Multiple SSID Secure Tunnel for QoS and Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The integration of cellular and WiFi networks poses security challenges due to the lack of encryption in WiFi networks, and the inability to provide quality of service (QoS) in DOCSIS access networks, which affects the quality of voice over packet (VOP) services.

Innovation Solution

A system and method that utilize multiple service set identifiers (SSID) to create secure data tunnels, dynamically providing QoS by transmitting SSIDs to modems, and using policy servers to determine and establish bandwidth requirements for secure data sessions, ensuring security and QoS across both cellular and WiFi networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If WiFi networks are used to provide wireless access, then network coverage and accessibility are improved, but security and QoS control are worsened due to lack of encryption and open access

Engineering Contradiction:
Improvenetwork coverageVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a secure data tunnel as an intermediary layer between the endpoint device and WiFi network. This tunnel encapsulates all data traffic, providing security and QoS control without requiring changes to the underlying WiFi network infrastructure. The tunnel acts as a mediator that protects sensitive information while allowing open WiFi access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network connection into two distinct parts: a secure encapsulated channel for sensitive data traffic and the public WiFi network for general access. By dividing the data stream into encapsulated packets within the tunnel, the system maintains security for critical communications while allowing unrestricted WiFi connectivity for other purposes.

Inventive Principle:
Principle #1Segmentation

2Productivity

If DOCSIS access network is used, then broadband data access is provided, but QoS control is worsened due to inability to provide guaranteed bandwidth for VOP services

Engineering Contradiction:
Improvebroadband data accessVSAvoidQoS
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent establishes QoS parameters and bandwidth guarantees in advance before VOP traffic enters the DOCSIS network. The system pre-configures the secure data tunnel with specific QoS requirements, ensuring that when voice traffic flows through the network, the necessary bandwidth and service quality are already reserved and guaranteed, rather than attempting to implement QoS after the fact.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If multiple wireless networks are combined for FMC, then service versatility is improved, but device complexity and security management are worsened

Engineering Contradiction:
Improveservice convergenceVSAvoiddual-mode handset
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal secure data tunnel that can operate across multiple network types (cellular, WiFi, DOCSIS) without requiring separate security implementations for each network. The tunnel provides a consistent security and QoS framework that works universally across different access networks, simplifying the complexity of managing multiple wireless technologies in a dual-mode handset.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8184530B1Providing quality of service (QOS) using multiple service set identifiers (SSID) simultaneously
Publication Date: 2012.05.22 T MOBILE INNOVATIONS LLC
  • US8184530B1 patent drawing
  • US8184530B1 patent drawing
  • US8184530B1 patent drawing

AI summary

Quality of Service (QoS) is provided to a secure data tunnel such an IPsec tunnel using information about the tunnel and the underlying data session to formulate a set of bandwidth requirements. A policy server operates to receive the information to create the set of bandwidth requirements which are enforced by a termination device. The termination device sets the bandwidths. QoS can be provided on a static or continuous basis. QoS can be provided on a dynamic basis. QoS can be provided at different levels depending on the type of data session. Multiple QoS can be provided for multiple data sessions existing simultaneously using multiple SSIDs.