Unified Guest Access Tunneling for Wired Wireless Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network schemes face challenges in providing unified and scalable guest access for both wired and wireless devices, as they require different configurations and architectures, leading to inefficiencies in managing mobility and security policies across mobility sub-domains.
Innovation Solution
The implementation of a network infrastructure architecture that includes mobility sub-domains with mobility controllers and tunneling endpoints, which establish tunnels to guest controllers for managing guest access, ensuring consistent policies and seamless roaming across sub-domains, using a unified approach for both wired and wireless traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If different configurations and architectures are used for wired and wireless guest access, then guest access can be supported for both device types, but system complexity increases and scalability is reduced
Solution Approach 1:
The patent implements a universal tunneling-based architecture where both wired and wireless guest devices are handled through the same guest controller and tunneling mechanism. The guest controller receives tunneling traffic from both wired access switches and wireless access points, applying unified guest access policies to all device types, thereby eliminating the need for separate configuration architectures while maintaining broad compatibility
Solution Approach 2:
The patent introduces a guest controller as an intermediary component that mediates between access switches/APs and the core network for both wired and wireless guest devices. This intermediary receives tunneling traffic from diverse sources, performs centralized authentication and policy enforcement, and forwards traffic appropriately, simplifying the overall system architecture by providing a single point of control for all guest access scenarios
2Adaptability or versatility
If different architectures are used for wired and wireless guest access, then both access types can be supported, but mobility management becomes less efficient
Solution Approach 1:
The tunneling mechanism implemented in the patent provides a universal mobility management approach that works for both wired and wireless guest devices. When a guest device moves between access points or switches, the tunnel is dynamically updated to maintain connectivity, providing seamless roaming experience with consistent policy enforcement regardless of the access type or location within the network
3Reliability
If separate configurations are used for wired and wireless guest access, then specific requirements can be met, but security policy enforcement becomes more complex
Solution Approach 1:
The guest controller serves as a centralized security policy enforcement point that receives all guest traffic through tunnels from both wired and wireless access devices. It implements unified authentication, authorization, and accounting (AAA) functions, applying consistent security policies to all guest devices regardless of access type, thereby simplifying policy management while maintaining robust security controls through centralized oversight
Data Source
AI summary
Techniques are provided to enable a support for guest access of devices in a network. At a controller apparatus in a first mobility sub-domain of a network comprising a plurality of mobility sub-domains, a request message containing a request for guest network access for a device is received from a first access switch in the first mobility sub-domain. The controller apparatus forwards the request message to a guest controller. At a tunneling endpoint apparatus in the first mobility sub-domain, a tunnel is established to the guest controller to carry traffic between the device and the guest controller. Traffic for the device passes in a tunnel between the first access switch and the tunneling endpoint apparatus in the first mobility sub-domain, through the tunneling endpoint apparatus in the first mobility sub-domain and in the tunnel between the routing apparatus in the first mobility sub-domain and the guest controller.


