Network Access Server for Secure Home Network Roaming

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Wi-Fi network authentication methods, particularly in public hotspots, lack secure access control mechanisms, allowing unauthorized access to home networks and requiring complex VPN software for secure connections, which can lead to security vulnerabilities and user inconvenience.

Innovation Solution

A method and system that implement a centralized authentication mechanism using a Captive Portal and RADIUS server with an additional layer of authentication through an IP Flow authenticator and VPN Tunnel Manager, allowing users to securely access their home network without dedicated VPN software, while disabling VPN connections by default and requiring secondary authentication for enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If VPN software is installed on client devices to establish secure end-to-end connections, then network security is improved, but device complexity and ease of operation deteriorate due to extra software requirements and configuration complexity

Engineering Contradiction:
Improvenetwork securityVSAvoidclient software complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a network access server as an intermediary that performs authentication and establishes secure tunnels between the client device and home network. The NAS acts as a mediator that handles the complex security functions centrally, eliminating the need for VPN software installation and configuration on client devices while maintaining secure connectivity

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If centralized authentication is implemented at the network core, then unauthorized access is prevented, but the system complexity increases due to additional authentication servers and mechanisms

Engineering Contradiction:
Improveaccess control securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network access server performs multiple functions including authentication, authorization, accounting, and secure tunnel establishment within a single centralized system. This multi-functional approach consolidates what could be separate complex systems into one integrated solution that provides comprehensive security without proportionally increasing overall system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The authentication system automatically verifies user credentials against stored profiles and dynamically creates secure access sessions without requiring manual intervention. The RADIUS server autonomously handles authentication requests, validates credentials, and manages session creation, reducing operational complexity while maintaining strong access control

Inventive Principle:
Principle #25Self-service

3Reliability

If encryption is implemented between authorized devices using WPA2 protocol, then home network security is improved, but public hotspot access and seamless roaming deteriorate due to encryption compatibility issues between different networks

Engineering Contradiction:
Improvehome network securityVSAvoidhotspot network compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the security implementation into two distinct layers: public hotspot networks use open access points with centralized authentication for compatibility and roaming, while home networks maintain WPA2 encryption for security. The network access server acts as a transition point that enables seamless authentication and secure tunnel establishment between these segmented networks, allowing devices to move freely between public and private networks without reconfiguration

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2939391B1Method and system for secure network access
Publication Date: 2020.02.26 BRITISH TELECOM PLC
  • EP2939391B1 patent drawingFigure 1
  • EP2939391B1 patent drawingFigure 2
  • EP2939391B1 patent drawingFigure 3~4

AI summary

In a hotspot Wi-Fi network, users can access the Internet from a variety of access points. The users' credentials are centrally authenticated within the network core to ensure they are allowed on the hotspot network. To improve security and provide selective access, a further authenticator function in the network manages access to private and/or restricted network resources.