Cloud-Based WLAN User Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing wireless local area networks (WLANs) with varying user access levels is burdensome due to hardware-based management, especially when multiple users with different access levels share a common client device, leading to complex network resource and user management.

Innovation Solution

Implementing cloud-based user identities to manage access levels, allowing WLAN owners to impose internet access controls, bandwidth limitations, and quality of service rules based on user accounts rather than device-specific configurations, using a server to authenticate user credentials and configure wireless client devices accordingly.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If hardware-based management with multiple SSIDs and access profiles is used to create different levels of network access, then user access control capability is improved, but administrative overhead and device complexity increase significantly

Engineering Contradiction:
Improveuser access control capabilityVSAvoidadministrative overhead
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent replaces hardware-based access control mechanisms (multiple SSIDs, device-specific profiles) with cloud-based credential verification. The authentication system moves from local hardware configuration to remote server-based identity management, substituting mechanical/configurational complexity with software-based credential validation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a cloud-based authentication server as an intermediary between the wireless access point and users. This mediator handles credential verification and access level determination centrally, eliminating the need for complex local hardware configurations and reducing administrative overhead at the network edge.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If device-specific configurations are used for each client device, then access control precision is improved, but management complexity and time consumption increase

Engineering Contradiction:
Improveaccess control precisionVSAvoidmanagement time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements universal user credentials that work across multiple devices and networks. Instead of requiring separate device-specific configurations, a single user credential can authenticate across different client devices while maintaining precise access control based on user identity rather than device identity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses cloud-stored user credential profiles that can be copied or replicated across multiple authentication sessions and devices. The access control policy is copied from the central server to multiple access points, ensuring consistent precision without requiring manual reconfiguration at each device.

Inventive Principle:
Principle #26Copying

3Productivity

If multiple users share a common client device, then device utilization efficiency is improved, but network resource allocation and access control become complicated

Engineering Contradiction:
Improvedevice utilization efficiencyVSAvoidnetwork resource management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent applies local quality by associating specific access levels and network resource allocations with individual user credentials rather than the shared device. Each user maintains their own access profile and permissions, allowing differentiated control even when multiple users share the same physical device.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent segments the shared device's network access into distinct user-level authentication sessions. Each user credentials creates a separate logical access context, dividing the monolithic device-level access control into finer-grained user-level segments that can be independently managed.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3178243B1Per-user wireless traffic handling
Publication Date: 2021.01.27 GOOGLE LLC
  • EP3178243B1 patent drawingFigure 1
  • EP3178243B1 patent drawingFigure 2
  • EP3178243B1 patent drawingFigure 3

AI summary

A method and system for accessing a wireless local area network are provided. The method and system include receiving, from a wireless client device, an authentication request comprising credentials for a user account of a cloud-based service and forwarding the authentication request to a server associated with the cloud-based service for authentication of the credentials. An authentication response and a configuration profile associated with the user account of the cloud-based service is received from the server. The authentication response is forwarded to the wireless client device. An association request is received from the wireless client device and the wireless client device is associated with the wireless local area network in response to the association request. The association of the wireless client device with the wireless local area network is configured according to the received configuration profile associated with the user account.