Authentication Server Network Device Configuration via EAP

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network access technologies fail to ensure proper network configuration of remote devices, which can lead to communication problems and security risks due to improper configuration, such as outdated firmware or incorrect security settings.

Innovation Solution

An authentication server provides device configuration information during the authentication process, using an extended Extensible Authentication Protocol (EAP) to ensure that remote devices are properly configured before granting access to the network, by bundling configuration data into EAP messages and verifying installation status through a sub-type field in Protected Extensible Authentication Protocol (PEAP) or Type-Length-Value Flexible Authentication via Secure Tunneling (TLV-FAST) protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional authentication protocols are used to allow remote device access to the network, then network accessibility is improved, but network security and configuration reliability deteriorate due to improper device configuration

Engineering Contradiction:
Improvenetwork accessibilityVSAvoiddevice configuration reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by providing device configuration information to the remote device during the authentication process, before the device is granted full network access. This ensures that the device receives proper configuration (firmware updates, security settings, network parameters) in advance, eliminating configuration issues before they can affect network security or operations.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If device configuration is provided after authentication, then configuration flexibility is improved, but network security deteriorates by allowing improperly configured devices onto the network

Engineering Contradiction:
Improveconfiguration flexibilityVSAvoidnetwork security risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent reverses the conventional sequence by providing configuration information during the authentication process itself, rather than after authentication completes. This preliminary provision of configuration ensures that devices are properly configured before they gain network access, maintaining security while preserving configuration flexibility through the ability to push updated configurations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback by having the remote device send a response message back to the authentication server indicating whether it has successfully installed the provided configuration information. This feedback mechanism allows the server to verify proper configuration before granting network access, ensuring security while maintaining flexibility to provide updated configurations.

Inventive Principle:
Principle #23Feedback

3Reliability

If authentication process is extended to include configuration verification, then device configuration reliability is improved, but authentication process complexity increases

Engineering Contradiction:
Improvedevice configuration reliabilityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the configuration provision process with the existing authentication process by embedding configuration information within EAP (Extensible Authentication Protocol) messages. This integration allows configuration to be delivered during the normal authentication exchange without requiring a separate configuration phase, thus improving reliability while minimizing additional complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent makes the authentication protocol multi-functional by enabling it to perform both authentication and configuration delivery through the same EAP message exchange. The authentication server simultaneously verifies device credentials and provides configuration information, eliminating the need for separate dedicated configuration protocols or additional communication rounds.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Productivity

If configuration information is bundled into EAP messages, then communication efficiency is improved, but protocol complexity increases

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidprotocol complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent combines multiple functions into a single EAP message by bundling configuration information (such as firmware updates, security settings, or network parameters) within the existing authentication protocol messages. This approach improves communication efficiency by delivering configuration data during the normal authentication exchange without requiring additional separate message exchanges or protocol handshakes.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS7546632B2Methods and apparatus to configure a network device via an authentication protocol
Publication Date: 2009.06.09 CISCO TECHNOLOGY INC
  • US7546632B2 patent drawing
  • US7546632B2 patent drawing
  • US7546632B2 patent drawing

AI summary

A system supplies configuration information, via an EAP protocol, to a remote device trying to access the network. An authentication server performs an authentication exchange by receiving, from a remote device, a connection attempt to access the network. The authentication server performs an authentication exchange with the remote device to allow the remote device access to the network. During the authentication exchange, a configuration selection characteristic associated with the remote device is identified. A device configuration to be applied to the remote device, based on the configuration selection characteristic, is determined. The authentication server provides the determined device configuration to the remote device, via an EAP protocol, to allow the remote device to install the determined device configuration prior to being allowed access to the network.