Client Device Capability Validation in Wireless Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current WLAN authentication methods fail to effectively manage connections from diverse client devices, leading to inefficiencies as legacy devices can connect to modern networks, preventing full utilization of advanced capabilities and impacting network efficiency.

Innovation Solution

Implementing a system where a network device extracts client device capabilities from connection requests and transmits them to an association validation server for comparison against preconfigured policies, allowing or denying access based on compatibility, and deauthenticating devices that do not meet the required standards during the association validation phase.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If WLAN authentication is based only on user credentials, then all client devices can connect to the network, but network efficiency deteriorates due to legacy devices unable to utilize advanced capabilities

Engineering Contradiction:
Improveclient device compatibilityVSAvoidnetwork efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by validating client device capabilities during the association phase before full network access is granted. The access point extracts capability information from association requests and forwards it to the authentication server for validation against policy requirements, preventing inefficient connections before they impact network performance

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication process is segmented into distinct phases: association phase where capability validation occurs, and network access phase where authenticated devices gain full connectivity. This segmentation allows the system to enforce capability requirements without blocking basic network functionality for compatible devices

Inventive Principle:
Principle #1Segmentation

2Productivity

If capability-based validation is implemented, then network efficiency improves by preventing legacy device connections, but device complexity increases due to additional authentication requirements

Engineering Contradiction:
Improvenetwork efficiencyVSAvoidauthentication system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The authentication server acts as an intermediary between the access point and client devices for capability validation. It receives capability information from access points, validates against stored policies, and returns validation results, thereby distributing complexity away from access points and centralizing it in a dedicated server

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts capability validation as a separate, independent function from the basic authentication process. Capability information is extracted from association requests and validated separately against policy requirements, allowing the system to enforce capability requirements without fundamentally redesigning the existing authentication infrastructure

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If legacy devices are allowed to connect, then ease of operation is maintained for all devices, but advanced network features cannot be fully utilized

Engineering Contradiction:
Improvedevice connection simplicityVSAvoidfeature utilization reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies local quality by applying different connection policies to different client devices based on their capabilities. Devices that meet capability requirements gain access to advanced features, while legacy devices maintain basic connectivity, allowing each device to operate at its appropriate capability level without affecting others

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10057770B2Deauthenticate a client device during an association validation phase based on a plurality of capabilities associated with the client device
Publication Date: 2018.08.21 HEWLETT PACKARD ENTERPRISE DEV LP
  • US10057770B2 patent drawing
  • US10057770B2 patent drawing
  • US10057770B2 patent drawing

AI summary

Certain implementations of the present disclosure relates to a method, device, and medium to perform association validation of a client device's request during an association validation phase based on a plurality of capabilities associated with the client device. The network device receives an association request to connect to a wireless network. Then, the network device extracts a parameter specific to the client device from the association request, and determines a plurality of capabilities associated with the client device based on a value of the parameter. Then, the network device transmits the plurality of capabilities to an authentication server during an association validation phase, and receives an association validation decision corresponding to the connection request from an association validation/authentication server. If the association validation decision indicates that the client device is denied access to the wireless network, the network device deauthenticates the client device during the association validation phase.