Network Access Server Dynamic Load Balancing for Radius Requests
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network access control systems face challenges in managing authentication requests efficiently, particularly in balancing load across geographically distributed systems to minimize latency and maximize availability, especially during peak periods and in different time zones.
Innovation Solution
A network access server (NAS) device probes geographically distributed NAC systems to determine latency and load, then selects the appropriate system for authentication requests based on the request type's latency tolerance, prioritizing low-latency systems for initial and multi-transaction requests while allowing higher latency for re-authentication and single-transaction requests, thereby optimizing load balancing across different time zones.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If authentication requests are sent to a single NAC system, then the system structure is simple, but the load balancing capability and latency performance deteriorate
Solution Approach 1:
The patent segments the NAC system into multiple geographically distributed NAC systems (local and remote). The NAS device can select different NAC systems based on authentication request type, dividing the authentication workload across multiple systems to improve load balancing while maintaining manageable complexity through clear segmentation rules.
Solution Approach 2:
The patent implements dynamic selection of NAC systems based on authentication request characteristics. The system dynamically determines whether to use local or remote NAC systems based on factors such as authentication request type (initial vs. re-authentication), latency requirements, and load conditions, enabling adaptive load balancing without permanent complex infrastructure.
2Loss of time
If all authentication requests are sent to the lowest latency NAC system, then latency performance is improved, but the NAC system capacity requirement increases
Solution Approach 1:
The patent applies different quality requirements to different authentication request types. Initial authentication requests (which require low latency) are directed to the lowest latency NAC system, while re-authentication requests (which can tolerate higher latency) are directed to other NAC systems. This differential approach optimizes latency for critical requests while distributing overall load to avoid capacity bottlenecks.
Solution Approach 2:
The patent changes the routing parameter (NAC system selection) based on authentication request characteristics. By analyzing whether an authentication request is latency-sensitive or latency-tolerant, the system dynamically adjusts which NAC system handles the request, optimizing both latency performance and capacity utilization across the distributed NAC infrastructure.
3Reliability
If multiple NAC systems are deployed geographically distributed, then load balancing and availability are improved, but the system complexity and latency determination overhead increase
Solution Approach 1:
The patent performs preliminary probing of NAC systems to determine their latency characteristics and availability status before routing authentication requests. The NAS device maintains knowledge of which NAC systems are local versus remote and their relative latency positions, allowing it to make informed routing decisions without complex real-time calculations for each authentication request.
Solution Approach 2:
The patent introduces a simplified intermediary mechanism where the NAS device acts as an intelligent router between client devices and multiple NAC systems. The NAS device handles the complexity of monitoring and selecting appropriate NAC systems based on pre-determined characteristics (local vs. remote, latency positions), shielding the rest of the system from complex distributed system management while maintaining high availability through multiple NAC system options.
4Productivity
If latency-based routing is implemented for all authentication requests, then authentication performance is improved, but the processing overhead and complexity increase
Solution Approach 1:
The patent implements partial latency optimization by applying latency-based routing only to authentication requests that benefit from it (initial authentication requests and other latency-sensitive requests). For re-authentication requests and other latency-tolerant requests, the system uses simpler routing logic. This partial application of complex routing logic reduces overall processing overhead while maintaining productivity gains for critical authentication operations.
Data Source
AI summary
A network access server (NAS) device is described that is configured to load balance authentication requests to network access control (NAC) systems based on a type of the authentication request. The NAS device may probe or ping one or more geographically distributed NAC systems to determine response latency and to receive load and status indications from the NAC systems. In response to receipt of an authentication request from a client device, the NAS device may select one NAC system from among the one or more NAC systems based on the load and status indications of the NAC systems and the type of authentication request received.


