Roaming Terminal Re-authentication Prevention via VLAN Change Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Re-authentication of wireless computing devices when migrating between access points in a wireless network disrupts service and user experience, particularly due to changes in IP addresses within Virtual Local Area Networks (VLANs).
Innovation Solution
Implementing a method where access controllers detect and manage changes in access points and VLANs, synchronizing user information and modifying communication streams to conceal migration, allowing seamless access point transitions without re-authentication by maintaining a consistent IP address and updating connection tables in the Broadband Remote Access Server (BRAS) and Authentication, Authorization, Accounting (AAA) server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If re-authentication is performed when a user terminal migrates between access points, then network security is maintained, but service continuity is disrupted and user experience deteriorates
Solution Approach 1:
The system performs preliminary authentication before roaming occurs. The access controller pre-establishes authentication credentials and forwards them to the target access controller before the user terminal actually migrates. This preliminary action ensures that when roaming happens, authentication is already complete, maintaining both security and service continuity.
Solution Approach 2:
The access controller acts as an intermediary between the user terminal and the authentication server during roaming. It caches authentication credentials locally and uses them to facilitate seamless handover between access points without requiring direct re-authentication with the terminal, thus maintaining security while enabling continuous service.
2Adaptability or versatility
If IP address changes occur during access point migration, then network routing is updated, but re-authentication is triggered disrupting service
Solution Approach 1:
The system performs preliminary IP address allocation and routing configuration before the user terminal actually roams to a new access point. The access controller pre-configures the target access controller with the user's IP address and routing information, so that when migration occurs, the IP address remains consistent and no re-authentication is needed.
Solution Approach 2:
The access controller creates a copy of the user's authentication context and forwarding rules and transfers it to the target access controller before roaming. This copying mechanism ensures that the target controller already has the user's IP address and session information, enabling seamless handover without service disruption.
3Productivity
If access controllers forward packets transparently during roaming, then service continuity is maintained, but network security control may be compromised
Solution Approach 1:
The access controller performs preliminary security validation by verifying the user's authentication credentials and generating forwarding rules before the actual roaming occurs. This preliminary security check ensures that transparent forwarding during roaming is performed only for authenticated users with proper authorization, maintaining both service continuity and network security.
Solution Approach 2:
The system implements a feedback mechanism where the access controller continuously monitors roaming activities and updates forwarding rules based on authentication status. When a user roams, the controller receives feedback about the new location and adjusts packet forwarding accordingly, ensuring security policies are maintained while enabling continuous service.
Data Source
AI summary
A method and device for preventing a roaming user terminal from re-authentication are provided. The method includes: when Virtual Local Area Network (VLAN) of a roaming user terminal changes, change information of the roaming user terminal is reported to a Broadband Remote Access Server (BRAS) via an Access Controller (AC) and the BRAS reports modified information of the roaming user terminal to an Authentication, Authorization, Accounting server (AAA server).


