Wireless Access Point Segmentation for Device-Specific Network Policies
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless network access control methods cannot differentiate between wireless devices and applications, leading to uniform treatment of all users on public networks, which hinders the ability to implement tailored access policies based on device or application type.
Innovation Solution
A wireless access point is configured to detect and classify wireless devices and applications by reading MAC addresses and data protocols, allowing for the implementation of segmented access policies that provide unimpeded or restricted access to the network based on the detected type.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If uniform access control is implemented for all wireless devices on public networks, then network security is maintained through consistent policies, but the ability to implement tailored access policies based on device or application type is lost
Solution Approach 1:
The patent segments wireless devices into different categories (e.g., personal devices, guest devices, IoT devices) and applies different access control policies to each segment. The access point classifies devices based on MAC address patterns, connection behavior, and device characteristics, then enforces appropriate security policies for each category, allowing both security consistency within segments and policy differentiation across segments.
Solution Approach 2:
The patent implements local quality by applying specific access control characteristics to different device types. Each device category receives customized policy treatment (e.g., bandwidth limits, access hours, permitted services) based on its specific needs and security requirements, rather than applying a single uniform policy to all devices.
2Adaptability or versatility
If device classification and segmented access policies are implemented, then tailored access control is enabled, but system complexity increases due to detection and classification requirements
Solution Approach 1:
The patent implements a universal classification system at the access point that handles multiple device types and policy requirements through a single unified mechanism. The access point uses general MAC address analysis and connection pattern detection to classify diverse devices into predefined categories, applying appropriate policies without requiring device-specific configurations or complex identification procedures for each device type.
Solution Approach 2:
The patent simplifies classification by monitoring changes in key parameters such as MAC address patterns, connection timing, data transmission rates, and protocol usage. By tracking these parameter changes over time, the system automatically adapts device classifications and adjusts access policies without requiring manual intervention or complex analytical algorithms.
3Measurement precision
If MAC address reading and protocol detection are performed for device classification, then accurate device identification is achieved, but processing time and computational resources increase
Solution Approach 1:
The patent implements partial action by performing MAC address reading and protocol detection selectively rather than continuously for all devices. The system initially classifies devices based on MAC address patterns alone, then performs more intensive protocol detection only when classification is ambiguous or when security policies require additional verification, reducing overall processing time while maintaining identification accuracy.
Solution Approach 2:
The patent performs preliminary MAC address analysis during the initial connection handshake phase, before full protocol detection is required. By pre-classifying devices based on MAC address patterns and connection characteristics during authentication, the system reduces subsequent processing time while maintaining accurate device identification for policy enforcement.
Data Source
AI summary
Various methods and apparatus are described in for a wireless access point. The wireless access point allows access to a wireless LAN that has two or more service set identifiers (SSIDs). At least one of the SSIDs is associated with a public wireless LAN. The wireless access point implements a segmentation policy that 1) provides unimpeded access to a Wide Area network through the public wireless LAN based on a first type of application or a first type of device detected by the wireless access point and 2) restricts access to the Wide Area network through the public wireless LAN by requiring an authorization check to access the Wide Area network based on detecting a second type of application.


