simultaneous optimization of throughput and security for different data flows.
Solution Approach 2:
The patent introduces a gateway or network infrastructure as an intermediary that terminates unencrypted downlink traffic from unauthenticated Wi-Fi access points and re-encrypts it before forwarding to the mobile device. This intermediary enables secure communication over untrusted Wi-Fi networks without requiring device authentication at the access point.
3Adaptability or versatility
If devices connect to unauthenticated Wi-Fi access points, then availability and capacity are improved, but security and reliability deteriorate
Solution Approach 1:
The patent segments the communication channels into downlink and uplink paths. Downlink traffic routes through unauthenticated Wi-Fi access points for high throughput, while uplink traffic routes through authenticated channels (3G/4G or authenticated Wi-Fi) for security. This segmentation allows simultaneous optimization of throughput and security for different data flows.
Solution Approach 2:
The patent introduces a gateway or network infrastructure as an intermediary that terminates unencrypted downlink traffic from unauthenticated Wi-Fi access points and re-encrypts it before forwarding to the mobile device. This intermediary enables secure communication over untrusted Wi-Fi networks without requiring device authentication at the access point.
Data Source
Figure 1a~1c
Figure 2
Figure 3~4
AI summary
Technologies are generally described for providing wireless communications. In some examples, a method performed under control of a mobile operating server may include determining whether there is an authenticated wireless access point around a mobile device, if there is no authenticated wireless access point, determining whether there is a non-authenticated wireless access point whose capacity is over a predetermined value around the mobile device and if there is a non-authenticated wireless access point whose capacity is over the predetermined value, instructing the mobile device to connect to a wireless local area network provided by the non-authenticated wireless access point.