Relay Node Network Access Control Separation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network access control systems face scalability issues and high costs due to the need for robust access controllers at each sub-network, which also slow down network performance by managing both control and data paths, leading to increased hardware requirements and limited scalability.
Innovation Solution
Implementing an intermediate relay node that separates control and data paths, allowing the access controller to manage only the control path and reducing the burden on hardware by distributing authentication across multiple relay nodes, thereby reducing the need for multiple access controllers and enhancing network scalability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a robust access controller is deployed at each sub-network to manage both control and data paths, then network security and access control reliability are improved, but hardware costs and device complexity increase significantly
Solution Approach 1:
The patent segments the network access control system into multiple components: access controllers at sub-network level, a central authentication server, and relay nodes. Each component has specialized functions, allowing the system to maintain reliability through distributed architecture while reducing the complexity burden on individual devices.
Solution Approach 2:
The patent introduces relay nodes as intermediary components that handle data path forwarding while access controllers focus on control path management. This intermediary layer separates the control and data planes, allowing access controllers to maintain security functions without bearing the full burden of high-speed data forwarding, thus reducing hardware requirements.
2Reliability
If an access controller manages both control path and data path traffic, then comprehensive network access control is achieved, but network performance deteriorates due to the single point of failure and high computing load
Solution Approach 1:
The patent divides the network traffic management into separate control path and data path channels. The control path handles authentication and authorization signals, while the data path handles user traffic. This segmentation allows parallel processing of control and data traffic, improving overall network performance while maintaining comprehensive access control.
Solution Approach 2:
Relay nodes serve as intermediaries that receive authenticated traffic from access controllers and forward it along the data path without requiring continuous access controller intervention. This intermediary mechanism eliminates the access controller as a bottleneck, improving network throughput while maintaining security through the control path.
3Reliability
If dedicated access controllers are deployed at each sub-network to maintain control, then access control functionality is ensured, but scalability is limited due to increasing hardware requirements and costs
Solution Approach 1:
The patent creates a universal architecture where relay nodes can serve multiple sub-networks and access controllers. The central authentication server provides unified authentication services across the entire network. This multi-functional design allows the system to scale by adding new sub-networks and relay nodes without requiring proportionally increased access controller resources at each location.
Solution Approach 2:
The patent transitions from a flat architecture where each sub-network requires a full-featured access controller to a hierarchical architecture with multiple layers: sub-network level relay nodes, regional access controllers, and a central authentication server. This dimensional change in system organization allows scalable expansion by adding nodes at any level without linearly increasing overall system complexity and cost.
Data Source
AI summary
A computer system for authenticating and managing network traffic may comprise a network link providing a connection to a network, an authentication, authorization, and accounting (AAA) server configured to provide AAA management for the network link, an access controller configured to communicate with the AAA server and to control access to the network link, and a subnetwork of client devices connected to an intermediate relay node. The client devices may be configured to communicate with the access controller and the network link through the intermediate relay node. Also methods and processes by which an intermediate relay node and an access controller may operate in the network for authentication of client devices and routing of network traffic.


