Authenticating Passive Devices via ARP Capture
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Passive devices, which cannot actively transmit traffic, are not effectively authenticated in existing network systems, leading to restricted access and communication challenges due to their configuration within specific virtual local area networks (VLANs).
Innovation Solution
A network device configures a passive device with an IP address belonging to a different VLAN, allowing egress traffic and adding ports to the broadcast domain of another VLAN to elicit an ARP response, which is then authenticated using an authentication server, enabling access once the MAC address is recognized as authorized.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If passive devices are configured within specific VLANs for network segmentation, then network security and organization are improved, but passive devices cannot effectively access networks or be authenticated due to port blocking and traffic restrictions
Solution Approach 1:
The patent introduces an intermediary authentication mechanism where the network device acts as a mediator between the passive device and the authentication server. The network device captures ARP requests from passive devices, extracts MAC addresses, and submits them for authentication without requiring the passive device to actively initiate authentication sequences. This intermediary approach allows passive devices to be authenticated while maintaining VLAN segmentation security.
Solution Approach 2:
The system performs preliminary authentication actions by pre-configuring the network device to monitor and capture ARP requests from passive devices before full network access is granted. The network device proactively extracts MAC addresses from these requests and submits them to the authentication server in advance, enabling the passive device to be authenticated without requiring active participation from the device itself.
2Reliability
If MAC-based authentication is implemented for network access control, then network security is improved, but passive devices cannot be authenticated because they cannot actively transmit authentication traffic
Solution Approach 1:
The patent enables passive devices to authenticate themselves indirectly through their ARP requests. The passive device generates an ARP request to resolve the gateway IP address, and the network device captures this request to extract the MAC address for authentication. The passive device essentially authenticates itself through its normal ARP operation without needing to actively participate in authentication protocols, making the system adaptable to passive devices that cannot run authentication clients.
Solution Approach 2:
The network device serves as an intermediary that translates the passive device's ARP request into an authentication submission. It captures the ARP request, extracts the MAC address, and submits it to the authentication server, bridging the gap between passive device capabilities and authentication requirements.
3Reliability
If ports are blocked to prevent unauthenticated device access, then network security is improved, but passive devices cannot receive necessary network traffic for authentication and communication
Solution Approach 1:
The patent applies local quality by allowing specific types of traffic (ARP requests) to pass through the blocked port while maintaining overall port blocking for unauthenticated devices. The network device configures the port to block most traffic but permits ARP requests from passive devices, enabling MAC address extraction for authentication while maintaining security restrictions on other traffic types.
Solution Approach 2:
The system allows partial traffic flow by permitting ARP requests to pass through blocked ports specifically for authentication purposes. This partial action enables the necessary authentication traffic to reach the passive device and return to the network device without opening the port to general traffic, maintaining security while enabling authentication functionality.
Data Source
AI summary
Some embodiments provide a method, executable by a network device, that receives a first set of commands instructing the network device to allow network traffic to egress out of an authentication port of the network device. The authentication port is configured to belong to a first virtual local area network (VLAN). An unauthenticated device is connected to the authentication port. The method further receives a second set of commands instructing the network device to add ports belonging to the first VLAN to a broadcast domain of a second VLAN. The method also broadcasts an address request to the broadcast domain of the second VLAN. The method further receives, from the unauthenticated device, a response to the address request.


