802.1X Port Binding for Multi-Device VLAN Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network access control protocols, such as 802.1X, are limited to supporting a single device per port and do not effectively manage authorization for multiple devices attempting to access different virtual local area networks (VLANs) through a single access port, leading to potential unauthorized access and security vulnerabilities.

Innovation Solution

Implementing a method where multiple devices can authenticate and access specific VLANs through a single access port by forming bindings between device MAC addresses and VLANs, using an authentication, authorization, and accounting (AAA) server to manage access control lists (ACLs) and filter packets based on VLAN-specific permissions, allowing only authorized devices to access their designated VLANs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If 802.1X protocol is used for network access control, then authentication and authorization of devices is improved, but the protocol is limited to supporting only one device per port

Engineering Contradiction:
Improveauthentication and authorizationVSAvoidnumber of devices per port
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the single port into multiple virtual ports by introducing VLAN (Virtual Local Area Network) concepts. Each VLAN acts as a separate logical segment, allowing multiple devices to be authenticated and authorized on different VLANs through a single physical port. This segmentation enables the system to maintain security while supporting multiple devices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a dimensional layer by introducing VLAN identifiers alongside the traditional single-device-per-port constraint. Instead of limiting access to one device, the system now manages access across multiple dimensions by assigning devices to different VLANs, thereby enabling multiple devices per port while maintaining authentication and authorization controls.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Adaptability or versatility

If multiple devices are allowed to access through a single port, then device connectivity and versatility are improved, but network security and unauthorized access control deteriorate

Engineering Contradiction:
Improvenumber of devices per portVSAvoidunauthorized access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by assigning specific VLANs to specific devices based on their authentication status. Each device receives access rights tailored to its specific VLAN assignment, creating localized access control policies. This ensures that while multiple devices can access the network simultaneously, each device is restricted to its authorized VLAN only, preventing unauthorized access.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent introduces VLANs as intermediary structures between the physical network infrastructure and individual devices. These VLAN intermediaries act as mediators that enforce access control policies, allowing multiple devices to share a physical port while maintaining secure, isolated communication paths through the VLAN layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If access control lists and packet filtering are implemented, then network security is improved, but network complexity and processing overhead increase

Engineering Contradiction:
Improvenetwork securityVSAvoidaccess control management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes VLANs multi-functional, serving multiple purposes simultaneously: they provide network segmentation, enable access control, support packet filtering, and facilitate quality of service (QoS) policies. By consolidating these functions into a single mechanism, the system improves security without proportionally increasing complexity, as VLANs handle multiple control tasks that would otherwise require separate systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7539189B2Apparatus and methods for supporting 802.1X in daisy chained devices
Publication Date: 2009.05.26 CISCO TECHNOLOGY INC
  • US7539189B2 patent drawing
  • US7539189B2 patent drawing
  • US7539189B2 patent drawing

AI summary

Disclosed are apparatus and methods for authenticating a device to access a network through an access control port. In one embodiment, one or more first authentication packets for authenticating a first device or user to access a first network domain via a particular access port of a network device are received, for example, by an access control port. The particular access port is configured to control access for packets attempting to ingress into one or more network domains. When the first device or user is authorized to access the first domain, a first binding between the first device and the first domain is formed. The first binding specifies that the first device is allowed to access the first domain and the first binding is associated with the particular access port of the network device. When a packet is received that is attempting to ingress into the first domain and the ingressing packet matches the first binding, the ingressing packet is allowed to access the first domain. In contrast, when a packet is received that is attempting to ingress into the first domain and the ingressing packet does not match the first binding, the ingressing packet is blocked from accessing the first domain.