SASE Access via ISP IP Pool Mapping for Client-Less Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

SASE implementations relying on software clients for remote access can be inefficient and impractical due to the explosion in connected devices, making it difficult to determine trustworthiness of devices without clients.

Innovation Solution

Utilizing ISP authentication processes, such as PPPoE or DOCSIS connections, as a proxy of trust to establish access to SASE services for client-less devices by mapping IP addresses and access IDs to tiers of service, enabling secure network connectivity without client installation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software clients are installed on devices for SASE authentication, then security control and authentication capability are improved, but device complexity and deployment difficulty increase

Engineering Contradiction:
Improveauthentication capabilityVSAvoidclient installation requirement
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication function from the software client and relocates it to the network infrastructure level (ISP authentication system). Instead of requiring authentication software on each device, the system uses network-layer authentication mechanisms (PPPoE, DOCSIS) to verify device identity and grant access to SASE services, thereby eliminating the need for client installation while maintaining security control.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary authentication mechanism between the device and SASE service. The ISP authentication system acts as a mediator that verifies device credentials and establishes trust relationships, allowing devices to access SASE services without direct client-based authentication. This intermediary layer simplifies device requirements while preserving security enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If software clients are used for access control, then security enforcement is improved, but scalability and efficiency deteriorate due to explosion in connected devices

Engineering Contradiction:
Improvesecurity enforcementVSAvoidaccess efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent enables devices to access SASE services through self-service authentication mechanisms provided by the ISP infrastructure. Devices automatically authenticate using network-layer credentials (PPPoE usernames/passwords or DOCSIS certificates) without requiring manual client configuration or enrollment. This self-service approach at the network layer dramatically improves scalability for IoT and connected devices while maintaining security enforcement.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The ISP authentication system serves as an intermediary that handles authentication for大量 devices efficiently. By processing authentication at the network access layer rather than requiring device-level client software, the system can handle massive numbers of connected devices (including IoT) with standardized network protocols, improving access efficiency while preserving security control.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If trust verification is performed at device level, then security accuracy is improved, but system complexity and operational difficulty increase

Engineering Contradiction:
Improvetrust verification accuracyVSAvoidtrust determination complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts the trust verification function from the device level and relocates it to the network infrastructure level. Instead of devices performing complex self-assessment or client-based trust evaluation, the ISP authentication system performs trust verification at the network access layer using standardized protocols (PPPoE, DOCSIS), simplifying device requirements while maintaining verification accuracy.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system enables automatic trust verification through self-service authentication mechanisms. Devices present credentials to the ISP authentication system, which automatically verifies trust relationships and grants or denies access without requiring complex device-level trust assessment logic. This reduces device complexity while maintaining security accuracy.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12634261B2Methods and systems for providing network connectivity to a secure access service edge (SASE) domain via an ISP using IP pools
Publication Date: 2026.05.19 VERSA NETWORKS
  • US12634261B2 patent drawing
  • US12634261B2 patent drawing
  • US12634261B2 patent drawing

AI summary

Methods and system for providing network connectivity are disclosed. In an example, a method for providing network connectivity involves receiving from an Internet Service Provider (ISP) Internet Protocol (IP) address pool-to-tier mappings, generating an IP address-to-tier mapping at a Secure Access Service Edge (SASE) domain from the IP address pool-to-tier mappings, and forwarding traffic received at the SASE domain from a Broadband Network Gateway (BNG) of the ISP according to the IP address-to-tier mapping, wherein the traffic is received at the SASE domain from the BNG of the ISP only after access to the ISP is granted using an access ID.