Network Security Controller for Encrypted Wi-Fi Calling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Secure enterprise networks often block Wi-Fi calls due to encrypted tunnels, such as IPSec, as they cannot discern the type and content of traffic, leading to potential security breaches, thereby preventing cellular devices from making and receiving calls over these networks.

Innovation Solution

Implementing a network security controller that selectively allows encrypted tunnels for Wi-Fi calling by verifying trusted sources, destinations, and encryption parameters, while denying unknown entities and monitoring traffic to ensure compliance with security criteria, thereby allowing secure Wi-Fi calling while maintaining network integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encrypted tunnels are blocked to maintain security, then network security is improved, but mobile communication functionality deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoidmobile communication functionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments encrypted traffic into different categories by creating separate inspection mechanisms: deep packet inspection for unencrypted traffic and metadata-only inspection for encrypted traffic. This allows the network to handle different types of traffic differently, permitting authorized encrypted communications (like Wi-Fi calling) while blocking unauthorized ones, thus resolving the contradiction between security and functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary security appliance that acts as a mediator between the network and encrypted traffic. This appliance performs deep packet inspection on unencrypted portions and extracts metadata from encrypted portions to make authorization decisions. The intermediary enables encrypted communications to proceed when authorized while maintaining security controls, thus resolving the contradiction.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If deep packet inspection is applied to all traffic, then security monitoring is improved, but processing overhead and complexity increase

Engineering Contradiction:
Improvesecurity monitoringVSAvoidprocessing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by making the inspection method dependent on the traffic type: unencrypted traffic receives deep packet inspection with full content analysis, while encrypted traffic receives only metadata inspection. This localized approach to inspection quality allows comprehensive monitoring where possible while reducing complexity where encryption prevents full inspection, thus resolving the contradiction between monitoring capability and processing complexity.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10785195B2Mobile communications over secure enterprise networks
Publication Date: 2020.09.22 CISCO TECHNOLOGY INC
  • US10785195B2 patent drawing
  • US10785195B2 patent drawing
  • US10785195B2 patent drawing

AI summary

In various implementations, a method includes receiving a request to establish an end-to-end encrypted session between a device in an enterprise network and an external entity that is outside the enterprise network. In some implementations, the end-to-end encrypted session allows encrypted packets to be transmitted between the device and the external entity. In various implementations, the method includes determining whether the request satisfies an enterprise security criterion for establishing the end-to-end encryption session. In various implementations, the method includes in response to determining that the request satisfies the enterprise security criterion, triggering the establishment of the end-to-end encrypted session between the device in the enterprise network and the external entity that is outside the enterprise entity.