Secure Tunnel Onboarding for Unauthenticated Client Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional BYOD device onboarding processes are cumbersome, requiring users to input credentials multiple times and rely on client-side applications that are platform-specific, leading to administrative overhead and potential unauthorized access to disallowed network resources.

Innovation Solution

The enhanced BYOD device onboarding process employs a secure tunnel using Tunnel Extensible Authentication Protocol (TEAP) and EAP-TLS, allowing security certificates and device configurations to be transmitted within the tunnel, eliminating the need for a captive portal and reducing administrative burden by allowing a single device enrollment process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a captive portal is used for BYOD device onboarding, then user authentication can be performed, but the process becomes cumbersome requiring multiple credential inputs and blocking access to network resources

Engineering Contradiction:
Improveauthentication securityVSAvoidonboarding process simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts the authentication and configuration delivery functions from the traditional captive portal framework. Instead of using a web-based captive portal that blocks access, the system uses a background authentication service that validates credentials and delivers configurations without interfering with normal network access, thus maintaining security while improving user experience

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a configuration delivery service as an intermediary between the authentication service and client devices. This mediator receives authenticated devices, delivers security configurations and certificates, and coordinates the onboarding process without requiring user interaction with a captive portal interface, thereby simplifying the process while maintaining reliable authentication

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If platform-specific client-side applications are deployed for device configuration, then authentication mechanisms can be enforced, but administrative overhead increases

Engineering Contradiction:
Improveauthentication mechanism enforcementVSAvoidadministrative overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal configuration delivery mechanism that works across multiple platforms without requiring platform-specific applications. The configuration delivery service communicates with diverse client devices through standard protocols, delivering authentication configurations and certificates in a platform-agnostic manner, thereby enforcing authentication mechanisms while reducing administrative overhead for managing multiple application deployments

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent replaces the mechanical approach of deploying and managing platform-specific client applications with a service-based approach. Instead of installing software agents on each device type, the system uses a network service that delivers configurations remotely, substituting the need for platform-specific mechanics with a universal service interface that achieves the same authentication enforcement goals

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Ease of operation

If security certificates are transmitted outside a secure tunnel, then device configuration can be delivered, but communication security is compromised

Engineering Contradiction:
Improveconfiguration deliveryVSAvoidcommunication security risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent establishes a secure tunnel using the TEAP authentication protocol before any configuration data or security certificates are transmitted. The tunnel is set up in advance during the authentication phase, creating an encrypted communication channel that protects subsequent configuration delivery, thus enabling secure configuration transmission without exposing communications to security risks

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11924195B2Onboarding an unauthenticated client device within a secure tunnel
Publication Date: 2024.03.05 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11924195B2 patent drawing
  • US11924195B2 patent drawing
  • US11924195B2 patent drawing

AI summary

Example method includes: establishing a secure tunnel with an unauthenticated client device associated with a user of a restricted network; receiving user credentials associated with the user and transmitted from the unauthenticated client device within the secure tunnel; validating the received user credentials; and transmitting at least a client certificate and device configuration information to the unauthenticated client device within the secure tunnel such that the unauthenticated client device is able to access the restricted network after installing the client certificate and applying the device configurations based on the received device configuration information.