Access Controller IP Allocation for Portal Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In mobile Metropolitan Area Networks (MANs), the current portal authentication method wastes address resources as unauthenticated users are assigned public network IP addresses, leading to IP address shortages and inefficient address utilization, as they occupy addresses even if they do not intend to access the network.

Innovation Solution

Implementing a method where the Access Controller (AC) assigns private network IP addresses to unauthenticated users and public network IP addresses only after successful authentication, using a DHCP relay role to manage IP addresses efficiently and release them when users disconnect, thereby optimizing IP address allocation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If public network IP addresses are assigned to unauthenticated users, then network access is simplified, but IP address resources are wasted and address utilization efficiency deteriorates

Engineering Contradiction:
Improvenetwork access simplicityVSAvoidIP address resource waste
Core Design Contradiction:
Ease of operationVSLoss of energy

Solution Approach 1:

The patent implements preliminary authentication before IP address assignment. The AC performs portal authentication on users before assigning public network IP addresses, ensuring that only authenticated users receive public addresses. This preliminary action prevents unauthenticated users from occupying IP address resources, thereby resolving the contradiction between access simplicity and resource efficiency.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If public network IP addresses are assigned to all users, then network tracing becomes easier, but IP address shortage worsens due to inefficient allocation

Engineering Contradiction:
Improveuser tracing accuracyVSAvoidavailable IP address quantity
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent applies local quality by differentiating IP address assignment based on user authentication status. Authenticated users receive public network IP addresses for precise tracing, while unauthenticated users are redirected to portal authentication pages. This localized differentiation ensures that public addresses are allocated only where tracing is necessary, preventing address exhaustion while maintaining tracing accuracy for legitimate users.

Inventive Principle:
Principle #3Local quality

3Loss of energy

If the AC manages IP address allocation centrally, then address utilization efficiency improves, but system complexity increases

Engineering Contradiction:
Improveaddress resource efficiencyVSAvoidAC system complexity
Core Design Contradiction:
Loss of energyVSDevice complexity

Solution Approach 1:

The AC is designed with multi-functionality, serving as both an authentication controller and a DHCP server. By integrating portal authentication and IP address management into a single device, the patent eliminates the need for separate authentication and address allocation systems. This universal approach improves address utilization efficiency while avoiding the complexity of inter-device communication and coordination between separate authentication and DHCP servers.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10050971B2Portal authentication method and access controller
Publication Date: 2018.08.14 HEWLETT PACKARD ENTERPRISE DEV LP
  • US10050971B2 patent drawing
  • US10050971B2 patent drawing
  • US10050971B2 patent drawing

AI summary

In a portal authentication method, a DHCP request message sent by a terminal is received by an AC. In response to finding that a user of the terminal is an unauthenticated user, a private network IP address is assigned to the terminal. After portal authentication of the terminal is finished, a wireless connection of the terminal is terminated by the AC. When a DHCP request message sent by the terminal again is received, a determination that the user of the terminal passes the authentication is made by the AC, a public network IP address is assigned to the terminal, and an accounting request message is sent to a RADIUS server. After finding that the terminal is offline, an accounting stop message is sent by the AC to the RADIUS server, the wireless connection of the terminal is disconnected, and the public network IP address is released.