Multipoint Tunneling Authentication for Wireless Access Point Roaming

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless digital networks, mobile nodes and access points frequently changing locations lead to delays in updating location information and authentication, impacting network security, speed, and reliability, particularly when mobile nodes move between access points or update attributes.

Innovation Solution

Implementing a multipoint tunneling communication mode with dynamic management of tunnels and half-tunnels, incorporating IP authentication, multicast, DHCP, and ARP, to adapt to changing network topologies and ensure continuous service by creating and modifying routing configurations in response to discovered hosts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If mobile nodes and access points frequently change locations to provide roaming capability, then network coverage and accessibility are improved, but delays occur in updating location information and authentication

Engineering Contradiction:
Improveroaming capabilityVSAvoidlocation update delay
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-establishing tunnels between access points and the network core before mobile nodes actually move between them. When an access point detects a mobile node, it proactively sets up tunneling paths in advance, so that when roaming occurs, the authentication and location update processes can proceed without significant delay because the infrastructure is already in place.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces tunneling protocols and intermediate routing mechanisms as mediators between mobile nodes and the network core. These intermediaries handle the authentication and location update processes, allowing mobile nodes to roam between access points without direct re-authentication to the core network, thereby reducing the time loss associated with frequent location changes.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication processes are performed frequently when mobile nodes move between access points, then network security is improved, but network speed and reliability deteriorate due to additional delays

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts the authentication process from the frequent roaming events. Instead of performing full authentication every time a mobile node moves between access points, the system separates the initial authentication (performed when the mobile node first joins the network) from the subsequent handover processes. The tunneling mechanism allows mobile nodes to move between access points without triggering repeated authentication cycles, thus maintaining security while preserving network speed.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The tunneling infrastructure establishes continuous data paths between mobile nodes and the network core that persist across access point boundaries. This continuity allows data flow to maintain steady throughput even as mobile nodes roam, because the authenticated session and routing paths remain active throughout the movement, preventing interruptions that would otherwise occur during re-authentication.

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If location information is updated and propagated to all network components, then network reliability is improved, but time consumption increases due to propagation delays

Engineering Contradiction:
Improvenetwork reliabilityVSAvoidpropagation delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the network into tunnel-based domains where location information is propagated locally within each tunnel segment rather than being broadcast to all network components. When a mobile node's location changes, the update is propagated only through the relevant tunnel paths to the necessary routing components, rather than flooding the entire network. This segmentation dramatically reduces propagation delay while maintaining the reliability needed for proper routing.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7616613B2Internet protocol authentication in layer-3 multipoint tunneling for wireless access points
Publication Date: 2009.11.10 CISCO TECHNOLOGY INC
  • US7616613B2 patent drawing
  • US7616613B2 patent drawing
  • US7616613B2 patent drawing

AI summary

Enhanced tunnel communication mode creation, management and tuning in a network that includes wireless access points (APs) and user authentication. Tunnels can be dynamically managed to adapt to the changing topology of a network with APs. User devices such as mobile phones, laptop computers, personal digital assistants, or other devices can be added or dropped from an assigned AP. APs, routers, switches or other devices can also be added, removed, or modified in their network characteristics. Special control is also provided for IP multicast, Dynamic Host Configuration Protocol (DHCP), Address Resolution Protocol (ARP) and other network features.