SASE Gateway Client-less Connectivity Transition

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

SASE implementations face inefficiencies in access control due to reliance on software clients for remote access, particularly in mobile access and IoT endpoints, making client-based access control impractical.

Innovation Solution

A method and system for transitioning a wireless device between client-less and client-based connectivity using a SASE domain, where SIM-based authentication with an MNO provides a proxy of trust, allowing client-less devices to access the network through an MNO and SASE, with IP address and access ID mapping for secure connectivity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software clients are installed on devices to enable authentication to SASE, then security control is improved, but device complexity and ease of operation deteriorate due to installation and maintenance requirements

Engineering Contradiction:
Improvesecurity controlVSAvoidclient installation and maintenance
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a SASE gateway as an intermediary component that handles authentication and security functions centrally. Instead of requiring software clients on each device, the gateway acts as a mediator that processes authentication requests, manages device identities, and enforces security policies, thereby eliminating the need for complex client installations while maintaining security control

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts authentication and security management functions from individual devices and consolidates them into a centralized SASE gateway. By taking out the client software requirement from each device and centralizing these functions in the gateway, the system reduces device complexity while preserving security control through centralized management

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If software clients are installed on devices for SASE authentication, then access control is improved, but ease of operation worsens due to impracticality in mobile access and IoT endpoints

Engineering Contradiction:
Improveaccess controlVSAvoidmobile access and IoT connectivity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent creates a universal access mechanism through the SASE gateway that serves multiple device types (mobile devices, IoT endpoints, traditional devices) without requiring device-specific software clients. The gateway provides multi-functional authentication and access control capabilities that work across diverse platforms and device types, improving ease of operation while maintaining access control

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The SASE gateway serves as an intermediary that handles authentication for various device types without requiring software clients on the devices themselves. The gateway mediates between diverse devices (mobile, IoT, traditional) and the SASE network, providing universal access control that is easy to operate across all device types

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If SIM-based authentication with MNO is used for client-less connectivity, then ease of operation is improved, but device complexity increases due to dual connectivity management

Engineering Contradiction:
Improveclient-less connectivity setupVSAvoiddual connectivity management
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The SASE gateway acts as an intermediary that manages the complexity of dual connectivity (SIM-based and IP-based) on behalf of devices. The gateway handles the coordination between different connectivity modes, managing authentication and traffic routing, thereby improving ease of operation for devices while the gateway absorbs the management complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If IP address mapping is implemented for transitioning between connectivity modes, then adaptability is improved, but loss of information increases due to mapping overhead

Engineering Contradiction:
Improveconnectivity mode transitionVSAvoidmapping overhead
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The SASE gateway serves as an intermediary that manages IP address mapping and connectivity mode transitions. The gateway maintains the mapping information centrally and handles the translation between different connectivity modes (SIM-based to IP-based), thereby providing adaptability for mode transitions while the gateway absorbs the information management overhead rather than requiring it at the device level

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11622313B1Methods and systems for transitioning between client-less and client-based network connectivity to a secure access service edge (SASE) domain
Publication Date: 2023.04.04 VERSA NETWORKS
  • US11622313B1 patent drawing
  • US11622313B1 patent drawing
  • US11622313B1 patent drawing

AI summary

Method and systems for transitioning a wireless device between client-less connectivity and client-based connectivity are disclosed. In an embodiment, a method for transitioning a wireless device between client-less connectivity and client-based connectivity involves forwarding traffic from a wireless device through a SASE domain, receiving a request for information related to a SASE gateway in the SASE domain from the wireless device, transmitting information related to the SASE gateway from the SASE domain to the wireless device in response to the request, and transitioning the wireless device between client-less connectivity to the SASE gateway and client-based connectivity to the SASE gateway.