802.1x Extension for Multi-User Device Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing multi-user client computing devices face challenges in securely managing 802.1x authentication settings, as these settings are persisted across users and cannot be dynamically adjusted based on the logged-in user, leading to security risks and increased administrative overhead.

Innovation Solution

Implementing an 802.1x extension on multi-user client computing devices that leverages the verified user credentials to select and perform 802.1x authentication specific to the logged-in user, and automatically disconnects from the LAN when the user logs off, thereby preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If 802.1x authentication settings are persisted on the multi-user client computing device for one user, then that user can access the LAN, but other users who should not have access will also be able to access the LAN creating security risks

Engineering Contradiction:
ImproveLAN access securityVSAvoidAuthentication configuration management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the authentication settings by creating separate 802.1x authentication profiles for different users. Each profile is associated with specific user credentials and authentication parameters, allowing the system to select and apply the appropriate profile based on which user is currently logged in to the multi-user device.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic authentication configuration where the 802.1x settings are not static but change based on the logged-in user. The system automatically detects which user is active and dynamically applies the corresponding authentication profile, making the security configuration adaptive rather than fixed.

Inventive Principle:
Principle #15Dynamics

2Reliability

If an administrator manually configures 802.1x authentication settings each time a user logs in, then proper user-specific access control is achieved, but this is unfeasible in enterprise environments due to administrative overhead

Engineering Contradiction:
ImproveUser-specific access controlVSAvoidAdministrative efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent enables the multi-user client computing device to automatically manage its own 802.1x authentication configuration without requiring administrator intervention for each user login. The system self-service by automatically detecting the logged-in user, selecting the appropriate authentication profile, and applying the correct settings, thereby eliminating manual administrative overhead.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements preliminary configuration by pre-establishing multiple 802.1x authentication profiles in advance, each associated with specific user credentials and authentication parameters. This preliminary setup allows the system to quickly and automatically apply the appropriate profile when a user logs in, without requiring real-time administrative configuration.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If isolated subnets are created to allow different authentication types for different users, then authentication flexibility is improved, but this increases the cost and overhead of the LAN/WLAN infrastructure

Engineering Contradiction:
ImproveAuthentication type flexibilityVSAvoidLAN/WLAN infrastructure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent makes the 802.1x authentication system universal by enabling a single LAN/WLAN infrastructure to support multiple authentication types and user profiles simultaneously. Instead of requiring separate subnets for different authentication methods, the system can dynamically apply different authentication types (such as PEAP, EAP-TLS, or PAP) within the same network segment based on the active user profile.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Ease of operation

If the same authentication type is used for all users on a multi-user client computing device, then configuration simplicity is maintained, but user-specific security requirements cannot be met

Engineering Contradiction:
ImproveAuthentication configuration simplicityVSAvoidUser-specific security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies local quality by associating specific authentication parameters and types with individual user profiles rather than applying a uniform configuration to all users. Each user profile can have customized authentication settings tailored to their specific security requirements and access needs, while the system maintains overall configuration simplicity through automated profile management.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12341767B2Applying logged-in-user-specific 802.1x security on a multi-user client computing device
Publication Date: 2025.06.24 DELL PROD LP
  • US12341767B2 patent drawing
  • US12341767B2 patent drawing
  • US12341767B2 patent drawing

AI summary

Logged-in-user-specific 802.1x security can be applied on a multi-user client computing device. An 802.1x extension can be provided on a multi-user client computing device to leverage user credentials that are verified to log a user into the multi-user client computing device to select and perform 802.1x authentication for connecting the multi-user client computing device to a LAN. The 802.1x extension may also leverage the user credentials to obtain and use one or more certificates as part of the 802.1x authentication. When the user logs off of the multi-user client computing device, the 802.1x extension can automatically disconnect the multi-user client computing device from the LAN to prevent a subsequently logged in user from obtaining unauthorized access to the LAN.