Management of network intercept portals for network devices with durable and non-durable identifiers

A network management system using persistent and non-persistent identifiers enforces captive portals for additional authentication, addressing HS2.0 limitations, ensuring seamless and secure network access with enhanced user interaction.

JP2025169415APending Publication Date: 2025-11-12NOMADIX INC
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
JP2025139553
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2020-02-21
Filing Date
2025-08-25
Publication Date
2025-11-12

AI Technical Summary

Technical Problem

Existing network management systems face challenges in implementing captive portals with Hotspot 2.0 (HS2.0) protocols, as most devices do not support the new Release 3 features, leading to incomplete authentication and venue-specific commands, such as accepting terms of use or correcting declined payments, which are necessary for network access.

Method used

A network management system that utilizes persistent and non-persistent identifiers to manage user devices, directing them to captive portals for additional authentication or input requirements, even when HS2.0 authentication is successful, by integrating with RADIUS servers and cloud network management servers to enforce additional user interactions.

Benefits of technology

Ensures seamless and secure network access by enforcing additional authentication or venue-specific commands, even for devices that do not fully support HS2.0 Release 3 features, enhancing user interaction and network management capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025169415000001_ABST
    Figure 2025169415000001_ABST
Patent Text Reader

Abstract

To provide management of network intercept portals for network devices with durable and non-durable identifiers.SOLUTION: Durable and non-durable identifiers of a user device are utilized to authenticate the user device to cause the user device to be directed to a network intercept portal or captive portal to the user device based on whether additional user input is needed from the user device. A cloud network management server identifies a user device based on a previously stored association between a durable identifier associated with the user device and a non-durable identifier associated with the user device. The user device may be redirected to a network intercept portal or captive portal to obtain the additional user input requested by the cloud network management server.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] TECHNICAL FIELD The present disclosure relates to the field of providing computer network access. [Background technology]

[0002] Network management systems may be used to provide access to a network, such as the Internet, for multiple users. Several types of network management systems may be used to provide access to multiple users and their corresponding network-enabled user devices. Network management systems may be used to control Internet access in public and private venues. At a given time, a network management system may manage hundreds or thousands of user devices requesting content from the Internet.

[0003] The embodiments described herein are illustrated by way of example, and not limitation, in the figures of the accompanying drawings in which like reference numerals indicate similar elements and in which: [Brief explanation of the drawings]

[0004] [Figure 1] 1 illustrates a network implementation according to an aspect of the present disclosure. [Figure 2] 1 illustrates a cross section of various access points in a multiple dwelling unit (MDU) context in accordance with aspects of the present disclosure. [Figure 3] 1 illustrates a network environment including a network management system for connecting user devices to an external network according to an aspect of the present disclosure. [Figure 4] 1 illustrates a workflow for performing an in-band portal authentication method according to an aspect of the present disclosure. [Figure 5] 1 illustrates an example of an in-band portal authentication method according to an aspect of the present disclosure. [Figure 6] 1 illustrates a workflow for performing an out-of-band portal authentication method according to an aspect of the present disclosure. [Figure 7]1 illustrates an example of an out-of-band portal authentication method according to an aspect of the present disclosure. [Figure 8] 1 illustrates a network environment and workflow for extending the Hotspot 2.0 specification according to an aspect of the present disclosure. [Figure 9] 1 illustrates a flow of communication through a gateway device according to an aspect of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION

[0005] <Introduction> A typical network management system can receive network access parameters such as bandwidth, policies, and captive portal URLs from an upstream RADIUS (Remote Authentication Dial-In User Service) server. On the other hand, with Hotspot ("HS") 2.0 (EAP-SIM / AKA, EAP-TTLS, EAP-TLS, or any other secure 802.1x authentication method), a user's device is authenticated by upstream RADIUS and then continues to connect and use Wi-Fi® seamlessly and securely without a captive portal. With HS2.0 / EAP-SIM / AKA / TTLS / TLS, there is no current mechanism for enabling a captive portal. However, there may be reasons to implement a captive portal with the HS2.0 protocol, as discussed below.

[0006] The Wi-Fi Alliance recently released a new HS2.0 specification ("Release 3"), which is incorporated herein by reference in its entirety. This new release includes three new ANQP (Access Network Query Protocol) elements: Operator Icon Metadata, Venue URL, and Advice of Charge. The Venue URL element allows for the display of custom venue information on a user device. The manner of display is operator and implementation dependent. This element identifies a URL, and the network resource (e.g., a web page) at that URL can be displayed following a user request or proactively when the device makes another ANQP request. Release 3 also includes network subscription repair, which can include the process of correcting a subscriber's network subscription problem. This can include providing new credentials to the mobile device (e.g., due to expiration), updating the Per Provider Subscription (PPS) managed object (MO) on the mobile device (e.g., because data needs to be refreshed), or performing online functions to renew the network subscription.

[0007] A venue URL is similar to a captive portal, except that the user is not actually captive. A venue URL is a web page that pops up on the user's device for a few seconds displaying a remote URL. The user can ignore the action requested by the URL and continue accessing the network. This URL is provided by upstream RADIUS in a vendor-specific attribute (VSA) so it can be remotely controlled at the site-wide access point or individual device level. This allows large venues (such as conference centers or hotels) that may have different messaging requirements in different areas (e.g., gym, restaurant, public area / reception, guest rooms) to inject different messages. Thus, instead of having a traditional captive portal where users must register their email and room number or other items, a network management device or system can provide a message on the user's screen when they unlock their user device. In some cases, a venue URL can be used to enable a captive portal.

[0008] Hotspot 2.0 is a complex specification. Most device manufacturers have not implemented the complete specification. Therefore, not all user or operator devices may support Release 3 features, such as HS2.0 venueURL. Therefore, HS2.0 without Release 3 features may not be able to perform additional authentication or venue-specific commands. For example, venue-specific commands may include accepting terms of use, correcting a declined payment, or other use cases where the network provider requires the user to browse and interact with a web portal to provide one or more additional inputs. In some cases, additional authentication may be required on top of HS2.0 authentication. The additional authentication may be based on a loyalty program. Therefore, some of these features must be implemented in conjunction with the HS2.0 protocol.

[0009] These and other aspects of the present disclosure will now be described with reference to certain examples and implementations, which are intended to illustrate, not limit, the present disclosure. While the examples and implementations described herein focus on particular calculations and algorithms for purposes of illustration, those skilled in the art will understand that the examples are illustrative only and are not intended to be limiting.

[0010] <Network Access System> FIG. 1 illustrates an implementation of a network access system that may be used to implement one or more of the techniques described herein. The system includes various user devices 141, 143, 145, 147, 149, 151, 153, and 155. The user devices may include, for example, laptops, desktop computers, smartphones, PDAs, and any other wired or wireless network-enabled communication devices. The user devices 141, 143, 145, 147, 149, 151, 153, and 155 communicate with access points 121, 123, 125, 127, and 129. The access points 121, 123, 125, 127, and 129 provide wired or wireless communication with a network management device 103. The network management device 103 controls network communication between the access points and between the access points and the network 101. In some implementations, the network management device 103 is operated by a single entity. In one implementation, the network management device 103 creates a single network. Optionally, intermediate network devices 105, including, for example, routers, switches, hubs, repeaters, etc., may also be used to help provide communications between the access points 121, 123, 125, 127 and the network management device 103. The network 101 may be, for example, a public network such as the Internet. The network management device 103 (also referred to herein as a network management system) may include a network gateway, such as, for example, a network access gateway commercially available from Nomadix, Inc. of Woodland Hills, California. As will be appreciated by those skilled in the art from this disclosure, other network management devices may also be used.

[0011] Devices are typically programmed to automatically select between access points by, for example, determining which access point provides the strongest signal. A device may be between three different access points and be able to communicate with all of them, but ultimately choose one access point to communicate with. In some cases, an access point will not allow a device to communicate through that access point, in which case the user device attempts to communicate with another access point. For example, a user device may have the strongest signal with access point A but may only be authenticated with access point B. In this case, the user device communicates with access point B despite its weaker signal. It will be appreciated that a user device can be configured to select an access point based on any number of different selection options, including, for example, signal strength, bandwidth availability, access rights, access points corresponding to a particular SSID, etc. When an access point is out of range, the user device loses communication with that access point and attempts to discover another access point. In one implementation, switching between access points is seamless, e.g., there is no loss of network session, and the user may not even be aware that they have switched access points.

[0012] As shown in Figure 1, the network includes multiple physical areas, including apartment lobbies 107, apartment business centers 109, and apartment units 111. Although not shown in Figure 1, the network may include additional apartment lobbies, apartment business centers, and / or apartment units. Each physical area may include one or more access points. In some cases, two or more physical areas may share an access point.

[0013] In some implementations, access points announce their presence by broadcasting a service set identifier (SSID), extended service set identifier (ESSID), and / or basic service set identifier (BSSID), collectively referred to herein as SSID. In some implementations, the same SSID is assigned to all access points in a network. In other implementations, a different SSID is assigned to each access point or group of access points (or to each region or group of regions) in the network. In still other implementations, multiple SSIDs may be assigned to the same set of access points. In this regard, virtual SSIDs corresponding to different groupings of access points may be established. The network management device 103 may provide different levels of service to different users across multiple SSIDs or across the same SSID based on the user's pre-shared key (e.g., Wi-Fi password) and / or based on persistent and / or non-persistent identifiers associated with the user's user device, such as a MAC address and / or a user profile (or one or more parameters included in the user profile) stored on the user device.

[0014] <Level of service> Because the bandwidth accessed by all users can be centrally managed (e.g., by a wireless controller or wireless PSK manager described herein), bandwidth limits can be set per user, per device, or per user type (e.g., resident or guest) regardless of the number of devices each subscriber may have. In one implementation, within a single SSID network, persistent and / or non-persistent identifiers associated with users or user devices can be assigned different levels of bandwidth (minimum and / or maximum), different levels of service, and / or different levels of access priority. For example, within a single SSID network, each hotel room can be assigned one or more Wi-Fi passwords and / or login credentials, and the assigned Wi-Fi passwords and / or login credentials can have different levels of bandwidth (minimum and / or maximum), different levels of service, and / or different levels of access priority (e.g., basic room vs. club-level room, room-only access vs. property-wide access, etc.).

[0015] <Multiple housing units (MDU)> FIG. 2 illustrates a cross-section of various access points in the context of an MDU. Dormitory 201 includes rooms 203, conference rooms 205, restaurant 207, and lobby 209. Rooms 203, conference rooms 205, restaurant 207, and lobby 209 include various access points 221. While illustrated as having one or more access points in each room, it should be understood that fewer or more access points can be used. For example, in one implementation, a single access point can be used for multiple rooms. As will also be understood by those skilled in the art, various types of facilities will benefit from the present disclosure. For example, while described primarily with respect to dormitories, other facilities including apartment complexes, schools, colleges, universities, hospitals, hotels, government buildings, businesses, or any other public or private networking system can use the present network management system.

[0016] <Network Management System> FIG. 3 illustrates one embodiment of a networking system 300 including a network management system 120 for managing connections between user devices 110 on an internal network 104 and an external network 140, such as the Internet. The network management system 120 may include multiple hardware components. For example, the network management system 120 may include network interfaces 122, 124 for receiving and transmitting network packets between the internal network and the external network. The size of the network packets may depend on the protocol or type of data carried by the network packets. The network management system 120 may include an antenna 130 for receiving and transmitting data over a wireless network. The network management system 120 may include a memory 126 for storing packets and programming instructions that may be executed by a hardware processor 128. In some embodiments, the instructions may be stored in the internal memory of the hardware processor 128. Although a single block is shown, the network management system 120 may include multiple hardware devices. In some embodiments, the network management system 120 may include a network gateway. The network management system 120 may also include one or more access points.

[0017] User and user device may be used interchangeably herein. A user may have one or more user devices associated with them. A user may use a user device to request a connection to an external network. A user device may include a unique ID (such as a MAC address number or SIM card number). Furthermore, a user or user device may also be identified based on a membership ID, a login ID, credit card information, or any other identification parameter.

[0018] Network environment 300 may also include a venue system 150, an authentication, authorization, and accounting (AAA) / RADIUS system 160, and a cloud network management server 170. Venue system 150 may include computing systems associated with a venue to which a user is requesting network access from their user device. In one embodiment, venue system 150 may include a venue management system.

[0019] The AAA / RADIUS system 160 (also referred to herein as a RADIUS server) provides centralized authentication, authorization, and accounting (AAA) management for users connecting to and using network services. Additional information regarding RADIUS and AAA protocols is provided in "Understanding RADIUS," Cisco publication June 29, 2007, which is incorporated herein by reference in its entirety.

[0020] Cloud network management server 170 provides cloud solutions that give service providers (e.g., hotel owners, brands, managed service providers, etc.) greater control and visibility of their network capabilities and performance. For example, cloud network management server 170 may provide a wide range of network management tools, including, for example, a guest high-speed internet access (HSIA) portal, management and reporting capabilities, a conference room scheduler, and network management devices (also referred to herein as gateways, Nomadix Service Engines, or NSEs). Cloud network management server 170 may also provide a full range of access plans and authentication types with Passpoint® (also known as Hotspot 2.0). Although HS2.0 is used herein as an example, the techniques described herein can be applied to other standards or protocols.

[0021] The AAA / RADIUS system 160, cloud network management server 170, and / or venue system 150 may contain information about users and / or their user devices that may be used by the control system to determine whether to grant network access and / or how available bandwidth should be shared among users and / or user devices. This information may include loyalty points, class assignments, credit cards, user preferences, login information, etc.

[0022] <Example workflow for in-band portal authentication method> 4 illustrates a workflow for performing an in-band portal authentication method according to an aspect of the present disclosure. At (1), a user device 402 connects to an access point / controller (also referred to herein as an AP) 404. At (2), the AP 404 sends an access request to a network management device (NSE) 406. At (3), the network management device 406 sends a proxy access request to a RADIUS server 408 (e.g., on behalf of the AP 404). At (4), the RADIUS server 408 decrypts the EAP-TTLS message. At (5), the RADIUS server 408 sends a RADIUS authentication request to a network management server 410. At (6), the network management server 410 returns a success message to the RADIUS server 408 and indicates to the RADIUS server 408 that additional user input is required before the user device 402 can be granted network access. At (7), the RADIUS server 408 forwards an indication from the network management server 410 that the requested access is permitted but that additional user input is required.

[0023] At (8), the network management device 406 sends a message to the AP 404 indicating that the requested access is permitted, but does not indicate that additional input is required. At (9), the AP 404 assumes that the user device 402 is permitted network access and sends an Accounting-Start request to the network management device 406 to be forwarded to the RADIUS server 408. For example, the Accounting-Start request packet may include the user ID, access point, and network address, as well as a unique session identifier. At (10), the network management device 406 drops the Accounting-Start request and does not forward it to the RADIUS server 408. At (11.1), the user device 402 accesses a network resource, and at (11.2), the network management device 406 brings the user device 402 to another network resource different from the one requested by the user device 402 (e.g., a captive portal configured to receive additional user input required to be permitted network access).

[0024] At (12), the user device 402 provides additional user input requested by the network management server 410, and at (13), the user completes the captive portal. At (14), the network management server 410 sends an HTTP 200 OK success status response to the user device 402 and at (15), sends a message to the network management device 406 indicating that the user's RADIUS session should be modified (e.g., so that the user is no longer redirected to the captive portal). In response, at (16), the network management device 406 enables Internet access for the user device 402. At (17), the network management device 406 sends an accounting-start request to the RADIUS server 408, and at (18), the RADIUS server 408 sends a RADIUS accounting-start message to the network management server 410. At (19), the AP 404 sends an accounting-stop request to the network management device 406 indicating that the connection to the user device 402 is being terminated. At (20), the network management server 406 sends a proxy accounting stop request to the RADIUS server 408 on behalf of the AP 404.

[0025] Although not shown in FIG. 4, in response to (5) and / or (12), the network management server 410 may check the stored association to identify the user device 402 using a non-persistent identifier (e.g., a randomized MAC address) of the user device 406, determine whether the user device 402 meets all requirements to be granted the authentication or network access request, and respond to the RADIUS server 408 or other component based on that determination.

[0026] <In-band portal authentication method> Referring now to FIG. 5, an example in-band portal authentication method 500 is described. The example method 500 may be performed, for example, by the network management device described in FIG. 3. The method 500 illustrates an example algorithm that may be programmed using any suitable programming environment or language to create machine code executable by a CPU or microcontroller. Various implementations may be coded using assembly, C, Objective-C, C++, JAVA, Ruby, or other human-readable languages, and then compiled, assembled, or otherwise converted into machine code that may be loaded into a read-only memory (ROM), erasable programmable read-only memory (EPROM), or other recordable memory coupled to and executed by a CPU or microcontroller. For example, the network management device may include one or more hardware computing devices and non-transitory physical computer storage that stores instructions that, when executed by the one or more hardware computing devices, cause the one or more hardware computing devices to perform the steps of the method 500. For convenience, the steps of example method 500 are described as being performed by a network management device. In some implementations, one or more steps described herein as being performed by a network management device may instead be performed by a cloud network management server or another component described herein.

[0027] At block 502, the network management device receives a request from a user device to access a first network resource on an external network.

[0028] At block 504, the network management device transmits an access request to the RADIUS server, the access request including a persistent identifier associated with the user device and a non-persistent identifier associated with the user device.

[0029] At block 506, the network management device receives from the RADIUS server a first indication that the access request is permitted and a second indication that additional user input is required by the cloud network management server in communication with the RADIUS server.

[0030] At block 508, the network management device forwards the first instruction to a radio controller associated with the user device without forwarding the second instruction.

[0031] At block 510, the network management device receives an accounting start request to forward to the RADIUS server an indication that authorized network access for the user device has begun.

[0032] At block 512, the network management device does not forward the accounting-start request to the RADIUS server, but instead directs the user device to a second network resource configured to receive additional user input requested by the cloud network management server.

[0033] At block 514, the network management device receives a third indication from the cloud network management server that additional input is being provided by the user device.

[0034] In block 516, the network management device, following receipt of the third instruction from the cloud network management server, transmits to the RADIUS server an indication that authorized network access for the user device has begun. For example, the instruction may be a RADIUS Accounting Start message.

[0035] At block 518, the network management device directs the user device to a first network resource on the external network.

[0036] 5 may be removed (e.g., not performed) and / or the order in which method 500 is performed may be rearranged. In some implementations, additional blocks may be added to method 500. Implementations of the present disclosure are not limited to or by the example shown in FIG. 5, and other variations may be implemented without departing from the spirit of the present disclosure.

[0037] <Example workflow for out-of-band portal authentication method> 6 illustrates a workflow for performing an out-of-band portal authentication method according to an aspect of the present disclosure. At (1), a user device 602 connects to an access point / controller (also referred to herein as an AP) 604. At (2), the AP 604 sends an access request directly to a RADIUS server 608. At (3), the RADIUS server 608 sends an access-challenge request to obtain additional information from the AP 604. For example, the additional information may include a user profile stored on the user device 602 and / or a persistent or non-persistent identifier of the user device 602. Alternatively, such information may be included in the request in (2). At (4), the RADIUS server 608 decrypts the EAP-TTLS message. At (5), the RADIUS server 608 sends a RADIUS authentication request to the network management server 610. At (6), the network management server 610 returns a success message to the RADIUS server 608 indicating that the authentication request is authorized. At (7), the RADIUS server 608 forwards the instruction from the network management server 610 to the AP 604.

[0038] At (8), the AP 604 sends an Accounting Start request to the RADIUS server 608, and at (9), the user device 602 initiates network access (e.g., by obtaining a DHCP lease). In response, at (10.1), the network management device 606 sends another authentication request to the RADIUS server 608 using the MAC address (or another persistent or non-persistent identifier associated with the user device 602). At (10.2), the RADIUS server 608 sends another RADIUS authentication request to the network management server 610, and at (10.3), the network management server 610 rejects the RADIUS authentication request and returns a message indicating that the authentication request was not authorized. At (10.4), the RADIUS server 608 sends a message to the network management device 606 indicating that the authentication request made at (10.1) was rejected and that the user device 602 should be directed to a captive portal. At (11), the user device 602 accesses a network resource, and at (12), the network management device 606 brings the user device 602 to another network resource different from the one requested by the user device 602 (e.g., a captive portal configured to receive additional user input required by the network management server 606 for the user device 602 to be granted network access).

[0039] At (13), the user device 602 provides additional user input requested by the network management server 610 and submits the user input through the captive portal. For example, this request may include the randomized MAC address of the user device 602, and the network management server 610 may look up the randomized MAC address in its database that stores associations between randomized MAC addresses and persistent identifiers (e.g., those found in Passpoint or other user profiles stored on the user device). Based on the information provided in the request satisfying the additional user input requirements, the network management server 610 determines that the user device 602 meets all requirements to be granted network access and begins its process for removing the captive portal.

[0040] At (14), the network management server 610 sends a login request to the network management device 606 indicating that the additional user input requirements have been met, and in response, at (15), the network management device 606 sends an access request to the RADIUS server 608. At (16), the RADIUS server 608 grants the access request (e.g., based on prior instructions from the network management server 610 or by requesting that access be granted by the network management server 610 in response to receiving the request at (15)). At (17), the network management device 606 enables Internet access for the user device 602. At (18), the network management device 606 sends an Accounting-Start request to the RADIUS server 608, and at (19), the RADIUS server 608 sends a RADIUS Account-Start message to the network management server 610. At (20), the network management server 610 sends an HTTP 200 OK success status response to the user device 602 and / or directs the user device to the requested network resource.

[0041] At (21), the user device 602 disconnects or times out, and at (22), the AP 604 sends an accounting stop request directly to the RADIUS server 608. At (23), the network management device 606 sends an accounting stop request to the RADIUS server 608 after the timeout.

[0042] Although not shown in FIG. 6, in response to (5), (10.2), and / or (13), the network management server 610 may check the stored association to identify the user device 602 using a non-persistent identifier (e.g., a randomized MAC address) of the user device 606, determine whether the user device 602 meets all requirements to be granted the authentication or network access request, and respond to the RADIUS server 608 or other component based on that determination.

[0043] <Out-of-band portal authentication method> Referring now to FIG. 7 , an example out-of-band portal authentication method 700 is described. The example method 700 may be performed, for example, by the cloud network management server described in FIG. 3 . Method 700 illustrates an example algorithm that may be programmed using any suitable programming environment or language to create machine code executable by a CPU or microcontroller. Various implementations may be coded using assembly, C, Objective-C, C++, JAVA, Ruby, or other human-readable languages, and then compiled, assembled, or otherwise converted into machine code that may be loaded into a read-only memory (ROM), erasable programmable read-only memory (EPROM), or other recordable memory coupled to and executed by a CPU or microcontroller. For example, the cloud network management server may include one or more hardware computing devices and non-transitory physical computer storage that stores instructions that, when executed by the one or more hardware computing devices, cause the one or more hardware computing devices to perform the steps of method 700. For convenience, the steps of example method 700 are described as being performed by a cloud network management server. In some implementations, one or more steps described herein as being performed by a cloud network management server may instead be performed by a network management device or another component described herein.

[0044] At block 702, the cloud network management server receives a first authentication request from a RADIUS server to authenticate a user device, the authentication request including a persistent identifier associated with the user device and a non-persistent identifier associated with the user device.

[0045] At block 704, the cloud network management server stores an association between a persistent identifier associated with the user device and a non-persistent identifier associated with the user device.

[0046] At block 706, the cloud network management server transmits an indication to the RADIUS server that the first authentication request is allowed.

[0047] At block 708, the cloud network management server receives a second authentication request from the RADIUS server to authenticate the user device, the authentication request including a non-persistent identifier associated with the user device.

[0048] At block 710, the cloud network management server identifies the user device using the non-persistent identifier and the association between the persistent and non-persistent identifiers included in the second authentication request.

[0049] At block 712, the cloud network management server determines that additional user input is required before granting network access to the user device.

[0050] At block 714, the cloud network management server transmits an indication to the RADIUS server that the first authentication request is denied.

[0051] At block 716, the cloud network management server receives additional user input from the user device.

[0052] At block 718, the cloud network management server transmits to the network management device associated with the user device an indication that the user device should be granted network access.

[0053] 7 may be removed (e.g., not performed) and / or the order in which method 700 is performed may be rearranged. In some implementations, additional blocks may be added to method 700. Implementations of the present disclosure are not limited to or by the example shown in FIG. 7, and other variations may be implemented without departing from the spirit of the present disclosure.

[0054] <Example of network architecture and workflow> 8 and 9 show a network architecture including a workflow for integrating a gateway with HS2.0 to enable some of the features described above. One challenge in integrating additional authentication or other venue-specific operations is that a user device may need access to the network to be directed to a specific link for authentication or remediation. This can be a challenging situation, as a user needs to be able to connect to the network, or at least a portion of the network, to gain access to the network.

[0055] As shown in Figures 8 and 9, when a user device requests specific content on the network, the HS2.0 profile installed on the device can be used to enable first-level access. The gateway is in between all communications and can facilitate integration. The network management system can integrate with a venue system (such as a hotel loyalty program). The network management system can also connect with a Radius server and an HS2.0 dashboard. Based on information received from the Radius server, the network management system can provide parameters to the HS2.0 dashboard. The parameters can include, for example, a captive portal URL. These parameters may not be understood by the wireless access controller. However, based on obtaining authentication, the wireless access controller can grant the user device access to the network. The gateway understands the parameters, and once network access is granted, the gateway can continue to redirect the user device to the captive portal URL until a specific action is taken by the user, such as accepting terms of use. The network management system is also in the data flow and anticipates the redirection of the user device to the captive portal URL. In some cases, the redirection may occur over a period of time. The gateway can maintain a flag stored in memory to continue redirecting the user device to the captive portal URL. The network management system can allow parameters from the Radius server to be integrated with the HS2.0 dashboard.

[0056] <Enumeration Implementation (EI)> Some examples of Enumeration Implementations (EI) are provided in this section without limitation.

[0057] EI1: A system for enabling a captive portal using persistent and non-persistent device identifiers, the system including: a cloud network management server configured to communicate with a RADIUS server to authenticate a user device; and a network management device configured to receive a request for access to a first network resource on an external network from the user device, transmit the access request to the RADIUS server, where the access request includes a persistent identifier associated with the user device and a non-persistent identifier associated with the user device, receive from the RADIUS server a first indication that the access request is authorized and a second indication that additional user input is required by the cloud network management server, forward the first indication to a wireless controller associated with the user device without forwarding the second indication, receive an accounting-start request to forward to the RADIUS server an indication that authorized network access for the user device has begun, and direct the user device to a second network resource configured to receive the additional user input required by the cloud network management server without forwarding the accounting-start request to the RADIUS server.

[0058] EI2: The system of EI1, wherein the network management device is further configured to receive a third indication from the cloud network management server that additional input has been provided by the user device and direct the user device to a first network resource on the external network.

[0059] EI3: The system of EI2, wherein the network management device is further configured to, upon receiving a third instruction from the cloud network management server, transmit to the RADIUS server an instruction that authorized network access for the user device has begun.

[0060] EI4: The system of EI1, in which the second network resource is a web page and the external network is the Internet.

[0061] EI5: The system of EI1, wherein additional inputs required by the cloud network management server include user consent to updated protocols related to network access granted to the user device.

[0062] EI6: The system of EI1, wherein the persistent identifier associated with the user device is a parameter included in a user profile stored on the user device in accordance with the Hotspot 2.0 specification.

[0063] EI7: The system of EI1, wherein the non-persistent identifier associated with the user device is a Media Access Control (MAC) address of the user device.

[0064] EI8: A computer-implemented method comprising: receiving a request for access to a first network resource on an external network from a user device; transmitting the access request to a RADIUS server, the access request including a persistent identifier associated with the user device and a non-persistent identifier associated with the user device; receiving from the RADIUS server a first indication that the access request is granted and a second indication that additional user input is required by a cloud network management server in communication with the RADIUS server; forwarding the first indication to a wireless controller associated with the user device without forwarding the second indication; receiving an accounting-start request to forward to the RADIUS server an indication that network access authorized for the user device has begun; and directing the user device to a second network resource configured to receive the additional user input required by the cloud network management server without forwarding the accounting-start request to the RADIUS server.

[0065] EI9: The computer-implemented method of EI8, further comprising receiving a third indication from the cloud network management server that additional input is being provided by the user device, and directing the user device to a first network resource on the external network.

[0066] EI10: The computer-implemented method of EI9, further comprising, following receipt of a third instruction from the cloud network management server, transmitting to the RADIUS server an indication that authorized network access for the user device has been initiated.

[0067] EI11: The computer-implemented method of EI8, wherein the second network resource is a web page and the external network is the Internet.

[0068] EI12: The computer-implemented method of EI8, wherein the additional input required by the cloud network management server includes user consent to updated protocols related to network access granted to the user device.

[0069] EI13: The computer-implemented method of EI8, wherein the persistent identifier associated with the user device is a parameter included in a user profile stored on the user device in accordance with the Hotspot 2.0 specification.

[0070] EI14: The computer-implemented method of EI8, wherein the non-persistent identifier associated with the user device is a Media Access Control (MAC) address of the user device.

[0071] EI15: Non-transitory computer-readable physical storage storing instructions that, when executed by a computing system, cause the computing system to at least receive a request for access to a first network resource on an external network from a user device; transmit the access request to a RADIUS server, where the access request includes a persistent identifier associated with the user device and a non-persistent identifier associated with the user device; receive from the RADIUS server a first indication that the access request is allowed and a second indication that additional user input is required by a cloud network management server; forward the first indication to a wireless controller associated with the user device without forwarding the second indication; receive an accounting-start request to forward to the RADIUS server an indication that network access authorized for the user device has been initiated; and direct the user device to a second network resource configured to receive the additional user input required by the cloud network management server without forwarding the accounting-start request to the RADIUS server.

[0072] EI16: Non-transitory computer-readable physical storage of EI15 that stores further instructions that, when executed by the computing system, cause the computing system to receive a third indication from the cloud network management server that additional input has been provided by the user device and direct the user device to a first network resource on the external network.

[0073] EI17: Non-transitory computer-readable physical storage of EI16 storing further instructions that, when executed by the computing system, cause the computing system, following receipt of a third instruction from the cloud network management server, to transmit to the RADIUS server an indication that authorized network access for the user device has begun.

[0074] EI18: Non-transitory computer-readable physical storage of EI15, wherein additional input required by the cloud network management server includes user consent to updated protocols related to network access granted to user devices.

[0075] EI19: Non-transitory computer-readable physical storage of EI15, wherein the persistent identifier associated with the user device is a parameter contained in a user profile stored on the user device in accordance with the Hotspot 2.0 specification.

[0076] EI20: Non-transitory computer-readable physical storage of EI15, wherein the non-persistent identifier associated with the user device is the Media Access Control (MAC) address of the user device.

[0077] EI21: A computer-implemented method comprising the steps of receiving a first authentication request to authenticate a user device from a RADIUS server, the authentication request including a persistent identifier associated with the user device and a non-persistent identifier associated with the user device; storing an association between the persistent identifier associated with the user device and the non-persistent identifier associated with the user device; transmitting an indication that the first authentication request is granted to the RADIUS server; receiving a second authentication request to authenticate the user device from the RADIUS server, the authentication request including the non-persistent identifier associated with the user device; identifying the user device using the non-persistent identifier included in the second authentication request and the association between the persistent identifier and the non-persistent identifier; determining that additional user input is required before granting network access to the user device; transmitting an indication that the first authentication request is denied to the RADIUS server; receiving the additional user input from the user device; and transmitting an indication that the user device should be granted network access to a network management device associated with the user device.

[0078] <Terminology> All methods and tasks described herein may be performed by a computer system and may be fully automated. A computer system may, in some cases, include multiple separate computers or computing devices (e.g., physical servers, workstations, storage arrays, cloud computing resources, etc.) that communicate and interoperate over a network to perform the described functions. Each such computing device typically includes a processor that executes program instructions or modules stored in memory or other non-transitory computer-readable storage media or devices (e.g., solid-state storage devices, disk drives, etc.). Various functions disclosed herein may be embodied in such program instructions or implemented in the computer system's application-specific circuitry (e.g., ASIC or FPGA). When a computer system includes multiple computing devices, these devices may, but need not, be collocated. Results of the disclosed methods and tasks may be persistently stored by converting physical storage devices, such as solid-state memory chips or magnetic disks, to different states. In some embodiments, the computer system may be a cloud-based computing system in which processing resources are shared by multiple separate entities or other users.

[0079] The processes described herein or illustrated in the figures of this disclosure may be initiated in response to an event, such as on a predetermined or dynamically determined schedule, on demand when initiated by a user or system administrator, or in response to some other event. When such processes are initiated, a set of executable program instructions stored on one or more non-transitory computer-readable media (e.g., hard drives, flash memory, removable media, etc.) may be loaded into memory (e.g., RAM) of a server or other computing device. The executable instructions may then be executed by a hardware-based computer processor of the computing device. In some embodiments, such processes, or portions thereof, may be implemented serially or in parallel on multiple computing devices and / or multiple processors.

[0080] Depending on the embodiment, certain acts, events, or functions of any of the processes or algorithms described herein may occur in a different order, or may be added, combined, or omitted altogether (e.g., not all of the described acts or events are necessary to practice an algorithm). Furthermore, in some embodiments, acts or events may occur simultaneously rather than sequentially, for example, through multithreading, interrupt processing, or multiple processors or processor cores, or on other parallel architectures.

[0081] The various illustrative logic blocks, modules, routines, and algorithm steps described in connection with the embodiments disclosed herein can be implemented as electronic hardware (e.g., an ASIC or FPGA device), computer software executing on computer hardware, or a combination of both. Furthermore, the various illustrative logic blocks and modules described in connection with the embodiments disclosed herein can be implemented or performed by machines such as processor devices, digital signal processors (“DSPs”), application specific integrated circuits (“ASICs”), field programmable gate arrays (“FPGAs”) or other programmable logic devices, discrete gate or transistor logic, discrete hardware components, or any combination thereof designed to perform the functions described herein. The processor device can be a microprocessor, but alternatively, the processor device can be a controller, microcontroller, or state machine, combinations thereof, etc. The processor device can include electrical circuitry configured to process computer-executable instructions. In another embodiment, the processor device includes an FPGA or other programmable device that performs logical operations without processing computer-executable instructions. A processor device may also be implemented as a combination of computing devices, such as a DSP and a microprocessor, multiple microprocessors, one or more microprocessors in conjunction with a DSP core, or any other such configuration. Although described herein primarily with respect to digital technology, a processor device may also include primarily analog components. For example, some or all of the rendering techniques described herein may be implemented in analog circuitry or mixed analog and digital circuitry.The computing environment can include any type of computer system, including, but not limited to, a computer system based on a microprocessor, mainframe computer, digital signal processor, portable computing device, device controller, or computational engine within an appliance, to name a few.

[0082] Elements of a method, process, routine, or algorithm described in connection with the embodiments disclosed herein may be embodied directly in hardware, in a software module executed by a processor device, or in a combination of the two. A software module may reside in RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, a hard disk, a removable disk, a CD-ROM, or any other form of non-transitory computer-readable storage medium. An exemplary storage medium may be coupled to the processor device such that the processor device can read information from, and write information to, the storage medium. Alternatively, the storage medium may be integrated into the processor device. The processor device and the storage medium may reside in an ASIC. The ASIC may reside in a user terminal. Alternatively, the processor device and the storage medium may reside as discrete components in a user terminal.

[0083] As used herein, conditional language, particularly "can," "could," "might," "may," "e.g.," and the like, is intended to generally convey that certain embodiments include certain features, elements, or steps, while other embodiments do not, unless specifically stated otherwise or understood differently within the context in which it is used. Thus, such conditional language is not generally intended to imply that features, elements, or steps are somehow required in one or more embodiments, or that one or more embodiments necessarily include logic for determining, with or without other input or prompts, whether or not these features, elements, or steps are included or performed in any particular embodiment. Terms such as "comprising," "including," and "having" are synonymous and are used inclusively in an open-ended manner and do not exclude additional elements, features, acts, operations, etc. Additionally, the term "or" is used in its inclusive sense (rather than its exclusive sense), so that, for example, when used to connect a list of elements, "or" means one, some, or all of the elements in the list. The term "set" is used to include "one or more." For example, a set of objects may include a single object or multiple objects.

[0084] Disjunctive language, such as the phrase "at least one of X, Y, or Z," is generally understood differently depending on the context in which it is used to indicate that an item, term, etc. can be either X, Y, or Z, or any combination thereof (e.g., X, Y, or Z), unless specifically stated otherwise. Thus, such disjunctive language is generally not intended to, and should not, imply that an embodiment requires that at least one X, at least one Y, and at least one Z are each present.

[0085] Any process descriptions, elements, or blocks depicted in the flow diagrams described herein and / or in the accompanying drawings should be understood as potentially representing modules, segments, or portions of code that comprise one or more executable instructions for implementing a particular logical function or element within the process. As will be appreciated by those skilled in the art, alternative implementations in which elements or functions may be omitted depending on the functionality involved, or performed in a different order than that shown or discussed, including substantially simultaneously or in reverse order, are included within the scope of the embodiments described herein.

[0086] Unless otherwise specified, articles such as "a" or "an" should generally be construed to include one or more listed items. Thus, phrases such as "a device configured to" are intended to include one or more listed devices. Such one or more listed devices may also be collectively configured to perform the referenced items. For example, "a processor configured to perform items A, B, and C" may include a first processor configured to perform item A working in conjunction with a second processor configured to perform items B and C.

[0087] While the above detailed description illustrates, describes, and points out novel features applied to various embodiments, it will be understood that various omissions, substitutions, and changes in the form and details of the devices or algorithms shown may be made without departing from the scope of the present disclosure. As will be recognized, some features may be used or practiced separately from others, and therefore certain embodiments described herein may be embodied in forms that do not provide all of the features and benefits described herein. All changes that come within the meaning and range of equivalency of the claims are intended to be embraced within their scope.

Claims

1. 1. A system for enabling a captive portal using persistent and non-persistent device identifiers, comprising: a cloud network management server configured to communicate with a RADIUS server to authenticate user devices; receiving a request from a user device to access a first network resource on an external network; transmitting an access request to the RADIUS server, wherein the access request includes a persistent identifier associated with the user device and a non-persistent identifier associated with the user device; receiving a first indication from the RADIUS server that the access request is permitted and a second indication that additional user input is required by the cloud network management server; forwarding the first instruction to a wireless controller associated with the user device without forwarding the second instruction; receiving an accounting-start request for forwarding to the RADIUS server an indication that authorized network access for the user device has begun; directing the user device to a second network resource configured to receive the additional user input requested by the cloud network management server without forwarding the accounting-start request to the RADIUS server. a network management device configured to: A system including:

2. the network management device, receiving a third indication from the cloud network management server that the additional input is being provided by the user device; directing the user device to the first network resource on the external network The system of claim 1 further configured to:

3. 3. The system of claim 2, wherein the network management device is further configured, subsequent to receiving the third instruction from the cloud network management server, to transmit to the RADIUS server an indication that authorized network access for the user device has begun.

4. The system of claim 1 , wherein the second network resource is a web page and the external network is the Internet.

5. The system of claim 1 , wherein the additional input requested by the cloud network management server includes user consent to updated protocols related to the network access permitted to the user device.

6. The system of claim 1 , wherein the persistent identifier associated with the user device is a parameter contained in a user profile stored on the user device according to the Hotspot 2.0 specification.

7. The system of claim 1 , wherein the non-persistent identifier associated with the user device is a media access control (MAC) address of the user device.

8. 1. A computer-implemented method comprising: receiving a request from a user device to access a first network resource on an external network; transmitting an access request to a RADIUS server, the access request including a persistent identifier associated with the user device and a non-persistent identifier associated with the user device; receiving a first indication from the RADIUS server that the access request is permitted and a second indication that additional user input is required by a cloud network management server in communication with the RADIUS server; forwarding the first instruction to a wireless controller associated with the user device without forwarding the second instruction; receiving an accounting-start request for forwarding to the RADIUS server an indication that authorized network access for the user device has begun; directing the user device to a second network resource configured to receive the additional user input requested by the cloud network management server without forwarding the accounting-start request to the RADIUS server; 10. A computer-implemented method comprising:

9. receiving a third indication from the cloud network management server that the additional input is being provided by the user device; directing the user device to the first network resource on the external network; The computer-implemented method of claim 8 further comprising:

10. 10. The computer-implemented method of claim 9, further comprising, subsequent to receiving the third instruction from the cloud network management server, transmitting to the RADIUS server an indication that authorized network access for the user device has begun.

11. The computer-implemented method of claim 8 , wherein the second network resource is a web page and the external network is the Internet.

12. The computer-implemented method of claim 8 , wherein the additional input requested by the cloud network management server includes user consent to updated protocols related to the network access permitted to the user device.

13. The computer-implemented method of claim 8 , wherein the persistent identifier associated with the user device is a parameter contained in a user profile stored on the user device according to the Hotspot 2.0 specification.

14. The computer-implemented method of claim 8 , wherein the non-persistent identifier associated with the user device is a media access control (MAC) address of the user device.

15. 1. A non-transitory computer-readable physical storage device that, when executed by a computing system, provides the computing system with at least: receiving a request from a user device to access a first network resource on an external network; transmitting an access request to a RADIUS server, wherein the access request includes a persistent identifier associated with the user device and a non-persistent identifier associated with the user device; receiving from the RADIUS server a first indication that the access request is permitted and a second indication that additional user input is required by a cloud network management server; forwarding the first instruction to a wireless controller associated with the user device without forwarding the second instruction; receiving an accounting-start request for forwarding to the RADIUS server an indication that authorized network access for the user device has begun; directing the user device to a second network resource configured to receive the additional user input requested by the cloud network management server without forwarding the accounting-start request to the RADIUS server. Non-transitory computer-readable physical storage for storing instructions.

16. When executed by the computing system, the computing system: receiving a third indication from the cloud network management server that the additional input is being provided by the user device; directing the user device to the first network resource on the external network 16. The non-transitory computer-readable physical storage of claim 15 for storing further instructions.

17. 17. The non-transitory computer-readable physical storage of claim 16, storing further instructions that, when executed by the computing system, cause the computing system, subsequent to receiving the third instruction from the cloud network management server, to transmit to the RADIUS server an indication that authorized network access for the user device has begun.

18. 16. The non-transitory computer-readable physical storage of claim 15, wherein the additional input requested by the cloud network management server includes user consent to updated protocols related to the network access granted to the user device.

19. 16. The non-transitory computer-readable physical storage of claim 15, wherein the persistent identifier associated with the user device is a parameter contained in a user profile stored on the user device in accordance with the Hotspot 2.0 specification.

20. 16. The non-transitory computer-readable physical storage of claim 15, wherein the non-persistent identifier associated with the user device is a media access control (MAC) address of the user device.

Citation Information

Patent Citations

  • A portal aggregation service that maps subscriber device identifiers to portal addresses to which connection and authentication requests are redirected and that facilitates mass subscriber device configuration.

    JP2019537176A

  • 802.1X protocol-based multicasting control method

    US20040172559A1

  • Wireless connection device

    US20100229216A1

  • System and method for online activation of wireless internet service

    US20130247219A1

  • Wireless Analytics in Physical Spaces

    US20140195380A1