802.1x Extension for Multi-User Device Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing multi-user client computing devices face challenges in securely managing 802.1x authentication settings, as these settings are persisted across users and cannot be dynamically adjusted based on the logged-in user, leading to security risks and increased administrative overhead.
Innovation Solution
Implementing an 802.1x extension on multi-user client computing devices that leverages the verified user credentials to select and perform 802.1x authentication specific to the logged-in user, and automatically disconnects from the LAN when the user logs off, thereby preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If 802.1x authentication settings are persisted on the multi-user client computing device for one user, then that user can access the LAN, but other users who should not have access will also be able to access the LAN creating security risks
Solution Approach 1:
The patent segments the authentication settings by creating separate 802.1x authentication profiles for different users. Each profile is associated with specific user credentials and authentication parameters, allowing the system to select and apply the appropriate profile based on which user is currently logged in to the multi-user device.
Solution Approach 2:
The patent implements dynamic authentication configuration where the 802.1x settings are not static but change based on the logged-in user. The system automatically detects which user is active and dynamically applies the corresponding authentication profile, making the security configuration adaptive rather than fixed.
2Reliability
If an administrator manually configures 802.1x authentication settings each time a user logs in, then proper user-specific access control is achieved, but this is unfeasible in enterprise environments due to administrative overhead
Solution Approach 1:
The patent enables the multi-user client computing device to automatically manage its own 802.1x authentication configuration without requiring administrator intervention for each user login. The system self-service by automatically detecting the logged-in user, selecting the appropriate authentication profile, and applying the correct settings, thereby eliminating manual administrative overhead.
Solution Approach 2:
The patent implements preliminary configuration by pre-establishing multiple 802.1x authentication profiles in advance, each associated with specific user credentials and authentication parameters. This preliminary setup allows the system to quickly and automatically apply the appropriate profile when a user logs in, without requiring real-time administrative configuration.
3Adaptability or versatility
If isolated subnets are created to allow different authentication types for different users, then authentication flexibility is improved, but this increases the cost and overhead of the LAN/WLAN infrastructure
Solution Approach 1:
The patent makes the 802.1x authentication system universal by enabling a single LAN/WLAN infrastructure to support multiple authentication types and user profiles simultaneously. Instead of requiring separate subnets for different authentication methods, the system can dynamically apply different authentication types (such as PEAP, EAP-TLS, or PAP) within the same network segment based on the active user profile.
4Ease of operation
If the same authentication type is used for all users on a multi-user client computing device, then configuration simplicity is maintained, but user-specific security requirements cannot be met
Solution Approach 1:
The patent applies local quality by associating specific authentication parameters and types with individual user profiles rather than applying a uniform configuration to all users. Each user profile can have customized authentication settings tailored to their specific security requirements and access needs, while the system maintains overall configuration simplicity through automated profile management.
Data Source
AI summary
Logged-in-user-specific 802.1x security can be applied on a multi-user client computing device. An 802.1x extension can be provided on a multi-user client computing device to leverage user credentials that are verified to log a user into the multi-user client computing device to select and perform 802.1x authentication for connecting the multi-user client computing device to a LAN. The 802.1x extension may also leverage the user credentials to obtain and use one or more certificates as part of the 802.1x authentication. When the user logs off of the multi-user client computing device, the 802.1x extension can automatically disconnect the multi-user client computing device from the LAN to prevent a subsequently logged in user from obtaining unauthorized access to the LAN.


