Edge Configuration Device for Non-SPB Network Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network authentication and configuration processes are time-consuming and require significant expertise, especially for non-SPB devices trying to access SPB networks, as they need manual input of configuration information and are not compatible with SPB standards.

Innovation Solution

An edge configuration device automatically authenticates and configures non-SPB devices by accessing a remote access control server or management server, using fabric attach messages to obtain SPB configuration information and integrate them into the network, allowing SPB-compatible VLAN and ISID settings without manual intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual authentication and configuration processes are used for non-SPB devices accessing SPB networks, then network security and proper configuration are ensured, but the process becomes time-consuming and requires significant network administrator expertise

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication and configuration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

An edge configuration device is introduced as an intermediary between non-SPB end devices and the SPB network. This device automatically performs authentication by sending identity information to an access control server and obtains SPB configuration information, eliminating the need for manual administrator intervention while ensuring proper security protocols are followed

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication and configuration process is automated so that the system serves itself without requiring external administrator input. The edge configuration device automatically sends authentication requests, receives configuration information from the access control server, and configures the network connection without human intervention

Inventive Principle:
Principle #25Self-service

2Manufacturing precision

If manual configuration input is required for non-SPB devices, then configuration accuracy can be verified, but the complexity of the process increases and requires expert knowledge

Engineering Contradiction:
Improveconfiguration accuracyVSAvoidauthentication process complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The edge configuration device acts as an intermediary that handles the complexity of SPB configuration internally. It automatically translates non-SPB device identity information into proper SPB configuration parameters by communicating with the access control server, maintaining configuration accuracy without exposing the complexity to users

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The manual mechanical process of administrators configuring devices is replaced with an automated electronic system. The edge configuration device electronically exchanges authentication and configuration messages with the access control server, replacing manual configuration steps with automated digital processes

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If non-SPB devices are integrated into SPB networks without automation, then network control and security management are maintained, but administrative effort and expertise requirements increase

Engineering Contradiction:
Improvenetwork compatibilityVSAvoidadministrative effort
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The edge configuration device provides universal functionality by supporting both SPB and non-SPB devices. It can handle authentication for various types of end devices while automatically translating their identity information into SPB-compatible configuration, enabling diverse device integration without increasing administrative burden

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system performs self-service by automatically managing the integration of non-SPB devices into the SPB network. The edge configuration device autonomously handles authentication requests, receives configuration information from the access control server, and configures network parameters without requiring administrator intervention

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2924950B1Authentication of client devices in networks
Publication Date: 2020.05.13 EXTREME NETWORKS INC
  • EP2924950B1 patent drawingFigure 1
  • EP2924950B1 patent drawingFigure 2
  • EP2924950B1 patent drawingFigure 3

AI summary

Implementations relate to authentication of end devices in networks. In some implementations, a method includes receiving identity information at an edge configuration device from an end device via a connection, where the identity information identifies the end device or one or more users associated with the end device. A request is sent from the edge configuration device to an access control server connected to the network in response to receiving the identity information, where the request requests authentication for the end device. Authentication is received at the edge configuration device from the access control server for the end device to connect to a network connected to the edge configuration device.