SASE Domain Network Connectivity via MNO Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
SASE implementations face inefficiencies in access control due to reliance on software clients for remote access, which becomes impractical with the rise of mobile access and IoT endpoints, especially in determining trustworthiness of devices without SASE clients.
Innovation Solution
The method involves using Mobile Network Operators (MNOs) to provide access IDs and IP addresses to the SASE domain, leveraging SIM-based or non-SIM-based authentication to create a trusted relationship, allowing client-less devices to access the network by generating IP address-to-tenant mappings and forwarding traffic accordingly.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If software clients are installed on devices to enable remote access to SASE, then authentication and security control are improved, but device complexity and ease of operation deteriorate due to installation and maintenance requirements
Solution Approach 1:
The patent extracts the authentication function from the device side (software client) and relocates it to the network side (MNO core network). The MNO's AAA server handles authentication, authorization, and accounting functions, eliminating the need for SASE clients on endpoints while maintaining security control through network-based policies.
Solution Approach 2:
The MNO's core network infrastructure is leveraged to provide multi-functional services including authentication, authorization, accounting, and SASE policy enforcement. This universal platform serves multiple purposes: mobile network access control and enterprise SASE security, eliminating the need for separate client software on devices.
2Reliability
If software clients are required for SASE access control, then security management is improved, but scalability and ease of operation worsen with the explosion of IoT endpoints
Solution Approach 1:
Devices obtain SASE access automatically through the MNO's existing authentication infrastructure without manual client installation or configuration. The MNO's AAA server automatically authenticates devices and enforces SASE policies based on device identity and network location, enabling self-service access for IoT endpoints and mobile devices alike.
Solution Approach 2:
The MNO's core network infrastructure serves as a universal authentication platform for both traditional mobile devices and IoT endpoints. The same AAA server and policy framework that manage mobile subscriber access also enforce SASE security policies, providing scalable access control across diverse device types without requiring device-specific clients.
3Ease of operation
If MNO authentication is used as a proxy of trust for SASE access, then ease of operation and scalability are improved, but device complexity and authentication reliability may worsen without proper trust establishment
Solution Approach 1:
The MNO's AAA server acts as an intermediary between the device and the SASE policy enforcement point. It receives authentication requests from devices, verifies credentials against the MNO's subscriber database, and forwards authorization decisions to the SASE gateway. This intermediary role establishes a chain of trust where the SASE domain relies on the MNO's proven authentication capabilities.
Solution Approach 2:
The MNO performs preliminary authentication and trust establishment before the device attempts to access the SASE domain. The AAA server pre--authenticates devices using MNO credentials, establishes their identity, and prepares authorization contexts in advance. This preliminary action ensures that when devices reach the SASE gateway, trust is already established, simplifying the access process while maintaining reliability.
Data Source
AI summary
Methods and system for providing network connectivity are disclosed. In an embodiment, a method for providing network connectivity involves receiving from a Mobile Network Operator (MNO) an access ID and an IP address at a SASE domain, wherein the access ID and the IP address correspond to a wireless device, generating an IP address-to-tenant mapping at the SASE domain by applying the access ID and the IP address to an access ID-to-tenant mapping, and forwarding traffic received at the SASE domain from the wireless device via the MNO according to the IP address-to-tenant mapping.


