Smart Access Point Network Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network access control systems face scalability issues and single-point failures, particularly in central in-band systems, which lead to latency and require significant capital expenditures, while out-of-band systems do not provide seamless connectivity for roaming users due to the need for repeated authentication and policy enforcement at each switch.

Innovation Solution

The implementation of a smart access point (AP) system that performs policy enforcement and user authentication, allowing seamless mobility by sharing session information and authentication status across multiple access points, thereby eliminating the need for re-authentication and reducing latency through centralized management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a central in-band NAC system is used to manage user authentication and network policy enforcement, then seamless connectivity for roaming users is achieved, but latency increases and scalability is limited due to all data traffic passing through the dedicated device

Engineering Contradiction:
Improveseamless connectivityVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the centralized NAC function into distributed access points that autonomently perform authentication and policy enforcement locally. Each access point operates as an independent decision-making unit, eliminating the need for all traffic to pass through a central device, thus reducing latency while maintaining seamless roaming capability through shared authentication state.

Inventive Principle:
Principle #1Segmentation

2Reliability

If a central in-band NAC system is used to manage user authentication and network policy enforcement, then seamless connectivity is provided, but capital expenditure increases due to the need to add more dedicated devices to support large numbers of users

Engineering Contradiction:
Improveseamless connectivityVSAvoidcapital expenditure
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system divides the NAC functionality across multiple access points rather than requiring a single centralized device. This segmentation allows the network to scale horizontally by adding access points only where needed, reducing the total hardware cost compared to deploying multiple dedicated central NAC devices to support large user bases.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The access points perform multiple functions including authentication, authorization, accounting, and policy enforcement locally, eliminating the need for separate dedicated NAC devices. This multi-functionality reduces the overall hardware footprint and capital expenditure while maintaining seamless connectivity capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Extent of automation

If a central in-band NAC system is used, then user authentication and network policy enforcement are centralized, but the system becomes a single point of failure requiring significant capital expenditure for redundancy

Engineering Contradiction:
Improvecentralized managementVSAvoidsingle point of failure
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The patent segments the centralized NAC function into distributed access points that autonomently perform authentication and policy enforcement locally. Each access point operates as an independent decision-making unit, eliminating the need for all traffic to pass through a central device, thus reducing latency while maintaining seamless roaming capability through shared authentication state.

Inventive Principle:
Principle #1Segmentation

4Quantity of substance

If an out-of-band NAC system is used to avoid single point of failure, then scalability is improved, but seamless connectivity for roaming users is lost due to repeated authentication at each switch

Engineering Contradiction:
ImprovescalabilityVSAvoidauthentication time
Core Design Contradiction:
Quantity of substanceVSLoss of time

Solution Approach 1:

The patent merges the authentication state across multiple access points by having them share authentication information. When a user roams between access points, the new access point queries the shared authentication state and allows immediate access without re-authentication, combining the scalability of distributed systems with the seamless connectivity of centralized systems.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

Access points continuously share authentication state information through feedback mechanisms. When a user connects to a new access point, the system uses feedback about the user's authentication status from previous access points to enable seamless roaming without repeated authentication, thus maintaining both scalability and connectivity.

Inventive Principle:
Principle #23Feedback

5Reliability

If an out-of-band NAC system is used, then system redundancy is achieved, but network performance decreases due to repeated authentication and policy enforcement at each switch during roaming

Engineering Contradiction:
Improvesystem redundancyVSAvoidnetwork performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges the authentication state across multiple access points by having them share authentication information. When a user roams between access points, the new access point queries the shared authentication state and allows immediate access without re-authentication, combining the scalability of distributed systems with the seamless connectivity of centralized systems.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8763075B2Method and apparatus for network access control
Publication Date: 2014.06.24 ADTRAN INC
  • US8763075B2 patent drawing
  • US8763075B2 patent drawing
  • US8763075B2 patent drawing

AI summary

A method and apparatus for network access control includes an apparatus for granting a computing device access to a network, the apparatus having a plurality of substantially similar access devices, wherein each access device comprises a status-determination module to determine an access status based at least in part on whether the computing device is compliant with an access policy, an access-grant module configured for receiving an access status corresponding to the computing device from one or more of the access devices, and granting the computing device access to the network according to at least one of the access status determined by the status-determination module or the received access status.