Passpoint Profile Expiration Control for Zombie Wi-Fi Accounts
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In community-wide managed Wi-Fi networks, inactive or invalid Passpoint profiles, known as 'zombie profiles', continue to consume resources by repeatedly attempting to connect, leading to increased operational costs and load on radius servers due to spurious access requests.
Innovation Solution
Implement a zombie profile manager that employs a suite of solutions including command applications, email reminders, blacklisting mechanisms, and walled gardens to identify and delete or update invalid profiles, thereby reducing spurious radius requests.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If Passpoint profiles are manually installed on client devices, then seamless connectivity and automated access are enabled, but zombie profiles continue to consume network resources and generate spurious radius requests after account suspension
Solution Approach 1:
The system performs preliminary actions by notifying users of upcoming profile expiration before the actual expiration occurs. Email notifications are sent at configured intervals (e.g., 7 days, 1 day before expiration) to alert users that their Passpoint profiles will soon expire, giving them advance opportunity to update credentials or remove profiles before they become zombie profiles consuming network resources.
Solution Approach 2:
The system implements feedback mechanisms through email notifications that provide users with information about their profile status and expiration timelines. The notifications include actionable information such as expiration dates and instructions for profile management, enabling users to respond appropriately to prevent resource waste from zombie profiles.
2Ease of operation
If zombie profiles are allowed to persist on client devices, then user convenience is maintained, but operational costs increase due to processing spurious radius requests
Solution Approach 1:
The system enables self-service by empowering users to manage their own Passpoint profiles through email notifications. Users receive alerts about profile expiration and can independently update their credentials or remove profiles from their devices, eliminating the need for manual intervention by network administrators and reducing the formation of zombie profiles that generate costly spurious radius requests.
Solution Approach 2:
The system changes the parameter of profile validity by implementing expiration dates and notifying users of upcoming expirations. This parameter change approach allows profiles to transition from active to expired state in a controlled manner, with users informed in advance, thereby preventing indefinite persistence of zombie profiles and the associated operational costs.
3Device complexity
If profile expiration is not communicated to users, then system simplicity is maintained, but resource wastage increases as users remain unaware of lapsed accounts
Solution Approach 1:
The system introduces an intermediary communication channel (email notifications) between the network system and users regarding profile expiration. This intermediary mechanism conveys expiration information without requiring complex changes to the core Passpoint authentication system, maintaining relative simplicity while effectively preventing resource wastage by keeping users informed of their profile status.
Data Source
AI summary
Facilitating removal of lapsed profiles for a client attempting to access a Wi-Fi network by repeatedly sending requests to a server, the request includes a network address and profile of the client. For a lapsed profile, the server sends a message to a user regarding the lapse, where the message includes a list of all network addresses for client devices used to download the lapsed profile, and blacklists all clients used to download the lapsed profile after a rejected access request to prevent other access point from receiving spurious requests from the blacklisted clients. The Wi-Fi network may include numerous access points managed by a community Wi-Fi service provider and include a roaming access service provider allowing mobile client devices to subsequently access the AP devices automatically after a first successful access.


