Remote Roaming Management System for Seamless Visitor Network Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing visitor-based network (VBN) systems require users to re-register when moving between sub-networks, disrupting seamless internet access and complicating network management.
Innovation Solution
A remote roaming management system that includes a VBN server, an authorization assisting device, a registration driver, a registration data store, and an authorization module, which assigns appropriate IP addresses and manages authorization requests to allow user devices to roam between sub-networks without re-registration, using a set of assignable IP address ranges and maintaining registration data for seamless network access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If users move between sub-networks in a visitor based network, then network mobility is improved, but users must re-register which causes service interruption and loss of time
Solution Approach 1:
The patent introduces a remote roaming server as an intermediary between the user device and individual VBN servers. This mediator maintains persistent registration data and authorization information, allowing users to move between sub-networks without re-registering at each location. The remote roaming server acts as a central coordination point that manages user credentials across multiple VBN servers, eliminating the need for repeated registration processes.
Solution Approach 2:
The remote roaming server provides universal authorization services across multiple sub-networks and VBN servers. Instead of requiring separate registration with each VBN server, the system implements a universal registration mechanism where one registration at the remote roaming server grants access to multiple sub-networks. This multi-functional approach allows the same authorization credentials to work across different network domains.
2Duration of action of stationary object
If a mechanism allows user devices to move between sub-networks without re-registration, then service continuity is improved, but network security and authorization management complexity increases
Solution Approach 1:
The authorization management system is segmented into distinct functional components: the remote roaming server handles registration and credential management, individual VBN servers handle local network access control, and authorization assisting devices handle real-time authorization requests. This segmentation distributes complexity across multiple specialized components rather than concentrating all authorization logic in a single system, making the overall system more manageable and maintainable.
Solution Approach 2:
The system performs preliminary authorization actions by pre-registering user devices at the remote roaming server before they access individual sub-networks. Authorization credentials are prepared and validated in advance, so when users move between sub-networks, the authorization process is already complete. This preliminary action eliminates the need for real-time authorization negotiations when users move, maintaining service continuity while managing security requirements.
Data Source
AI summary
An authorization assisting device sends to the VBN server an authorization request for access to the WAN by a requesting user device. A registration driver has a set of assignable IP address ranges for multiple routing realms, and assigns an IP address to a user device from a relevant IP address range depending on a routing realm from which communication from the user device is received. The assignable IP address ranges include one or more authorization address ranges from which the registration driver assigns an IP address to a user device whose authorization request is received from the authorization assisting device. An authorization module processes the authorization request to generate an authorization response granting or denying access to the WAN by the requesting user device based on registration data in a registration data store and the information in the authorization request.


