Network Re-convergence Point Authentication Caching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network infrastructure devices face challenges in rapidly reauthenticating hosts and implementing network traffic policies when hosts change their ingress location or experience network events such as device failures or wireless roaming, leading to delays in network convergence and resource consumption.

Innovation Solution

A network infrastructure device controller and infrastructure devices preemptively store authentication information and policies at re-convergence points, which are located in close proximity to convergence points, allowing for accelerated authentication and policy implementation when hosts reconnect, thereby reducing the need for reauthorization and minimizing resource consumption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hosts reauthenticate and reapply policies after changing ingress location or experiencing network events, then network convergence and policy implementation are ensured, but network convergence time increases and resources are consumed

Engineering Contradiction:
Improvenetwork convergenceVSAvoidconvergence time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-storing authentication information and traffic policies at re-convergence points before hosts actually migrate. When a host moves to a re-convergence point, the authentication and policies are already cached there, eliminating the need for time-consuming reauthentication and policy reapplication, thus reducing convergence time while maintaining reliability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by creating copies of authentication information and traffic policies from the original convergence point and storing them at re-convergence points. This allows the re-convergence point to immediately use the copied authentication data and policies without contacting the original convergence point, significantly accelerating the reconnection process

Inventive Principle:
Principle #26Copying

2Reliability

If hosts reauthenticate and reapply policies after changing ingress location or experiencing network events, then network convergence and policy implementation are ensured, but resource consumption increases

Engineering Contradiction:
Improvenetwork convergenceVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies preliminary action by pre-storing authentication information and traffic policies at re-convergence points before hosts actually migrate. When a host moves to a re-convergence point, the authentication and policies are already cached there, eliminating the need for time-consuming reauthentication and policy reapplication, thus reducing convergence time while maintaining reliability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by creating copies of authentication information and traffic policies from the original convergence point and storing them at re-convergence points. This allows the re-convergence point to immediately use the copied authentication data and policies without contacting the original convergence point, significantly accelerating the reconnection process

Inventive Principle:
Principle #26Copying

3Speed

If authentication information and policies are stored at re-convergence points in close proximity to convergence points, then reconnection speed is improved, but network device complexity increases

Engineering Contradiction:
Improvereconnection speedVSAvoidnetwork device complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the network into convergence points and re-convergence points with distinct roles. Convergence points handle initial authentication and policy distribution, while re-convergence points handle reconnections. This segmentation allows reconnection operations to be distributed across multiple devices, improving reconnection speed without overloading any single device

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent uses intermediaries by introducing re-convergence points as intermediary devices between hosts and the central controller. These intermediaries cache authentication information and policies locally, reducing the need for direct communication between hosts and the controller during reconnection, thus improving speed while distributing complexity across the network

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10448246B2Network re-convergence point
Publication Date: 2019.10.15 HEWLETT PACKARD ENTERPRISE DEV LP
  • US10448246B2 patent drawing
  • US10448246B2 patent drawing
  • US10448246B2 patent drawing

AI summary

In an example, a re-convergence point is determined for a convergence point in a network. A host is currently connected to the convergence point for example to access the network. Authentication information and a policy for the host is sent to the re-convergence point prior to the host connecting to the re-convergence point to access the network.