PoE Device Authentication for Power Budget Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Non-authenticated powered devices continue to consume power, reducing the available power for authenticated devices in Power over Ethernet systems, leading to inefficiencies and potential power budget depletion.

Innovation Solution

Implement an authentication manager that grants provisional power to devices, analyzes user and device data for authentication, and uses an authenticated-power-profile to manage power supply dynamically, ensuring only authenticated devices receive sustained power while non-authenticated devices are managed through defined actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If provisional power is granted to all powered devices without authentication, then all devices can power up and negotiate PoE power needs, but non-authenticated devices continue to consume power reducing available power for other devices

Engineering Contradiction:
Improvepower negotiationVSAvoidavailable power
Core Design Contradiction:
Ease of operationVSLoss of energy

Solution Approach 1:

The system performs preliminary authentication actions before finalizing power allocation. Devices must complete authentication procedures (such as 802.1X authentication) before being granted sustained power reservations, ensuring that power is only allocated to authorized devices after verification

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The power allocation system dynamically adjusts power reservations based on authentication status. Initially, provisional power may be granted for negotiation purposes, but sustained power reservations are only established after successful authentication, allowing the system to adapt power distribution in real-time based on device authorization

Inventive Principle:
Principle #15Dynamics

2Loss of energy

If authentication is required before power supply, then power can be reserved for authenticated devices, but the authentication process adds complexity to the power management system

Engineering Contradiction:
Improvepower budget managementVSAvoidauthentication management
Core Design Contradiction:
Loss of energyVSDevice complexity

Solution Approach 1:

The authentication manager integrates multiple authentication methods (such as 802.1X authentication, MAC address filtering, and device profile matching) into a single unified system that can handle various device types and authentication requirements through a common interface and standardized process

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Loss of energy

If power is reserved for authenticated devices only, then available power for authenticated devices increases, but non-authenticated devices cannot power up to complete authentication

Engineering Contradiction:
Improvepower availabilityVSAvoiddevice authorization
Core Design Contradiction:
Loss of energyVSAdaptability or versatility

Solution Approach 1:

The system provides preliminary provisional power allocation that allows devices to power up and perform authentication negotiations without committing sustained power reservations. This preliminary power is sufficient for basic operation and authentication procedures but is automatically revoked or not converted to permanent reservations for unauthorized devices

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system changes power allocation parameters based on authentication outcomes. Successful authentication transitions a device from provisional power status to authenticated power status with sustained reservations, while failed authentication results in power denial or timeout, dynamically adjusting power parameters according to authorization verification

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12526266B2Authentication of a power over Ethernet device
Publication Date: 2026.01.13 CISCO TECHNOLOGY INC
  • US12526266B2 patent drawing
  • US12526266B2 patent drawing
  • US12526266B2 patent drawing

AI summary

In one embodiment, a method includes receiving a request from a powered device for power to be supplied from power sourcing equipment to the powered device; granting, in response to the request, provisional power to the powered device; receiving, an authentication request from the powered device to authenticate the powered device and reserve power; analyzing user data and device data to determine an authentication status for the powered device; denying power within a power budget for the powered device in response to the analyzing determining that the authentication status for the powered device corresponds to a failed authentication; and using an authenticated-power-profile to determine one or more actions to be performed with respect to the powered device having the failed authentication, in response to a defined number of failed authentications or an expiration of a timeout period defining an amount of time allowed to authenticate the powered device.