Network Access Node Multiple User Detection via Intermediary Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Service providers and network operators face challenges in detecting when multiple users access a network through a single network access node, as existing techniques are often used to circumvent billing and authentication, making it difficult to accurately monitor and evaluate usage patterns.
Innovation Solution
Implementing a system that evaluates network traffic metrics, such as connection counts, web browsers, and operating systems, and uses passive and active checks, like cookie transmission and Netbios probes, to determine if multiple users are accessing the network through a single MAC address, enhancing detection reliability through multi-stage evaluations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If network address translation (NAT) and port address translation (PAT) are used to translate MAC addresses and IP addresses, then network resource efficiency is improved, but detection of multiple users accessing through a single access node becomes difficult
Solution Approach 1:
The system performs preliminary actions by transmitting identification data (such as cookies or Netbios probes) to user devices before final authentication. This allows the gateway to establish a mapping between the network access node's MAC address and the actual user device's MAC address in advance, enabling subsequent detection of multiple users even when NAT/PAT is employed.
Solution Approach 2:
The invention introduces an intermediary identification mechanism (cookies, Netbios probes, or other identification data) that acts as a mediator between the network access node and the gateway. This intermediary carries unique information that allows the gateway to distinguish between multiple user devices sharing a single access node, resolving the detection difficulty caused by NAT/PAT address translation.
2Ease of operation
If a single MAC address is used for authentication, then authentication simplicity is improved, but accuracy of user identification deteriorates
Solution Approach 1:
The authentication process is segmented into multiple stages: initial authentication using the network access node's MAC address, followed by transmission of unique identification data to each user device, and final verification at the gateway. This segmentation maintains the simplicity of initial MAC-based authentication while adding precision through device-specific identification data.
Solution Approach 2:
The system adds another dimension to user identification by introducing device-specific identification data (such as cookies or Netbios responses) beyond the single MAC address. This creates a multi-dimensional identification space where users are distinguished not just by the access node's MAC address but also by their unique device identifiers, thereby improving identification accuracy without complicating the base authentication mechanism.
Data Source
AI summary
Techniques are described for detecting use of a network access node by multiple users to gain access to a network. Packets are received from a network device in communication with the network access node. The packets are evaluated with reference to a plurality of metrics. Each of the metrics is independently representative of an estimated number of user devices from which the packets originate.


