Web Authentication Portal for Mobile IP Roaming
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication procedures for mobile wireless devices roaming from wide area networks to public WLANs, such as 'hotspots', rely on weak web-based authentication due to lack of support for IEEE 802.1x/EAP on millions of devices, necessitating continued use of web-based authentication for Evolved Packet Core (EPC) - WLAN interworking.
Innovation Solution
Implementing a robust web authentication technique by redirecting mobile wireless device requests to an authentication portal using a temporary unauthenticated session with an IP address assigned by the wide area core network, allowing users to enter credentials for secure WWAN access, while maintaining IP address continuity and mobility.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If web-based authentication is used for public WLAN access, then compatibility with existing mobile devices is maintained, but security is weakened
Solution Approach 1:
The patent introduces a portal server as an intermediary between the mobile device and the authentication system. The portal server captures web traffic, extracts credentials, and forwards them to the authentication server. This intermediary approach allows the system to maintain compatibility with web-based authentication while adding security layers through centralized credential verification and logging.
Solution Approach 2:
The patent replaces direct device-to-authentication-server communication with a web-based credential capture mechanism. Instead of requiring devices to implement complex 802.1x/EAP protocols, the system uses standard web browsing behavior to collect credentials, substituting mechanical protocol implementation with a software-based web interception approach that works across all devices.
2Reliability
If IEEE 802.1x/EAP authentication is implemented, then security is improved, but device compatibility deteriorates due to lack of support on millions of devices
Solution Approach 1:
The patent enables the authentication system to adapt to the device's capabilities automatically. The portal server monitors web traffic and determines whether the device supports web-based authentication or 802.1x/EAP. This self-service approach allows the system to select the appropriate authentication method without requiring device changes, maintaining compatibility while enabling security improvements where supported.
Solution Approach 2:
The patent changes the authentication parameters dynamically based on device capabilities. The system transitions from requiring uniform 802.1x/EAP implementation to supporting multiple authentication modes (web-based and 802.1x/EAP) with different parameter sets. This allows the same infrastructure to serve both legacy web-based devices and modern devices capable of stronger authentication.
3Adaptability or versatility
If mobile devices roam to public WLANs, then network flexibility is improved, but authentication complexity increases
Solution Approach 1:
The patent segments the authentication process into distinct phases: web traffic capture, credential extraction, credential verification, and authentication decision. The portal server handles the capture and extraction phases, while the authentication server handles verification. This segmentation simplifies the overall process by dividing complex authentication into manageable, independent stages that can be handled by different system components.
Solution Approach 2:
The portal server acts as an intermediary that simplifies authentication for mobile devices roaming to public WLANs. Instead of requiring devices to directly implement complex authentication protocols, the portal server intercepts standard web traffic and handles the authentication complexity centrally, reducing device-side complexity while maintaining network flexibility.
Data Source
AI summary
Techniques are provided for performing web authentication of mobile wireless devices that roam from a wireless wide area network to a wireless local area network. A redirect rule is invoked when a request is received from the mobile wireless device for world wide web access in order to obtain authentication for the mobile wireless device before permitting world wide web access. When a world wide web access request is received from the mobile wireless device, it is redirected to an authentication portal to allow a user of the mobile wireless device to enter user credentials to allow for world wide web access using the IP address.


