IEEE 802.1x Authentication for Ethernet Aggregation Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication mechanisms for subscriber broadband aggregation networks, such as PPPoE, are inadequate for supporting new services like voice and video over Ethernet access networks, as they are point-to-point connection-oriented and lack the ability to authenticate non-IP end-user services effectively.

Innovation Solution

The implementation of the IEEE 802.1x specification as a cross-platform authentication mechanism in subscriber broadband aggregation networks, allowing for Layer 2 authentication and authorization across multiple Ethertypes, enabling authentication of non-IP end-user services and providing quality of service configurations through an end-to-end authentication, authorization, and accounting (AAA) mechanism.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If PPPoE protocol is used for authentication, then point-to-point connection authentication is achieved, but it cannot support multipoint Ethernet services like voice and video effectively

Engineering Contradiction:
Improveauthentication effectivenessVSAvoidservice support capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies universality by making the authentication mechanism protocol-agnostic, allowing a single authentication framework to support multiple service types (voice, video, data) and transport protocols (Ethernet, ATM, IP) rather than being limited to PPPoE point-to-point connections only

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If PPPoE is used for Ethernet access, then authentication is provided, but it lacks ability to authenticate non-IP end-user services

Engineering Contradiction:
Improveauthentication capabilityVSAvoidservice type coverage
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The authentication mechanism is designed to be protocol-independent and service-agnostic, enabling it to authenticate various service types including non-IP services like voice over Ethernet and video streaming, not limited to traditional IP-based PPPoE services

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments the authentication process from the service layer, implementing authentication at the transport layer that can independently verify credentials before service-specific processing, allowing separate authentication paths for different service types

Inventive Principle:
Principle #1Segmentation

3Reliability

If separate authentication mechanisms are implemented for different services, then service-specific security is improved, but system complexity increases

Engineering Contradiction:
Improveservice-specific securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple service authentication requirements into a single unified authentication framework that handles voice, video, and data services through common authentication procedures, reducing overall system complexity while maintaining service-specific security policies

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP1886447B1System and method for authentication of SP ethernet aggregation networks
Publication Date: 2017.10.25 CISCO TECHNOLOGY INC
  • EP1886447B1 patent drawing
  • EP1886447B1 patent drawing
  • EP1886447B1 patent drawing

AI summary

A Service Provider (SP) authentication method includes receiving a message from a subscriber-premises device, the message being compatible with an authentication protocol and being transported from the subscriber- premises device to a u-PE device operating in compliance with an IEEE 802.1 x compatible protocol. Access to the SP network is either allowed or denied access based on a logical identifier contained in the message. It is emphasized that this abstract is provided to comply with the rules requiring an abstract that will allow a searcher or other reader to quickly ascertain the subject matter of the technical disclosure. It is submitted with the understanding that it will not be used to interpret or limit the scope or meaning of the claims. 37 CFR 1.72(b).