Native Application Hotspot Bypassing Captive Portal Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Captive portal systems in communication networks require users to authenticate before accessing the internet, which can be inconvenient and disrupt the user experience, especially in scenarios where default captive portal behavior needs to be bypassed for specific applications or domains.

Innovation Solution

A native application connects to a communication network by sending requests to a specific IP address or URL that bypasses the default captive portal behavior, allowing users to access the network without authentication by identifying and interacting with the associated domain, thereby modifying the captive portal behavior to facilitate seamless access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If default captive portal behavior is used for network connection, then network security and authentication are ensured, but user convenience and access speed are reduced

Engineering Contradiction:
Improveuser convenienceVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies local quality by making the captive portal behavior application-specific rather than universal. Each application can have its own captive portal configuration, allowing some applications to bypass authentication while others require it. This is implemented through application-specific proxy settings and selective captive portal enforcement, enabling differentiated access control based on application needs.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts captive portal behavior based on application type, user preferences, and network conditions. The proxy server can dynamically redirect different applications to different authentication pages or allow direct access based on real-time policy decisions, making the authentication mechanism flexible rather than static.

Inventive Principle:
Principle #15Dynamics

2Reliability

If authentication process is required for network access, then network security is improved, but connection time and user experience are worsened

Engineering Contradiction:
Improvenetwork securityVSAvoidconnection time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-configuring application-specific proxy settings and authentication credentials before the user needs to connect. Applications can have pre-established authentication tokens or cached credentials that allow them to access the network without requiring real-time user authentication, reducing connection time while maintaining security through pre-validated access rights.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary proxy server that mediates between the client application and the authentication server. This intermediary can handle authentication requests in parallel, cache authentication results, and selectively forward traffic based on application requirements, thereby reducing the time penalty associated with authentication while maintaining security controls.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If captive portal behavior is bypassed for specific applications, then application functionality and user experience are improved, but network control and security oversight are reduced

Engineering Contradiction:
Improveapplication functionalityVSAvoidnetwork control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system implements local quality by allowing different captive portal behaviors for different applications. Each application can be configured with its own access policies, enabling some applications to bypass authentication while others must go through it. This selective approach maintains network control for critical applications while providing flexibility for user-friendly applications.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The proxy server incorporates feedback mechanisms that monitor application behavior and network conditions in real-time. Based on this feedback, the system can dynamically adjust authentication requirements, allowing applications to bypass captive portal behavior when safe and maintaining security oversight when needed, thus balancing adaptability with control.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3017632B1Native application hotspot
Publication Date: 2019.05.15 META PLATFORMS INC
  • EP3017632B1 patent drawingFigure 1
  • EP3017632B1 patent drawingFigure 2
  • EP3017632B1 patent drawingFigure 3

AI summary

In one embodiment, a method includes detecting interception of data sent by the computing device to a first network resource through a communication network. The first network resource corresponds to a particular domain of the communication network. The method also includes determining whether the communication network is administered by the particular domain; and automatically generating a request to access the communication network that identifies a second network resource based at least in part on the determination. The second network resource is configured to authenticate a user to the particular domain of the communication network. The method also includes sending the request to the second network resource to access the communication network.