SASE Domain Network Connectivity via MNO Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

SASE implementations face inefficiencies in access control due to reliance on software clients for remote access, which becomes impractical with the rise of mobile access and IoT endpoints, especially in determining trustworthiness of devices without SASE clients.

Innovation Solution

The method involves using Mobile Network Operators (MNOs) to provide access IDs and IP addresses to the SASE domain, leveraging SIM-based or non-SIM-based authentication to create a trusted relationship, allowing client-less devices to access the network by generating IP address-to-tenant mappings and forwarding traffic accordingly.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software clients are installed on devices to enable remote access to SASE, then authentication and security control are improved, but device complexity and ease of operation deteriorate due to installation and maintenance requirements

Engineering Contradiction:
Improveauthentication securityVSAvoidclient installation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication function from the device side (software client) and relocates it to the network side (MNO core network). The MNO's AAA server handles authentication, authorization, and accounting functions, eliminating the need for SASE clients on endpoints while maintaining security control through network-based policies.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The MNO's core network infrastructure is leveraged to provide multi-functional services including authentication, authorization, accounting, and SASE policy enforcement. This universal platform serves multiple purposes: mobile network access control and enterprise SASE security, eliminating the need for separate client software on devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If software clients are required for SASE access control, then security management is improved, but scalability and ease of operation worsen with the explosion of IoT endpoints

Engineering Contradiction:
Improveaccess control securityVSAvoidaccess control scalability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Devices obtain SASE access automatically through the MNO's existing authentication infrastructure without manual client installation or configuration. The MNO's AAA server automatically authenticates devices and enforces SASE policies based on device identity and network location, enabling self-service access for IoT endpoints and mobile devices alike.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The MNO's core network infrastructure serves as a universal authentication platform for both traditional mobile devices and IoT endpoints. The same AAA server and policy framework that manage mobile subscriber access also enforce SASE security policies, providing scalable access control across diverse device types without requiring device-specific clients.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If MNO authentication is used as a proxy of trust for SASE access, then ease of operation and scalability are improved, but device complexity and authentication reliability may worsen without proper trust establishment

Engineering Contradiction:
Improveaccess simplicityVSAvoidtrust establishment reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The MNO's AAA server acts as an intermediary between the device and the SASE policy enforcement point. It receives authentication requests from devices, verifies credentials against the MNO's subscriber database, and forwards authorization decisions to the SASE gateway. This intermediary role establishes a chain of trust where the SASE domain relies on the MNO's proven authentication capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The MNO performs preliminary authentication and trust establishment before the device attempts to access the SASE domain. The AAA server pre--authenticates devices using MNO credentials, establishes their identity, and prepares authorization contexts in advance. This preliminary action ensures that when devices reach the SASE gateway, trust is already established, simplifying the access process while maintaining reliability.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11812520B2Methods and systems for providing network connectivity to a secure access service edge (SASE) domain
Publication Date: 2023.11.07 VERSA NETWORKS
  • US11812520B2 patent drawing
  • US11812520B2 patent drawing
  • US11812520B2 patent drawing

AI summary

Methods and system for providing network connectivity are disclosed. In an embodiment, a method for providing network connectivity involves receiving from a Mobile Network Operator (MNO) an access ID and an IP address at a SASE domain, wherein the access ID and the IP address correspond to a wireless device, generating an IP address-to-tenant mapping at the SASE domain by applying the access ID and the IP address to an access ID-to-tenant mapping, and forwarding traffic received at the SASE domain from the wireless device via the MNO according to the IP address-to-tenant mapping.