Off-site Authentication for Standard Router Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional approaches to controlling user access to communications services in venues like hotels and conference centers require expensive, complex on-site gateways, which are costly and difficult to manage, especially for nomadic users who need access to the internet.
Innovation Solution
Implementing an off-site authentication system that uses standard on-site routers to forward unauthorized traffic to a cloud-based authentication system, where users are authenticated, and once authorized, their access is updated in the router's route map, allowing them to connect to external networks without the need for on-site packet modification or expensive gateways.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional on-site gateways are used to control user access, then user access control is achieved, but device complexity and cost increase significantly
Solution Approach 1:
The patent extracts the authentication functionality from the on-site gateway and relocates it to an off-site authentication server. The gateway retains only basic routing functions, while the complex authentication logic, captive portal serving, and authorization management are performed remotely by the authentication server, thereby reducing on-site device complexity while maintaining access control reliability
Solution Approach 2:
The patent introduces an off-site authentication server as an intermediary between the on-site gateway and external networks. This intermediary handles the complex authentication processes, serving captive portals to unauthorized users, verifying credentials, and managing authorization states, thereby eliminating the need for complex on-site gateway functionality
2Reliability
If on-site gateways with captive portal functionality are deployed, then user authentication is enabled, but ease of operation and maintenance deteriorate
Solution Approach 1:
The off-site authentication server automatically serves captive portal pages to unauthorized users based on their connection state. The system self-manages the authentication workflow by detecting unauthorized traffic, presenting the appropriate portal, collecting credentials, and updating gateway routing rules without requiring manual intervention, thereby improving ease of operation
Solution Approach 2:
The off-site authentication server acts as a centralized intermediary that manages authentication for multiple users and gateways. It maintains user session states, handles credential verification, and dynamically updates gateway routing tables, thereby centralizing management operations and improving maintainability
3Ease of manufacture
If standard routers are used instead of specialized gateways, then cost is reduced, but access control functionality must be simplified
Solution Approach 1:
The patent extracts the authentication functionality from the router/gateway device and relocates it to a separate off-site server. This allows the use of simple, inexpensive standard routers on-site while maintaining full authentication capability through the remote server, thereby reducing deployment cost without sacrificing access control functionality
Solution Approach 2:
The off-site authentication server provides universal authentication services to multiple on-site gateways and users through standardized protocols. It handles various authentication methods, serves different types of captive portals, and manages diverse user scenarios, thereby enabling simple routers to provide comprehensive access control through the multi-functional remote server
Data Source
AI summary
Systems and methods are described for off-site user access control to communications services via a site-based communications network. Embodiments operate in context of sites, each having one or more site-based networks in communication with external networks via one or more on-site routers. User devices are provided with controlled access to those external networks via wired or wireless connections between those user devices and the site based networks. In some embodiments, on-site routers maintain route maps that indicate which user devices are authorized. Standard routing functions are used so that traffic from authorized devices is routed normally, while traffic from unauthorized devices is automatically forwarded to an off-site (e.g., cloud-based) authentication system. As devices become remotely authenticated, the off-site authentication system can remotely update route maps of the on-site routers to add those devices.


