Proxy Network Node Authentication via Layer-2 Tunneling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network devices, such as layer-two switches, that are not connected to an authentication server cannot authenticate destination devices, disrupting network communication.

Innovation Solution

A network node acts as a proxy using a data link layer tunneling protocol to communicate with an authentication server via a network layer protocol, enabling authentication of client devices even when the node itself cannot access the server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a network node is not connected to an authentication server, then the network node architecture is simpler and costs are reduced, but the network node cannot authenticate destination devices

Engineering Contradiction:
Improvenetwork node architectureVSAvoidauthentication capability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent introduces an intermediary network node (the first network node) that acts as a mediator between the unauthenticated network nodes and the authentication server. This intermediary node performs the authentication function on behalf of nodes that cannot directly access the server, thereby maintaining authentication capability while preserving architectural simplicity at the individual node level.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication components are added to each network node, then authentication capability is improved, but device complexity and costs increase

Engineering Contradiction:
Improveauthentication capabilityVSAvoidnetwork node architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements multi-functionality by enabling network nodes to perform multiple roles: some nodes serve as authentication proxies while others function as regular network devices. The authentication server also serves multiple purposes by authenticating devices for different network nodes. This universal approach allows authentication capability to be distributed without requiring dedicated authentication components at every node.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses copying by having network nodes replicate authentication requests and responses through proxy nodes. Instead of each node having unique authentication components, the authentication logic is copied and transmitted through the network protocol, allowing any node to perform authentication by forwarding requests to an authenticated proxy node.

Inventive Principle:
Principle #26Copying

3Reliability

If network nodes use network layer authentication protocols, then authentication security is improved, but nodes must be connected to authentication servers which increases complexity

Engineering Contradiction:
Improveauthentication securityVSAvoidnetwork connectivity requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses an intermediary proxy node that bridges the gap between nodes using network layer authentication protocols and nodes that cannot directly connect to the authentication server. The proxy node handles the network layer authentication communication, allowing secure authentication without requiring direct connectivity between all nodes and the server.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent introduces a dimensional change by adding a proxy network layer between the data link layer (where the unauthenticated nodes operate) and the network layer authentication protocol. This additional dimension allows nodes to maintain their simple architecture while still accessing authentication services through the proxy infrastructure.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS8584209B1Authentication using a proxy network node
Publication Date: 2013.11.12 JUNIPER NETWORKS INC
  • US8584209B1 patent drawing
  • US8584209B1 patent drawing
  • US8584209B1 patent drawing

AI summary

A method includes detecting a presence of a device on a network associated with a node, where the node is not connected to an authentication server and is configured to communicate with the device using a data link layer authentication protocol; communicating, with another node, using a data link layer tunneling protocol, to authenticate the device as a result of detecting the presence of the device, where the other node communicates with the authentication server, using a network layer authentication protocol, that enables the other node to receive an authentication notification associated with the device; receiving, from the other node, the authentication notification that indicates that the device has been authenticated, where the authentication notification is received using the data link layer tunneling protocol; and sending, to the device, an indication that the device is authorized to communicate with the network, where the sending includes establishing an authentication session that enables the device to communicate with the network.