802.1X Authentication for Shared Media Ports
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional port-based security methods, such as IEEE 802.1X authentication, fail to scale effectively for shared media ports, allowing unauthorized users to access trusted subnetworks when multiple client nodes are connected, compromising network security.
Innovation Solution
Implementing a technique that partitions the shared media port into logical subinterfaces with a MAC filter to authenticate each client node individually, using a MAC filter to determine access permissions and dynamically create entries based on client-node MAC addresses and authentication states, ensuring secure access to trusted subnetworks while allowing unauthenticated users to access untrusted subnetworks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional port-based security methods (IEEE 802.1X authentication) are used for shared media ports, then authentication can be implemented for client nodes, but unauthorized users can still access trusted subnetworks when multiple client nodes are connected, compromising network security
Solution Approach 1:
The patent divides the shared media port into multiple virtual subinterfaces, each associated with a specific client node's MAC address. This segmentation allows the port to handle multiple client nodes independently, applying authentication and security policies per subinterface rather than allowing all nodes to access all subnetworks once any single node is authenticated.
2Ease of operation
If the shared media port is opened after initial authentication, then authenticated users can access the network, but unauthorized users connected to the same port can also access trusted subnetworks
Solution Approach 1:
The patent applies different access permissions and security characteristics to different virtual subinterfaces created within the shared media port. Each subinterface is configured with specific quality attributes (authentication state, allowed subnetworks) tailored to its associated client node, ensuring that unauthorized users cannot access trusted subnetworks even when the port is opened for authenticated users.
3Reliability
If port-based authentication is implemented for each client node individually on a shared media port, then network security is maintained, but the complexity of managing multiple authentication states increases
Solution Approach 1:
The patent creates virtual subinterfaces that can be dynamically instantiated for each client node on the shared media port. These subinterfaces serve multiple functions: they track individual authentication states, enforce per-node security policies, and manage access to different subnetworks. This universal approach simplifies authentication management by providing a standardized mechanism that handles both authenticated and unauthenticated nodes uniformly.
Data Source
AI summary
The present invention provides a technique for securely implementing port-based authentication on a shared media port in an intermediate node, such as a router. To that end, the invention provides enhanced port-based network access control that includes client-based control at the shared media port. Unlike previous implementations, the port does not permit multiple client nodes to access a trusted subnetwork as soon as a user at any one of those nodes is authenticated by the subnetwork. Instead, port-based authentication is performed for every client node that attempts to access the trusted subnetwork through the shared media port. As such, access to the trusted subnetwork is not compromised by unauthenticated client nodes that “piggy-back” over the shared media port after a user at another client node has been authenticated by the trusted subnetwork.


