Wireless Device Network Access via 802.1x and Non-802.1x Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technical specifications, such as TS 24.234, do not fully define how wireless devices can access a Home Public Land Mobile Network (HPLMN) using combined IEEE 802.1x and non-802.1x authentication mechanisms, particularly when roaming beyond the HPLMN coverage area.

Innovation Solution

A method and apparatus that enable a wireless device to detect available networks by monitoring SSID broadcasts, identify 802.1x and non-802.1x capable networks, and attempt connections using defined authentication mechanisms, with operator policies guiding the selection between authentication types to access the HPLMN.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a wireless device attempts to access HPLMN services through multiple authentication mechanisms (802.1x and non-802.1x) while roaming, then the reliability of network access is improved, but the device complexity and authentication process complexity increase

Engineering Contradiction:
Improvenetwork access reliabilityVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication process into two distinct mechanisms: 802.1x authentication and non-802.1x authentication. The wireless device and network separately implement and evaluate each authentication type independently, allowing the device to attempt one mechanism while the network prepares fallback options through operator policies without requiring the device to handle all complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Operator policies act as an intermediary that guides the authentication process. The policies are stored in the network and transmitted to the wireless device, providing pre-configured instructions on which authentication mechanisms to attempt and in what order. This intermediary absorbs the complexity of managing multiple authentication types, allowing the device to follow straightforward policy-driven instructions rather than implementing complex authentication logic itself

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the technical specification defines detailed working of combined 802.1x and non-802.1x mechanisms, then the ease of operation is improved, but the device complexity increases

Engineering Contradiction:
Improveauthentication process easeVSAvoidimplementation complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

Operator policies are prepared in advance by the network operator and stored in the network before the wireless device needs to authenticate. These policies contain pre-determined instructions about which authentication mechanisms are available and in what order they should be attempted. This preliminary preparation eliminates the need for the device to dynamically decide between authentication types, simplifying the device's operational burden while ensuring proper authentication sequence

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Instead of requiring the wireless device to implement complex logic for selecting and managing multiple authentication mechanisms, the patent inverts the approach: the network operator pre-configures the authentication strategy through operator policies, and the device simply follows these instructions. The complexity is shifted from the device side to the network operator side, making device implementation easier while maintaining operational effectiveness

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentEP2456129B1Apparatus and associated method for facilitating access to a home or other public network
Publication Date: 2018.08.08 BLACKBERRY LTD
  • EP2456129B1 patent drawingFigure 1
  • EP2456129B1 patent drawingFigure 2~4
  • EP2456129B1 patent drawingFigure 3

AI summary

A method and a wireless device, the method comprising: obtaining information indicating whether at least one wireless local area network (WLAN) supports 802.1x authentication, the information being contained within a broadcast message; determining whether to use a non-802. 1x authentication mechanism based on an indicator stored at the wireless device, the non-802.1x authentication mechanism comprising a tunnel procedure; based on the information and the indicator stored at the wireless device, identifying, via the at least one WLAN, any available network using at least one of a 802.1x authentication mechanism or a non-802.1x authentication mechanism; and indicating at least one network identified using at least one of the 802. 1x authentication mechanism or the non-802.1x authentication mechanism.