Client Connectivity Across Networks with Direct Captive-Portal Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure communication technologies, such as VPNs, face challenges when transitioning from a secure network to a non-secure network with restricted access, as they often fail to authenticate with captive portals, leading to interrupted or blocked data transmission.

Innovation Solution

A method and apparatus that allow a client device to communicate with a VPN server over a first network while attempting to access a second network with a captive portal, forwarding authentication information directly to the second network without sending it to the VPN server, and establishing a bonded connection using both networks for secure data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a client device attempts to access a second network with captive portal while connected to a VPN server over a first network, then the client device can potentially benefit from multiple network connections, but the authentication information routing becomes complex and may fail to authenticate properly

Engineering Contradiction:
Improvenetwork access capabilityVSAvoidauthentication routing complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the network authentication process by creating separate authentication channels for different networks. The client device maintains distinct authentication states for the first network (VPN) and second network (captive portal), allowing independent authentication routing without interference. This segmentation resolves the complexity by treating each network's authentication as a separate subsystem.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism (network manager/component) that mediates between the client device and multiple networks. This intermediary handles the complex routing logic, determining which authentication information should be sent to which network based on current connection states. The intermediary abstracts the complexity from the user while enabling multi-network access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication information is forwarded to the VPN server, then secure communication is maintained, but access to the second network with captive portal is blocked

Engineering Contradiction:
Improvesecure communicationVSAvoidnetwork access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent inverts the traditional authentication routing logic. Instead of always routing authentication through the VPN server (as would be expected for security), the system intelligently routes authentication information directly to the captive portal when accessing the second network, while maintaining VPN encryption for data transmission. This inversion resolves the contradiction by separating authentication routing from data transmission routing.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent applies different security measures to different parts of the communication process. Authentication information is handled differently from data transmission - authentication goes directly to the appropriate network (bypassing VPN for captive portal), while data transmission remains encrypted through the VPN tunnel. This local differentiation of security measures allows both secure communication and captive portal access to coexist.

Inventive Principle:
Principle #3Local quality

3Productivity

If the client device switches from one network to another, then network optimization is achieved, but connection interruption and data loss occur

Engineering Contradiction:
Improvenetwork efficiencyVSAvoidconnection continuity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements preliminary actions to prepare for network switching before it occurs. The system pre-establishes authentication on the second network (captive portal) while still connected to the first network (VPN). By completing authentication in advance, the system ensures that when network switching occurs for optimization, the connection can be seamlessly transferred without interruption or data loss.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent maintains continuity of useful action by keeping the VPN connection active while simultaneously establishing captive portal authentication. Rather than completely switching from one network to another, the system maintains both connections and transitions traffic between them smoothly. This continuous operation prevents connection interruptions and ensures uninterrupted data transmission.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS20250279983A1Connection management over multiple networks
Publication Date: 2025.09.04 CONNECTIFY
  • US20250279983A1 patent drawing
  • US20250279983A1 patent drawing
  • US20250279983A1 patent drawing

AI summary

One example may include receiving data, via a client device, over a first connection of a first network, sending a request, via the client device, to access a second network detected by the client device while the client device is communicating over the first network, responsive to receiving a captive portal from the second network, forwarding, via the client device, authentication information over a second connection to the second network, and receiving additional data, by the client device, over the first connection provided by the first network and a second connection provided by the second network after the authentication information is approved.