Network Device Probing for Client Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing BYOD authentication processes are cumbersome and inefficient, consuming significant network bandwidth and posing security risks due to the need for multiple discovery and authentication steps, which can lead to delays and inappropriate access policies.
Innovation Solution
A network device acts as an intermediary to probe client devices for device-type information during the initial authentication phase, sharing this information with the authentication server to apply appropriate access policies, thereby reducing the need for post-authentication discovery and minimizing bandwidth usage, and ensuring real-time evaluation and verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional multi-step discovery and authentication processes are used, then device identification and security verification can be achieved, but network bandwidth is consumed and authentication delays occur
Solution Approach 1:
The patent applies preliminary action by obtaining device-type information during the initial authentication phase before full network access is granted. The network device probes the client device early in the process to categorize it, so that appropriate access policies can be applied immediately without requiring post-authentication discovery steps, thereby reducing bandwidth consumption and authentication delays
Solution Approach 2:
The patent extracts the device discovery function from the post-authentication phase and moves it to the authentication phase itself. By separating the device-type identification step from the main authentication flow and performing it concurrently, the system eliminates the need for separate discovery processes that consume additional network bandwidth
2Reliability
If multiple discovery and authentication steps are performed, then comprehensive device verification is achieved, but authentication time increases
Solution Approach 1:
The patent merges the device discovery function with the authentication process by obtaining device-type information during the initial authentication phase. The network device probes the client device and categorizes it concurrently with credential verification, combining multiple functions into a single integrated process that reduces total authentication time while maintaining verification comprehensiveness
Solution Approach 2:
Device-type information is obtained preliminarily during the authentication phase before full network access is granted. This preliminary categorization allows the system to apply appropriate access policies immediately upon authentication completion, eliminating the need for post-authentication discovery steps and reducing overall authentication delay
3Productivity
If device-type information is obtained during authentication phase, then post-authentication discovery is reduced, but additional probing mechanisms are required
Solution Approach 1:
The network device serves as an intermediary between the client device and the authentication server. It performs the probing function by sending identity requests to client devices and extracting device-type information from the responses, then relays this information to the authentication server. This intermediary approach consolidates the probing complexity in a single component rather than requiring complex probing mechanisms across multiple system elements
Data Source
AI summary
Examples described herein relate to techniques for authenticating a client device by obtaining device-type information during an initial phase of authentication process. According to some examples, identifying a client device intending to connect to a network and sending an identity-request thereto. Receiving an identity-response from the client device along with device-type information. Identifying a device category from a set of device categories corresponding to identified device-type information. Selecting a device policy applicable to the identified device-type information. Authenticating the client device to enable access to the network and applying the selected device policy to the client device.


