SASE Gateway Client-less Connectivity Transition
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
SASE implementations face inefficiencies in access control due to reliance on software clients for remote access, particularly in mobile access and IoT endpoints, making client-based access control impractical.
Innovation Solution
A method and system for transitioning a wireless device between client-less and client-based connectivity using a SASE domain, where SIM-based authentication with an MNO provides a proxy of trust, allowing client-less devices to access the network through an MNO and SASE, with IP address and access ID mapping for secure connectivity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If software clients are installed on devices to enable authentication to SASE, then security control is improved, but device complexity and ease of operation deteriorate due to installation and maintenance requirements
Solution Approach 1:
The patent introduces a SASE gateway as an intermediary component that handles authentication and security functions centrally. Instead of requiring software clients on each device, the gateway acts as a mediator that processes authentication requests, manages device identities, and enforces security policies, thereby eliminating the need for complex client installations while maintaining security control
Solution Approach 2:
The patent extracts authentication and security management functions from individual devices and consolidates them into a centralized SASE gateway. By taking out the client software requirement from each device and centralizing these functions in the gateway, the system reduces device complexity while preserving security control through centralized management
2Reliability
If software clients are installed on devices for SASE authentication, then access control is improved, but ease of operation worsens due to impracticality in mobile access and IoT endpoints
Solution Approach 1:
The patent creates a universal access mechanism through the SASE gateway that serves multiple device types (mobile devices, IoT endpoints, traditional devices) without requiring device-specific software clients. The gateway provides multi-functional authentication and access control capabilities that work across diverse platforms and device types, improving ease of operation while maintaining access control
Solution Approach 2:
The SASE gateway serves as an intermediary that handles authentication for various device types without requiring software clients on the devices themselves. The gateway mediates between diverse devices (mobile, IoT, traditional) and the SASE network, providing universal access control that is easy to operate across all device types
3Ease of operation
If SIM-based authentication with MNO is used for client-less connectivity, then ease of operation is improved, but device complexity increases due to dual connectivity management
Solution Approach 1:
The SASE gateway acts as an intermediary that manages the complexity of dual connectivity (SIM-based and IP-based) on behalf of devices. The gateway handles the coordination between different connectivity modes, managing authentication and traffic routing, thereby improving ease of operation for devices while the gateway absorbs the management complexity
4Adaptability or versatility
If IP address mapping is implemented for transitioning between connectivity modes, then adaptability is improved, but loss of information increases due to mapping overhead
Solution Approach 1:
The SASE gateway serves as an intermediary that manages IP address mapping and connectivity mode transitions. The gateway maintains the mapping information centrally and handles the translation between different connectivity modes (SIM-based to IP-based), thereby providing adaptability for mode transitions while the gateway absorbs the information management overhead rather than requiring it at the device level
Data Source
AI summary
Method and systems for transitioning a wireless device between client-less connectivity and client-based connectivity are disclosed. In an embodiment, a method for transitioning a wireless device between client-less connectivity and client-based connectivity involves forwarding traffic from a wireless device through a SASE domain, receiving a request for information related to a SASE gateway in the SASE domain from the wireless device, transmitting information related to the SASE gateway from the SASE domain to the wireless device in response to the request, and transitioning the wireless device between client-less connectivity to the SASE gateway and client-based connectivity to the SASE gateway.


