Roaming Terminal Re-authentication Prevention via VLAN Change Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Re-authentication of wireless computing devices when migrating between access points in a wireless network disrupts service and user experience, particularly due to changes in IP addresses within Virtual Local Area Networks (VLANs).

Innovation Solution

Implementing a method where access controllers detect and manage changes in access points and VLANs, synchronizing user information and modifying communication streams to conceal migration, allowing seamless access point transitions without re-authentication by maintaining a consistent IP address and updating connection tables in the Broadband Remote Access Server (BRAS) and Authentication, Authorization, Accounting (AAA) server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If re-authentication is performed when a user terminal migrates between access points, then network security is maintained, but service continuity is disrupted and user experience deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoidservice continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary authentication before roaming occurs. The access controller pre-establishes authentication credentials and forwards them to the target access controller before the user terminal actually migrates. This preliminary action ensures that when roaming happens, authentication is already complete, maintaining both security and service continuity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The access controller acts as an intermediary between the user terminal and the authentication server during roaming. It caches authentication credentials locally and uses them to facilitate seamless handover between access points without requiring direct re-authentication with the terminal, thus maintaining security while enabling continuous service.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If IP address changes occur during access point migration, then network routing is updated, but re-authentication is triggered disrupting service

Engineering Contradiction:
Improvenetwork routingVSAvoidservice disruption
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The system performs preliminary IP address allocation and routing configuration before the user terminal actually roams to a new access point. The access controller pre-configures the target access controller with the user's IP address and routing information, so that when migration occurs, the IP address remains consistent and no re-authentication is needed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The access controller creates a copy of the user's authentication context and forwarding rules and transfers it to the target access controller before roaming. This copying mechanism ensures that the target controller already has the user's IP address and session information, enabling seamless handover without service disruption.

Inventive Principle:
Principle #26Copying

3Productivity

If access controllers forward packets transparently during roaming, then service continuity is maintained, but network security control may be compromised

Engineering Contradiction:
Improveservice continuityVSAvoidnetwork security control
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The access controller performs preliminary security validation by verifying the user's authentication credentials and generating forwarding rules before the actual roaming occurs. This preliminary security check ensures that transparent forwarding during roaming is performed only for authenticated users with proper authorization, maintaining both service continuity and network security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements a feedback mechanism where the access controller continuously monitors roaming activities and updates forwarding rules based on authentication status. When a user roams, the controller receives feedback about the new location and adjusts packet forwarding accordingly, ensuring security policies are maintained while enabling continuous service.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9173082B2Preventing roaming user terminal re-authentication
Publication Date: 2015.10.27 HEWLETT PACKARD ENTERPRISE DEV LP
  • US9173082B2 patent drawing
  • US9173082B2 patent drawing
  • US9173082B2 patent drawing

AI summary

A method and device for preventing a roaming user terminal from re-authentication are provided. The method includes: when Virtual Local Area Network (VLAN) of a roaming user terminal changes, change information of the roaming user terminal is reported to a Broadband Remote Access Server (BRAS) via an Access Controller (AC) and the BRAS reports modified information of the roaming user terminal to an Authentication, Authorization, Accounting server (AAA server).