Captive Portal Redirection via HTML Frameset

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless communications, existing technologies face challenges in securely managing multiple devices per user in BYOD environments, particularly in routing unauthenticated devices to external captive portals without relying on HTTP Status Code redirects, which can be undesirable.

Innovation Solution

A network device, such as an access point with transparent HTTP proxy functionality, returns a response message with display layout information, specifically an HTML frameset, to prompt unauthenticated client devices to access an external captive portal, thereby avoiding HTTP Status Code redirects and ensuring secure access to network resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If HTTP Status Code redirects are used to route unauthenticated devices to captive portal, then network access control is implemented, but security is compromised and network control is reduced

Engineering Contradiction:
Improvenetwork access controlVSAvoidsecurity risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the redirect functionality from the HTTP protocol layer and implements it at the wireless network layer instead. The access point intercepts wireless association requests and redirects unauthenticated devices to the captive portal before they can establish full network connectivity, eliminating the need for HTTP Status Code redirects and the associated security vulnerabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs authentication and portal redirection actions before the device establishes full network access. By intercepting association requests and presenting the captive portal during the connection establishment phase, the system ensures authentication occurs preliminarily, preventing unauthorized access before HTTP transactions can occur.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If HTTP Status Code redirects are used for captive portal authentication, then device routing is achieved, but device complexity and protocol dependency increase

Engineering Contradiction:
Improvedevice routingVSAvoidprotocol dependency
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces the access point as an intermediary that handles redirect logic at the wireless layer. Instead of relying on HTTP protocol mechanisms, the access point directly manages device routing by intercepting association requests and presenting captive portal information elements, simplifying the overall system by removing protocol layer dependencies.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the HTTP protocol-based redirect mechanism with a wireless layer-based redirect mechanism. By substituting the HTTP Status Code redirect system with wireless association request interception and captive portal information element insertion, the system eliminates protocol dependency and reduces device complexity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Ease of operation

If unauthenticated devices are allowed to access network resources, then ease of access is improved, but security and network control deteriorate

Engineering Contradiction:
Improveaccess便利性VSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary anti-action by preventing unauthenticated access before it can occur. The access point intercepts association requests from unauthenticated devices and presents the captive portal during the connection establishment phase, blocking unauthorized access attempts before they can reach network resources.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The system performs authentication actions preliminarily during the wireless association phase. By presenting the captive portal and requiring authentication before full network access is granted, the system ensures security measures are in place before any network resource access can occur, maintaining both ease of access and network security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9332054B2Captive portal redirection using display layout information
Publication Date: 2016.05.03 HEWLETT PACKARD ENTERPRISE DEV LP
  • US9332054B2 patent drawing
  • US9332054B2 patent drawing
  • US9332054B2 patent drawing

AI summary

According to one embodiment of the invention, a method for controlling access to a network by a network device comprises returning a message prompting connectivity to a captive portal that is different from a HTTP Source Code redirect. The message is an HTML document such as a frameset.