Local RADIUS Attribute Caching for Network Access Reliability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network access systems fail to ensure client device access when an external RADIUS server is inaccessible, as they rely on centralized authentication, leading to network access halts when the server is down.

Innovation Solution

Implementing a local RADIUS attribute storage mechanism within the branch office network, allowing network controllers to authenticate and assign roles and VLANs using previously received RADIUS attributes from the external server, even when the server is inaccessible.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized RADIUS server authentication is used, then authentication security and centralized control are improved, but network access reliability deteriorates when the server is inaccessible

Engineering Contradiction:
Improvenetwork access reliabilityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by caching RADIUS attributes (roles and VLANs) locally at the network controller before the RADIUS server becomes inaccessible. During normal operation, the system pre-retrieves and stores authentication attributes locally, so when the RADIUS server becomes unavailable, the network controller can immediately use the cached attributes to maintain network access without requiring real-time server communication.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies local quality by transitioning from entirely centralized authentication to a hybrid approach where authentication attributes are stored locally at the network controller while maintaining the ability to update from the centralized RADIUS server. This allows the system to have both centralized security management and local fallback capability, with different parts of the authentication system serving different functions.

Inventive Principle:
Principle #3Local quality

2Productivity

If local RADIUS attribute caching is implemented, then network access availability is improved during server outages, but security control may deteriorate

Engineering Contradiction:
Improvenetwork access availabilityVSAvoidsecurity control reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary authentication by obtaining and caching RADIUS attributes from the RADIUS server during normal operation. This cached data is then used to maintain network access when the server becomes unavailable, ensuring continuous productivity while maintaining security based on previously verified credentials.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback by continuously monitoring the availability of the RADIUS server. When the server becomes available again, the system retrieves updated RADIUS attributes to refresh the local cache, ensuring that security policies are updated and any changes in authentication requirements are propagated to the network controller.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9531700B2Authentication survivability for assigning role and VLAN based on cached radius attributes
Publication Date: 2016.12.27 HEWLETT PACKARD ENTERPRISE DEV LP
  • US9531700B2 patent drawing
  • US9531700B2 patent drawing
  • US9531700B2 patent drawing

AI summary

A system and method is described that allows the assignment of roles and/or VLANs to an authenticated client device even when an external remote authentication dial in user service (RADIUS) server is inaccessible. In particular, using RADIUS key-reply attributes stored locally after a previous successful authentication using the external RADIUS server, an internal RADIUS server may perform authentication and pass the stored RADIUS key-reply attributes to an authentication module for assignment of a role and/or VLAN to the client device. Accordingly, roles and/or VLANs may be assigned to enforce access privileges of the client device even when an external RADIUS server is inaccessible.