Dynamic Quarantine for IEEE 802.1x Network Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
IEEE 802.1x networks lack effective user authentication beyond client device credentials, allowing unauthorized access if the device is compromised, and frequent password changes inconvenience legitimate users.
Innovation Solution
Implementing a multi-factor authentication system that temporarily quarantines client devices based on predefined triggers or increased suspicion, requiring users to complete a workflow for identity verification to regain access to network resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multi-factor authentication is implemented to enhance security, then network security is improved, but user convenience deteriorates due to additional authentication requirements
Solution Approach 1:
The system dynamically adjusts authentication requirements based on risk assessment. When a client device is identified as potentially compromised (through device quarantine triggers), multi-factor authentication is activated. When the device is confirmed legitimate, the system operates in transparent mode without additional authentication steps, thus adapting security measures to actual risk levels rather than applying them uniformly.
Solution Approach 2:
The patent applies different authentication mechanisms to different situations and devices. Instead of requiring MFA for all users at all times, the system selectively applies enhanced authentication only to specific cases where device quarantine triggers indicate potential security risks, while maintaining transparent operation for legitimate devices.
2Reliability
If frequent password changes are required to prevent unauthorized access, then network security is improved, but user burden increases significantly
Solution Approach 1:
The system replaces static frequent password change policies with dynamic risk-based authentication. Instead of forcing all users to change passwords at fixed intervals regardless of actual risk, the system activates additional authentication measures only when device quarantine triggers suggest a security concern, thereby maintaining security while reducing unnecessary user burden.
3Ease of operation
If transparent authentication is used to simplify access, then user convenience is improved, but security against compromised devices deteriorates
Solution Approach 1:
The patent introduces device quarantine triggers as an intermediary mechanism between transparent authentication and security enforcement. These triggers monitor device behavior and characteristics to identify potentially compromised devices. When triggers are activated, the system intervenes to require additional authentication, while allowing transparent operation for devices that pass monitoring, thus mediating between convenience and security.
Solution Approach 2:
The system performs preliminary security checks through device quarantine triggers before granting transparent access. By monitoring device characteristics and behaviors in advance, the system can identify and block potentially compromised devices before they gain unauthorized access, preventing security issues rather than reacting to them after authentication occurs.
Data Source
AI summary
The present disclosure discloses a system and method for providing multi-factor authorization for IEEE 802.1x-enabled networks. Specifically, a network device authenticates a client device to obtain access to network resources in a network via a network authentication protocol. The network device then detects a device quarantine trigger indicating an increased level of suspicion that a current user of the client device is a non-authenticated user. In response to the device quarantine trigger, the network device temporarily places the client device from an authenticated state to a quarantined state pending completion of a particular workflow by the current user. The client device has limited access to the network resources while in the quarantined state regardless of a previous successful user and/or device authentication.


