Switch Authentication Domain Change IP Address Renewal

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In network admission control systems, clients cannot automatically obtain new IP addresses when the authentication domain changes, leading to connectivity issues and high operational costs due to the need for manual intervention and limited scalability.

Innovation Solution

A method and apparatus that periodically send authentication request messages to clients, receive response messages, and send authentication domain change messages to clients when the authentication domain changes, allowing them to automatically obtain new IP addresses without manual intervention, even when other devices are connected between the client and the switch.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the switch disables and re-enables ports to force clients to obtain new IP addresses when authentication domain changes, then clients can obtain new IP addresses, but network connectivity for other clients is affected and operational complexity increases

Engineering Contradiction:
ImproveIP address update reliabilityVSAvoidnetwork operation complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts the port disable/enable operation from the global switch control and applies it only to the specific port where authentication domain change occurs. This is achieved by sending port disable/enable messages only to the affected port's client through the authentication domain change message mechanism, rather than disabling all switch ports.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary message mechanism (authentication domain change message) that carries both the authentication domain information and the port control instructions. This message acts as a mediator between the switch and the client, enabling the client to understand and execute port state changes without manual intervention.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual intervention is required to release and reapply for IP addresses when authentication domain changes, then IP address updates can be obtained, but operational costs increase and scalability decreases

Engineering Contradiction:
ImproveIP address update reliabilityVSAvoidsystem scalability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent enables clients to automatically obtain new IP addresses through self-service. When the switch detects an authentication domain change, it sends an authentication domain change message to the client, which triggers the client to automatically release the old IP address and obtain a new one from the DHCP server, eliminating the need for manual user intervention.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements a feedback mechanism where the switch monitors authentication domain changes and automatically triggers IP address renewal processes. The switch receives authentication information, detects domain changes, and sends corresponding control messages to clients, creating a closed-loop feedback system that automatically maintains IP address validity.

Inventive Principle:
Principle #23Feedback

3Reliability

If switch ports are disabled to force IP address renewal, then clients can obtain new IP addresses, but network connectivity is interrupted during the process

Engineering Contradiction:
ImproveIP address update reliabilityVSAvoidnetwork connectivity interruption time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements periodic authentication request messages sent by the switch to clients. Instead of continuously monitoring and immediately reacting to every authentication domain change, the system uses periodic checks to detect changes and trigger IP address renewal only when necessary, reducing unnecessary port disable/enable operations and minimizing connectivity interruptions.

Inventive Principle:
Principle #19Periodic action

4Extent of automation

If the client is directly connected to the switch, then the client can perceive port state changes and obtain new IP addresses automatically, but the solution does not work when other devices are connected between the client and switch

Engineering Contradiction:
Improveautomatic IP address renewalVSAvoidnetwork topology adaptability
Core Design Contradiction:
Extent of automationVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal message mechanism (authentication domain change message) that can be transmitted through various network topologies. The message can be forwarded by intermediate devices such as routers or gateways, enabling the automatic IP address renewal function to work not only in direct switch-client connections but also in complex network topologies with multiple intermediate devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20140130125A1Method and apparatus for allocating and obtaining IP address
Publication Date: 2014.05.08 HUAWEI TECH CO LTD
  • US20140130125A1 patent drawing
  • US20140130125A1 patent drawing
  • US20140130125A1 patent drawing

AI summary

A switch sends an authentication request message to a client at intervals of a preset duration. A response message sent by the client is received. The response message carries authentication information of a user carried on the client. An authentication message is sent to a server according to the response message. An authentication reply message sent by the server is received. The authentication reply message carries information about an authentication domain authorized by the server to the user. It is determined, according to the authentication reply message, whether the authentication domain of the user is changed. If the authentication domain of the user is changed, an authentication domain change message is sent to the client according to the authentication reply message, so that the client obtains an IP address again.