WLAN Roaming Authentication via Access Point Meta-Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems for authorizing roaming device traffic in wireless local area networks face challenges with Network Address Translation (NAT), as they require authentication servers to have knowledge of the subscriber's actual IP address, which is not feasible when NAT occurs between the allocation point and the client device, leading to increased signaling overhead and scalability issues.
Innovation Solution
A method and system that allows an authentication server to remotely determine if traffic with a NAT translated IP address is associated with an authenticated device by using meta-data messages generated by the access point, which undergo the same NAT translation as the device's packets, enabling automatic authorization of subsequent traffic without referring to the NAT server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If the authentication server requires knowledge of the subscriber's actual IP address to authorize roaming traffic, then traffic authorization accuracy is improved, but system scalability deteriorates due to increased signaling overhead and the need for NAT server coordination
Solution Approach 1:
The patent introduces a meta-data message as an intermediary carrier that transports the subscriber's actual IP address from the access point to the authentication server. This meta-data message acts as a mediator that resolves the information asymmetry caused by NAT, allowing the authentication server to obtain the real IP address without direct coordination with the NAT server, thereby maintaining authorization accuracy while improving scalability
Solution Approach 2:
The access point performs preliminary action by embedding the subscriber's actual IP address in the meta-data message before forwarding it to the authentication server. This preliminary inclusion of authentication information in the meta-data message eliminates the need for subsequent signaling exchanges with the NAT server, reducing overhead and improving system scalability
2Difficulty of detecting and measuring
If separate SSIDs are used to separate guest and subscriber traffic, then traffic monitoring capability is improved, but network configuration complexity increases
Solution Approach 1:
The patent applies local quality by implementing different authentication mechanisms for different traffic types: meta-data messages follow a simplified direct authentication path while regular data traffic follows the standard NAT routing path. This allows targeted monitoring and authentication without requiring complete network reconfiguration, balancing monitoring capability with configuration simplicity
Data Source
AI summary
A system and method for recognising traffic generated from an authenticated a device roaming in a wireless local area network and related aspects are provided. An authentication server is arranged to authorise communications traffic originating from a wireless access point to use a roaming service, the traffic comprising an NAT translated IP address. The server first authorises a WLAN roaming device, and then processes a meta-data message received from a WLAN access point in which the source address of the message comprises the source address of the roaming device at the WLAN access point. The server then determines, from the information provided in the meta-data message when it is received by the authentication server, which includes at this point a NAT translated source address in the meta-data message what the NAT translated source address of traffic from said authenticated roaming device will be. This enables the authentication server to authenticate internet-bound traffic having said NAT translated source address. In this way, all traffic generated by the roaming device whilst that NAT translated IP address is valid is automatically authorised to use a roaming service to access the internet.


