WLAN Authentication Server Tunnel Selection for Service Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Public or operator WLAN systems lack the ability to enable access to a broader range of services, as they do not provide dedicated signaling for setting up services between a WLAN terminal device and the WLAN network, limiting users to direct Internet access only.

Innovation Solution

A method and system that authenticate user terminals, select user data processing nodes based on selection information, and create tunnel connections between access networks and user data processing nodes, allowing access to third-party network services by signaling tunnel parameter information between authentication servers and access networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If public or operator WLAN systems provide only direct Internet access without dedicated signaling for service setup, then the system is simple to implement, but the service access capability is limited

Engineering Contradiction:
Improveservice access capabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies universality by enabling the WLAN system to perform multiple functions: it can provide both direct Internet access and access to third-party network services through the same infrastructure. The authentication server and access network are enhanced to handle multiple service types (Internet access, corporate intranet, operator services) using a unified signaling mechanism based on EAP protocols and tunnel parameters, making the system versatile without requiring separate dedicated systems for each service type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary mechanism in the form of an authentication server that acts as a mediator between the WLAN terminal device and various network services. This intermediary processes authentication requests, selects appropriate user data processing nodes based on service information, and establishes tunnel connections to the desired services. The intermediary enables complex service access while keeping the terminal device relatively simple.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If WLAN systems support multiple simultaneous connections to different services, then user mobility and network flexibility are enhanced, but the complexity of connection management increases

Engineering Contradiction:
Improvenetwork flexibilityVSAvoidconnection management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling the authentication server to automatically perform service selection and tunnel establishment based on information provided by the terminal device. The system autonomously authenticates users, selects appropriate user data processing nodes, configures tunnel parameters, and manages multiple connections without requiring complex manual configuration or intervention. This automation reduces the perceived complexity for users while maintaining high network flexibility.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies dynamics by making the connection management system adaptive and flexible. The authentication server dynamically selects user data processing nodes based on real-time service information, and tunnel connections can be established, modified, or terminated as needed. The system can handle multiple simultaneous connections with different parameters, allowing users to access multiple services concurrently while the system adapts to changing network conditions and service requirements.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8077681B2Method and system for establishing a connection via an access network
Publication Date: 2011.12.13 NOKIA TECHNOLOGIES OY
  • US8077681B2 patent drawing
  • US8077681B2 patent drawing
  • US8077681B2 patent drawing

AI summary

A method and system for establishing a connection via an access network (30) communicating with at least one user terminal, and at least one backbone network (100) comprising at least one user terminal authentication and authorization means (50) and at least one user data processing node (60, 62), wherein the connection of a user terminal (10) is authenticated to the access network (30) and one of the at least one user data processing nodes (60, 62) is selected based on selection information transferred in the authentication signaling. Then, a tunnel parameter information of the selected user data processing node is signaled to the access network (30) and a tunnel connection is created between the access network (30) and the selected user data processing node (60) based on the tunnel parameter information.