Captive Portal Redirection via HTML Frameset
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In wireless communications, existing technologies face challenges in securely managing multiple devices per user in BYOD environments, particularly in routing unauthenticated devices to external captive portals without relying on HTTP Status Code redirects, which can be undesirable.
Innovation Solution
A network device, such as an access point with transparent HTTP proxy functionality, returns a response message with display layout information, specifically an HTML frameset, to prompt unauthenticated client devices to access an external captive portal, thereby avoiding HTTP Status Code redirects and ensuring secure access to network resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If HTTP Status Code redirects are used to route unauthenticated devices to captive portal, then network access control is implemented, but security is compromised and network control is reduced
Solution Approach 1:
The patent extracts the redirect functionality from the HTTP protocol layer and implements it at the wireless network layer instead. The access point intercepts wireless association requests and redirects unauthenticated devices to the captive portal before they can establish full network connectivity, eliminating the need for HTTP Status Code redirects and the associated security vulnerabilities.
Solution Approach 2:
The patent performs authentication and portal redirection actions before the device establishes full network access. By intercepting association requests and presenting the captive portal during the connection establishment phase, the system ensures authentication occurs preliminarily, preventing unauthorized access before HTTP transactions can occur.
2Ease of operation
If HTTP Status Code redirects are used for captive portal authentication, then device routing is achieved, but device complexity and protocol dependency increase
Solution Approach 1:
The patent introduces the access point as an intermediary that handles redirect logic at the wireless layer. Instead of relying on HTTP protocol mechanisms, the access point directly manages device routing by intercepting association requests and presenting captive portal information elements, simplifying the overall system by removing protocol layer dependencies.
Solution Approach 2:
The patent replaces the HTTP protocol-based redirect mechanism with a wireless layer-based redirect mechanism. By substituting the HTTP Status Code redirect system with wireless association request interception and captive portal information element insertion, the system eliminates protocol dependency and reduces device complexity.
3Ease of operation
If unauthenticated devices are allowed to access network resources, then ease of access is improved, but security and network control deteriorate
Solution Approach 1:
The patent applies preliminary anti-action by preventing unauthenticated access before it can occur. The access point intercepts association requests from unauthenticated devices and presents the captive portal during the connection establishment phase, blocking unauthorized access attempts before they can reach network resources.
Solution Approach 2:
The system performs authentication actions preliminarily during the wireless association phase. By presenting the captive portal and requiring authentication before full network access is granted, the system ensures security measures are in place before any network resource access can occur, maintaining both ease of access and network security.
Data Source
AI summary
According to one embodiment of the invention, a method for controlling access to a network by a network device comprises returning a message prompting connectivity to a captive portal that is different from a HTTP Source Code redirect. The message is an HTML document such as a frameset.


