Access Point Authentication Offload During RADIUS Server Outages

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network authentication systems, particularly in enterprise wireless networks, face issues such as RADIUS server overload leading to IEEE 802.1x failures and delayed authentication, causing frustration for users and administrators.

Innovation Solution

Electronic devices are equipped to perform selective authentication by accessing predefined hash functions and authentication parameters stored in memory, enabling them to authenticate and establish secure communication with other devices even when the authentication computer is unavailable, using techniques like EAP and a four-way handshake.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IEEE 802.1x authentication is used with RADIUS server for enterprise wireless networks, then authentication security is improved, but network access reliability deteriorates when server is unavailable or overloaded

Engineering Contradiction:
Improveauthentication securityVSAvoidnetwork access speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary authentication by having the access point perform authentication checks using locally stored authentication information before forwarding requests to the RADIUS server. This preliminary action allows legitimate clients to connect immediately while suspicious connections are blocked, improving network access speed without compromising security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The access point acts as an intermediary between clients and the RADIUS server by implementing a caching mechanism that stores authentication information locally. This intermediary layer allows the system to function independently when the server is unavailable, preventing complete system failure and maintaining productivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If RADIUS server is used for centralized authentication, then authentication management is improved, but system availability deteriorates when server becomes unavailable

Engineering Contradiction:
Improveauthentication managementVSAvoidsystem availability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the authentication system into two independent parts: centralized authentication management (RADIUS server) and local authentication execution (access point with caching). This segmentation allows the access point to maintain local authentication capabilities, ensuring system availability even when the centralized server is unavailable.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The access point implements a caching mechanism that stores authentication information in advance before it is needed. This beforehand cushioning ensures that when the RADIUS server becomes unavailable, the access point can continue to authenticate clients using the cached information, maintaining system availability.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

3Extent of automation

If authentication requests are forwarded to remote RADIUS server, then centralized control is improved, but authentication delay increases due to network communication

Engineering Contradiction:
Improvecentralized controlVSAvoidauthentication delay
Core Design Contradiction:
Extent of automationVSLoss of time

Solution Approach 1:

The access point performs preliminary authentication using locally cached credentials before communicating with the RADIUS server. This preliminary action eliminates the need for real-time server communication for routine authentication, significantly reducing authentication delay while maintaining centralized control for policy enforcement.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements partial authentication at the access point level using cached information, rather than requiring complete authentication through the RADIUS server for every connection. This partial action approach reduces authentication delay while still maintaining centralized control for security policy enforcement.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12537691B2Offloading authentication to an authenticator
Publication Date: 2026.01.27 RUCKUS IP HOLDINGS LLC
  • US12537691B2 patent drawing
  • US12537691B2 patent drawing
  • US12537691B2 patent drawing

AI summary

An electronic device (such as an access point) that selectively performs authentication to a network is described. During operation, the electronic device provides an identity request addressed to the second electronic device. Then, the electronic device receives, associated with the second electronic device, an identity response. In response, when the authentication computer is unavailable, the electronic device accesses, in memory, a predefined hash function and associated authentication parameters for an authentication technique. Next, the electronic device performs authentication with the second electronic device based at least in part on the predefined hash function, where the authentication is compatible with the authentication technique (a type of Extensible Authentication Protocol or EAP). Moreover, the electronic device generates an encryption key, and establishes secure communication with the second electronic device by performing a four-way handshake with the second electronic device based at least in part on the encryption key.