Network Authentication Pre-Auth Distribution for Seamless Roaming
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In networks with multiple edge devices or access points, clients must repeatedly authenticate with a central authentication server when moving between nodes, leading to bottlenecks, connectivity disruptions, and unnecessary delays.
Innovation Solution
A network device that pre-authenticates clients by distributing authentication information across authorized nodes, using an authentication manager to query client credentials and update shared admission tables, allowing seamless access across multiple network points without re-authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If clients are authenticated by a central authentication server at each access point, then network security is maintained, but the authentication server becomes a bottleneck and client connectivity is disrupted when moving between nodes
Solution Approach 1:
The patent implements pre-authentication where the client is authenticated in advance at the current access point before moving to a new one. The authentication information is cached at both the current and target access points, so when the client roams, the target access point can immediately admit the client without contacting the central authentication server, thus maintaining security while eliminating re-authentication delays
Solution Approach 2:
The patent introduces an intermediary mechanism where authentication information is shared between access points through a distributed caching system. Instead of direct communication between the client and central authentication server at each node, the system uses cached authentication data at intermediate access points to facilitate seamless roaming while maintaining the security framework
2Reliability
If clients are re-authenticated at each network node, then authentication security is ensured, but time is lost and connectivity is disrupted
Solution Approach 1:
The system performs pre-authentication by caching authentication credentials at the target access point before the client actually moves there. This preliminary action ensures that when the client roams, authentication has already been completed in advance, eliminating re-authentication time while maintaining security through the cached credentials
3Productivity
If authentication information is distributed across multiple nodes, then re-authentication is eliminated, but system complexity increases
Solution Approach 1:
The patent introduces an intermediary authentication manager component that coordinates the distribution of authentication information between access points. This intermediary handles the complexity of managing cached credentials, determining which access points should have authentication information, and ensuring security policies are maintained, thereby enabling seamless roaming without requiring complex modifications to each individual access point
Data Source
AI summary
A network device for distributing authentication information between authorized nodes for purposes of concurrently “pre-authenticating” a mobile user at a plurality of points throughout a LAN is disclosed. When a client attempts to access the network through the network device, the network device attempts to authenticate the client based on the credentials presented by the user. If authenticated, the client is admitted into the network at the network device and the client's pre-authentication information transmitted to one or more network nodes associated with an authentication group. Upon receipt of the pre-authentication information, the one or more network nodes are authorized to admit the client into the network at those nodes in addition to the network device at which the client was initially authenticated, thereby concurrently pre-authorizing the client at multiple points across the network.


