Physical Link Authentication for Layer 3 VPN Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Layer 3 VPN solutions face security concerns due to the inability to validate the physical location of the VPN access router, making them insecure for devices without web-browser capabilities or those operated remotely, and requiring authentication-proxy functionality that is not universally applicable.

Innovation Solution

A method is introduced where an encrypted string is used to authenticate the physical link between a gateway and an access provider, utilizing pre-existing information like the expected gateway location and the access provider's public key to verify the response and establish a secure tunnel, allowing devices to access a headend without user login authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If Layer 3 VPN solution is used to enable remote connectivity, then flexibility and remote access capability are improved, but security is worsened due to inability to validate physical location

Engineering Contradiction:
Improveremote access capabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an authentication-proxy server as an intermediary between the VPN access-router and remote devices. This server validates device identities and manages authentication, acting as a mediator that enables secure remote access without requiring physical location validation of the access-router itself. The authentication-proxy handles authentication requests and grants access permissions, resolving the security concern while maintaining remote connectivity flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary authentication of devices before allowing them to establish VPN connections. The authentication-proxy server pre-validates device identities and credentials, and only after successful authentication are devices permitted to access the network. This preliminary security check ensures that even though physical location cannot be validated in Layer 3 VPN, device identity can be verified in advance, maintaining security while enabling remote access.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If authentication-proxy functionality is implemented to address security concerns, then security is improved, but device compatibility is worsened for devices without web-browser capabilities

Engineering Contradiction:
ImprovesecurityVSAvoiddevice compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The authentication-proxy server implements multiple authentication methods to serve diverse device types. It supports both web-based authentication (for devices with browsers) and alternative authentication mechanisms (for devices without browsers). This multi-functional approach allows the same authentication infrastructure to handle various device capabilities, maintaining both security and broad device compatibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system changes authentication parameters based on device capabilities. For devices with web-browser capabilities, it uses web-based authentication forms and pages. For devices without such capabilities, it employs alternative authentication methods such as certificate-based authentication, token-based authentication, or API-based authentication. This parameter adaptation allows the authentication-proxy to maintain security while accommodating diverse device types.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If Layer 2 VPN solution is used to ensure fixed physical location, then security is improved through location validation, but flexibility is worsened as devices cannot be operated remotely

Engineering Contradiction:
ImprovesecurityVSAvoidremote operation capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Instead of validating the physical location of the access-router (as in Layer 2 VPN), the patent inverts the approach by validating the identity and credentials of remote devices attempting to connect. Rather than requiring the access point to be at a fixed location, the system allows any location but requires strong authentication of the connecting device. This inversion maintains security through identity verification while enabling remote operation flexibility.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS8886934B2Authorizing physical access-links for secure network connections
Publication Date: 2014.11.11 CISCO TECHNOLOGY INC
  • US8886934B2 patent drawing
  • US8886934B2 patent drawing
  • US8886934B2 patent drawing

AI summary

A method of authenticating a network link of a first device to a second device is described. The method includes communicating a challenge request including a challenge value from the first device to the second device, wherein challenge value is unique to the challenge request. The method further includes receiving a challenge response from the second device, in which the challenge response includes encrypted data pertaining to the first device, and authenticating the network link based on the first device decrypting the encrypted data included in the challenge response from the second device.