Inter Subnet Roaming via Wireless Domain Service Credential Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional wireless network authentication and registration processes cause interruptions and delays when mobile nodes roam between geographical areas, as they require re-authentication and registration, which can be time-consuming and resource-intensive, especially when many nodes attempt to authenticate with a single central resource.

Innovation Solution

The system facilitates seamless roaming by enabling wireless domain services to share authentication credentials across subnets, allowing for partial authentication processes and reducing the need for full authentication upon initial access, thereby minimizing interruptions and enabling faster movement between geographical areas.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication and registration processes are used when mobile nodes roam between geographical areas, then security and network management are maintained, but communication interruptions and delays occur due to re-authentication requirements

Engineering Contradiction:
Improveauthentication securityVSAvoidroaming delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary authentication actions by establishing authentication credentials and context information in advance before the mobile node actually roams. When roaming occurs, the authentication is already partially completed, allowing the mobile node to quickly transition to the new subnet without undergoing full re-authentication, thus maintaining security while minimizing roaming delay

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention introduces an intermediary authentication mechanism where authentication context and credentials are transferred between network domains through intermediate entities. This intermediary process allows seamless authentication across subnets by mediating the authentication exchange, preventing direct repeated authentication with central resources and reducing bottlenecks

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If full authentication processes are performed each time mobile nodes enter new geographical areas, then network security is ensured, but network resources are consumed and communication continuity is disrupted

Engineering Contradiction:
Improvenetwork securityVSAvoidcommunication continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Instead of performing complete full authentication processes, the system applies partial authentication actions by validating only the necessary authentication credentials that are already established. This partial action approach maintains network security by verifying essential authentication information while avoiding redundant authentication steps, thus preserving communication continuity

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The invention ensures continuity of useful action by maintaining authentication context and credentials active across subnet transitions. The authentication process is designed to continue seamlessly rather than restart, allowing mobile nodes to maintain productive communication while moving between geographical areas without interruption

Inventive Principle:
Principle #20Continuity of useful action

3Extent of automation

If multiple mobile nodes authenticate with a single central authentication resource, then centralized security management is achieved, but bottlenecks and delays occur during simultaneous authentication attempts

Engineering Contradiction:
Improvecentralized authentication managementVSAvoidauthentication speed
Core Design Contradiction:
Extent of automationVSSpeed

Solution Approach 1:

The authentication process is segmented into multiple independent components that can be processed in parallel. Instead of requiring all authentication operations to pass through a single central resource sequentially, the authentication context is divided and distributed across multiple network entities, allowing simultaneous authentication attempts to be handled concurrently without creating bottlenecks

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The invention transitions from a single-dimension centralized authentication model to a multi-dimensional distributed authentication architecture. By adding spatial and functional dimensions to the authentication process, multiple mobile nodes can authenticate simultaneously through different paths and entities while maintaining centralized security policy enforcement, thereby increasing authentication speed

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS7624270B2Inter subnet roaming system and method
Publication Date: 2009.11.24 CISCO TECHNOLOGY INC
  • US7624270B2 patent drawing
  • US7624270B2 patent drawing
  • US7624270B2 patent drawing

AI summary

The present invention communication network system and method facilitates authentication and registration in a communication network as mobile nodes move from one geographical region to another. Multiple wireless domain services (WDSs) share client authentication information permitting relatively seamless roaming between subnets with minimal interruptions and delays. In one embodiment, a wireless domain service network communication method is performed utilizing partial authentication processes. A mobile node engages in an authentication protocol with a first wireless domain service (WDS) access point in a first subnet. The authentication credentials are forwarded to a second wireless domain service in a second subnet if the authentication protocol is successfully completed. The forwarded authentication credentials are utilized to authenticate the client entering the service area of the second wireless domain service in the second subnet. The authentication credentials can be “pushed” or “pulled” from the first wireless domain service to the second wireless domain service.