Secure Tunnel Onboarding for Unauthenticated Client Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional BYOD device onboarding processes are cumbersome, requiring users to input credentials multiple times and rely on client-side applications that are platform-specific, leading to administrative overhead and potential unauthorized access to disallowed network resources.
Innovation Solution
The enhanced BYOD device onboarding process employs a secure tunnel using Tunnel Extensible Authentication Protocol (TEAP) and EAP-TLS, allowing security certificates and device configurations to be transmitted within the tunnel, eliminating the need for a captive portal and reducing administrative burden by allowing a single device enrollment process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a captive portal is used for BYOD device onboarding, then user authentication can be performed, but the process becomes cumbersome requiring multiple credential inputs and blocking access to network resources
Solution Approach 1:
The patent extracts the authentication and configuration delivery functions from the traditional captive portal framework. Instead of using a web-based captive portal that blocks access, the system uses a background authentication service that validates credentials and delivers configurations without interfering with normal network access, thus maintaining security while improving user experience
Solution Approach 2:
The patent introduces a configuration delivery service as an intermediary between the authentication service and client devices. This mediator receives authenticated devices, delivers security configurations and certificates, and coordinates the onboarding process without requiring user interaction with a captive portal interface, thereby simplifying the process while maintaining reliable authentication
2Reliability
If platform-specific client-side applications are deployed for device configuration, then authentication mechanisms can be enforced, but administrative overhead increases
Solution Approach 1:
The patent implements a universal configuration delivery mechanism that works across multiple platforms without requiring platform-specific applications. The configuration delivery service communicates with diverse client devices through standard protocols, delivering authentication configurations and certificates in a platform-agnostic manner, thereby enforcing authentication mechanisms while reducing administrative overhead for managing multiple application deployments
Solution Approach 2:
The patent replaces the mechanical approach of deploying and managing platform-specific client applications with a service-based approach. Instead of installing software agents on each device type, the system uses a network service that delivers configurations remotely, substituting the need for platform-specific mechanics with a universal service interface that achieves the same authentication enforcement goals
3Ease of operation
If security certificates are transmitted outside a secure tunnel, then device configuration can be delivered, but communication security is compromised
Solution Approach 1:
The patent establishes a secure tunnel using the TEAP authentication protocol before any configuration data or security certificates are transmitted. The tunnel is set up in advance during the authentication phase, creating an encrypted communication channel that protects subsequent configuration delivery, thus enabling secure configuration transmission without exposing communications to security risks
Data Source
AI summary
Example method includes: establishing a secure tunnel with an unauthenticated client device associated with a user of a restricted network; receiving user credentials associated with the user and transmitted from the unauthenticated client device within the secure tunnel; validating the received user credentials; and transmitting at least a client certificate and device configuration information to the unauthenticated client device within the secure tunnel such that the unauthenticated client device is able to access the restricted network after installing the client certificate and applying the device configurations based on the received device configuration information.


