Emergency SSID Access Control for WLAN Guest Terminals

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

WLANs face challenges in providing reliable and secure emergency access for both guest and authorized terminals to telecommunications services, especially in handling real-time applications like VoWLAN, while ensuring the same voice quality and reliability as legacy PSTN or GSM systems, and meeting regulatory requirements for emergency call connectivity.

Innovation Solution

A method is introduced that allows terminals to access a LAN via dedicated emergency SSIDs, using an access control function to admit data packets to the LAN, with features like DHCP-based destination address acquisition, NAT for routing, and multicast addressing, ensuring secure and reliable emergency call routing to a PSAP, independent of specific signaling schemes, and supporting multiple WLAN access points.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If guest terminals are restricted from accessing corporate LANs to maintain security, then network security is improved, but emergency access capability deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoidemergency access capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the network access by creating a separate emergency SSID (service set identifier) that is distinct from the regular corporate WLAN. This emergency SSID provides a dedicated access path for emergency calls that bypasses normal security restrictions, while the main corporate network maintains its security policies. The segmentation allows guest terminals to access emergency services without compromising overall network security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary access point that specifically handles emergency SSID connections. This access point acts as a mediator between guest terminals and the emergency calling infrastructure, allowing emergency access while maintaining isolation from the core corporate network. The intermediary enables emergency functionality without requiring guest terminals to have full network access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If emergency SSID access is opened to all terminals including guests, then emergency access capability is improved, but network security control deteriorates

Engineering Contradiction:
Improveemergency access capabilityVSAvoidaccess control complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by configuring specific access points to handle emergency SSID connections with relaxed security policies, while other access points continue to enforce strict corporate security. The emergency functionality is localized to specific network segments and access points rather than being applied network-wide, allowing differentiated access control based on location and function.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements preliminary action by pre-configuring emergency SSIDs and associated access points before emergencies occur. The emergency access infrastructure is prepared in advance with predetermined security policies and routing rules, so that when an emergency call is initiated, the terminal can immediately connect without requiring complex real-time authentication or authorization decisions.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If multiple emergency SSIDs are defined for different scenarios, then adaptability is improved, but device complexity increases

Engineering Contradiction:
Improveemergency scenario coverageVSAvoidSSID configuration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamics by allowing the emergency SSID configuration to be dynamically adjusted based on the situation. Rather than requiring static pre-configuration of multiple SSIDs for every possible emergency scenario, the system can activate or deactivate specific emergency SSIDs as needed, and terminals can dynamically select appropriate emergency access points based on their location and the nature of the emergency.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS7877785B2Method of providing a guest terminal with emergency access to a WLAN
Publication Date: 2011.01.25 ALCATEL LUCENT SA
  • US7877785B2 patent drawing
  • US7877785B2 patent drawing
  • US7877785B2 patent drawing

AI summary

The invention concerns a method of providing a terminal (10) with an emergency access over a WLAN (2) to a LAN (3), and a communication system (1) to execute this method. The LAN (3) comprises one or more access points (20) and an access control function (21) which admits data packets from users of the WLAN (2) associated with a first SSID to the LAN (3). One or more emergency SSIDs dedicated to allow access to the LAN (3) in an emergency case are defined. An emergency call is initiated by sending data packets from the terminal (10) associated with a selected emergency SSID to one of the one or more access points (20). The access control function (21) admits the data packets from the terminal (10) associated with the selected emergency SSID to the LAN (3). The data packets from the terminal (10) associated with the selected emergency SSID are routed, after admission to the LAN (3), to an emergency answering point (60).