Roaming Credential Authentication for VPN Session Establishment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In Wi-Fi roaming scenarios, users face cumbersome and duplicative processes when attempting to access secure information, requiring repeated input of usernames and passwords to establish VPN sessions across different networks.

Innovation Solution

The system employs a secure communication tunnel, such as EAP-TTLS, between the client and the AAA server, allowing for authentication without resubmitting credentials, and utilizes a key package with dual encryption keys and an access control list to secure communications, with the AAA agent managing authentication and key distribution to ensure security and reduce user burden.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the client inputs username and password for Wi-Fi authentication at the partner network, then the client gains access to the partner network services, but the client must re-submit the same credentials to establish a VPN session to access secure information at the home network

Engineering Contradiction:
Improveauthentication processVSAvoidtime for repeated credential input
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system performs preliminary action by capturing and storing the username and password during the initial Wi-Fi authentication process at the partner network. These credentials are then reused for the VPN session establishment without requiring the user to re-input them, thereby eliminating redundant authentication steps while maintaining security through the use of captured credentials in the appropriate context

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the system requires separate authentication for Wi-Fi access and VPN session establishment, then security is maintained through multiple verification steps, but the user experience becomes cumbersome and processing load increases

Engineering Contradiction:
Improvesecurity verificationVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system merges the Wi-Fi authentication process and VPN session establishment process by using the same username and password credentials for both purposes. The captured credentials from Wi-Fi authentication are directly utilized for VPN authentication, combining what were previously separate authentication flows into a unified process that reduces complexity while maintaining security through consistent credential verification across both access types

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If the client stores and transmits credentials multiple times across different authentication processes, then access is enabled across multiple networks and services, but the exposure of credentials increases and processing demands on the client increase

Engineering Contradiction:
Improveaccess across networksVSAvoidcredential exposure
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary action by capturing the credentials during the initial Wi-Fi authentication process and storing them securely for subsequent use. This preliminary capture and storage eliminates the need for repeated credential transmission and input in later VPN authentication processes, thereby reducing credential exposure opportunities and processing demands while maintaining adaptability for access across different networks and services

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8887256B2Establishing virtual private network session using roaming credentials
Publication Date: 2014.11.11 CABLE TELEVISION LAB INC
  • US8887256B2 patent drawing
  • US8887256B2 patent drawing
  • US8887256B2 patent drawing

AI summary

Providing virtual private network (VPN) sessions or other types of secure or private access to data when a client authorized to access the data travels or otherwise roams from a home network to a partner network is contemplated. The VPN session may be established as part of or as a result of an authentication process undertaken by the client when gaining access to the partner network, such as but not necessarily limited to a home network authentication process undertaken at the partner network to authenticate the client to access partner network services.