WLAN Session Control via IAPP Protocol for Access Termination
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In RADIUS-based WLAN networks, there is no standardized method for a Wireless Serving Node (WSN) to initiate session termination or re-authentication in IEEE 802.1X scenarios, leading to weak session control, especially when users run out of credit or are idle, and current solutions either lack effectiveness or are limited to specific AP types.
Innovation Solution
The WSN uses the IAPP protocol and layer-2 frames to cancel sessions across Access Points (APs), allowing for standardized session termination and re-authentication by emulating AP-specific messages, even when not physically an AP, ensuring timely access control and account management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the WSN uses standard RADIUS protocol for session control, then compatibility with existing RADIUS infrastructure is maintained, but the ability to initiate session termination or re-authentication is insufficient
Solution Approach 1:
The patent introduces the IAPP protocol as an intermediary mechanism between the WSN and APs. The WSN sends IAPP MOVE-notify messages to APs to initiate session termination or re-authentication, bridging the gap between RADIUS accounting functionality and the need for active session control. This intermediary approach allows the WSN to control sessions without requiring proprietary RADIUS extensions.
Solution Approach 2:
The patent enables the WSN to perform multiple functions using existing protocols. By combining RADIUS accounting data with IAPP session control messages, the WSN can both track user sessions and actively manage them (termination, re-authentication). This multi-functionality resolves the contradiction by making the WSN versatile without requiring new protocol specifications.
2Reliability
If proprietary protocols are used for session control, then effective session termination is achieved, but compatibility across different AP types is limited
Solution Approach 1:
The IAPP protocol was designed as a universal inter-AP protocol that can be implemented across different AP types and vendors. By using IAPP instead of proprietary solutions, the patent achieves effective session termination while maintaining broad compatibility. The WSN can send standardized IAPP messages to any IAPP-compliant AP in the network.
Solution Approach 2:
The patent positions the WSN as an intermediary that translates accounting decisions into standardized IAPP control messages. This intermediary role allows the system to use universal IAPP protocol rather than AP-specific proprietary protocols, achieving both effectiveness and compatibility.
3Loss of time
If the WSN monitors user credit and initiates session termination, then timely access control is achieved, but the lack of standardized methods weakens control reliability
Solution Approach 1:
The patent implements preliminary monitoring of user credit and session status by the WSN through RADIUS accounting. Before session termination is needed, the WSN continuously tracks account balance and session duration, allowing it to initiate timely session control actions when credit is exhausted or idle time limits are reached.
Solution Approach 2:
The WSN acts as an intermediary between RADIUS accounting information and actual session control execution. It receives accounting updates, makes control decisions, and executes them through standardized IAPP messages to APs, creating a reliable standardized path from monitoring to action.
4Reliability
If IEEE 802.1X authentication is used, then security is improved, but the ability for non-AP nodes to control sessions is reduced
Solution Approach 1:
The patent segments the session control functionality into distinct components: IEEE 802.1X handles authentication security at the AP-UE interface, while IAPP handles session management at the WSN-AP interface. This segmentation allows both high security authentication and flexible session control by non-AP nodes to coexist without conflict.
Solution Approach 2:
The WSN serves as an intermediary that operates at a different layer than the 802.1X authentication process. While 802.1X secures the authentication exchange between UE and AP, the WSN uses IAPP to control the resulting session, enabling flexible session management without compromising authentication security.
Data Source
AI summary
A network is provided comprising at least one access point and one access-controlling node whereby the identity of the station can be approved by the access controlling node. The at least one access-controlling node issues at least one Inter-Access Point Protocol message causing the access point with which the station is currently associated to disassociate the given station thereby terminating the access for the given station.


