Network Address Transparency via User Role Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network resource access control systems face challenges in balancing security and automation, particularly in environments where administrators lack control over end-user device software inventory and cannot manage client supplicant installations, leading to issues with dynamic VLAN assignment and IP address reassignment for IoT devices.

Innovation Solution

A system that uses a virtual networking construct to authenticate endpoints and dynamically assign VLANs based on user identity, maintaining IP transparency and flexible security policies across the network fabric, while allowing third-party authentication and authorization systems to interface with the network for policy-driven access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If port-based authentication methods are used, then security control is improved, but device complexity and configuration difficulty increase

Engineering Contradiction:
Improvesecurity controlVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a network controller as an intermediary component that centralizes authentication and authorization logic. Instead of implementing complex port-based authentication configurations on multiple network switches, the controller acts as a mediator that receives authentication requests, determines user identities, and dynamically assigns VLANs. This intermediary approach maintains security control while significantly reducing configuration complexity across the network infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables endpoints to authenticate themselves automatically through web-based or MAC bypass methods without requiring manual port configuration. The network controller automatically processes authentication requests, identifies user identities, and assigns appropriate VLANs based on pre-configured policies. This self-service mechanism eliminates the need for administrators to manually configure each port, reducing configuration complexity while maintaining security.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If web-based or MAC bypass authentication is used, then ease of operation is improved, but security control deteriorates

Engineering Contradiction:
Improveauthentication simplicityVSAvoidsecurity control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary configuration of authentication policies, user identities, and VLAN assignments in the network controller before actual endpoint connections are made. Administrators pre-define which user identities should be assigned to which VLANs based on their roles and requirements. When endpoints connect through web-based or MAC bypass authentication, the controller refers to these pre-configured policies to make automated security decisions, thereby maintaining security control while enabling simple authentication operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The network controller implements feedback mechanisms where authentication requests from endpoints are automatically processed, user identities are determined, and VLAN assignments are dynamically adjusted based on pre-configured policies. The system continuously monitors authentication events and enforces access control policies in real-time. This feedback loop ensures that even simple authentication methods like MAC bypass maintain security control through automated policy enforcement.

Inventive Principle:
Principle #23Feedback

3Reliability

If IP address reassignment is implemented for VLAN changes, then network security is improved, but loss of information increases

Engineering Contradiction:
Improvenetwork securityVSAvoidIP address continuity
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments the network into multiple virtual networks (VLANs) that operate independently at Layer 2, while maintaining a unified Layer 3 addressing scheme. Each VLAN can be configured with its own broadcast domain and security policies, but endpoints retain their IP addresses across VLAN transitions. The network controller manages the segmentation and routing between VLANs, allowing security isolation at Layer 2 without requiring IP address changes. This segmentation approach maintains IP address continuity while achieving network security through virtual network isolation.

Inventive Principle:
Principle #1Segmentation

4Adaptability or versatility

If dynamic VLAN assignment is implemented, then adaptability is improved, but device complexity increases

Engineering Contradiction:
ImproveVLAN assignment flexibilityVSAvoidnetwork control complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The network controller is designed as a universal platform that handles multiple authentication methods (web-based, MAC bypass, 802.1X), determines various types of user identities, and manages VLAN assignments across different network scenarios. The controller implements a unified policy framework that can accommodate diverse endpoint types and authentication mechanisms while maintaining consistent VLAN assignment logic. This multi-functional design provides adaptability for different authentication scenarios without proportionally increasing device complexity, as the controller handles diverse functions through a single integrated system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10462007B2Network address transparency through user role authentication
Publication Date: 2019.10.29 CISCO TECHNOLOGY INC
  • US10462007B2 patent drawing
  • US10462007B2 patent drawing
  • US10462007B2 patent drawing

AI summary

Changes are made to a virtual network for an endpoint based on the authenticated user identity of the endpoint. The system includes a server and a controller associated with a network fabric to which the endpoint is connected. The network fabric includes network elements to carry network traffic for the endpoint. The server authenticates the endpoint associated with a network address and determines a user identity of the endpoint based on the authentication. The server determines a first virtual network associated with the user identity. The controller receives a notification from the server that the network traffic for the endpoint associated with the network address is to be routed over the first virtual network. The controller updates routing information to associate the network address with the first virtual network and sends the updated routing information to the network elements of the network fabric.