Dynamic VLAN Assignment for 802.1X User Load Balancing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for managing 802.1X authenticated users in virtual local area networks (VLANs) often lead to over-subscription, resulting in excessive broadcast traffic and administrative complexities, especially when a large number of users are assigned to the same VLAN, which can exhaust network bandwidth and resources.

Innovation Solution

A dynamic user assignment technique that optimally distributes authenticated users across multiple VLANs based on factors like the number of users, available bandwidth, and user classes, using the RADIUS service to select the most suitable VLAN for each user, thereby reducing the likelihood of over-subscription and simplifying VLAN configuration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If a large number of users are assigned to the same VLAN, then user connectivity is maintained, but broadcast traffic increases and network bandwidth is exhausted

Engineering Contradiction:
Improvenumber of users per VLANVSAvoidnetwork bandwidth consumption
Core Design Contradiction:
Quantity of substanceVSLoss of energy

Solution Approach 1:

The patent segments the large VLAN into multiple smaller VLANs based on user authentication. When a user authenticates via 802.1X, the system dynamically assigns them to an appropriate VLAN, effectively dividing the large broadcast domain into smaller, more manageable segments. This reduces broadcast traffic within each VLAN while maintaining user connectivity.

Inventive Principle:
Principle #1Segmentation

2Device complexity

If static VLAN assignment is used, then configuration is simple, but administrative complexity increases when managing large numbers of users

Engineering Contradiction:
ImproveVLAN configuration complexityVSAvoiduser management ease
Core Design Contradiction:
Device complexityVSEase of operation

Solution Approach 1:

The patent implements dynamic VLAN assignment based on user authentication status and attributes. Instead of static pre-configuration, the system dynamically determines VLAN membership at authentication time using 802.1X credentials and RADIUS attributes. This automation reduces administrative burden while maintaining simple VLAN configurations.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system enables self-service automated VLAN assignment where users authenticate with their credentials and are automatically placed in the appropriate VLAN without manual administrator intervention. The RADIUS server automatically processes authentication and assigns VLANs based on pre-configured policies and user attributes.

Inventive Principle:
Principle #25Self-service

3Productivity

If dynamic user assignment is implemented, then user distribution is optimized, but system complexity increases

Engineering Contradiction:
Improveuser distribution efficiencyVSAvoidauthentication system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces the RADIUS server as an intermediary between the authentication system and VLAN assignment. The RADIUS server handles the complex logic of user authentication, attribute evaluation, and VLAN selection, while the network infrastructure remains relatively simple. This intermediary absorbs the complexity of dynamic assignment algorithms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system uses parameter changes in user authentication attributes to drive dynamic VLAN assignment. By evaluating different authentication parameters, user classes, and RADIUS attributes, the system dynamically selects appropriate VLANs without requiring complex infrastructure changes. The complexity is managed through parameter-based decision logic.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS7447166B1Method to distribute IEEE 802.1X authenticated users among multiple broadcast domains
Publication Date: 2008.11.04 CISCO TECHNOLOGY INC
  • US7447166B1 patent drawing
  • US7447166B1 patent drawing
  • US7447166B1 patent drawing

AI summary

A technique optimizes the distribution of authenticated users among a plurality of broadcast domains, such as virtual local area networks (VLAN). Users are dynamically assigned to different broadcast domains based on various factors, including but not limited to the number of authenticated users already participating in each broadcast domain, the available bandwidth in each broadcast domain, user classes associated with users participating in each broadcast domain, etc. Based on one or more of these factors, authenticated users are optimally distributed (“load balanced”) among the plurality of broadcast domains, thereby reducing the amount of broadcast traffic and configuration within each domain.