VPN Gateway Captive Portal Authentication via Dynamic Firewall Rules
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face challenges in securely accessing captive Wi-Fi networks for devices protected by virtual private network (VPN) gateways, as bypassing these gateways to interact with captive portals compromises security, and existing solutions do not effectively manage network traffic to allow secure Internet access while maintaining protection.
Innovation Solution
The proposed solution configures firewall rules of the VPN gateway to probe the captive network, discover the captive portal, redirect network traffic for authentication, and establish a VPN tunnel, minimizing exposure to public networks while ensuring secure access, using HTTP requests and AI-driven templates to manage access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the VPN gateway is bypassed to allow interaction with the captive portal, then network access to the captive network is achieved, but the security of the devices protected by the VPN gateway is lowered
Solution Approach 1:
The patent introduces a captive portal detection mechanism as an intermediary layer between the VPN gateway and the captive network. This mechanism detects captive portals and manages authentication requests without requiring complete bypass of the VPN gateway, thereby maintaining security while enabling network access. The intermediary handles the interaction with captive portals through controlled firewall rule modifications rather than full gateway bypass.
Solution Approach 2:
The patent implements dynamic firewall rule configuration that automatically adjusts network traffic handling based on detected captive portal conditions. The firewall rules are modified temporarily to allow captive portal authentication, then restored to maintain security. This dynamic adjustment enables the system to adapt between security and accessibility needs without permanent compromise.
2Reliability
If the VPN gateway strictly enforces security rules, then devices are protected from public network threats, but automatic authentication with captive portals cannot be performed
Solution Approach 1:
The patent enables the system to perform self-service authentication by automatically detecting captive portals and handling authentication requests without requiring manual user intervention. The VPN gateway itself performs the authentication sequence by dynamically modifying firewall rules to allow captive portal communication, then restoring security rules after authentication completes. This self-service approach maintains automation while preserving security.
Solution Approach 2:
The patent implements preliminary detection of captive portals before attempting VPN tunnel establishment. The system proactively identifies captive network conditions and prepares authentication sequences in advance, modifying firewall rules beforehand to enable automatic authentication. This preliminary action prevents authentication failures that would occur if strict security rules blocked captive portal communication.
3Ease of operation
If firewall rules are modified to allow captive portal access, then authentication is enabled, but the attackable surface area of the protected network increases
Solution Approach 1:
The patent applies local quality by making firewall rule modifications highly specific and targeted. Instead of broad rule changes that would open the entire network to attacks, the system modifies only the specific firewall rules necessary for captive portal authentication. The changes are localized to authentication traffic only, preserving security for all other network communications while enabling authentication capability.
Solution Approach 2:
The patent implements partial action by making minimal necessary modifications to firewall rules - only enough to allow captive portal authentication traffic. The system avoids excessive rule changes that would unnecessarily expand the attackable surface area. After authentication completes, the partial modifications are reverted, ensuring that only the minimum required change is applied temporarily.
Data Source
AI summary
An approach is proposed that contemplates system and method to configure firewall rules of a VPN gateway of a protected network so that users of devices in the protected network can access Internet securely via a captive network. First, the proposed approach enables the VPN gateway to probe the captive network with an HTTP request to discover a captive portal of the captive network. After the captive portal is discovered, one or more firewall rules of the VPN gateway are added so that network traffic from the devices in the protected network are redirected to the captive portal for authentication. Once the users are authenticated and a VPN tunnel is established between the VPN gateway and a remote VPN tunnel terminal, the firewall rules previously added are removed from the VPN gateway and all network traffic from the devices in the protected network are routed over the VPN tunnel.


