Relay Access Node Tunneling for Wireless Identity Separation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wireless connection methods for mobile devices through wireless access nodes are vulnerable to identity-theft and usurpation, as they allow spoofing of MAC and IP addresses, putting both broadband Internet connection modem owners and guest mobile device owners at risk of security threats, with all traffic being attributed to the modem owner.
Innovation Solution
A method and system that commissions a wireless connection with authentication to a remote relay access node, encapsulating data between the guest mobile device and the Internet service provider through a tunnel between the hosting wireless access node and the relay node, ensuring the service provider interacts with the relay node rather than the access node, thereby separating and managing traffic securely.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a mobile device connects to a wireless access node using traditional authentication methods, then the device can access the Internet, but the access node owner is held responsible for all traffic generated by the mobile device, creating security risks
Solution Approach 1:
The patent introduces a commissioned relay access node as an intermediary between the mobile device and the service provider. This relay node acts as a mediator that receives data from the mobile device via the hosting access node, processes it, and forwards it to the service provider. This intermediary structure separates the identity responsibility from the actual traffic source, allowing the mobile device to be properly identified while still connecting through the hosting access node's network infrastructure.
2Adaptability or versatility
If traditional NAT (Network Address Translation) is used to translate mobile device IP addresses behind the modem's WAN IP address, then Internet connectivity is provided, but the modem owner is identified as the traffic source instead of the actual mobile device
Solution Approach 1:
The patent segments the network communication into distinct functional parts: the hosting access node provides network access infrastructure, the commissioned relay access node handles traffic forwarding and identification, and the mobile device generates actual traffic. This segmentation allows each component to perform its specific function without compromising the overall system, enabling proper traffic source identification while maintaining Internet access capability.
3Reliability
If authentication and encryption modules are installed on both the mobile device and wireless access node, then secure connection is established, but the system complexity increases
Solution Approach 1:
The patent extracts the authentication and identification functionality from the hosting access node and places it in the commissioned relay access node. This extraction allows the hosting access node to maintain a simpler role focused on providing network access, while the relay node handles the complex authentication and identification tasks. This separation reduces the complexity burden on the hosting access node while maintaining security requirements.
Data Source
AI summary
A method and system for commissioning a wireless connection with a related authentication and the eventual encryption to a remote relay node, whereto an electronic mobile device is connected to a hosting wireless access node for transmitting/receiving data to/from a service provider available on the Internet by means of a commissioned relay access node selected by an authentication and commissioning manager. The data transfer between the mobile device and the service provider is encapsulated into the tunnel between the hosting wireless access node and the commissioned relay access node and is finally forwarded by the commissioned relay access node to the service provider. The service provider thereby is exchanging data with the commissioned relay access node and not directly with the hosting wireless access node.


