Inter-Subnet Pre-Authentication via Wireless Location Register

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The IEEE 802.11i standard for wireless local area networks (WLAN) does not effectively enable pre-authentication across different subnets, leading to issues with roaming associations and network connectivity, as access points may not know how to locate or route to access points with different radio MAC addresses within other subnets.

Innovation Solution

A method and system utilizing a wireless domain server (WDS) and wireless location register (WLR) service layer to resolve radio MAC addresses across subnets, allowing pre-authentication requests to be forwarded and processed through a hierarchical network structure, ensuring secure communication between authenticators across different subnets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If pre-authentication requests are sent to access points on different subnets using radio MAC addresses, then pre-authentication capability is improved, but routing and location resolution become impossible

Engineering Contradiction:
Improvepre-authentication capabilityVSAvoidrouting and location resolution
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent introduces a location register as an intermediary component that maintains a mapping between radio MAC addresses and IP addresses of access points. When a pre-authentication request needs to be routed to an AP on a different subnet, the requesting AP queries the location register to obtain the target AP's IP address, enabling proper routing across subnets. This mediator resolves the contradiction by providing the missing location information without requiring direct knowledge at the AP level.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent adds a new dimension to the addressing system by introducing IP addresses as a second layer identifier alongside radio MAC addresses. While radio MAC addresses identify the physical wireless interface, IP addresses provide network layer routing information. This dimensional addition allows the system to simultaneously maintain wireless identity (MAC) and network routing (IP), resolving the contradiction between pre-authentication capability and routability.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Device complexity

If access points use radio MAC addresses for identification, then wireless station identification is simplified, but cross-subnet communication becomes impossible

Engineering Contradiction:
Improveidentification complexityVSAvoidcross-subnet communication
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent makes the access point identification system multi-functional by using radio MAC addresses for wireless station identification (original function) and IP addresses for network routing (additional function). The location register enables this dual functionality by mapping between the two address types, allowing the same identification infrastructure to serve both wireless management and network communication purposes.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent adds the IP address dimension to the existing radio MAC address identification system. This allows access points to maintain simple radio MAC-based identification for wireless operations while simultaneously supporting cross-subnet communication through IP-based routing. The location register bridges these two dimensions, enabling both simple identification and complex communication.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Device complexity

If pre-authentication is limited to the same subnet, then routing is simplified, but roaming performance deteriorates

Engineering Contradiction:
Improverouting complexityVSAvoidroaming performance
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The location register acts as a mediator that enables cross-subnet pre-authentication without requiring complex routing logic at the access point level. By centralizing the address resolution function in the location register, the system maintains simple AP routing (APs only need to communicate within their subnet) while still achieving cross-subnet pre-authentication through the intermediary's address translation service.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the address resolution function from the pre-authentication process. Instead of requiring access points to perform complex cross-subnet routing, the system divides the functionality: APs handle local pre-authentication requests, while the location register handles cross-subnet address resolution. This segmentation allows each component to operate simply while achieving complex overall functionality.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7477747B2Method and system for inter-subnet pre-authentication
Publication Date: 2009.01.13 CISCO TECHNOLOGY INC
  • US7477747B2 patent drawing
  • US7477747B2 patent drawing
  • US7477747B2 patent drawing

AI summary

A method and system for performing pre-authentication across inter-subnets. A pre-authentication request is received by a first access point associated with a first subnet from a mobile node requesting that is requesting pre-authentication with a second access point associated with a second subnet. The request is forwarded by the access point to a first authenticator that is the authenticator for the first subnet. The first authenticator obtains from a root infrastructure node the address for a second authenticator that is the authenticator for the second access point. The first authenticator then pre-authenticates the mobile node with the second authenticator by sending a message to the address for the second authenticator.