SIM-Based Access Control for Mobile Tethering Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current devices for accessing wide area networks via mobile communication networks, such as smartphones configured for connection sharing, have security vulnerabilities due to the potential for malicious software to circumvent access control mechanisms, particularly when using captive portals.

Innovation Solution

A device with a SIM card-based control module that implements secure authentication and data processing, using a TUN interface and RADIUS protocol to manage channel access, isolating the access controller from the operating system and ensuring authentication occurs within the secure SIM card environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If captive portal techniques are used for access control, then internet access can be monitored and authenticated, but security vulnerabilities arise due to malicious software that can circumvent the access controller

Engineering Contradiction:
Improveaccess control securityVSAvoidmalicious software exploits
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a TUN interface as an intermediary layer between the access controller and the network stack. This virtual network interface device mediates all network traffic, allowing the access controller to authenticate users through captive portals while the TUN interface ensures that all traffic passes through controlled channels. The intermediary structure prevents malicious software from directly accessing or bypassing the authentication mechanism, as all network communications must route through the TUN interface which enforces security policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the access controller is integrated into the operating system, then captive portal functionality can be implemented, but the system becomes vulnerable to software-based attacks

Engineering Contradiction:
Improvecaptive portal implementationVSAvoidauthentication security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the authentication system into distinct functional components: the access controller handles captive portal logic and user authentication, while the TUN interface manages network traffic control and security enforcement. This segmentation separates the authentication functionality from the operating system's core network stack, creating isolated security zones. The access controller can be updated or replaced without affecting the underlying OS, and the TUN interface provides a controlled boundary that prevents software attacks from compromising the authentication mechanism.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If wireless connection is used for tethering, then multiple devices can access internet and the device can be positioned for better reception, but security control over the connection channel becomes more difficult

Engineering Contradiction:
Improvewireless tethering capabilityVSAvoidconnection channel security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The TUN interface acts as a mediator that sits between the wireless network interface and the network stack, intercepting and controlling all traffic regardless of the connection type. Whether the device is connected via USB tethering or wireless WiFi/Bluetooth, the TUN interface ensures that all traffic passes through the authenticated channel. This intermediary structure maintains security control even when wireless connections are used, as the TUN interface enforces authentication policies at the network layer rather than relying on physical connection security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10602355B2Device for accessing a wide area network via a mobile communication network
Publication Date: 2020.03.24 ORANGE SA
  • US10602355B2 patent drawing
  • US10602355B2 patent drawing
  • US10602355B2 patent drawing

AI summary

A device for accessing a wide area network via a mobile communication network. The device includes a first connection module for connection to the mobile communication network, a second connection module suitable for generating a local network, a data processing module and a subscriber identification card. The data processing module is configured to connect the first and second connection modules via a channel. The subscriber identification card is configured to implement a control module suitable for controlling the use of the channel.