EAP Host Architecture for Network Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network authentication mechanisms are complex and prone to abuse, with supplicants carrying significant security-related code that increases risk, especially in resource-limited devices, and lack standardized interfaces for access control functions.

Innovation Solution

The EAP host provides standardized interfaces for access control functionality within networks, separating network access control functions from supplicant code and allowing new EAP methods to be easily integrated, reducing supplicant complexity and security risk.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication functionality is embedded within supplicant code, then access control can be performed, but supplicant complexity and security risk increase

Engineering Contradiction:
Improveaccess control functionalityVSAvoidsupplicant complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts authentication functionality from supplicant code by introducing a separate EAP host component. The EAP host is installed within the server and provides authentication services to multiple supplicants, thereby removing the burden of embedded authentication code from each supplicant while maintaining access control functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The EAP host acts as an intermediary between the server and supplicants. It provides standardized interfaces that facilitate integration of access control functionality into the network, serving as a mediator that enables authentication without requiring complex code within each supplicant.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple authentication mechanisms are supported, then network security is enhanced, but system complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The EAP host provides a universal platform that supports multiple authentication mechanisms through standardized interfaces. It can accommodate various EAP methods and authentication protocols without requiring separate implementations for each mechanism, thereby enhancing network security while managing system complexity through a single multi-functional component.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments the authentication system into distinct components: the EAP host on the server side and simplified supplicants on the client side. This segmentation allows multiple authentication mechanisms to be supported on the server through the EAP host while keeping individual supplicants simple and resource-efficient.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If supplicant code includes all security-related functionality, then standalone operation is possible, but code size and maintenance burden increase

Engineering Contradiction:
Improvestandalone operationVSAvoidcode size and maintenance
Core Design Contradiction:
Ease of operationVSEase of manufacture

Solution Approach 1:

The patent merges security-related functionality into the server-side EAP host, which is shared across multiple supplicants. This consolidation reduces the code size of individual supplicants and centralizes maintenance efforts on the server side, while supplicants maintain standalone operation capabilities through standardized interfaces.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8286223B2Extensible access control architecture
Publication Date: 2012.10.09 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8286223B2 patent drawing
  • US8286223B2 patent drawing
  • US8286223B2 patent drawing

AI summary

Software for managing access control functions in a network. The software includes a host that receives access control commands or information and calls one or more methods. The methods perform access control functions and communicate access control results or messages to be transmitted. The host may be installed in a network peer seeking access to the network or in a server controlling access to the network. When installed in a peer, the host receives commands and exchanges information with a supplicant. When installed in an access control server, the host receives commands and exchanges information with an authenticator. The host has a flexible architecture that enables multiple features, such as allowing the same methods to be used for authentication by multiple supplicants, providing ready integration of third party access control software, simplifying network maintenance by facilitating upgrades of authenticator software and enabling access control functions other than peer authentication.