EP3554046A1

System and method for providing secure network access

Abstract

Secure network access is provided by connecting a secure network provisioning device to a security authority, acquiring one or more network profiles, configuring one or more network interfaces of the secure network provisioning device with data corresponding to attributes of the acquired network profiles, switching the secure network provisioning device from an acquisition mode to a gateway mode, and connecting the secure network provisioning device to a client device. The secure network provisioning device includes a first set of network communication interfaces requiring configuration blocks to enable access to associated networks, a second set of network communication interfaces free from a requirement for configuration prior to network access, a communication interface gateway module configured to gate network traffic between network communication interfaces and a network profile acquisition module configured to acquire network profiles containing data required to configure the communication interfaces of the first set.

EP3554046A1, drawing sheet 1
Sheet 1 of 9

Term

Term ended

Projected expiry passed 29 July 2025, 1.2 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

15 claims: 11 independent, 4 dependent

  1. 1
    A method of providing secure network access to a client device (206, 208, 210, 212) using a secure network provisioning device (214, 302, 702), the method comprising:connecting (404) the secure network provisioning device (214, 302, 702) to a security authority (704) while the secure network provisioning device (214, 302, 702) is in an acquisition mode;the secure network provisioning device (214, 302, 702), while in said acquisition mode, acquiring (406) at least one network profile (312) from the security authority (704);configuring (408) at least one network interface (304, 306) of the secure network provisioning device (214, 302, 702) with data corresponding to attributes of said at least one network profile (312);switching (410) the secure network provisioning device (214, 302, 702) from the acquisition mode to a gateway mode;connecting (412) the secure network provisioning device (214, 302, 702) to a client device (206, 208, 210, 212);and for each of said at least one network profile, providing the client device (206, 208, 210, 212) with access to a wireless access point (202, 204) of the secure network (200) associated with the network profile (312) through the secure network provisioning device (214, 302, 702), wherein the client device (206, 208, 210, 212) does not gain access to the at least one network profile (312).
  2. 4
    The method of any one of claims 1-3, wherein connecting (404) the secure network provisioning device (214, 302, 702) to the security authority (704) requires physical proximity of the secure network provisioning device (214, 302, 702) and the security authority (704).
  3. 5
    The method of any one of claims 1-4, wherein acquiring said at least one network profile (312) comprises engaging in a network profile (312) acquisition protocol between the security authority and the secure network provisioning device (214, 302, 702).
  4. 6
    The method of any one of claims 1-5, wherein access to the secure network (200) requires valid authentication credentials.
  5. 7
    The method of any one of claims 1-6, wherein the network profile (312) comprises the authentication credentials required to access the secure network (200).
  6. 8
    A computer-readable medium having thereon computer-executable instructions that, when executed by a processor, cause the processor to perform the method one of claims 1 to 7 .
  7. 9
    A secure network provisioning device (214, 302, 702) having an acquisition mode and a gateway mode, configured to:connect (404) to a security authority (704) while the secure network provisioning device (214, 302, 702) is in the acquisition mode;acquire (406), while in said acquisition mode, at least one network profile (312) from the security authority (704);configure (408) at least one network interface (304, 306) of the secure network provisioning device (214, 302, 702) with data corresponding to attributes of said at least one network profile (312) ;switch (410) from the acquisition mode to a gateway mode;connect (412) the secure network provisioning device (214, 302, 702) to a client device (206, 208, 210, 212);and provide the client device (206, 208, 210, 212) with access to a wireless access point (202, 204) of the secure network (200) associated with the network profile (312) through the secure network provisioning device (214, 302, 702), wherein the client device (206, 208, 210, 212) does not gain access to the at least one network profile (312).
  8. 12
    The system of any one of claims 9-11, wherein connecting (404) the secure network provisioning device (214, 302, 702) to the security authority (704) requires physical proximity of the secure network provisioning device (214, 302, 702) and the security authority (704).
  9. 13
    The system of any one of claims 9-12, wherein acquiring said at least one network profile (312) comprises engaging in a network profile (312) acquisition protocol between the security authority and the secure network provisioning device (214, 302, 702).
  10. 14
    The system of any one of claims 9-13, wherein access to the secure network (200) requires valid authentication credentials.
  11. 15
    The system of any one of claims 9-14, wherein the network profile (312) comprises the authentication credentials required to access the secure network (200).