Detecting Wireless AP Configuration Errors via Authentication Weight Tracking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Detecting and locating roaming/mobility configuration problems in wireless network devices is time-consuming and reactive, often resulting in overloading of authentication servers due to excessive re-authentication, requiring days or weeks of troubleshooting and involving end-user queries.

Innovation Solution

A management server communicates with an authentication server to receive event logs and adjusts weights for access points (APs) and wireless local area network (WLAN) controllers (WLCs) based on authentication requests, identifying improperly configured devices by tracking roaming conditions and triggering unnecessary re-authentications, thereby pinpointing configuration issues.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If roaming/mobility is not properly configured on APs and WLCs, then endpoint devices perform re-authentication during roaming events, but this causes overloading of the authentication server and scalability problems

Engineering Contradiction:
Improveroaming functionalityVSAvoidauthentication server capacity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary analysis of authentication requests to identify configuration issues before they cause server overload. By proactively detecting improperly configured APs and WLCs through weight tracking and pattern recognition, the system prevents excessive re-authentication events from occurring, thereby protecting authentication server capacity while ensuring reliable roaming functionality.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If traditional debugging methods are used to locate roaming configuration problems, then individual endpoint devices are queried, but this process is time-consuming and reactive, taking days or weeks

Engineering Contradiction:
Improveproblem location accuracyVSAvoidtroubleshooting time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system enables self-service troubleshooting by automatically analyzing authentication request patterns and identifying improperly configured network devices. The weight tracking mechanism and automated detection algorithms eliminate the need for manual debugging of individual endpoint devices, providing precise problem location information instantly rather than requiring days or weeks of reactive troubleshooting.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements continuous feedback monitoring of authentication requests to detect configuration issues in real-time. By tracking weights associated with different APs and WLCs based on authentication patterns, the system provides ongoing feedback about system health and configuration problems, enabling immediate detection and resolution rather than delayed reactive troubleshooting.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If endpoint devices roam between APs controlled by different WLCs, then authentication requests are generated, but excessive requests indicate improper roaming configuration

Engineering Contradiction:
Improveroaming capabilityVSAvoidconfiguration management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system introduces an intermediary analysis layer between endpoint devices and authentication servers that monitors authentication request patterns. This intermediary tracks weights associated with different WLCs and APs, identifying configuration issues without requiring changes to endpoint devices or authentication server logic. The intermediary detects when roaming between different WLCs generates excessive authentication requests, indicating improper configuration, while preserving full roaming capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10212039B1Detecting network device configuration errors using authentication requests from wireless endpoints
Publication Date: 2019.02.19 CISCO TECHNOLOGY INC
  • US10212039B1 patent drawing
  • US10212039B1 patent drawing
  • US10212039B1 patent drawing

AI summary

A management server communicates with an authentication server that authenticates endpoints, which are configured to connect wirelessly with access points (APs) controlled by respective ones of a plurality of controllers. Weights for the APs and the controllers are stored. Event logs detailing requests for authentication of the endpoints are received. For each request, roaming conditions for the endpoint that triggered the request are determined. Also, a respective weight of one or more of the AP connected with the endpoint and of the controller that controls the AP is increased by a respective amount depending on whether the roaming conditions are caused by the AP and the controller being improperly configured or properly configured. Identities of ones of the APs and the controllers having weights that exceed one or more weight thresholds each indicative of an improperly configured AP or controller are stored.