Web Authentication Portal for Mobile IP Roaming

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication procedures for mobile wireless devices roaming from wide area networks to public WLANs, such as 'hotspots', rely on weak web-based authentication due to lack of support for IEEE 802.1x/EAP on millions of devices, necessitating continued use of web-based authentication for Evolved Packet Core (EPC) - WLAN interworking.

Innovation Solution

Implementing a robust web authentication technique by redirecting mobile wireless device requests to an authentication portal using a temporary unauthenticated session with an IP address assigned by the wide area core network, allowing users to enter credentials for secure WWAN access, while maintaining IP address continuity and mobility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If web-based authentication is used for public WLAN access, then compatibility with existing mobile devices is maintained, but security is weakened

Engineering Contradiction:
Improvedevice compatibilityVSAvoidauthentication security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a portal server as an intermediary between the mobile device and the authentication system. The portal server captures web traffic, extracts credentials, and forwards them to the authentication server. This intermediary approach allows the system to maintain compatibility with web-based authentication while adding security layers through centralized credential verification and logging.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces direct device-to-authentication-server communication with a web-based credential capture mechanism. Instead of requiring devices to implement complex 802.1x/EAP protocols, the system uses standard web browsing behavior to collect credentials, substituting mechanical protocol implementation with a software-based web interception approach that works across all devices.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If IEEE 802.1x/EAP authentication is implemented, then security is improved, but device compatibility deteriorates due to lack of support on millions of devices

Engineering Contradiction:
Improveauthentication securityVSAvoiddevice compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent enables the authentication system to adapt to the device's capabilities automatically. The portal server monitors web traffic and determines whether the device supports web-based authentication or 802.1x/EAP. This self-service approach allows the system to select the appropriate authentication method without requiring device changes, maintaining compatibility while enabling security improvements where supported.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent changes the authentication parameters dynamically based on device capabilities. The system transitions from requiring uniform 802.1x/EAP implementation to supporting multiple authentication modes (web-based and 802.1x/EAP) with different parameter sets. This allows the same infrastructure to serve both legacy web-based devices and modern devices capable of stronger authentication.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If mobile devices roam to public WLANs, then network flexibility is improved, but authentication complexity increases

Engineering Contradiction:
Improvenetwork flexibilityVSAvoidauthentication procedure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication process into distinct phases: web traffic capture, credential extraction, credential verification, and authentication decision. The portal server handles the capture and extraction phases, while the authentication server handles verification. This segmentation simplifies the overall process by dividing complex authentication into manageable, independent stages that can be handled by different system components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The portal server acts as an intermediary that simplifies authentication for mobile devices roaming to public WLANs. Instead of requiring devices to directly implement complex authentication protocols, the portal server intercepts standard web traffic and handles the authentication complexity centrally, reducing device-side complexity while maintaining network flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8769626B2Web authentication support for proxy mobile IP
Publication Date: 2014.07.01 CISCO TECHNOLOGY INC
  • US8769626B2 patent drawing
  • US8769626B2 patent drawing
  • US8769626B2 patent drawing

AI summary

Techniques are provided for performing web authentication of mobile wireless devices that roam from a wireless wide area network to a wireless local area network. A redirect rule is invoked when a request is received from the mobile wireless device for world wide web access in order to obtain authentication for the mobile wireless device before permitting world wide web access. When a world wide web access request is received from the mobile wireless device, it is redirected to an authentication portal to allow a user of the mobile wireless device to enter user credentials to allow for world wide web access using the IP address.