User Domain Based White List Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing public wireless local area networks (PwLAN) struggle to provide differentiated access to Internet services based on user authentication and authorization, as White Lists are typically applied uniformly across all users, failing to account for individual user domains or home providers, leading to complexities in service differentiation and payment methods.
Innovation Solution
Implementing a method to dynamically determine user domain-based White Lists by associating users with their home providers, allowing access to specific hosts or services based on their domain, enabling differentiated access and payment methods, and integrating this with network management systems to manage authentication and accounting.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If a uniform White List is applied to all users at the gateway, then implementation is simple, but service differentiation capability is poor
Solution Approach 1:
The patent segments the White List configuration by introducing user domain as a classification dimension. Instead of a single uniform White List, the system creates multiple White Lists associated with different user domains (home providers). The gateway determines which White List to apply based on the user's domain information, enabling service differentiation while maintaining manageable configuration through domain-based grouping.
Solution Approach 2:
The patent applies local quality by allowing different White List configurations for different user domains. Each domain can have its own customized White List tailored to specific service requirements, payment methods, or access policies. This enables localized service differentiation at the domain level while the overall system remains coordinated through the gateway's domain-based selection mechanism.
2Adaptability or versatility
If different White Lists are configured for different users, then service differentiation is improved, but system complexity increases
Solution Approach 1:
The patent extracts the White List selection logic from the gateway configuration and associates it with user domain information. By extracting and separating the domain-based selection criterion, the system manages complexity by organizing White Lists according to domains rather than individual users. This reduces configuration complexity while maintaining service differentiation capability.
Solution Approach 2:
The patent creates a universal domain-based White List mechanism that serves multiple functions: service differentiation, payment method determination, and access control. By making the White List system multi-functional and domain-oriented, the patent reduces overall system complexity by using a single domain-based criterion to drive multiple service decisions, rather than requiring separate configurations for each function.
3Reliability
If White List determination requires user authentication first, then security is improved, but access to free services before authentication is blocked
Solution Approach 1:
The patent enables preliminary determination of White List membership based on user domain information that can be obtained before full authentication. By performing preliminary actions (domain identification and White List matching) before complete authentication, the system allows unauthenticated users to access services in their domain's White List while maintaining the ability to enforce authentication when needed. This balances security with ease of operation for free services.
Data Source
AI summary
A method is disclosed for determining a whether access to host requested by a user is permitted. User identifying information is obtained using any of a variety of techniques. The method includes determining a user domain, which indicates an identity of the user's home service provider. A list of hosts is determined based on the home provider. If the requested host is in the list of hosts, then the user is allowed access to the requested host though the user is not authorized. The list of hosts may be determined by one or more attributes from an actual or implied user profile, such as a domain name.


