Convergent WAPI Network Architecture in Local MAC Mode
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The autonomous architecture of Wireless Local Area Networks (WLANs) with WAPI protocol faces challenges in large-scale deployments, including high management costs, inconsistent configuration, labor-intensive parameter updates, and security threats due to the standalone management of Access Points (APs, which hinders the development and security of wireless techniques.
Innovation Solution
Implementing a convergent WAPI network architecture in a local Medium Access Control (MAC) mode by splitting the MAC and WAPI functions into a Wireless Terminal Point (WTP) and an Access Controller (AC), enabling centralized management, unified configuration, and secure key management through the WAI and WPI protocols, ensuring seamless integration and security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If autonomous architecture is used in WLAN with WAPI protocol, then each AP can operate independently, but management cost increases and configuration consistency becomes difficult to maintain in large-scale deployments
Solution Approach 1:
The patent segments the AP functionality into two separate entities: the WTP (Wireless Terminal Point) that handles local wireless operations and the AC (Access Controller) that handles centralized management and control. This segmentation allows independent operation at the wireless interface while enabling centralized management for configuration consistency and reduced management overhead in large-scale deployments.
Solution Approach 2:
The patent introduces an Access Controller (AC) as an intermediary between the WTPs and the network management system. The AC acts as a mediator that receives control messages from the network, processes them, and distributes appropriate commands to multiple WTPs, thereby simplifying network management and maintaining configuration consistency across large-scale deployments.
2Adaptability or versatility
If manual configuration of AP parameters is performed, then configuration can be customized, but labor consumption and cost increase significantly
Solution Approach 1:
The patent implements self-service mechanisms where the AC automatically discovers WTPs, retrieves their capabilities, and distributes appropriate configuration parameters without requiring manual intervention. The system can dynamically adapt configurations based on network conditions and WTP capabilities, maintaining adaptability while eliminating the time-consuming manual configuration process.
Solution Approach 2:
The patent establishes feedback loops between WTPs and the AC where WTPs report their status, capabilities, and performance metrics to the AC. The AC uses this feedback information to automatically adjust and optimize configurations, enabling customized settings to be applied efficiently without manual labor while maintaining adaptability to changing network conditions.
3Area of stationary object
If APs are deployed in distributed positions for better coverage, then network coverage improves, but security protection becomes more difficult
Solution Approach 1:
The patent introduces the AC as a security intermediary that centralizes security management functions. The AC authenticates WTPs, manages security credentials, and controls access policies, thereby providing robust security protection even when WTPs are deployed in distributed positions for extended network coverage. The AC acts as a trusted mediator that secures the distributed architecture.
Solution Approach 2:
The patent extracts security-critical functions from the distributed WTPs and concentrates them in the centralized AC. By taking out authentication, key management, and security policy enforcement from the physically distributed WTPs and placing them in the secure AC, the system achieves both wide network coverage through distributed WTPs and strong security protection through centralized security management.
Data Source
AI summary
A method for implementing a convergent Wireless Local Area Network (WLAN) Authentication and Privacy Infrastructure (WAPI) network architecture in a local Medium Access Control (MAC) mode is provided and includes the following steps: the MAC function and WAPI function of Access Point (AP) are divided between Wireless Terminal Point (WTP) and Access Controller (AC) to construct a local MAC mode; the convergence of WAPI protocol and the convergent WLAN network architecture is implemented in the local MAC mode; the process of association and connection between Station (STA), WTP and AC is performed; the process of notification of the beginning of the execution of the WLAN Authentication Infrastructure (WAI) protocol between AC and WTP is performed; the process of the execution of the WAI protocol between STA and AC is performed; the process of notification of the end of the execution of the WAI protocol between AC and WTP is performed; the process of encrypted communication between WTP and STA is performed by use of WPI.


