802.1X Keepalive Mechanism for Abnormal Disconnection Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current WLAN access methods, such as 802.1X + EAP, lack a Keeplive mechanism, leading to resource waste and security risks due to the inability to detect abnormal disconnections by subscribers, resulting in inaccurate billing and memory consumption issues for authenticating nodes.

Innovation Solution

Implementing a bidirectional Keeplive mechanism between 802.1X clients and authenticating nodes using EAPOL messages to detect abnormal disconnections and maintain session states, allowing for timely resource management and security enhancements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If no Keeplive mechanism is implemented in 802.1X access protocol, then the protocol remains simple and lightweight, but the authenticating node cannot detect abnormal disconnections timely, leading to resource waste and security risks

Engineering Contradiction:
Improvedetection accuracy of abnormal disconnectionVSAvoidprotocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the Keeplive mechanism with the existing EAPOL message structure of 802.1X protocol. By reusing the established EAPOL message framework and integrating keepalive functionality into existing authentication messages, the solution achieves reliable connection detection without requiring a completely new protocol structure, thus balancing reliability improvement with minimal protocol complexity increase

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The EAPOL messages in the 802.1X protocol are designed to serve multiple functions: authentication, authorization, and connection status detection. By making the existing EAPOL messages multi-functional, the patent eliminates the need for separate dedicated keepalive messages, thereby improving detection capability while avoiding additional protocol complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If supplementary means such as unicast ARP request or idle subscriber traffic detection are used to detect abnormal disconnection, then detection capability is improved, but additional protocol enablement is required and more resources are consumed

Engineering Contradiction:
Improvedetection capabilityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent combines the detection function with the existing authentication traffic. The same EAPOL messages used for 802.1X authentication are also used for connection status detection, eliminating the need for separate detection traffic. This merging approach improves detection capability while avoiding additional resource consumption from supplementary detection protocols

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication messages are designed to serve dual purposes: establishing authentication and monitoring connection status. By making the authentication traffic multi-functional, the system achieves reliable detection without requiring additional dedicated detection resources, thus resolving the contradiction between detection capability and resource consumption

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Quantity of substance

If the authenticating node manages constantly increasing number of online subscribers without timely detection mechanism, then network coverage and subscriber capacity increase, but the authenticating node becomes loaded gradually, leading to resource waste

Engineering Contradiction:
Improvenumber of online subscribersVSAvoidmemory resource consumption
Core Design Contradiction:
Quantity of substanceVSLoss of energy

Solution Approach 1:

The patent implements periodic sending of EAPOL messages at defined intervals to maintain authentication sessions and detect abnormal disconnections. This periodic action allows the system to manage large numbers of subscribers efficiently by systematically refreshing session states and identifying disconnected users, thereby preventing unbounded memory growth while supporting scalable subscriber capacity

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The authenticating node uses the periodic EAPOL message exchange to receive feedback from subscribers about their connection status. When a subscriber fails to respond to periodic messages, the node receives feedback indicating abnormal disconnection and can promptly release resources. This feedback mechanism enables efficient management of large subscriber populations by dynamically adjusting resource allocation based on actual connection states

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP2950499B1802.1x access session keepalive method, device, and system
Publication Date: 2018.09.12 ZTE CORP
  • EP2950499B1 patent drawingFigure 1~2
  • EP2950499B1 patent drawingFigure 3~5
  • EP2950499B1 patent drawingFigure 6

AI summary

The present invention relates to the field of communications. Disclosed are an 802.IX access session keepalive method, device, and system. The method comprises: during network access of a 802.IX client, an authenticating node used for access authentication sending, to the 802.IX client according to an actual keepalive period of the authenticating node, a keepalive request message used for determining whether the 802.IX client is off-net abnormally; and during a preset duration of the authenticating node, if the authenticating node does not receive a keepalive response message from the 802.IX client in response to the keepalive request message, the authenticating node determining that the 802.IX client is off-net abnormally; otherwise, determining that the 802.IX client is on-net normally. The embodiments of the present invention improve network resource utilization, reduce the security problem caused by too heavy load of the authenticating node, and lower the risk of errors in charging on time.