Wireless Profile Provisioning via Dynamic Access Point Updates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current IEEE 802.11 wireless LAN protocols lack a mechanism for dynamically updating client profiles without manual pre-configuration or re-authentication, leading to service disruptions when resource requests such as SSID, security, or bandwidth do not match authorization policies, and there is no way for an Access Point to transmit new wireless network access parameters.
Innovation Solution
A system and method that allows an access point to dynamically provision a client with a new wireless profile after association, using an authentication server and a profile server to authenticate and provide alternate profiles, including parameters like SSID, security settings, and QoS, without requiring pre-configuration or re-authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the client uses manual pre-configuration or auto profile switching, then the client can establish wireless connection, but the client experiences service disruption when resource requests do not match authorization policy and must go through authentication again
Solution Approach 1:
The access point pre-provisions alternate profiles to the client during the initial association phase, before any resource requests or authorization checks occur. This preliminary provisioning ensures the client has the necessary profile information ready, eliminating the need for re-authentication when profile switching is required later.
Solution Approach 2:
The access point acts as an intermediary between the authentication server and the client, receiving alternate profiles from the authentication server and transmitting them to the client. This intermediary role allows the client to receive updated profile information without directly engaging in the authentication process.
2Loss of information
If the access point transmits new wireless network access parameters, then the client can discover permitted access parameters, but the current IEEE 802.11 management frames only provide generic error codes without transmission mechanism
Solution Approach 1:
The profile information is segmented into distinct information elements that can be independently transmitted and processed. Each profile parameter (SSID, security settings, QoS parameters) is structured as a separate element within the management frame, allowing for flexible transmission and selective updating without requiring complete frame restructuring.
Solution Approach 2:
The management frame structure is made dynamic to accommodate variable profile information. The frame includes length fields and type indicators that allow the access point to transmit different profile parameters as needed, rather than using a fixed static structure. This enables efficient transmission of only the necessary profile updates.
3Adaptability or versatility
If the client switches to a different SSID and VLAN for voice or video applications, then the QoS requirements can be met, but the client must go through authentication again and cannot use previous link layer encryption keys
Solution Approach 1:
The client is empowered to autonomously switch between profiles using the alternate profile information previously provisioned by the access point. The client can select and apply the appropriate profile for different applications (voice, video, data) without requiring manual authentication intervention, making the system self-service oriented.
Solution Approach 2:
The client's operational parameters are dynamically changed by switching between different profile configurations. Each profile contains specific parameters for SSID, VLAN, security settings, and QoS. The client modifies these parameters based on the provisioned alternate profiles without changing the fundamental authentication relationship with the network.
Data Source
AI summary
A system and method to enable an access point to dynamically provision a WLAN client with a new wireless profile once an association is established based on the infrastructure policy. A client can be directed to use a new profile without the need for pre-configuration and going through another authentication process. The new wireless profile can be provided to the client either during or after association, with or without the protection of link layer security key.


