IEEE 802.1x Authentication for Ethernet Aggregation Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication mechanisms for subscriber broadband aggregation networks, such as PPPoE, are inadequate for supporting new services like voice and video over Ethernet access networks, as they are point-to-point connection-oriented and lack the ability to authenticate non-IP end-user services effectively.
Innovation Solution
The implementation of the IEEE 802.1x specification as a cross-platform authentication mechanism in subscriber broadband aggregation networks, allowing for Layer 2 authentication and authorization across multiple Ethertypes, enabling authentication of non-IP end-user services and providing quality of service configurations through an end-to-end authentication, authorization, and accounting (AAA) mechanism.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If PPPoE protocol is used for authentication, then point-to-point connection authentication is achieved, but it cannot support multipoint Ethernet services like voice and video effectively
Solution Approach 1:
The patent applies universality by making the authentication mechanism protocol-agnostic, allowing a single authentication framework to support multiple service types (voice, video, data) and transport protocols (Ethernet, ATM, IP) rather than being limited to PPPoE point-to-point connections only
2Reliability
If PPPoE is used for Ethernet access, then authentication is provided, but it lacks ability to authenticate non-IP end-user services
Solution Approach 1:
The authentication mechanism is designed to be protocol-independent and service-agnostic, enabling it to authenticate various service types including non-IP services like voice over Ethernet and video streaming, not limited to traditional IP-based PPPoE services
Solution Approach 2:
The patent segments the authentication process from the service layer, implementing authentication at the transport layer that can independently verify credentials before service-specific processing, allowing separate authentication paths for different service types
3Reliability
If separate authentication mechanisms are implemented for different services, then service-specific security is improved, but system complexity increases
Solution Approach 1:
The patent merges multiple service authentication requirements into a single unified authentication framework that handles voice, video, and data services through common authentication procedures, reducing overall system complexity while maintaining service-specific security policies
Data Source
AI summary
A Service Provider (SP) authentication method includes receiving a message from a subscriber-premises device, the message being compatible with an authentication protocol and being transported from the subscriber- premises device to a u-PE device operating in compliance with an IEEE 802.1 x compatible protocol. Access to the SP network is either allowed or denied access based on a logical identifier contained in the message. It is emphasized that this abstract is provided to comply with the rules requiring an abstract that will allow a searcher or other reader to quickly ascertain the subject matter of the technical disclosure. It is submitted with the understanding that it will not be used to interpret or limit the scope or meaning of the claims. 37 CFR 1.72(b).


