Cache-based wireless client authentication
Abstract
Methods and systems for caching of remote server MAC authentication to enable fast roaming are provided. According to one embodiment, MAC addresses of wireless client devices contained within authentication requests associated with the wireless client devices and corresponding authentication status information provided by an authentication server associated with a wireless local area network (WLAN) responsive to the authentication requests are cached by a wireless network controller of the WLAN. A MAC-based authentication request is received by the wireless network controller from a wireless access point (AP) managed by the wireless network controller on behalf of a roaming wireless client device. It is determined whether cached authentication status information exists for the MAC address of the roaming wireless client device and if so, then the roaming wireless client device is permitted or denied access to the WLAN via the AP based on the cached authentication status information.
Claims
exact text as granted — not AI-modified1 . A method comprising:
caching, by a wireless network controller of a wireless local area network (WLAN), within a cache (i) Media Access Control (MAC) addresses of wireless client devices contained within authentication requests associated with the wireless client devices and (ii) corresponding authentication status information provided by an authentication server associated with the WLAN responsive to the authentication requests; receiving, by the wireless network controller, a MAC-based authentication request from a wireless access point (AP) managed by the wireless network controller on behalf of a roaming wireless client device, wherein the MAC-based authentication request contains a MAC address of the roaming wireless client device; determining, by the wireless network controller, whether the cache contains cached authentication status information for the MAC address of the roaming wireless client device; and when said determining is affirmative, then causing, by the wireless network controller, the roaming wireless client device to be permitted or denied access to the WLAN via the AP based on the cached authentication status information.
2 . The method of claim 1 , further comprising:
issuing, by the wireless network controller, the MAC-based authentication request to the authentication server to determine a current authentication status of the roaming wireless client device; and receiving, by the wireless network controller, the current authentication status of the roaming wireless client device from the authentication server.
3 . The method of claim 1 , further comprising when the current authentication status differs from the cached authentication status information and the current authentication status represents a successful authentication of the roaming wireless client device, then continuing to allow the roaming wireless client device to access the WLAN via the AP.
4 . The method of claim 1 , further comprising when the current authentication status differs from the cached authentication status information and the current authentication status represents an unsuccessful authentication of the roaming wireless client device, then revoking access to the WLAN by the wireless client device via the AP.
5 . The method of claim 1 , further comprising when said determining is negative, then:
issuing, by the wireless network controller, the MAC-based authentication request to the authentication server to determine a current authentication status of the roaming wireless client device; delaying permitting or denying, by the wireless network controller, access to the WLAN by the roaming wireless client device until after a response to the authentication request is received from the authentication server; receiving, by the wireless network controller, the current authentication status of the roaming wireless client device from the authentication server; and responsive to receipt of the current authentication status, causing, by the wireless network controller, the roaming wireless client device to be permitted or denied access to the WLAN via the AP based on the current authentication status.
6 . The method of claim 1 , wherein the authentication server comprises a remote server, a Remote Authentication Dial-in User Service (RADIUS) server, a Terminal Access Controller Access-Control System (TACACS) server or a Lightweight Directory Access Protocol (LDAP) server.
7 . A non-transitory program storage device readable by a wireless network controller of a wireless local area network (WLAN), embodying a program of instructions executable by one or more processors of the wireless network controller to perform an authentication method, the method comprising:
caching within a cache of the wireless network controller (i) Media Access Control (MAC) addresses of wireless client devices contained within authentication requests associated with the wireless client devices and (ii) corresponding authentication status information provided by an authentication server associated with the WLAN responsive to the authentication requests; receiving a MAC-based authentication request from a wireless access point (AP) managed by the wireless network controller on behalf of a roaming wireless client device, wherein the MAC-based authentication request contains a MAC address of the roaming wireless client device; determining whether the cache contains cached authentication status information for the MAC address of the roaming wireless client device; and when said determining is affirmative, then causing the roaming wireless client device to be permitted or denied access to the WLAN via the AP based on the cached authentication status information.
8 . The non-transitory program storage device of claim 7 , wherein the method further comprises:
issuing the MAC-based authentication request to the authentication server to determine a current authentication status of the roaming wireless client device; and receiving the current authentication status of the roaming wireless client device from the authentication server.
9 . The non-transitory program storage device of claim 7 , wherein the method further comprises when the current authentication status differs from the cached authentication status information and the current authentication status represents a successful authentication of the roaming wireless client device, then continuing to allow the roaming wireless client device to access the WLAN via the AP.
10 . The non-transitory program storage device of claim 7 , wherein the method further comprises when the current authentication status differs from the cached authentication status information and the current authentication status represents an unsuccessful authentication of the roaming wireless client device, then revoking access to the WLAN by the wireless client device via the AP.
11 . The non-transitory program storage device of claim 7 , wherein the method further comprises when said determining is negative, then:
issuing the MAC-based authentication request to the authentication server to determine a current authentication status of the roaming wireless client device; delaying permitting or denying access to the WLAN by the roaming wireless client device until after a response to the authentication request is received from the authentication server; receiving the current authentication status of the roaming wireless client device from the authentication server; and responsive to receipt of the current authentication status, causing the roaming wireless client device to be permitted or denied access to the WLAN via the AP based on the current authentication status.
12 . The non-transitory program storage device of claim 7 , wherein the authentication server comprises a remote server, a Remote Authentication Dial-in User Service (RADIUS) server, a Terminal Access Controller Access-Control System (TACACS) server or a Lightweight Directory Access Protocol (LDAP) server.Join the waitlist — get patent alerts
Track US2016087954A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.