Mobility Gateway Secure IP Tunnel for Untrusted Wireless Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless networking technologies face challenges in securely coupling untrusted wireless access networks to trusted controlled networks, particularly in ensuring seamless mobility and secure data transmission without requiring Internet Protocol Security (IPSec)/Internet Key Exchange (IKE) on user equipment.

Innovation Solution

Establishing a secure Internet Protocol (IP) tunnel between an access point device associated with a wireless network and a cellular packet core network, using a mobility gateway to authenticate devices and manage IP addresses, allowing for seamless mobility and secure data transmission without the need for IPSec/IKE on user equipment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a secure tunnel is established between wireless access network and packet core network, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a mobility gateway as an intermediary component that establishes and manages secure IP tunnels between the wireless access network and packet core network. The gateway handles authentication, IP address allocation, and tunnel management, thereby providing security without requiring complex security implementations on user equipment. The gateway acts as a mediator that simplifies the security architecture by centralizing security functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If IPSec/IKE is implemented on user equipment, then security is improved, but power consumption increases

Engineering Contradiction:
ImprovesecurityVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts security functions (IPSec/IKE) from user equipment and relocates them to the mobility gateway. By removing the security implementation burden from mobile devices, the patent significantly reduces power consumption on user equipment while maintaining security through the gateway's tunnel establishment and management capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If seamless mobility is ensured through secure tunnel, then connectivity is improved, but network complexity increases

Engineering Contradiction:
ImproveconnectivityVSAvoidnetwork complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The mobility gateway performs multiple functions including authentication, IP address allocation, tunnel management, and mobility handling. By consolidating these diverse functions into a single multi-functional gateway, the patent enables seamless mobility and continuous connectivity while avoiding the need for multiple separate complex systems throughout the network.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9521145B2Methods and apparatuses to provide secure communication between an untrusted wireless access network and a trusted controlled network
Publication Date: 2016.12.13 MAVENIR SYST INC
  • US9521145B2 patent drawing
  • US9521145B2 patent drawing
  • US9521145B2 patent drawing

AI summary

A secure communication channel between an access point (AP) device associated with a wireless network and a mobile gateway (GW) device of a packet core network is established. Data is exchanged between the wireless network and the packet core network through the secure channel. A client device (UE) is authenticated through the secure communication channel. Device identity information is received from the AP device. A session request is sent to the packet core network. An IP address for the device is received from the packet core network. The communication between the AP device and the packet core network becomes secure without need to run an IP secure protocol on the UE that saves the battery power on the UE. Establishing the fully secure communication between the UE and the packet core network while saving the UE power provides a significant advantage for the mobile technology world.