Wireless LAN Access Point Authentication-Based Traffic Segregation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for distinguishing between guest and local users in wireless LANs require separate access points or maintenance of hardware databases, which are inefficient and inconvenient.
Innovation Solution
A method that uses an authentication server to determine the status of users seeking access at a single access point, routing traffic accordingly, allowing both guests and local users to access the wireless LAN without separate access points, using IEEE 802.1x or web browser-based authentication to differentiate between them.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate access points are used for guests and local users, then traffic segregation is achieved, but device complexity and infrastructure cost increase
Solution Approach 1:
The patent combines guest access and local user access into a single access point by using authentication-based differentiation. The access point authenticates users and routes their traffic differently based on their status (guest or local user), eliminating the need for separate physical access points while maintaining proper traffic segregation.
Solution Approach 2:
The patent introduces an authentication server as an intermediary that determines user status and provides routing information to the access point. This mediator enables the access point to differentiate between guests and local users without requiring separate hardware infrastructure, resolving the contradiction between traffic segregation and device complexity.
2Adaptability or versatility
If MAC address-based distinction is used, then user identification is achieved, but ease of operation deteriorates due to registration requirements
Solution Approach 1:
The patent changes the identification parameter from hardware-based (MAC address) to authentication-based (credentials verified by authentication server). This allows local users to access the network using their existing credentials without registering their wireless cards, significantly improving ease of operation while maintaining the ability to distinguish between users.
3Reliability
If authentication-based routing is implemented, then traffic segregation is improved, but device complexity increases due to authentication server requirements
Solution Approach 1:
The patent makes the access point multi-functional by enabling it to perform both authentication and routing functions based on user status. The single access point handles both guest and local user connections, authenticates them, and routes their traffic appropriately, reducing the need for additional dedicated infrastructure while improving routing accuracy.
Data Source
AI summary
A wireless Local Area Network (LAN 11) capable of providing “enterprise guest” hosting includes at least one an e-open wireless LAN access point (15) that provides access to both guests and local users. Upon receipt of a request for access, the access point forwards the request to an authentication proxy. The authentication proxy then authenticates the party requesting access in accordance with that party's status (that is, whether the party is a local user or guest). Upon successful authentication, the network routes the traffic from a local user differently as compared to that for a guest. For example traffic from guests goes to gateway for receipt in an external network such as the Internet, whereas traffic from the local user goes to a local network, e.g., a corporate intranet. In this way, the Wireless LAN 11, after ascertaining the status of the party requesting access, can limit guest traffic according to the guest access policy.

