Cloud Network Access Authentication Without RADIUS Servers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The implementation of a centralized Remote Authentication Dial-In User Service (RADIUS) server can be impracticable or excessively costly, necessitating a need for reliable and efficient network communication solutions without a dedicated RADIUS server.
Innovation Solution
A cloud server restricts network access after a Pre-Shared Key (PSK) is transmitted, redirects users to an identity provider for authentication, and allows access based on successful authentication and attribute receipt, eliminating the need for a RADIUS server by using Security Assertion Markup Language (SAML) or single sign-on (SSO) authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a centralized RADIUS server is implemented for network authentication, then authentication reliability is improved, but system cost and complexity increase significantly
Solution Approach 1:
The patent extracts the authentication function from the traditional centralized RADIUS server model and implements it through cloud-based identity providers. The cloud server redirects users to external identity providers for authentication, separating the authentication mechanism from the network infrastructure and eliminating the need for dedicated RADIUS servers while maintaining authentication reliability.
Solution Approach 2:
The patent employs universal authentication protocols (SAML, OAuth, OIDC) that work across multiple identity providers and cloud services. This multi-functional approach allows the same authentication framework to support various authentication methods and providers, reducing system complexity while maintaining reliability through standardized, widely-supported protocols.
2Reliability
If a centralized RADIUS server is deployed for network access control, then network security is improved, but implementation cost increases
Solution Approach 1:
The patent implements self-service authentication where users independently complete authentication with identity providers using their existing credentials. The cloud server automatically processes authentication results and enforces access control policies without requiring manual RADIUS server configuration or maintenance, significantly reducing implementation and operational costs while maintaining security.
Solution Approach 2:
The cloud server acts as an intermediary between the network and identity providers, translating authentication requests and responses. This mediator approach allows the system to leverage existing identity provider infrastructure and security mechanisms without requiring direct integration with traditional RADIUS servers, reducing implementation costs while maintaining network security.
3Ease of operation
If MAC address filtering is used to allow network access, then ease of operation is improved, but security and flexibility deteriorate
Solution Approach 1:
The patent implements dynamic access control where authentication requirements change based on user context, device type, and network conditions. The cloud server can enforce different authentication policies for different users and devices, allowing MAC address filtering for simple cases while requiring full authentication for others, providing both ease of operation and adaptability.
Solution Approach 2:
The patent applies different authentication mechanisms to different users and devices based on their specific needs and characteristics. MAC address filtering is applied locally to trusted devices, while other users undergo full authentication processes, creating localized quality variations in access control that balance ease of operation with security and flexibility.
Data Source
AI summary
Embodiments of a device and method are disclosed. In an embodiment, a method for communications involves at a cloud server, restricting network access of a user after a Pre-Shared Key (PSK) of the user is transmitted, and at the cloud server, redirecting the user to an identity provider for authentication after restricting network access of the user.


