Off-site Authentication for Standard Router Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional approaches to controlling user access to communications services in venues like hotels and conference centers require expensive, complex on-site gateways, which are costly and difficult to manage, especially for nomadic users who need access to the internet.

Innovation Solution

Implementing an off-site authentication system that uses standard on-site routers to forward unauthorized traffic to a cloud-based authentication system, where users are authenticated, and once authorized, their access is updated in the router's route map, allowing them to connect to external networks without the need for on-site packet modification or expensive gateways.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional on-site gateways are used to control user access, then user access control is achieved, but device complexity and cost increase significantly

Engineering Contradiction:
Improveuser access controlVSAvoidgateway complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication functionality from the on-site gateway and relocates it to an off-site authentication server. The gateway retains only basic routing functions, while the complex authentication logic, captive portal serving, and authorization management are performed remotely by the authentication server, thereby reducing on-site device complexity while maintaining access control reliability

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an off-site authentication server as an intermediary between the on-site gateway and external networks. This intermediary handles the complex authentication processes, serving captive portals to unauthorized users, verifying credentials, and managing authorization states, thereby eliminating the need for complex on-site gateway functionality

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If on-site gateways with captive portal functionality are deployed, then user authentication is enabled, but ease of operation and maintenance deteriorate

Engineering Contradiction:
Improveauthentication capabilityVSAvoidsystem management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The off-site authentication server automatically serves captive portal pages to unauthorized users based on their connection state. The system self-manages the authentication workflow by detecting unauthorized traffic, presenting the appropriate portal, collecting credentials, and updating gateway routing rules without requiring manual intervention, thereby improving ease of operation

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The off-site authentication server acts as a centralized intermediary that manages authentication for multiple users and gateways. It maintains user session states, handles credential verification, and dynamically updates gateway routing tables, thereby centralizing management operations and improving maintainability

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of manufacture

If standard routers are used instead of specialized gateways, then cost is reduced, but access control functionality must be simplified

Engineering Contradiction:
Improvedeployment costVSAvoidaccess control functionality
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent extracts the authentication functionality from the router/gateway device and relocates it to a separate off-site server. This allows the use of simple, inexpensive standard routers on-site while maintaining full authentication capability through the remote server, thereby reducing deployment cost without sacrificing access control functionality

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The off-site authentication server provides universal authentication services to multiple on-site gateways and users through standardized protocols. It handles various authentication methods, serves different types of captive portals, and manages diverse user scenarios, thereby enabling simple routers to provide comprehensive access control through the multi-functional remote server

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9917840B2Off-site user access control
Publication Date: 2018.03.13 GUEST TEK INTERACTIVE ENTERTAINMENT
  • US9917840B2 patent drawing
  • US9917840B2 patent drawing
  • US9917840B2 patent drawing

AI summary

Systems and methods are described for off-site user access control to communications services via a site-based communications network. Embodiments operate in context of sites, each having one or more site-based networks in communication with external networks via one or more on-site routers. User devices are provided with controlled access to those external networks via wired or wireless connections between those user devices and the site based networks. In some embodiments, on-site routers maintain route maps that indicate which user devices are authorized. Standard routing functions are used so that traffic from authorized devices is routed normally, while traffic from unauthorized devices is automatically forwarded to an off-site (e.g., cloud-based) authentication system. As devices become remotely authenticated, the off-site authentication system can remotely update route maps of the on-site routers to add those devices.