Pre-authentication Across 802.11 VLAN Boundaries

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless local area network (WLAN) systems face limitations in mobile client device roaming across different virtual local area networks (VLANs or subnetworks, requiring re-authentication and causing connectivity disruptions, especially when handoffs occur between access points with different VLANs or subnetworks.

Innovation Solution

The method involves pre-authentication by encapsulating Ethernet pre-authentication frames within IP packets to enable seamless roaming across VLAN or subnet boundaries, using network mapping to determine IP addresses corresponding to destination infrastructure devices and sending pre-authentication frames across routers, allowing continuous connections without breaking the radio link.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a mobile client device roams between access points on different WLANs with different VLANs or subnetworks using traditional authentication methods, then authentication security is maintained, but connection continuity is disrupted and roaming time exceeds 100 milliseconds

Engineering Contradiction:
Improveconnection continuityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements pre-authentication by having the mobile client device send authentication frames to the destination access point before actually roaming to it. The current access point forwards these pre-authentication frames through the network infrastructure to the destination access point, so that when the handoff occurs, authentication is already complete or nearly complete, reducing roaming time to under 100 milliseconds while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism where the current access point and network infrastructure act as mediators to forward pre-authentication frames between the mobile client device and the destination access point across different VLANs or subnetworks. This intermediary forwarding allows authentication to proceed in advance without requiring the mobile device to be physically connected to the destination access point yet

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If pre-authentication frames are sent across different VLANs or subnetworks using traditional Ethernet addressing, then roaming between WLANs is enabled, but frames are dropped at router boundaries due to layer-2 addressing limitations

Engineering Contradiction:
Improveroaming capability across WLANsVSAvoidframe delivery success
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent uses the network infrastructure (routers, switches) as intermediaries to forward pre-authentication frames across VLAN or subnet boundaries. The current access point encapsulates or forwards the Ethernet pre-authentication frames through the network infrastructure, which handles the layer-3 routing necessary to deliver frames across different network segments to the destination access point

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transitions from pure layer-2 Ethernet addressing to a solution that operates across layer-3 IP networks. By enabling pre-authentication traffic to traverse IP-based infrastructure, the system adds a dimensional layer of network addressing and routing capability, allowing frames to be delivered across VLANs and subnets that would be inaccessible through layer-2 addressing alone

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS7869438B2Pre-authentication across an 802.11 layer-3 IP network
Publication Date: 2011.01.11 EXTREME NETWORKS INC
  • US7869438B2 patent drawing
  • US7869438B2 patent drawing
  • US7869438B2 patent drawing

AI summary

A method for pre-authentication in a wireless network is disclosed. The method begins by receiving, from a mobile client device, an Ethernet pre-authentication frame having an Ethernet address corresponding to a destination infrastructure device in the wireless network. Based upon a network mapping table, the method determines an internet protocol (IP) address that is mapped to the Ethernet address of the destination infrastructure device. The Ethernet pre-authentication frame is encapsulated inside an IP packet having the IP address. Then, the method routes the IP packet to the destination infrastructure device across WLANs with a different VLAN or subnetwork boundary in the wireless network.