Fallback Segmentation Security via IP-to-Map Mapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network segmentation is hindered by the lack of IP address to segment ID mapping in authentication systems, particularly when these systems are unreachable or when client devices fail to authenticate, leading to interoperability issues and cumbersome traffic management.
Innovation Solution
A mechanism where network devices determine client MAC address to segment ID mappings and generate IP address to segment ID mappings, utilizing a network management system to distribute these mappings, and implement fallback scenarios to tailor security levels based on authentication failures, ensuring continued network access and security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If authentication systems are used to authenticate client devices, then security is improved, but interoperability is hindered when authentication systems lack IP address to segment ID mapping data
Solution Approach 1:
The patent introduces a RADIUS server as an intermediary component that maintains the IP address to segment ID mapping database. The network device queries this intermediary server to obtain mapping information, resolving the interoperability issue without requiring the authentication system itself to have built-in mapping capabilities. This allows the system to work with different authentication systems while maintaining security and segmentation functionality.
2Productivity
If network segmentation is implemented based on authentication status, then traffic management is improved, but network access is interrupted when authentication systems are unreachable
Solution Approach 1:
The patent implements preliminary action by pre-configuring fallback segments and their corresponding segment IDs in the RADIUS server database before authentication failures occur. When the authentication system becomes unreachable, the network device can immediately query the pre-existing mapping data and assign devices to appropriate fallback segments, ensuring continuous traffic management without interruption. This eliminates the need for real-time authentication system access while maintaining segmentation-based traffic control.
3Reliability
If fallback scenarios are implemented to maintain network access, then reliability is improved, but security control is weakened without proper segment ID mappings
Solution Approach 1:
The patent implements feedback by continuously monitoring the reachability status of the authentication system and dynamically adjusting segment assignments based on real-time conditions. When the authentication system is reachable, devices are assigned to segments based on successful authentication. When unreachable, the system queries the RADIUS server for fallback mappings and assigns devices to appropriate fallback segments. This feedback mechanism ensures that security control is maintained through proper segment ID mappings even in fallback scenarios, preventing security weakening while preserving network access reliability.
Data Source
AI summary
In general, embodiments relate to a network device, including network device hardware including a processor; and memory comprising instructions which, when executed by the processor, performs a method for creating segment mapping in a network. The method includes entering a fallback mode in response to detecting a fallback scenario, determining, based on the fallback mode, a segment identification (ID) for a client device of the network, wherein the segment ID identifies a segment of the network including a client device, obtaining an Internet Protocol (IP) address to segment ID mapping, wherein the client device is associated with the IP address, and processing at least one packet from the client device using the IP address to segment ID mapping.


