Dynamic Reserve WLAN for Authentication Failures
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In large-scale WLAN deployments, RADIUS server overload or unavailability leads to authentication failures and delayed access, frustrating users and network administrators, as strong authentication is typically required for network access.
Innovation Solution
An electronic device dynamically provides a reserve WLAN with a reserve SSID, allowing access to insensitive services using less secure pre-shared-key authentication when the primary authentication server is offline, ensuring continued network access without relying on the RADIUS server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If strong authentication (IEEE 802.1x) is required for network access, then network security is improved, but authentication failure and delayed access occur when RADIUS server is unavailable
Solution Approach 1:
The system performs preliminary authentication by caching user credentials and authorization policies before RADIUS server failure occurs. When the server becomes unavailable, the access point can immediately authenticate users using pre-fetched authentication data, eliminating the need to wait for server response during normal operation.
Solution Approach 2:
The system establishes a backup authentication mechanism using pre-shared keys as a fallback when the primary RADIUS server becomes unavailable. This cushioning approach ensures that network access can continue with reduced security measures rather than complete failure, accepting temporary degradation of security to maintain connectivity.
2Reliability
If RADIUS server is used for authentication, then authentication security is improved, but authentication failure occurs when server is overloaded or unavailable
Solution Approach 1:
The access point acts as an intermediary authentication server when the RADIUS server is unavailable. It uses pre-shared keys and cached authorization data to mediate authentication requests locally, allowing users to access insensitive services without direct RADIUS server involvement.
Solution Approach 2:
The system segments network services into sensitive and insensitive categories. When RADIUS server is unavailable, authentication for insensitive services can proceed through local pre-shared key authentication at the access point, while sensitive services continue to require RADIUS server authentication. This segmentation allows partial network functionality to be maintained.
3Ease of operation
If reserve WLAN with pre-shared-key authentication is provided, then network access availability is improved, but authentication security is reduced
Solution Approach 1:
The system applies different authentication security levels to different network services. Pre-shared key authentication is applied locally at the access point for insensitive services when RADIUS server is unavailable, while strong IEEE 802.1x authentication via RADIUS server is maintained for sensitive services. Each service area has the appropriate quality of authentication applied to it.
Data Source
AI summary
An electronic device (such as an access point) that dynamically provides a reserve wireless local area network (WLAN) having a reserve service set identifier (SSID) is described. During operation, the electronic device may provide a WLAN having an SSID, where access to services in a network via the WLAN is gated by authentication performed by a computer. Note that the computer may include a controller of the electronic device or an authentication computer. When the computer is offline or communication with the computer is unavailable, the electronic device may dynamically provide the reserve WLAN having the reserve SSID, where access to a subset of the services in the network via the reserve WLAN is gated by second authentication performed by the electronic device. Moreover, the services may include sensitive (or more-secure) and insensitive (or less-secure) services, and the subset of the services may include the insensitive services.


