Proxy Network Node Authentication via Layer-2 Tunneling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network devices, such as layer-two switches, that are not connected to an authentication server cannot authenticate destination devices, disrupting network communication.
Innovation Solution
A network node acts as a proxy using a data link layer tunneling protocol to communicate with an authentication server via a network layer protocol, enabling authentication of client devices even when the node itself cannot access the server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a network node is not connected to an authentication server, then the network node architecture is simpler and costs are reduced, but the network node cannot authenticate destination devices
Solution Approach 1:
The patent introduces an intermediary network node (the first network node) that acts as a mediator between the unauthenticated network nodes and the authentication server. This intermediary node performs the authentication function on behalf of nodes that cannot directly access the server, thereby maintaining authentication capability while preserving architectural simplicity at the individual node level.
2Reliability
If authentication components are added to each network node, then authentication capability is improved, but device complexity and costs increase
Solution Approach 1:
The patent implements multi-functionality by enabling network nodes to perform multiple roles: some nodes serve as authentication proxies while others function as regular network devices. The authentication server also serves multiple purposes by authenticating devices for different network nodes. This universal approach allows authentication capability to be distributed without requiring dedicated authentication components at every node.
Solution Approach 2:
The patent uses copying by having network nodes replicate authentication requests and responses through proxy nodes. Instead of each node having unique authentication components, the authentication logic is copied and transmitted through the network protocol, allowing any node to perform authentication by forwarding requests to an authenticated proxy node.
3Reliability
If network nodes use network layer authentication protocols, then authentication security is improved, but nodes must be connected to authentication servers which increases complexity
Solution Approach 1:
The patent uses an intermediary proxy node that bridges the gap between nodes using network layer authentication protocols and nodes that cannot directly connect to the authentication server. The proxy node handles the network layer authentication communication, allowing secure authentication without requiring direct connectivity between all nodes and the server.
Solution Approach 2:
The patent introduces a dimensional change by adding a proxy network layer between the data link layer (where the unauthenticated nodes operate) and the network layer authentication protocol. This additional dimension allows nodes to maintain their simple architecture while still accessing authentication services through the proxy infrastructure.
Data Source
AI summary
A method includes detecting a presence of a device on a network associated with a node, where the node is not connected to an authentication server and is configured to communicate with the device using a data link layer authentication protocol; communicating, with another node, using a data link layer tunneling protocol, to authenticate the device as a result of detecting the presence of the device, where the other node communicates with the authentication server, using a network layer authentication protocol, that enables the other node to receive an authentication notification associated with the device; receiving, from the other node, the authentication notification that indicates that the device has been authenticated, where the authentication notification is received using the data link layer tunneling protocol; and sending, to the device, an indication that the device is authorized to communicate with the network, where the sending includes establishing an authentication session that enables the device to communicate with the network.


