Network Port Heterogeneous Authentication Policy Chain

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network authentication methods are limited to a single authentication methodology per network access port, restricting client devices to use only the configured method and requiring extensive manual administration for heterogeneous authentication scenarios.

Innovation Solution

Implementing a series of policies that combine multiple authentication methods, allowing switches or routers to automatically and sequentially apply different authentication protocols (such as 802.1x, MAC, and web-based login) to identify a compatible method for each client device, and dynamically classify them into appropriate Virtual Local Area Networks (VLANs).

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a single authentication methodology is configured on a network access port, then the authentication process is simple and manageable, but client devices are limited to only that specific authentication method and extensive manual administration is required when devices with different authentication capabilities need to connect

Engineering Contradiction:
Improveauthentication method compatibilityVSAvoidauthentication configuration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system dynamically selects and applies appropriate authentication methodologies based on the client device's capabilities and behavior. Instead of a static single-method configuration, the network access port can adaptively switch between 802.1x, MAC authentication, and web-based authentication methods depending on which method the client device responds to or requires.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The network access port is designed to support multiple authentication methodologies simultaneously through a unified configuration framework. The system can handle 802.1x authentication, MAC address-based authentication, and web-based login protocols through a single versatile authentication configuration that automatically determines which method to apply.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If multiple authentication methodologies are supported for heterogeneous client devices, then authentication flexibility and device compatibility are improved, but manual administration and configuration overhead increase significantly

Engineering Contradiction:
Improveauthentication method diversityVSAvoidadministrative overhead
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The authentication system performs self-service by automatically detecting which authentication methodology a client device supports and applying the appropriate method without requiring manual administrator intervention. The system monitors client responses to authentication probes and autonomously selects the compatible authentication protocol, eliminating the need for administrators to manually configure different authentication methods for each device type.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes authentication parameters dynamically based on client device characteristics and responses. Instead of maintaining fixed configuration parameters for each authentication method, the system adjusts which authentication protocol is active based on real-time device behavior and compatibility indicators, reducing administrative burden while supporting diverse authentication methods.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If a client device is blocked after failing 802.1x authentication, then security is maintained by preventing unauthorized access, but devices that use alternative authentication methods are incorrectly denied network access

Engineering Contradiction:
Improveauthentication accuracyVSAvoidauthentication method flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The authentication system dynamically transitions between different authentication methodologies when a client device fails initial authentication attempts. If 802.1x authentication fails, the system automatically attempts alternative methods such as MAC authentication or web-based login, adapting its approach based on the client's response patterns rather than permanently blocking the device.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system introduces intermediary authentication methods that bridge between 802.1x and other authentication protocols. When 802.1x authentication fails, intermediary mechanisms probe the client device to determine if it supports alternative authentication methods, serving as a mediator that prevents incorrect blocking while maintaining security through progressive authentication attempts.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2198584B1Facilitating heterogeneous authentication for allowing network access
Publication Date: 2016.08.31 ALCATEL LUCENT SA
  • EP2198584B1 patent drawingFigure 1
  • EP2198584B1 patent drawingFigure 2~3
  • EP2198584B1 patent drawingFigure 4

AI summary

A method comprises an operation for facilitating authentication of a client device attempting to connect to a port of a network element. Facilitating authentication includes determining whether the client device is configured for being authenticated using a first authentication mechanism and, in response to determining that the client device is not configured for being authenticated using the first authentication mechanism, determining whether the client device is configured for being authenticated using at least one other authentication mechanism. For each one of the authentication mechanisms, an operation is provided for providing the client device with network connectivity dependent upon a respective first classification policy structure in response to the client device being successfully authenticated and an operation is provided for providing the client device with network connectivity dependent upon a respective second classification policy structure different that the first classification policy structure in response to the client device failing to be successfully authenticated.