Split MAC WAPI Architecture for Centralized WLAN Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The autonomous architecture of Wireless Local Area Networks (WLANs) with WAPI protocol faces challenges in managing and securing a large number of Access Points (APs, leading to heavy management burdens, inconsistent configurations, and security risks due to the need for manual updates and protection of APs.

Innovation Solution

Implementing a convergent WAPI network architecture in split MAC mode, where the MAC and WAPI functions are divided between a Wireless Terminal Point (WTP) and an Access Controller (AC), enabling centralized management and secure, dynamic configuration of APs through a WPI protocol.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If autonomous architecture is used for WLAN management, then each AP can operate independently, but the management burden increases tremendously when deploying large-scale networks

Engineering Contradiction:
ImproveIndependent operation capabilityVSAvoidManagement burden
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the AP functionality into two parts: the autonomous BSS (Basic Service Set) operation at the AP level, and the centralized management functions at the AC (Access Controller) level. This segmentation allows APs to operate independently for basic wireless functions while the AC handles centralized configuration, monitoring, and control, thereby reducing the management burden in large-scale deployments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an AC (Access Controller) as an intermediary between the network administrator and multiple APs. The AC serves as a centralized management entity that handles configuration distribution, parameter updates, and monitoring for all APs in the network, eliminating the need for manual management of each individual AP and reducing overall system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If manual configuration is used for AP parameters, then configuration can be customized, but it consumes a lot of human and material resources

Engineering Contradiction:
ImproveConfiguration flexibilityVSAvoidConfiguration time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-configuring template parameters and policies at the AC level that can be automatically distributed to multiple APs. This allows for standardized configurations to be prepared in advance and deployed across the entire network simultaneously, dramatically reducing the time and resources required for manual configuration while maintaining the ability to customize when needed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent establishes a feedback mechanism where the AC continuously monitors AP status and configuration compliance. This feedback loop enables automatic detection of configuration drift or issues, allowing the system to self-correct or alert administrators only when necessary, thereby reducing the overall time and human resources required for configuration management.

Inventive Principle:
Principle #23Feedback

3Productivity

If dynamic configuration updates are implemented for all APs, then network performance can be optimized, but it becomes burdensome and even impossible to update configurations throughout large-scale WLAN

Engineering Contradiction:
ImproveNetwork performanceVSAvoidConfiguration update complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent merges the configuration management functions for all APs into a single centralized AC. This consolidation allows dynamic configuration updates to be issued once at the AC level and automatically propagated to all connected APs simultaneously, enabling real-time network optimization across large-scale deployments without the complexity of individually updating each AP.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The AC acts as an intermediary that receives, processes, and distributes configuration updates to multiple APs. This intermediary architecture enables efficient propagation of dynamic configuration changes across the entire network, ensuring all APs receive updates simultaneously while the AC handles the complexity of coordination and tracking.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Area of stationary object

If APs are deployed in distributed positions for coverage, then network coverage is improved, but security protection becomes difficult and security information may be leaked

Engineering Contradiction:
ImproveNetwork coverageVSAvoidSecurity protection
Core Design Contradiction:
Area of stationary objectVSReliability

Solution Approach 1:

The patent extracts critical security functions and sensitive configuration data from the distributed APs and centralizes them at the AC. By taking out security management responsibilities from physically vulnerable AP locations and concentrating them at a secure central location, the system maintains wide network coverage through distributed APs while improving security through centralized control and reduced attack surface at individual AP locations.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8855018B2Method for realizing convergent WAPI network architecture with split MAC mode
Publication Date: 2014.10.07 CHINA IWNCOMM
  • US8855018B2 patent drawing
  • US8855018B2 patent drawing
  • US8855018B2 patent drawing

AI summary

A method for realizing a convergent Wireless Local Area Networks (WLAN) Authentication and Privacy Infrastructure (WAPI) network architecture with a split Medium Access Control (MAC) mode involves the steps: a split MAC mode for realizing WLAN Privacy Infrastructure (WPI) by a wireless terminal point is constructed through separating the MAC function and the WAPI function of the wireless access point apart to the wireless terminal point and an access controller; integration of a WAPI and a convergent WLAN network system architecture is realized under the split MAC mode that the wireless terminal point realizes WPI; the association connection process is performed among a station point, a wireless terminal point and an access controller; the process for announcing the start of performing the WLAN Authentication Infrastructure (WAI) protocol between the access controller and the wireless terminal point is performed; the process for performing the WAI protocol between the station point and the access controller is performed; the process for announcing the end of performing the WAI protocol between the access controller and the wireless terminal point is performed; the secret communication process is performed between the wireless terminal point and the station by using WPI.