MAC Mobility Provisioning for Seamless 802.1x Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security protocols, such as IEEE 802.1x, require reauthentication of devices upon movement between switch ports or virtual switches, leading to packet loss and inefficiencies due to reliance on hardware-based disconnection methods like link down, sign off, and timeouts, which are impractical and fail to ensure secure communication in virtualized environments.
Innovation Solution
A software-based mechanism for provisional authentication allows devices to move between switch ports or virtual switches without packet loss by initiating a new authentication session at the destination, using an authentication agent to intercept and redirect authentication packets, and updating forwarding tables to ensure seamless reauthentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hardware-based disconnection methods (link down, sign off, timeout) are used for reauthentication, then network security is maintained, but device movement causes packet loss and network performance degradation
Solution Approach 1:
The patent implements MAC mobility provisioning that pre-establishes authentication state information in forwarding tables before device movement occurs. This allows the network to anticipate and prepare for device migration, maintaining security while avoiding the packet loss associated with reactive hardware-based disconnection methods.
Solution Approach 2:
The patent replaces hardware-based mechanical disconnection methods (link down, sign off, timeout) with a software-based forwarding table mechanism. By using MAC mobility provisioning and authentication state information in software-controlled forwarding tables, the system eliminates the need for physical link disruption while maintaining security policies.
2Reliability
If hardware-based reauthentication methods are used, then security protocols are enforced, but device movement requires impractical link disconnection and causes communication interruptions
Solution Approach 1:
The system pre-provisions MAC mobility information in forwarding tables before device movement, allowing seamless authentication state transfer. This eliminates the need for impractical link disconnection while maintaining security protocol enforcement through pre-configured authentication states.
Solution Approach 2:
The patent introduces MAC mobility provisioning as an intermediary mechanism between security protocols and device movement. This intermediary layer handles authentication state management in forwarding tables, allowing devices to move freely while security protocols continue to enforce authentication requirements without requiring link disconnection.
3Reliability
If traditional reauthentication methods are used, then authentication security is maintained, but packet loss occurs during the reauthentication process
Solution Approach 1:
The patent pre-establishes authentication state information in forwarding tables through MAC mobility provisioning before device movement occurs. This preliminary action ensures that authentication security is maintained while preventing packet loss by having the forwarding table already configured to recognize and forward packets for the moving device.
Solution Approach 2:
The system maintains continuous packet forwarding during device movement by keeping authentication state information active in forwarding tables. Instead of interrupting communication for reauthentication, the MAC mobility mechanism ensures continuous useful action by seamlessly maintaining packet flow while the device transitions between ports or switches.
Data Source
AI summary
A system and method for provisionally authenticating a host moving from a source port of a switch device to a destination port of the switch device is disclosed. The host is initially authenticated at the source port and blocked from forwarding network traffic at the destination port. During a provisional authentication session, an authentication agent executing on the switch intercepts one or more authentication packets sourced by the host and headed for the destination port of the switch device and redirects the authentication packets to an authentication server for validating the host at the destination port of the switch device. The switch device removes the block at the destination port in response to receiving an acknowledgment of successful authentication at the destination port from the authentication server.


