802.1X Authentication for Shared Media Ports

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional port-based security methods, such as IEEE 802.1X authentication, fail to scale effectively for shared media ports, allowing unauthorized users to access trusted subnetworks when multiple client nodes are connected, compromising network security.

Innovation Solution

Implementing a technique that partitions the shared media port into logical subinterfaces with a MAC filter to authenticate each client node individually, using a MAC filter to determine access permissions and dynamically create entries based on client-node MAC addresses and authentication states, ensuring secure access to trusted subnetworks while allowing unauthenticated users to access untrusted subnetworks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional port-based security methods (IEEE 802.1X authentication) are used for shared media ports, then authentication can be implemented for client nodes, but unauthorized users can still access trusted subnetworks when multiple client nodes are connected, compromising network security

Engineering Contradiction:
Improvenetwork securityVSAvoidsupport for multiple client nodes
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent divides the shared media port into multiple virtual subinterfaces, each associated with a specific client node's MAC address. This segmentation allows the port to handle multiple client nodes independently, applying authentication and security policies per subinterface rather than allowing all nodes to access all subnetworks once any single node is authenticated.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If the shared media port is opened after initial authentication, then authenticated users can access the network, but unauthorized users connected to the same port can also access trusted subnetworks

Engineering Contradiction:
Improveauthentication processVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies different access permissions and security characteristics to different virtual subinterfaces created within the shared media port. Each subinterface is configured with specific quality attributes (authentication state, allowed subnetworks) tailored to its associated client node, ensuring that unauthorized users cannot access trusted subnetworks even when the port is opened for authenticated users.

Inventive Principle:
Principle #3Local quality

3Reliability

If port-based authentication is implemented for each client node individually on a shared media port, then network security is maintained, but the complexity of managing multiple authentication states increases

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates virtual subinterfaces that can be dynamically instantiated for each client node on the shared media port. These subinterfaces serve multiple functions: they track individual authentication states, enforce per-node security policies, and manage access to different subnetworks. This universal approach simplifies authentication management by providing a standardized mechanism that handles both authenticated and unauthenticated nodes uniformly.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7624431B2802.1X authentication technique for shared media
Publication Date: 2009.11.24 CISCO TECHNOLOGY INC
  • US7624431B2 patent drawing
  • US7624431B2 patent drawing
  • US7624431B2 patent drawing

AI summary

The present invention provides a technique for securely implementing port-based authentication on a shared media port in an intermediate node, such as a router. To that end, the invention provides enhanced port-based network access control that includes client-based control at the shared media port. Unlike previous implementations, the port does not permit multiple client nodes to access a trusted subnetwork as soon as a user at any one of those nodes is authenticated by the subnetwork. Instead, port-based authentication is performed for every client node that attempts to access the trusted subnetwork through the shared media port. As such, access to the trusted subnetwork is not compromised by unauthenticated client nodes that “piggy-back” over the shared media port after a user at another client node has been authenticated by the trusted subnetwork.