Multiple Authenticated Identities for Single Wireless Association

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional wireless networks can only maintain a single authenticated session per link-layer association, limiting the ability to concurrently access multiple network services with different identities, which is a challenge in both 3GPP and 5G architectures due to the binding of layer-2 identities to a single authenticated identity.

Innovation Solution

The solution involves establishing multiple authenticated sessions on the same link-layer association using unique virtual MAC addresses and distinct identities, allowing client devices to connect to different networks with different credentials, thereby enabling concurrent access to various services without the need for Deep Packet Inspection or other expensive traffic treatment tools.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a single authenticated session is maintained per link-layer association, then network security and policy enforcement are simplified, but the ability to concurrently access multiple network services with different identities is limited

Engineering Contradiction:
Improveability to access multiple network services with different identitiesVSAvoidsession management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the single authenticated session into multiple virtual sessions by introducing virtual MAC addresses. Each virtual MAC address represents a distinct authenticated session with its own identity, allowing the client device to concurrently access multiple network services with different identities while maintaining a single physical link-layer association. This segmentation resolves the contradiction by enabling multi-identity access without requiring multiple physical connections.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces virtual MAC addresses as intermediaries between the client device and the network services. These virtual MAC addresses act as mediators that enable the client to present different identities to different network services while maintaining a single authenticated association with the access point. The virtual MAC addresses bridge the gap between the single physical connection and multiple identity requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If multiple authenticated sessions are established on the same link-layer association, then concurrent access to multiple services is enabled, but policy enforcement and traffic management become more complex

Engineering Contradiction:
Improveconcurrent service access capabilityVSAvoidpolicy enforcement complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent creates virtual copies of the MAC address (virtual MAC addresses) to represent different authenticated sessions. Each virtual MAC address is a copy that maintains the essential identifying characteristics needed for authentication and policy enforcement, but allows for distinct session management. This copying approach enables concurrent service access while keeping policy enforcement manageable through virtualization rather than requiring complex multi-connection management.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If Deep Packet Inspection or expensive traffic treatment tools are used to manage multiple identities, then service segmentation and policy enforcement are achieved, but system cost and complexity increase

Engineering Contradiction:
Improveservice segmentation capabilityVSAvoidtraffic treatment tool complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent replaces the mechanical system of Deep Packet Inspection and expensive traffic treatment tools with a virtualization-based approach using virtual MAC addresses. Instead of inspecting packet contents to identify and manage different services, the system uses virtual MAC addresses to inherently identify and segregate traffic belonging to different authenticated sessions. This substitution eliminates the need for complex DPI mechanisms while achieving the same service segmentation and policy enforcement goals.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11818572B2Multiple authenticated identities for a single wireless association
Publication Date: 2023.11.14 CISCO TECHNOLOGY INC
  • US11818572B2 patent drawing
  • US11818572B2 patent drawing
  • US11818572B2 patent drawing

AI summary

Multiple authenticated identities for a single wireless association may be provided. First, an Access Point (AP) may provide an association with a client device. The AP may then establish, on the association, a first authenticated session for the client device based on a first media access control (MAC) address and a first identity. Next, the AP may establish, on same the association, a second authenticated session for the client device based on a second MAC address and a second identity.