Access Point Authentication Offload During RADIUS Server Outages
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network authentication systems, particularly in enterprise wireless networks, face issues such as RADIUS server overload leading to IEEE 802.1x failures and delayed authentication, causing frustration for users and administrators.
Innovation Solution
Electronic devices are equipped to perform selective authentication by accessing predefined hash functions and authentication parameters stored in memory, enabling them to authenticate and establish secure communication with other devices even when the authentication computer is unavailable, using techniques like EAP and a four-way handshake.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If IEEE 802.1x authentication is used with RADIUS server for enterprise wireless networks, then authentication security is improved, but network access reliability deteriorates when server is unavailable or overloaded
Solution Approach 1:
The patent implements preliminary authentication by having the access point perform authentication checks using locally stored authentication information before forwarding requests to the RADIUS server. This preliminary action allows legitimate clients to connect immediately while suspicious connections are blocked, improving network access speed without compromising security.
Solution Approach 2:
The access point acts as an intermediary between clients and the RADIUS server by implementing a caching mechanism that stores authentication information locally. This intermediary layer allows the system to function independently when the server is unavailable, preventing complete system failure and maintaining productivity.
2Ease of operation
If RADIUS server is used for centralized authentication, then authentication management is improved, but system availability deteriorates when server becomes unavailable
Solution Approach 1:
The patent segments the authentication system into two independent parts: centralized authentication management (RADIUS server) and local authentication execution (access point with caching). This segmentation allows the access point to maintain local authentication capabilities, ensuring system availability even when the centralized server is unavailable.
Solution Approach 2:
The access point implements a caching mechanism that stores authentication information in advance before it is needed. This beforehand cushioning ensures that when the RADIUS server becomes unavailable, the access point can continue to authenticate clients using the cached information, maintaining system availability.
3Extent of automation
If authentication requests are forwarded to remote RADIUS server, then centralized control is improved, but authentication delay increases due to network communication
Solution Approach 1:
The access point performs preliminary authentication using locally cached credentials before communicating with the RADIUS server. This preliminary action eliminates the need for real-time server communication for routine authentication, significantly reducing authentication delay while maintaining centralized control for policy enforcement.
Solution Approach 2:
The system implements partial authentication at the access point level using cached information, rather than requiring complete authentication through the RADIUS server for every connection. This partial action approach reduces authentication delay while still maintaining centralized control for security policy enforcement.
Data Source
AI summary
An electronic device (such as an access point) that selectively performs authentication to a network is described. During operation, the electronic device provides an identity request addressed to the second electronic device. Then, the electronic device receives, associated with the second electronic device, an identity response. In response, when the authentication computer is unavailable, the electronic device accesses, in memory, a predefined hash function and associated authentication parameters for an authentication technique. Next, the electronic device performs authentication with the second electronic device based at least in part on the predefined hash function, where the authentication is compatible with the authentication technique (a type of Extensible Authentication Protocol or EAP). Moreover, the electronic device generates an encryption key, and establishes secure communication with the second electronic device by performing a four-way handshake with the second electronic device based at least in part on the encryption key.


