VLAN Override in Multiple BSSID Wireless Access Points

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The integration of Multiple BSSID (MBSSID) modes with VLAN override in wireless networks is challenging due to issues such as increased decryption errors and the need for manual configuration of wireless clients, which affects battery life and dynamic VLAN assignment.

Innovation Solution

Implementing a VLAN override mechanism in wireless access points that dynamically maps SSIDs to BSSIDs/VLANs, allowing the access points to learn the correct VLAN/BSSID for each mobile station during authentication and cache this information for proper domain control, thereby avoiding decryption errors and enhancing battery life.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single BSSID is used for all VLANs, then device complexity is reduced, but decryption errors increase and battery life decreases

Engineering Contradiction:
ImproveBSSID configuration complexityVSAvoiddecryption accuracy
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the single BSSID into multiple BSSIDs, each corresponding to a specific VLAN. This allows wireless clients to associate with the appropriate BSSID for their assigned VLAN, enabling correct decryption without requiring complex manual configuration. The segmentation resolves the contradiction by maintaining simplicity in configuration while improving decryption reliability through specialized BSSID-VLAN mapping.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by assigning different properties to different BSSIDs based on their associated VLANs. Each BSSID has specific decryption keys and characteristics tailored to its VLAN, allowing optimal decryption performance for each local context without requiring all clients to use a single generic BSSID configuration.

Inventive Principle:
Principle #3Local quality

2Manufacturing precision

If manual SSID configuration is required for each wireless client, then VLAN assignment accuracy improves, but ease of operation deteriorates

Engineering Contradiction:
ImproveVLAN assignment accuracyVSAvoidclient configuration ease
Core Design Contradiction:
Manufacturing precisionVSEase of operation

Solution Approach 1:

The patent implements self-service by enabling wireless clients to automatically obtain the correct BSSID and VLAN assignment through the authentication process. The access point dynamically provides the appropriate BSSID based on the client's authenticated identity and VLAN assignment, eliminating the need for manual SSID configuration while maintaining accurate VLAN assignment. The system serves itself by automatically matching clients to the correct network segments.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies preliminary action by pre-configuring multiple BSSIDs on the access point, each associated with a specific VLAN. This preliminary setup allows the authentication server to dynamically direct clients to the appropriate pre-configured BSSID without requiring manual client configuration. The action is prepared in advance at the access point, not at the client.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If multiple BSSIDs are implemented for different VLANs, then decryption accuracy improves, but device complexity increases

Engineering Contradiction:
Improvedecryption accuracyVSAvoidaccess point configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by designing the access point to handle multiple BSSIDs and VLANs through a unified authentication and association framework. The access point maintains a single authentication server relationship while supporting multiple BSSIDs, each serving different VLANs. This multi-functional capability improves decryption accuracy without proportionally increasing complexity, as the same authentication infrastructure serves all BSSIDs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The authentication server acts as an intermediary that manages the complexity of multiple BSSIDs and VLANs. It receives authentication requests, determines the appropriate VLAN assignment, and directs clients to the correct BSSID. This intermediary absorbs the complexity of coordinating multiple BSSIDs, presenting a simplified interface to both clients and the access point while ensuring accurate decryption through proper BSSID-VLAN matching.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If VLAN override is implemented with MBSSID, then adaptability improves, but ease of operation worsens due to configuration complexity

Engineering Contradiction:
Improvedynamic VLAN assignment capabilityVSAvoidconfiguration simplicity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent implements dynamics by enabling dynamic VLAN assignment through the authentication process. When a wireless client authenticates, the authentication server dynamically determines the appropriate VLAN and directs the client to the corresponding BSSID. This dynamic adaptation allows the network to flexibly assign clients to different VLANs based on their identity and policies, while the pre-configured BSSID structure maintains operational simplicity.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS7339915B2Virtual LAN override in a multiple BSSID mode of operation
Publication Date: 2008.03.04 CISCO TECHNOLOGY INC
  • US7339915B2 patent drawing
  • US7339915B2 patent drawing
  • US7339915B2 patent drawing

AI summary

Methods, apparatuses and systems directed to the integration of VLANs and wireless access points operating in a Multiple BSSID mode of operation. According to one implementation of the present invention, a wireless access point dynamically maps an SSID provided by a mobile station to a BSSID based on a VLAN assignment corresponding to the mobile station. In one implementation, the wireless access point learns the correct VLAN/BSSID for a given mobile station, while proxying an authentication session between the mobile station and an authentication server.