Captive Portal Visitor Authentication via SMS Identifier

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Visiting users face challenges in accessing the Internet through wireless short-range networks without compromising the owner's traffic security and requiring complex authentication processes.

Innovation Solution

A method that intercepts packets from visiting terminals, generates and assigns identifiers, and uses a captive portal to allow Internet access via a mobile communication network, routing visitor traffic securely and independently of the owner's network, utilizing NAT and VPN tunneling protocols for seamless connectivity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods (usernames/passwords) are used for visitor access, then network security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical authentication system (keyboards, password entry, username verification) with a mobile communication-based system. The identifier is automatically transmitted via mobile network to the base station, eliminating the need for physical interaction with authentication interfaces and complex password management.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a mobile communication network as an intermediary between the visitor terminal and the base station. Instead of direct authentication interaction, the mobile network serves as a mediator to transmit the identifier, simplifying the authentication process while maintaining security through the base station's verification capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If visitor traffic is routed through the owner's network, then device complexity is reduced, but object-affected harmful factors worsen due to security risks

Engineering Contradiction:
Improvenetwork configurationVSAvoiddata security risk
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the network traffic into two separate paths: owner traffic and visitor traffic. Visitor traffic is routed through a dedicated tunnel to the captive portal, while owner traffic continues through the normal network path. This segmentation isolates visitor traffic from the owner's private network, eliminating security risks while maintaining manageable complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts visitor traffic from the owner's network path and routes it through a separate tunnel to the captive portal. This extraction removes the potential security hazard of visitor traffic accessing the owner's network while still providing Internet access functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If complex authentication processes are implemented, then reliability is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveaccess controlVSAvoiduser interaction
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs automatic identifier verification and access authorization without requiring the visitor to manually complete complex authentication forms. The base station automatically receives the identifier via mobile network, verifies it, and grants access, making the process self-service oriented and extremely simple for the user.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The identifier is pre-generated and assigned to the visitor terminal before the authentication process begins. This preliminary preparation eliminates the need for real-time complex verification during the authentication moment, allowing for rapid and simple access granting while maintaining security through pre-configured authorization.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2179561B1Network access for a visiting user
Publication Date: 2018.09.05 ELISA OYJ
  • EP2179561B1 patent drawingFigure 1
  • EP2179561B1 patent drawingFigure 2
  • EP2179561B1 patent drawingFigure 3

AI summary

The invention relates to a method for a visitor (202) in a wireless short-range network to be allowed to access the Internet (50) in a system where the Internet traffic of a holder of a base station (30) of the wireless short-range network is separated from the visitor's traffic. The method comprises intercepting a packet sent by the visiting terminal (202) at a captive portal (42). The packet identifies the sender's address. The method comprises selecting or generating an identifier that pertains or is assigned to said address. Furthermore, the method comprises generating a website on which an identifier is shown to the visitor (202), receiving the identifier from the visitor via a mobile communication network (80) and opening access to the Internet (50) for the address associated with the identifier from the captive portal (42). Furthermore, the invention relates to a captive portal device, system and computer program including corresponding elements.