WiFi Roaming Authentication Load Reduction via AC-AP Interworking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In WiFi roaming systems, the frequent authentication and accounting processes between mobile stations and access points increase the load on authentication servers, particularly when a mobile station moves to a new access point, leading to increased traffic and server load.
Innovation Solution
Implementing a method where an Access Controller (AC) and Access Point (AP) interwork in a tunneling manner, allowing for re-authentication omission and minimizing accounting messages by storing station information, releasing old sessions, and accumulating accounting information, thus reducing the load on the authentication server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the AP interworks with the authentication server to process accounting for each station movement, then the authentication and accounting functions are properly executed, but the load of the authentication server and the AP increases significantly
Solution Approach 1:
The patent introduces an Access Controller (AC) as an intermediary between the AP and the authentication server. The AC handles authentication and accounting operations, allowing the AP to offload these processing tasks. This mediator approach resolves the contradiction by maintaining proper authentication/accounting execution while significantly reducing the load on both the AP and the authentication server, as the AC consolidates the processing burden.
2Reliability
If re-authentication is performed whenever a mobile station accesses a new AP, then the authentication security is maintained, but the authentication server load increases due to frequent authentication requests
Solution Approach 1:
The patent implements preliminary authentication where the mobile station is authenticated once by the AC, and this authentication result is cached and reused when the station moves to different APs. Instead of performing re-authentication at each AP transition, the system performs the authentication action in advance and reuses it, thereby maintaining security while dramatically reducing authentication server load during roaming operations.
3Power
If the AC and AP interwork in a tunneling manner with CAPWAP protocol, then the station session management function is separated and the AP load is reduced, but the accounting message generation for authentication server increases
Solution Approach 1:
The patent merges the accounting message generation function into the AC, consolidating it with the authentication processing. Instead of having the AP generate separate accounting messages for each station movement (which increases message quantity), the AC consolidates accounting operations and generates unified accounting messages, thereby reducing the total number of accounting messages sent to the authentication server while maintaining proper session management separation.
Data Source
AI summary
A WiFi roaming method and device which perform an authentication and accounting process once for multiple APs, thereby reducing the load of an authentication server (RADIUS) in a WiFi roaming method, which separates a terminal session management function and a traffic control function by a access controller and a access point interworked with a tunneling method according to a CAPWAP (Control and Provisioning of Wireless Access Points) protocol.


