Network Device Probing for Client Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing BYOD authentication processes are cumbersome and inefficient, consuming significant network bandwidth and posing security risks due to the need for multiple discovery and authentication steps, which can lead to delays and inappropriate access policies.

Innovation Solution

A network device acts as an intermediary to probe client devices for device-type information during the initial authentication phase, sharing this information with the authentication server to apply appropriate access policies, thereby reducing the need for post-authentication discovery and minimizing bandwidth usage, and ensuring real-time evaluation and verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional multi-step discovery and authentication processes are used, then device identification and security verification can be achieved, but network bandwidth is consumed and authentication delays occur

Engineering Contradiction:
Improvesecurity verificationVSAvoidnetwork bandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies preliminary action by obtaining device-type information during the initial authentication phase before full network access is granted. The network device probes the client device early in the process to categorize it, so that appropriate access policies can be applied immediately without requiring post-authentication discovery steps, thereby reducing bandwidth consumption and authentication delays

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts the device discovery function from the post-authentication phase and moves it to the authentication phase itself. By separating the device-type identification step from the main authentication flow and performing it concurrently, the system eliminates the need for separate discovery processes that consume additional network bandwidth

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If multiple discovery and authentication steps are performed, then comprehensive device verification is achieved, but authentication time increases

Engineering Contradiction:
Improvedevice verificationVSAvoidauthentication delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent merges the device discovery function with the authentication process by obtaining device-type information during the initial authentication phase. The network device probes the client device and categorizes it concurrently with credential verification, combining multiple functions into a single integrated process that reduces total authentication time while maintaining verification comprehensiveness

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

Device-type information is obtained preliminarily during the authentication phase before full network access is granted. This preliminary categorization allows the system to apply appropriate access policies immediately upon authentication completion, eliminating the need for post-authentication discovery steps and reducing overall authentication delay

Inventive Principle:
Principle #10Preliminary action

3Productivity

If device-type information is obtained during authentication phase, then post-authentication discovery is reduced, but additional probing mechanisms are required

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidprobing mechanism
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The network device serves as an intermediary between the client device and the authentication server. It performs the probing function by sending identity requests to client devices and extracting device-type information from the responses, then relays this information to the authentication server. This intermediary approach consolidates the probing complexity in a single component rather than requiring complex probing mechanisms across multiple system elements

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11956635B2Authenticating a client device
Publication Date: 2024.04.09 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11956635B2 patent drawing
  • US11956635B2 patent drawing
  • US11956635B2 patent drawing

AI summary

Examples described herein relate to techniques for authenticating a client device by obtaining device-type information during an initial phase of authentication process. According to some examples, identifying a client device intending to connect to a network and sending an identity-request thereto. Receiving an identity-response from the client device along with device-type information. Identifying a device category from a set of device categories corresponding to identified device-type information. Selecting a device policy applicable to the identified device-type information. Authenticating the client device to enable access to the network and applying the selected device policy to the client device.