Dynamic Reserve WLAN for Authentication Failures

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In large-scale WLAN deployments, RADIUS server overload or unavailability leads to authentication failures and delayed access, frustrating users and network administrators, as strong authentication is typically required for network access.

Innovation Solution

An electronic device dynamically provides a reserve WLAN with a reserve SSID, allowing access to insensitive services using less secure pre-shared-key authentication when the primary authentication server is offline, ensuring continued network access without relying on the RADIUS server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If strong authentication (IEEE 802.1x) is required for network access, then network security is improved, but authentication failure and delayed access occur when RADIUS server is unavailable

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary authentication by caching user credentials and authorization policies before RADIUS server failure occurs. When the server becomes unavailable, the access point can immediately authenticate users using pre-fetched authentication data, eliminating the need to wait for server response during normal operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system establishes a backup authentication mechanism using pre-shared keys as a fallback when the primary RADIUS server becomes unavailable. This cushioning approach ensures that network access can continue with reduced security measures rather than complete failure, accepting temporary degradation of security to maintain connectivity.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

2Reliability

If RADIUS server is used for authentication, then authentication security is improved, but authentication failure occurs when server is overloaded or unavailable

Engineering Contradiction:
Improveauthentication securityVSAvoidnetwork access availability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The access point acts as an intermediary authentication server when the RADIUS server is unavailable. It uses pre-shared keys and cached authorization data to mediate authentication requests locally, allowing users to access insensitive services without direct RADIUS server involvement.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments network services into sensitive and insensitive categories. When RADIUS server is unavailable, authentication for insensitive services can proceed through local pre-shared key authentication at the access point, while sensitive services continue to require RADIUS server authentication. This segmentation allows partial network functionality to be maintained.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If reserve WLAN with pre-shared-key authentication is provided, then network access availability is improved, but authentication security is reduced

Engineering Contradiction:
Improvenetwork access availabilityVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system applies different authentication security levels to different network services. Pre-shared key authentication is applied locally at the access point for insensitive services when RADIUS server is unavailable, while strong IEEE 802.1x authentication via RADIUS server is maintained for sensitive services. Each service area has the appropriate quality of authentication applied to it.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20240259800A1Dynamic Reserve WLAN Based on Authentication Availability
Publication Date: 2024.08.01 RUCKUS IP HOLDINGS LLC
  • US20240259800A1 patent drawing
  • US20240259800A1 patent drawing
  • US20240259800A1 patent drawing

AI summary

An electronic device (such as an access point) that dynamically provides a reserve wireless local area network (WLAN) having a reserve service set identifier (SSID) is described. During operation, the electronic device may provide a WLAN having an SSID, where access to services in a network via the WLAN is gated by authentication performed by a computer. Note that the computer may include a controller of the electronic device or an authentication computer. When the computer is offline or communication with the computer is unavailable, the electronic device may dynamically provide the reserve WLAN having the reserve SSID, where access to a subset of the services in the network via the reserve WLAN is gated by second authentication performed by the electronic device. Moreover, the services may include sensitive (or more-secure) and insensitive (or less-secure) services, and the subset of the services may include the insensitive services.