Network Address Transparency via User Role Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network resource access control systems face challenges in balancing security and automation, particularly in environments where administrators lack control over end-user device software inventory and cannot manage client supplicant installations, leading to issues with dynamic VLAN assignment and IP address reassignment for IoT devices.
Innovation Solution
A system that uses a virtual networking construct to authenticate endpoints and dynamically assign VLANs based on user identity, maintaining IP transparency and flexible security policies across the network fabric, while allowing third-party authentication and authorization systems to interface with the network for policy-driven access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If port-based authentication methods are used, then security control is improved, but device complexity and configuration difficulty increase
Solution Approach 1:
The patent introduces a network controller as an intermediary component that centralizes authentication and authorization logic. Instead of implementing complex port-based authentication configurations on multiple network switches, the controller acts as a mediator that receives authentication requests, determines user identities, and dynamically assigns VLANs. This intermediary approach maintains security control while significantly reducing configuration complexity across the network infrastructure.
Solution Approach 2:
The system enables endpoints to authenticate themselves automatically through web-based or MAC bypass methods without requiring manual port configuration. The network controller automatically processes authentication requests, identifies user identities, and assigns appropriate VLANs based on pre-configured policies. This self-service mechanism eliminates the need for administrators to manually configure each port, reducing configuration complexity while maintaining security.
2Ease of operation
If web-based or MAC bypass authentication is used, then ease of operation is improved, but security control deteriorates
Solution Approach 1:
The system performs preliminary configuration of authentication policies, user identities, and VLAN assignments in the network controller before actual endpoint connections are made. Administrators pre-define which user identities should be assigned to which VLANs based on their roles and requirements. When endpoints connect through web-based or MAC bypass authentication, the controller refers to these pre-configured policies to make automated security decisions, thereby maintaining security control while enabling simple authentication operations.
Solution Approach 2:
The network controller implements feedback mechanisms where authentication requests from endpoints are automatically processed, user identities are determined, and VLAN assignments are dynamically adjusted based on pre-configured policies. The system continuously monitors authentication events and enforces access control policies in real-time. This feedback loop ensures that even simple authentication methods like MAC bypass maintain security control through automated policy enforcement.
3Reliability
If IP address reassignment is implemented for VLAN changes, then network security is improved, but loss of information increases
Solution Approach 1:
The patent segments the network into multiple virtual networks (VLANs) that operate independently at Layer 2, while maintaining a unified Layer 3 addressing scheme. Each VLAN can be configured with its own broadcast domain and security policies, but endpoints retain their IP addresses across VLAN transitions. The network controller manages the segmentation and routing between VLANs, allowing security isolation at Layer 2 without requiring IP address changes. This segmentation approach maintains IP address continuity while achieving network security through virtual network isolation.
4Adaptability or versatility
If dynamic VLAN assignment is implemented, then adaptability is improved, but device complexity increases
Solution Approach 1:
The network controller is designed as a universal platform that handles multiple authentication methods (web-based, MAC bypass, 802.1X), determines various types of user identities, and manages VLAN assignments across different network scenarios. The controller implements a unified policy framework that can accommodate diverse endpoint types and authentication mechanisms while maintaining consistent VLAN assignment logic. This multi-functional design provides adaptability for different authentication scenarios without proportionally increasing device complexity, as the controller handles diverse functions through a single integrated system.
Data Source
AI summary
Changes are made to a virtual network for an endpoint based on the authenticated user identity of the endpoint. The system includes a server and a controller associated with a network fabric to which the endpoint is connected. The network fabric includes network elements to carry network traffic for the endpoint. The server authenticates the endpoint associated with a network address and determines a user identity of the endpoint based on the authentication. The server determines a first virtual network associated with the user identity. The controller receives a notification from the server that the network traffic for the endpoint associated with the network address is to be routed over the first virtual network. The controller updates routing information to associate the network address with the first virtual network and sends the updated routing information to the network elements of the network fabric.


