Switch Authentication Domain Change IP Address Renewal
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In network admission control systems, clients cannot automatically obtain new IP addresses when the authentication domain changes, leading to connectivity issues and high operational costs due to the need for manual intervention and limited scalability.
Innovation Solution
A method and apparatus that periodically send authentication request messages to clients, receive response messages, and send authentication domain change messages to clients when the authentication domain changes, allowing them to automatically obtain new IP addresses without manual intervention, even when other devices are connected between the client and the switch.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the switch disables and re-enables ports to force clients to obtain new IP addresses when authentication domain changes, then clients can obtain new IP addresses, but network connectivity for other clients is affected and operational complexity increases
Solution Approach 1:
The patent extracts the port disable/enable operation from the global switch control and applies it only to the specific port where authentication domain change occurs. This is achieved by sending port disable/enable messages only to the affected port's client through the authentication domain change message mechanism, rather than disabling all switch ports.
Solution Approach 2:
The patent introduces an intermediary message mechanism (authentication domain change message) that carries both the authentication domain information and the port control instructions. This message acts as a mediator between the switch and the client, enabling the client to understand and execute port state changes without manual intervention.
2Reliability
If manual intervention is required to release and reapply for IP addresses when authentication domain changes, then IP address updates can be obtained, but operational costs increase and scalability decreases
Solution Approach 1:
The patent enables clients to automatically obtain new IP addresses through self-service. When the switch detects an authentication domain change, it sends an authentication domain change message to the client, which triggers the client to automatically release the old IP address and obtain a new one from the DHCP server, eliminating the need for manual user intervention.
Solution Approach 2:
The patent implements a feedback mechanism where the switch monitors authentication domain changes and automatically triggers IP address renewal processes. The switch receives authentication information, detects domain changes, and sends corresponding control messages to clients, creating a closed-loop feedback system that automatically maintains IP address validity.
3Reliability
If switch ports are disabled to force IP address renewal, then clients can obtain new IP addresses, but network connectivity is interrupted during the process
Solution Approach 1:
The patent implements periodic authentication request messages sent by the switch to clients. Instead of continuously monitoring and immediately reacting to every authentication domain change, the system uses periodic checks to detect changes and trigger IP address renewal only when necessary, reducing unnecessary port disable/enable operations and minimizing connectivity interruptions.
4Extent of automation
If the client is directly connected to the switch, then the client can perceive port state changes and obtain new IP addresses automatically, but the solution does not work when other devices are connected between the client and switch
Solution Approach 1:
The patent creates a universal message mechanism (authentication domain change message) that can be transmitted through various network topologies. The message can be forwarded by intermediate devices such as routers or gateways, enabling the automatic IP address renewal function to work not only in direct switch-client connections but also in complex network topologies with multiple intermediate devices.
Data Source
AI summary
A switch sends an authentication request message to a client at intervals of a preset duration. A response message sent by the client is received. The response message carries authentication information of a user carried on the client. An authentication message is sent to a server according to the response message. An authentication reply message sent by the server is received. The authentication reply message carries information about an authentication domain authorized by the server to the user. It is determined, according to the authentication reply message, whether the authentication domain of the user is changed. If the authentication domain of the user is changed, an authentication domain change message is sent to the client according to the authentication reply message, so that the client obtains an IP address again.


