Network Access Control via MAC Portal Authentication in VxLAN

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In Virtual Extensible Local Area Networks (VxLAN), the separation of control and data planes prevents the use of traditional portal authentication, making it challenging to manage network access for terminals, especially when IP addresses need to be changed from temporary to service addresses.

Innovation Solution

The implementation of MAC Portal authentication, which involves interactions between a RADIUS Server, a Network Attached Server (NAS), and a terminal, using temporary and service roles to manage network access, including a process where a terminal is initially authenticated with a temporary IP address and later switched to a service IP address using a minimum lease mechanism to facilitate seamless network access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional portal authentication is used in VxLAN, then network access control can be implemented, but it cannot work due to the separation of control and data planes

Engineering Contradiction:
Improveauthentication effectivenessVSAvoidcompatibility with VxLAN architecture
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a MAC Portal authentication mechanism that uses the terminal's MAC address as an intermediary identifier instead of relying on IP addresses. This allows authentication to proceed through the control plane independently of data plane IP address allocation, making it compatible with VxLAN's separated architecture while maintaining authentication reliability

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If IP address follows the terminal in VxLAN, then mobility is supported, but traditional portal authentication cannot be used

Engineering Contradiction:
Improveterminal mobility supportVSAvoidauthentication capability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent uses MAC address as a stable intermediary identifier that remains constant regardless of IP address changes. The MAC Portal authentication binds the terminal's identity to its MAC address rather than IP address, enabling reliable authentication even when IP addresses follow the terminal during mobility

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent performs MAC Portal authentication before IP address allocation, establishing the terminal's identity and service role in advance. This preliminary authentication ensures that subsequent IP address changes do not affect the authenticated session, supporting terminal mobility while maintaining authentication reliability

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If temporary IP address is allocated to terminal, then initial network access is enabled, but service quality deteriorates without service IP address

Engineering Contradiction:
Improveinitial network accessVSAvoidservice quality
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent performs MAC Portal authentication and service role determination before allocating the service IP address. This preliminary action ensures that terminals receive appropriate service quality parameters (such as bandwidth, priority, and access rights) based on their authenticated identity, rather than relying on generic temporary IP address allocations

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the network parameters allocated to terminals based on their service role determined through MAC Portal authentication. Terminals transition from temporary IP address parameters to service IP address parameters with appropriate quality of service settings, ensuring both initial access capability and sustained service quality

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11159524B2Network access control
Publication Date: 2021.10.26 NEW H3C TECH CO LTD
  • US11159524B2 patent drawing
  • US11159524B2 patent drawing
  • US11159524B2 patent drawing

AI summary

The present disclosure discloses methods of controlling network access, NASs and non-transitory machine-readable storage mediums. In an example of the present disclosure, when a terminal comes online for a first time, a NAS obtains a temporary role for a terminal; when receiving an IP address request from the terminal, the NAS requests an IP address for the terminal, wherein a lease for the temporary IP address is a set minimum lease; the NAS forces the terminal to go offline when the portal authentication is successful; when the terminal comes online for a second time, the NAS obtains a service role for the terminal; when receiving an IP address request sent by the terminal at expiry of the lease for the temporary IP address, the NAS requests a service IP address for the terminal, wherein the service IP address belongs to an IP network segment corresponding to the service role.