Multiple Authenticated Identities for Single Wireless Association
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional wireless networks can only maintain a single authenticated session per link-layer association, limiting the ability to concurrently access multiple network services with different identities, which is a challenge in both 3GPP and 5G architectures due to the binding of layer-2 identities to a single authenticated identity.
Innovation Solution
The solution involves establishing multiple authenticated sessions on the same link-layer association using unique virtual MAC addresses and distinct identities, allowing client devices to connect to different networks with different credentials, thereby enabling concurrent access to various services without the need for Deep Packet Inspection or other expensive traffic treatment tools.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a single authenticated session is maintained per link-layer association, then network security and policy enforcement are simplified, but the ability to concurrently access multiple network services with different identities is limited
Solution Approach 1:
The patent segments the single authenticated session into multiple virtual sessions by introducing virtual MAC addresses. Each virtual MAC address represents a distinct authenticated session with its own identity, allowing the client device to concurrently access multiple network services with different identities while maintaining a single physical link-layer association. This segmentation resolves the contradiction by enabling multi-identity access without requiring multiple physical connections.
Solution Approach 2:
The patent introduces virtual MAC addresses as intermediaries between the client device and the network services. These virtual MAC addresses act as mediators that enable the client to present different identities to different network services while maintaining a single authenticated association with the access point. The virtual MAC addresses bridge the gap between the single physical connection and multiple identity requirements.
2Productivity
If multiple authenticated sessions are established on the same link-layer association, then concurrent access to multiple services is enabled, but policy enforcement and traffic management become more complex
Solution Approach 1:
The patent creates virtual copies of the MAC address (virtual MAC addresses) to represent different authenticated sessions. Each virtual MAC address is a copy that maintains the essential identifying characteristics needed for authentication and policy enforcement, but allows for distinct session management. This copying approach enables concurrent service access while keeping policy enforcement manageable through virtualization rather than requiring complex multi-connection management.
3Adaptability or versatility
If Deep Packet Inspection or expensive traffic treatment tools are used to manage multiple identities, then service segmentation and policy enforcement are achieved, but system cost and complexity increase
Solution Approach 1:
The patent replaces the mechanical system of Deep Packet Inspection and expensive traffic treatment tools with a virtualization-based approach using virtual MAC addresses. Instead of inspecting packet contents to identify and manage different services, the system uses virtual MAC addresses to inherently identify and segregate traffic belonging to different authenticated sessions. This substitution eliminates the need for complex DPI mechanisms while achieving the same service segmentation and policy enforcement goals.
Data Source
AI summary
Multiple authenticated identities for a single wireless association may be provided. First, an Access Point (AP) may provide an association with a client device. The AP may then establish, on the association, a first authenticated session for the client device based on a first media access control (MAC) address and a first identity. Next, the AP may establish, on same the association, a second authenticated session for the client device based on a second MAC address and a second identity.


