Wireless Access Point Segmentation for Device-Specific Network Policies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless network access control methods cannot differentiate between wireless devices and applications, leading to uniform treatment of all users on public networks, which hinders the ability to implement tailored access policies based on device or application type.

Innovation Solution

A wireless access point is configured to detect and classify wireless devices and applications by reading MAC addresses and data protocols, allowing for the implementation of segmented access policies that provide unimpeded or restricted access to the network based on the detected type.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If uniform access control is implemented for all wireless devices on public networks, then network security is maintained through consistent policies, but the ability to implement tailored access policies based on device or application type is lost

Engineering Contradiction:
Improvenetwork securityVSAvoidtailored access policies
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments wireless devices into different categories (e.g., personal devices, guest devices, IoT devices) and applies different access control policies to each segment. The access point classifies devices based on MAC address patterns, connection behavior, and device characteristics, then enforces appropriate security policies for each category, allowing both security consistency within segments and policy differentiation across segments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by applying specific access control characteristics to different device types. Each device category receives customized policy treatment (e.g., bandwidth limits, access hours, permitted services) based on its specific needs and security requirements, rather than applying a single uniform policy to all devices.

Inventive Principle:
Principle #3Local quality

2Adaptability or versatility

If device classification and segmented access policies are implemented, then tailored access control is enabled, but system complexity increases due to detection and classification requirements

Engineering Contradiction:
Improvedifferentiated access controlVSAvoiddetection and classification system
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal classification system at the access point that handles multiple device types and policy requirements through a single unified mechanism. The access point uses general MAC address analysis and connection pattern detection to classify diverse devices into predefined categories, applying appropriate policies without requiring device-specific configurations or complex identification procedures for each device type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent simplifies classification by monitoring changes in key parameters such as MAC address patterns, connection timing, data transmission rates, and protocol usage. By tracking these parameter changes over time, the system automatically adapts device classifications and adjusts access policies without requiring manual intervention or complex analytical algorithms.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If MAC address reading and protocol detection are performed for device classification, then accurate device identification is achieved, but processing time and computational resources increase

Engineering Contradiction:
Improvedevice identification accuracyVSAvoidclassification processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements partial action by performing MAC address reading and protocol detection selectively rather than continuously for all devices. The system initially classifies devices based on MAC address patterns alone, then performs more intensive protocol detection only when classification is ambiguous or when security policies require additional verification, reducing overall processing time while maintaining identification accuracy.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent performs preliminary MAC address analysis during the initial connection handshake phase, before full protocol detection is required. By pre-classifying devices based on MAC address patterns and connection characteristics during authentication, the system reduces subsequent processing time while maintaining accurate device identification for policy enforcement.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7499438B2Controlling wireless access to a network
Publication Date: 2009.03.03 COMMSCOPE TECHNOLOGIES LLC
  • US7499438B2 patent drawing
  • US7499438B2 patent drawing
  • US7499438B2 patent drawing

AI summary

Various methods and apparatus are described in for a wireless access point. The wireless access point allows access to a wireless LAN that has two or more service set identifiers (SSIDs). At least one of the SSIDs is associated with a public wireless LAN. The wireless access point implements a segmentation policy that 1) provides unimpeded access to a Wide Area network through the public wireless LAN based on a first type of application or a first type of device detected by the wireless access point and 2) restricts access to the Wide Area network through the public wireless LAN by requiring an authorization check to access the Wide Area network based on detecting a second type of application.