Authentication Server Port Mapping for Network Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing IEEE 802.1x authentication process globally authenticates devices based on their MAC address, allowing access from any authorized port, which lacks specificity and requires configuring MAC-to-Port associations on each switch.

Innovation Solution

Implementing a system where the authentication server uses a mapping table that associates port IDs with MAC addresses, allowing specific devices to connect only through designated ports, and enabling the use of other attributes like IP addresses, locations, or VLAN-IDs for authentication, thereby centralizing the authentication process and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If MAC address-based global authentication is used, then authentication simplicity is maintained, but access control specificity deteriorates

Engineering Contradiction:
Improveauthentication simplicityVSAvoidaccess control specificity
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent segments the authentication process into two independent components: device authentication (using MAC address) and port authentication (using port ID). This allows the system to maintain simple device-level authentication while adding specific port-level access control, resolving the contradiction between authentication simplicity and access control specificity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary authentication mechanism that sits between the device and the network resources. The port ID acts as an intermediary credential that bridges the gap between simple MAC address authentication and the need for specific access control, enabling both simplicity and precision simultaneously.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If MAC-to-Port associations are configured on each switch, then port-specific access control is achieved, but system complexity increases

Engineering Contradiction:
Improveport-specific access controlVSAvoidconfiguration complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent merges the device authentication and port authentication processes into a single unified authentication flow. Instead of requiring separate MAC-to-Port associations on each switch, the system combines both authentication factors (MAC address and port ID) into one centralized authentication process, reducing configuration complexity while maintaining port-specific access control.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication server acts as an intermediary that centralizes the MAC-to-Port association management. Instead of requiring each switch to maintain complex local associations, the authentication server holds and manages these mappings centrally, significantly reducing the configuration and maintenance complexity across the network.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If centralized authentication with multiple attributes is implemented, then security is enhanced, but authentication process complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication framework that can handle multiple attribute types (MAC address, port ID, and potentially other identifiers) through a single authentication process. This multi-functionality allows the system to enhance security by using multiple attributes while maintaining a consistent and manageable authentication process complexity through standardization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9253175B1Authentication of computing devices using augmented credentials to enable actions-per-group
Publication Date: 2016.02.02 MARVELL ASIA PTE LTD
  • US9253175B1 patent drawing
  • US9253175B1 patent drawing
  • US9253175B1 patent drawing

AI summary

In one or more embodiments, attributes other than a supplicant's MAC address can be used for the user name in the authentication process in a network computing environment. In at least some embodiments, doing so utilizes an association structure, such as a table, that is already resident at the authentication server. By using attributes other than a supplicant's MAC address, various matching scenarios can be provided by the authentication server in which authentication or authorization takes place responsive to satisfying conditions defined in the authentication server's association or database. Furthermore, a variety of non-authentication scenarios can be supported using the authentication server's association.