AAA Client Server Selection for Authentication Mechanisms

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current AAA network configurations face limitations in selecting the appropriate AAA server based on authentication mechanisms, leading to inefficiencies, high administration costs, and network traffic overload, especially in remote branch offices with disrupted links.

Innovation Solution

Implement a method where AAA clients detect the authentication mechanism used by supplicants and select compatible AAA servers, using association data and CLI commands to direct access requests to dedicated or full-scale servers based on authentication mechanisms and VPN tunnel types.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If AAA clients use a single AAA server for all authentication mechanisms, then network configuration is simplified, but network reliability deteriorates when links are disrupted

Engineering Contradiction:
Improvenetwork configurationVSAvoidservice continuity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments AAA servers into different types (full-scale AAA servers and lightweight AAA servers) and assigns them to different locations (central and remote branch offices). This segmentation allows remote offices to operate independently when links to central servers are disrupted, improving reliability while maintaining manageable configuration complexity through automated selection mechanisms.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If AAA clients forward all access requests to a full-scale AAA server, then authentication functionality is comprehensive, but network traffic and administration costs increase

Engineering Contradiction:
Improveauthentication functionalityVSAvoidnetwork traffic
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent extracts authentication functionality from the central full-scale AAA server and deploys lightweight AAA servers at remote branch offices. These lightweight servers handle authentication requests locally, reducing the volume of traffic that must traverse the WAN link to the central server while maintaining comprehensive authentication capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces lightweight AAA servers as cost-effective alternatives to full-scale AAA servers. These lightweight servers are deployed at remote offices where full-scale servers would be unnecessary and expensive, providing sufficient authentication functionality at lower cost and reduced traffic overhead.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Device complexity

If AAA clients select AAA servers based only on AAA protocol, then server selection is simple, but authentication efficiency deteriorates

Engineering Contradiction:
Improveserver selection mechanismVSAvoidauthentication efficiency
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The patent implements a dynamic server selection mechanism that goes beyond static protocol-based routing. The AAA client examines the specific authentication mechanism being used (e.g., EAP-FAST, EAP-TLS, LEAP) and dynamically selects the most appropriate AAA server type and location, optimizing authentication efficiency while managing complexity through automated decision-making.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS7890992B2Method and apparatus for selection of authentication servers based on the authentication mechanisms in supplicant attempts to access network resources
Publication Date: 2011.02.15 CISCO TECHNOLOGY INC
  • US7890992B2 patent drawing
  • US7890992B2 patent drawing
  • US7890992B2 patent drawing

AI summary

A computer-implemented method is provided for processing access requests in an AAA network. The method includes receiving an access request from a network device, identifying, based upon the access request, an authentication mechanism for facilitating AAA services for the network device and selecting, based on the identified authentication mechanism, a particular server from a plurality of servers that is compatible with the identified authentication mechanism.