Split MAC WAPI Architecture for Centralized WLAN Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The autonomous architecture of Wireless Local Area Networks (WLANs) with WAPI protocol faces challenges in managing and securing a large number of Access Points (APs, leading to heavy management burdens, inconsistent configurations, and security risks due to the need for manual updates and protection of APs.
Innovation Solution
Implementing a convergent WAPI network architecture in split MAC mode, where the MAC and WAPI functions are divided between a Wireless Terminal Point (WTP) and an Access Controller (AC), enabling centralized management and secure, dynamic configuration of APs through a WPI protocol.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If autonomous architecture is used for WLAN management, then each AP can operate independently, but the management burden increases tremendously when deploying large-scale networks
Solution Approach 1:
The patent segments the AP functionality into two parts: the autonomous BSS (Basic Service Set) operation at the AP level, and the centralized management functions at the AC (Access Controller) level. This segmentation allows APs to operate independently for basic wireless functions while the AC handles centralized configuration, monitoring, and control, thereby reducing the management burden in large-scale deployments.
Solution Approach 2:
The patent introduces an AC (Access Controller) as an intermediary between the network administrator and multiple APs. The AC serves as a centralized management entity that handles configuration distribution, parameter updates, and monitoring for all APs in the network, eliminating the need for manual management of each individual AP and reducing overall system complexity.
2Ease of operation
If manual configuration is used for AP parameters, then configuration can be customized, but it consumes a lot of human and material resources
Solution Approach 1:
The patent implements preliminary action by pre-configuring template parameters and policies at the AC level that can be automatically distributed to multiple APs. This allows for standardized configurations to be prepared in advance and deployed across the entire network simultaneously, dramatically reducing the time and resources required for manual configuration while maintaining the ability to customize when needed.
Solution Approach 2:
The patent establishes a feedback mechanism where the AC continuously monitors AP status and configuration compliance. This feedback loop enables automatic detection of configuration drift or issues, allowing the system to self-correct or alert administrators only when necessary, thereby reducing the overall time and human resources required for configuration management.
3Productivity
If dynamic configuration updates are implemented for all APs, then network performance can be optimized, but it becomes burdensome and even impossible to update configurations throughout large-scale WLAN
Solution Approach 1:
The patent merges the configuration management functions for all APs into a single centralized AC. This consolidation allows dynamic configuration updates to be issued once at the AC level and automatically propagated to all connected APs simultaneously, enabling real-time network optimization across large-scale deployments without the complexity of individually updating each AP.
Solution Approach 2:
The AC acts as an intermediary that receives, processes, and distributes configuration updates to multiple APs. This intermediary architecture enables efficient propagation of dynamic configuration changes across the entire network, ensuring all APs receive updates simultaneously while the AC handles the complexity of coordination and tracking.
4Area of stationary object
If APs are deployed in distributed positions for coverage, then network coverage is improved, but security protection becomes difficult and security information may be leaked
Solution Approach 1:
The patent extracts critical security functions and sensitive configuration data from the distributed APs and centralizes them at the AC. By taking out security management responsibilities from physically vulnerable AP locations and concentrating them at a secure central location, the system maintains wide network coverage through distributed APs while improving security through centralized control and reduced attack surface at individual AP locations.
Data Source
AI summary
A method for realizing a convergent Wireless Local Area Networks (WLAN) Authentication and Privacy Infrastructure (WAPI) network architecture with a split Medium Access Control (MAC) mode involves the steps: a split MAC mode for realizing WLAN Privacy Infrastructure (WPI) by a wireless terminal point is constructed through separating the MAC function and the WAPI function of the wireless access point apart to the wireless terminal point and an access controller; integration of a WAPI and a convergent WLAN network system architecture is realized under the split MAC mode that the wireless terminal point realizes WPI; the association connection process is performed among a station point, a wireless terminal point and an access controller; the process for announcing the start of performing the WLAN Authentication Infrastructure (WAI) protocol between the access controller and the wireless terminal point is performed; the process for performing the WAI protocol between the station point and the access controller is performed; the process for announcing the end of performing the WAI protocol between the access controller and the wireless terminal point is performed; the secret communication process is performed between the wireless terminal point and the station by using WPI.


