Virtual Device with Internet Protocol Security Tunnel
An electronic device that establishes one or more Internet Protocol Security (IPSec) tunnels with an Evolved Packet Core (EPC) for another electronic device is described. In particular, the electronic device may receive, from the other electronic device, Extensible Authentication Protocol (EAP) information using a wireless local area network (WLAN) communication protocol, where the EAP information includes credentials used by the EPC to authenticate the other electronic device. Then, the electronic device may establish, with the EPC, one or more IPSec tunnels on behalf of the other electronic device using a wired communication protocol, where the one or more IPSec tunnels originate and terminate at the electronic device. Next, the electronic device may communicate encrypted information with the other electronic device using the WLAN communication protocol, where the encrypted information is encrypted using a different encryption protocol than IPSec.
1 . An electronic device, comprising:
a node configured to couple to an antenna; and
an interface circuit, coupled to the node, configured to communicate with another electronic device using a wireless local area network (WLAN) communication protocol and an Evolved Packet Core (EPC) via a wired communication protocol, wherein the electronic device is configured to:
receive, at the interface circuit, Extensible Authentication Protocol (EAP) information using the WLAN communication protocol, wherein the EAP information includes credentials for authenticating the other electronic device to the EPC;
establish, via the interface circuit, one or more Internet Protocol Security (IPSec) tunnels associated with the EPC on behalf of the other electronic device using the wired communication protocol, wherein the one or more IPSec tunnels originate and terminate at the electronic device; and
communicate, via the interface circuit, encrypted information associated with the other electronic device using the WLAN communication protocol, wherein the encrypted information is encrypted using a different encryption protocol than IPSec.
2 . The electronic device of claim 1 , wherein the WLAN communication protocol comprises Wi-Fi.
3 . The electronic device of claim 1 , wherein the electronic device comprises a network function other than an access point.
4 . The electronic device of claim 1 , wherein the electronic device comprises a router.
5 . The electronic device of claim 1 , wherein the electronic device is configured to advertise, via the interface circuit, information for the other electronic device that indicates a capability to establish the one or more IPSec tunnels.
6 . The electronic device of claim 1 , wherein, prior to receiving the EAP information, the electronic device is configured to associate, via the interface circuit and using the WLAN communication protocol, with the other electronic device.
7 . The electronic device of claim 1 , wherein the encrypted information excludes a second encryption technique associated with the one or more IPSec tunnels.
8 . The electronic device of claim 1 , wherein, when communicating, via the interface circuit, a packet associated with the EPC using the one or more IPSec tunnels, the electronic device is configured to include an access point name (APN) in the packet.
9 . The electronic device of claim 1 , wherein the electronic device is configured to receive, via the interface circuit, a set of APNs associated with the electronic device and associated with different types of information; and
wherein, when communicating, via the interface circuit, a packet having a type of information that is associated with the EPC using the one or more IPSec tunnels, the electronic device is configured to select an APN associated with the type of information and to include the APN in the packet.
10 . The electronic device of claim 1 , wherein the encrypted information comprises Dynamic Host Configuration Protocol (DHCP) information associated with the EPC.
11 . The electronic device of claim 1 , wherein the credentials in the EAP information are encrypted.
12 . The electronic device of claim 1 , wherein the electronic device further comprises:
a processor; and
a memory, coupled to the processor, which stores a program module, wherein, when executed by the processor, the program module causes the electronic device to perform at least one of: the receiving, the establishing, and the communicating.
13 . A non-transitory computer-readable storage medium for use in conjunction with an electronic device, the computer-readable storage medium storing a program module, wherein, when executed by the electronic device, the program module causes the electronic device establish one or more Internet Protocol Security (IPSec) tunnels with an Evolved Packet Core (EPC) for another electronic device by performing one or more operations, comprising:
receiving, at an interface circuit in the electronic device, Extensible Authentication Protocol (EAP) information using a wireless local area network (WLAN) communication protocol, wherein the EAP information includes credentials for authenticating the other electronic device to the EPC;
establishing, via the interface circuit, the one or more Internet Protocol Security (IPSec) tunnels associated with the EPC on behalf of the other electronic device using a wired communication protocol, wherein the one or more IPSec tunnels originate and terminate at the electronic device; and
communicating, via the interface circuit, encrypted information associated with the other electronic device using the WLAN communication protocol, wherein the encrypted information is encrypted using a different encryption protocol than IPSec.
14 . The computer-readable storage medium of claim 13 , wherein the electronic device comprises a network function other than an access point.
15 . The computer-readable storage medium of claim 13 , wherein the one or more operations comprise advertising, via the interface circuit, information for the other electronic device that indicates a capability to establish the one or more IPSec tunnels.
16 . The computer-readable storage medium of claim 13 , wherein, prior to receiving the EAP information, the one or more operations comprise associate, via the interface circuit and using the WLAN communication protocol, with the other electronic device.
17 . The computer-readable storage medium of claim 13 , wherein the encrypted information excludes a second encryption technique associated with the one or more IPSec tunnels.
18 . The computer-readable storage medium of claim 13 , wherein, when communicating, via the interface circuit, a packet associated with the EPC using the one or more IPSec tunnels, the one or more operations comprise including an access point name (APN) in the packet.
19 . A method for establishing one or more Internet Protocol Security (IPSec) tunnels with an Evolved Packet Core (EPC) for another electronic device, comprising:
by an electronic device:
receiving, at the electronic device, Extensible Authentication Protocol (EAP) information using a wireless local area network (WLAN) communication protocol, wherein the EAP information includes credentials for authenticating the other electronic device to the EPC;
establishing the one or more Internet Protocol Security (IPSec) tunnels associated with the EPC on behalf of the other electronic device using a wired communication protocol, wherein the one or more IPSec tunnels originate and terminate at the electronic device; and
communicating encrypted information associated with the other electronic device using the WLAN communication protocol, wherein the encrypted information is encrypted using a different encryption protocol than IPSec.
20 . The method of claim 19 , wherein, when communicating a packet associated with the EPC using the one or more IPSec tunnels, the method comprises including an access point name (APN) in the packet.