Authentication Switches for Load Distribution in Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network authentication systems face challenges in achieving effective load distribution and balancing network usage and security, particularly in shared network environments, due to load imbalance among wireless access points and authentication switches.

Innovation Solution

A network authentication system that includes an authentication server and multiple authentication switches, where the authentication server processes and updates receiving port filters based on client terminal information to distribute load effectively and secure network connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of energy

If load information and identifiers are exchanged to avoid wasting communication band, then communication efficiency is improved, but load converges at points with good radio wave environment causing load unbalance among wireless access points

Engineering Contradiction:
Improvecommunication band wasteVSAvoidload distribution balance
Core Design Contradiction:
Loss of energyVSEase of operation

Solution Approach 1:

The patent introduces authentication switches as intermediary devices between client terminals and authentication servers. These switches act as mediators that can actively control and redirect authentication traffic, preventing direct convergence at single access points while maintaining communication efficiency through the intermediary switching layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the authentication network into multiple authentication switches, each handling specific authentication traffic. This segmentation distributes the load across multiple network nodes rather than concentrating it at single access points, thereby preventing load unbalance while maintaining communication efficiency.

Inventive Principle:
Principle #1Segmentation

2Reliability

If authentication switches are used to control communication, then network security is improved, but load converges on specific authentication switches making load distribution impossible

Engineering Contradiction:
Improvenetwork securityVSAvoidload distribution
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent dynamically changes the parameter of filter information in receiving port filters based on authentication terminal information. By modifying filter parameters according to terminal locations and authentication states, the system distributes authentication load across multiple switches while maintaining security through controlled filter updates.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent implements dynamic load distribution by continuously updating receiving port filters based on current authentication terminal information. This dynamic adjustment allows the system to adapt to changing load conditions while maintaining security, preventing static load convergence on specific switches.

Inventive Principle:
Principle #15Dynamics

3Productivity

If receiving port filters are updated based on authentication terminal information, then load distribution is improved, but system complexity increases due to filter management

Engineering Contradiction:
Improveload distribution efficiencyVSAvoidfilter management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where authentication switches automatically update their receiving port filters based on authentication terminal information received during normal authentication operations. This automated self-updating process reduces the need for manual filter management while improving load distribution efficiency.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent employs feedback mechanisms where authentication switches receive authentication terminal information and use it to dynamically adjust their receiving port filters. This feedback loop enables automatic load distribution improvement without requiring complex external management systems, as the switches self-adjust based on received information.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10003588B2Network authentication system, network authentication method and network authentication server
Publication Date: 2018.06.19 CLOUD BYTE LLC
  • US10003588B2 patent drawing
  • US10003588B2 patent drawing
  • US10003588B2 patent drawing

AI summary

A network authentication system includes a client terminal, an authentication server authenticating connection of the client terminal with an external network, and a plurality of authentication switches controlling communication of the client terminal with the external network. The authentication switch includes an authentication server processing unit notifying the authentication server of authentication terminal information, and a receiving port filter receives a specific packet. The authentication server, includes a terminal management storing unit storing the authentication terminal information, and an authentication switch management processing unit which, in order that the authentication switch authenticate the client terminal, determines filter information, that is set in the receiving port filter, based on the authentication terminal information, and notifies the authentication switch of the filter information. The authentication server processing unit updates the receiving port filter based on the filter information.