Authentication Server Port Mapping for Network Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing IEEE 802.1x authentication process globally authenticates devices based on their MAC address, allowing access from any authorized port, which lacks specificity and requires configuring MAC-to-Port associations on each switch.
Innovation Solution
Implementing a system where the authentication server uses a mapping table that associates port IDs with MAC addresses, allowing specific devices to connect only through designated ports, and enabling the use of other attributes like IP addresses, locations, or VLAN-IDs for authentication, thereby centralizing the authentication process and enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If MAC address-based global authentication is used, then authentication simplicity is maintained, but access control specificity deteriorates
Solution Approach 1:
The patent segments the authentication process into two independent components: device authentication (using MAC address) and port authentication (using port ID). This allows the system to maintain simple device-level authentication while adding specific port-level access control, resolving the contradiction between authentication simplicity and access control specificity.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism that sits between the device and the network resources. The port ID acts as an intermediary credential that bridges the gap between simple MAC address authentication and the need for specific access control, enabling both simplicity and precision simultaneously.
2Measurement precision
If MAC-to-Port associations are configured on each switch, then port-specific access control is achieved, but system complexity increases
Solution Approach 1:
The patent merges the device authentication and port authentication processes into a single unified authentication flow. Instead of requiring separate MAC-to-Port associations on each switch, the system combines both authentication factors (MAC address and port ID) into one centralized authentication process, reducing configuration complexity while maintaining port-specific access control.
Solution Approach 2:
The authentication server acts as an intermediary that centralizes the MAC-to-Port association management. Instead of requiring each switch to maintain complex local associations, the authentication server holds and manages these mappings centrally, significantly reducing the configuration and maintenance complexity across the network.
3Reliability
If centralized authentication with multiple attributes is implemented, then security is enhanced, but authentication process complexity increases
Solution Approach 1:
The patent implements a universal authentication framework that can handle multiple attribute types (MAC address, port ID, and potentially other identifiers) through a single authentication process. This multi-functionality allows the system to enhance security by using multiple attributes while maintaining a consistent and manageable authentication process complexity through standardization.
Data Source
AI summary
In one or more embodiments, attributes other than a supplicant's MAC address can be used for the user name in the authentication process in a network computing environment. In at least some embodiments, doing so utilizes an association structure, such as a table, that is already resident at the authentication server. By using attributes other than a supplicant's MAC address, various matching scenarios can be provided by the authentication server in which authentication or authorization takes place responsive to satisfying conditions defined in the authentication server's association or database. Furthermore, a variety of non-authentication scenarios can be supported using the authentication server's association.


