Authentication Proxy for Wi-Fi Roaming Cost Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing Wi-Fi roaming systems face challenges in efficiently managing guest access across multiple service providers, leading to high costs and complexity due to the need for direct roaming agreements between tier one mobile operators and numerous enterprises, which are often resolved by financial clearinghouses acting as Wi-Fi roaming hubs, resulting in increased tariffs and confusion.

Innovation Solution

Implementing a vendor-direct roaming exchange within the WLAN infrastructure, where authentication requests are sent to a cloud-based AAA proxy that maintains a list of service providers' authentication devices, allowing for automatic and secure guest access without relying on financial clearinghouses, thereby reducing costs and complexity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If direct roaming agreements are established between tier one mobile operators and numerous enterprises, then secure and automatic Wi-Fi guest access is achieved, but device complexity and operational complexity increase significantly

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidroaming agreement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an authentication proxy server as an intermediary component that mediates between the wireless controller and multiple mobile operator authentication devices. This proxy server receives authentication requests, forwards them to the appropriate operator based on the network access identifier, and returns responses, thereby eliminating the need for direct roaming agreements between operators and enterprises while maintaining secure authentication

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication proxy server provides universal authentication service for multiple mobile operators through a single interface. It maintains a list of mobile operator authentication devices and can authenticate users from different operators without requiring separate roaming agreements with each operator, thus reducing overall system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If financial clearinghouses act as Wi-Fi roaming hubs to manage guest access, then roaming coordination is achieved, but costs and tariffs increase

Engineering Contradiction:
Improveroaming coordinationVSAvoidroaming cost
Core Design Contradiction:
Ease of operationVSLoss of energy

Solution Approach 1:

The authentication proxy server serves as a technical intermediary that replaces the financial clearinghouse model. It enables direct authentication between enterprises and mobile operators without requiring financial intermediaries, thereby reducing roaming tariffs and costs while maintaining coordination capabilities

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the authentication coordination function from the financial clearinghouse model and implements it as a standalone authentication proxy server. This separation eliminates the need for financial intermediaries while preserving the essential roaming coordination functionality, reducing costs associated with clearinghouse services

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If multiple service providers' credentials are transferred back to each provider for authentication, then secure authentication is maintained, but processing time and operational complexity increase

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The authentication proxy server performs preliminary routing based on the network access identifier contained in the authentication request. By determining the appropriate mobile operator authentication device in advance and forwarding the request directly to that specific operator, the system reduces authentication processing time while maintaining security through proper credential verification

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9253636B2Wireless roaming and authentication
Publication Date: 2016.02.02 CISCO TECHNOLOGY INC
  • US9253636B2 patent drawing
  • US9253636B2 patent drawing
  • US9253636B2 patent drawing

AI summary

In one embodiment, a method includes receiving a Wi-Fi authentication request from a mobile device at a wireless controller, the request including a network access identifier, transmitting the request from the wireless controller to an authentication proxy, wherein the authentication proxy is in communication with a plurality of mobile operator authentication devices and operable to forward the request to one of the mobile operator authentication devices based on the network access identifier, and receiving a response to the request at the wireless controller, wherein the mobile device is permitted Wi-Fi access to a network by the wireless controller if the request is authenticated by the mobile operator authentication device. An apparatus and logic are also disclosed herein.