Access Point Pre-Association Denial Based on MAC Role

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network solutions for guest WiFi services are insufficient in managing unauthorized access and network congestion, as they lack flexibility and continue to incur overhead from denied association requests.

Innovation Solution

Implementing an intelligent pre-association denial system that uses media access control (MAC) addresses to determine device roles and selectively allow or deny connections based on contextual factors like time, location, and user identity, employing Agile Multiband Operations (MBO) and enhanced reason codes to manage network capacity and prioritize authorized devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the access point shuts down or password-protects the network to prevent unauthorized access, then security is improved, but flexibility and ease of operation deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidflexibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system dynamically adjusts network access policies based on contextual factors such as time of day, location, and user identity. The access point transitions between different operational states (open, password-protected, closed) according to predefined policies, providing both security and flexibility without requiring manual intervention.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes network parameters (access status, authentication requirements) based on contextual conditions. By monitoring factors like time, location, and device identity, the system automatically adjusts security parameters to balance protection and accessibility.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If the access point denies association requests to unauthorized devices, then unauthorized access is prevented, but network performance deteriorates due to continued probe transmissions

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidnetwork performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary evaluation of association requests against predefined policies before allowing connection. By pre-defining acceptable contexts (time, location, device identity), the system can quickly deny unauthorized requests without requiring multiple probe attempts, thus preventing unauthorized access while minimizing performance impact.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The system provides feedback to client devices about association denial status, enabling them to stop sending probe requests. This feedback mechanism reduces unnecessary network traffic from denied devices while maintaining security against unauthorized access.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11356923B2Client pre-association denial based on service policy
Publication Date: 2022.06.07 CISCO TECHNOLOGY INC
  • US11356923B2 patent drawing
  • US11356923B2 patent drawing
  • US11356923B2 patent drawing

AI summary

Techniques for selective association and denial of association are provided. Association requests from a first device and a second device are received at an access point. A first media access control (MAC) address of the first device is determined, and a second MAC address of the second device is determined. A first role of the first device and a second role of the second device are each identified, based on a predefined mapping between MAC addresses and roles. Upon determining that the first device is associated with the first role, a unicast response is returned to the first device, where the unicast response includes an association disallowed frame. Additionally, upon determining that the second device is associated with the second role, a unicast response is returned to the second device, where the unicast response allows the second device to associate with the access point.