Cloud Delivered Access via Pre-Authentication Virtual Network
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network technologies face challenges in providing dynamic and seamless cloud-delivered access, particularly in managing client device authentication and network configuration, which leads to static configurations and inefficient traffic management.
Innovation Solution
The implementation of a system that provides a client device with a pre-authentication virtual network and address, followed by authentication-based movement to a post-authentication virtual network, with traffic translation and dynamic IP address management, utilizing a fabric network architecture with components like Edge Devices, Border Devices, and a Map Server for efficient network management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a client device is provided with a pre-authentication virtual network and pre-authentication address, then the device can immediately connect to the network, but the network configuration remains static and insecure until authentication occurs
Solution Approach 1:
The system performs preliminary actions by providing the client device with a pre-authentication virtual network and pre-authentication address before actual authentication occurs. This allows the device to immediately connect to the network infrastructure while authentication is being processed in the background, resolving the contradiction between immediate connectivity and security verification.
Solution Approach 2:
The pre-authentication virtual network acts as an intermediary environment between the unauthenticated client device and the secure post-authentication network. This intermediary allows traffic flow while maintaining security boundaries, enabling both immediate connection and secure authentication processes to coexist.
2Reliability
If the client device is moved to a post-authentication virtual network after authentication, then network security is improved, but the network configuration requires dynamic changes
Solution Approach 1:
The system implements dynamic network configuration by automatically moving the client device from the pre-authentication virtual network to the post-authentication virtual network based on authentication status. This dynamic approach allows the network configuration to adapt to security requirements without manual intervention, improving security while managing complexity through automation.
Solution Approach 2:
The authentication system provides feedback about the client device's authentication status to the network configuration system. This feedback mechanism triggers automatic configuration changes, moving the device between virtual networks based on authentication outcomes, thereby improving security through automated responses to authentication events.
3Reliability
If traffic translation is implemented to translate to a post-authentication address, then network security and control are improved, but the traffic management system becomes more complex
Solution Approach 1:
The traffic translation system acts as an intermediary that translates between pre-authentication addresses and post-authentication addresses. This intermediary layer provides network control and security by mediating all traffic flow, while the translation complexity is managed centrally rather than at individual device levels.
Solution Approach 2:
The system creates a translated copy of the traffic flow through address translation rather than physically modifying the original traffic path. This copying approach maintains control and security while simplifying the implementation, as the translation can be performed through address mapping tables rather than complex traffic manipulation logic.
4Adaptability or versatility
If dynamic IP address management is implemented for post-authentication addresses, then network flexibility is improved, but the address management system becomes more complex
Solution Approach 1:
The system implements dynamic IP address management by automatically assigning and managing post-authentication addresses based on client device authentication and network conditions. This dynamic approach improves network flexibility and adaptability while centralizing the complexity of address management in the network infrastructure rather than requiring complex local device logic.
Data Source
AI summary
Cloud delivered access may be provided. A network device may provide a client device with a pre-authentication virtual network and a pre-authentication address. Next, a policy may be received in response to the client device authenticating. The client device may then be moved to a post-authentication virtual network based on the policy. A post-authentication address may then be obtained for the client device in response to moving the client device to a post-authentication virtual network. Traffic for the client device may then be translated to the post-authentication address.


