Network Access Node Multiple User Detection via Intermediary Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Service providers and network operators face challenges in detecting when multiple users access a network through a single network access node, as existing techniques are often used to circumvent billing and authentication, making it difficult to accurately monitor and evaluate usage patterns.

Innovation Solution

Implementing a system that evaluates network traffic metrics, such as connection counts, web browsers, and operating systems, and uses passive and active checks, like cookie transmission and Netbios probes, to determine if multiple users are accessing the network through a single MAC address, enhancing detection reliability through multi-stage evaluations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If network address translation (NAT) and port address translation (PAT) are used to translate MAC addresses and IP addresses, then network resource efficiency is improved, but detection of multiple users accessing through a single access node becomes difficult

Engineering Contradiction:
Improvenetwork resource efficiencyVSAvoiddetection of multiple users
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The system performs preliminary actions by transmitting identification data (such as cookies or Netbios probes) to user devices before final authentication. This allows the gateway to establish a mapping between the network access node's MAC address and the actual user device's MAC address in advance, enabling subsequent detection of multiple users even when NAT/PAT is employed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention introduces an intermediary identification mechanism (cookies, Netbios probes, or other identification data) that acts as a mediator between the network access node and the gateway. This intermediary carries unique information that allows the gateway to distinguish between multiple user devices sharing a single access node, resolving the detection difficulty caused by NAT/PAT address translation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If a single MAC address is used for authentication, then authentication simplicity is improved, but accuracy of user identification deteriorates

Engineering Contradiction:
Improveauthentication simplicityVSAvoiduser identification accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The authentication process is segmented into multiple stages: initial authentication using the network access node's MAC address, followed by transmission of unique identification data to each user device, and final verification at the gateway. This segmentation maintains the simplicity of initial MAC-based authentication while adding precision through device-specific identification data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system adds another dimension to user identification by introducing device-specific identification data (such as cookies or Netbios responses) beyond the single MAC address. This creates a multi-dimensional identification space where users are distinguished not just by the access node's MAC address but also by their unique device identifiers, thereby improving identification accuracy without complicating the base authentication mechanism.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS7474617B2Detection of multiple users of a network access node
Publication Date: 2009.01.06 GUEST TEK INTERACTIVE ENTERTAINMENT
  • US7474617B2 patent drawing
  • US7474617B2 patent drawing
  • US7474617B2 patent drawing

AI summary

Techniques are described for detecting use of a network access node by multiple users to gain access to a network. Packets are received from a network device in communication with the network access node. The packets are evaluated with reference to a plurality of metrics. Each of the metrics is independently representative of an estimated number of user devices from which the packets originate.