Wireless LAN Access Point Authentication-Based Traffic Segregation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for distinguishing between guest and local users in wireless LANs require separate access points or maintenance of hardware databases, which are inefficient and inconvenient.

Innovation Solution

A method that uses an authentication server to determine the status of users seeking access at a single access point, routing traffic accordingly, allowing both guests and local users to access the wireless LAN without separate access points, using IEEE 802.1x or web browser-based authentication to differentiate between them.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate access points are used for guests and local users, then traffic segregation is achieved, but device complexity and infrastructure cost increase

Engineering Contradiction:
Improvetraffic segregationVSAvoidaccess point infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines guest access and local user access into a single access point by using authentication-based differentiation. The access point authenticates users and routes their traffic differently based on their status (guest or local user), eliminating the need for separate physical access points while maintaining proper traffic segregation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces an authentication server as an intermediary that determines user status and provides routing information to the access point. This mediator enables the access point to differentiate between guests and local users without requiring separate hardware infrastructure, resolving the contradiction between traffic segregation and device complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If MAC address-based distinction is used, then user identification is achieved, but ease of operation deteriorates due to registration requirements

Engineering Contradiction:
Improveuser identificationVSAvoiduser access process
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent changes the identification parameter from hardware-based (MAC address) to authentication-based (credentials verified by authentication server). This allows local users to access the network using their existing credentials without registering their wireless cards, significantly improving ease of operation while maintaining the ability to distinguish between users.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If authentication-based routing is implemented, then traffic segregation is improved, but device complexity increases due to authentication server requirements

Engineering Contradiction:
Improvetraffic routing accuracyVSAvoidauthentication infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the access point multi-functional by enabling it to perform both authentication and routing functions based on user status. The single access point handles both guest and local user connections, authenticates them, and routes their traffic appropriately, reducing the need for additional dedicated infrastructure while improving routing accuracy.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8085740B2Techniques for offering seamless accesses in enterprise hot spots for both guest users and local users
Publication Date: 2011.12.27 INTERDIGITAL CE PATENT HOLDINGS SAS
  • US8085740B2 patent drawing
  • US8085740B2 patent drawing

AI summary

A wireless Local Area Network (LAN 11) capable of providing “enterprise guest” hosting includes at least one an e-open wireless LAN access point (15) that provides access to both guests and local users. Upon receipt of a request for access, the access point forwards the request to an authentication proxy. The authentication proxy then authenticates the party requesting access in accordance with that party's status (that is, whether the party is a local user or guest). Upon successful authentication, the network routes the traffic from a local user differently as compared to that for a guest. For example traffic from guests goes to gateway for receipt in an external network such as the Internet, whereas traffic from the local user goes to a local network, e.g., a corporate intranet. In this way, the Wireless LAN 11, after ascertaining the status of the party requesting access, can limit guest traffic according to the guest access policy.