Mobility Gateway Secure Tunnel WiFi Cellular Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless networking technologies face challenges in securely coupling untrusted wireless access networks to trusted controlled networks, particularly in ensuring seamless mobility and efficient IP address allocation without requiring Internet Protocol Security (IPSec)/Internet Key Exchange (IKE) on user equipment (UE).
Innovation Solution
Establishing a secure Internet Protocol (IP) tunnel between an access point (AP) device associated with a WiFi network and a cellular (packet core) network, using a mobility gateway (MGW) to manage IP addresses and authenticate UE devices, allowing for seamless mobility and IP address allocation without the need for IPSec/IKE on the UE.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If IPSec/IKE is implemented on user equipment for secure communication, then security is improved, but device complexity and energy consumption increase
Solution Approach 1:
The patent extracts the IPSec/IKE security functionality from the user equipment and relocates it to the network infrastructure (access point and gateway). The gateway device performs IP address allocation, authentication, and security management, while the access point handles IPSec tunnel establishment. This extraction reduces complexity on user equipment while maintaining security through network-side enforcement.
Solution Approach 2:
The patent introduces a gateway device as an intermediary between the untrusted wireless access network and the trusted packet core network. The gateway acts as a mediator that performs authentication, authorizes IP address allocation, and manages security policies, thereby securing communications without requiring complex IPSec implementations on end-user devices.
2Reliability
If IPSec/IKE is implemented on user equipment for secure communication, then security is improved, but energy consumption increases
Solution Approach 1:
The patent extracts the energy-intensive IPSec/IKE security processing from mobile user equipment and relocates it to the network infrastructure. The gateway and access point handle authentication and security management, significantly reducing battery consumption on mobile devices while maintaining equivalent security through network-side enforcement.
3Reliability
If manual IP address allocation is used in wireless networks, then security control is improved, but productivity and ease of operation deteriorate
Solution Approach 1:
The patent implements an automated IP address allocation system where the gateway device serves itself by automatically authenticating devices, authorizing IP address assignments, and managing the IP address pool without manual intervention. This self-service automation maintains security control through policy enforcement while dramatically improving productivity and ease of operation.
Solution Approach 2:
The patent establishes feedback loops where the gateway device monitors network conditions, device authentication status, and IP address availability to dynamically make allocation decisions. This automated feedback mechanism ensures security policies are enforced while efficiently managing IP address resources without manual intervention.
4Ease of operation
If seamless mobility is implemented across networks, then ease of operation is improved, but device complexity increases
Solution Approach 1:
The patent introduces the gateway device as an intermediary that manages mobility between the wireless access network and packet core network. The gateway maintains device context, handles authentication state, and coordinates IP address management, enabling seamless mobility while keeping device complexity low by centralizing mobility management in the network infrastructure.
Data Source
AI summary
A request for an IP address for a client device having a first identifier information is received from an AP device. The request for the IP address is associated with a first communication protocol. The first identifier information is compared to a second identifier information. The second identifier information is associated with a second communication protocol. The second communication protocol is different from the first communication protocol. The IP address for the client device based on comparing.


