Switch Port Access Control Using Device Attribute Policies
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional switch port security systems are inefficient and prone to errors due to the need for extensive lists of MAC addresses for device authorization, which is impractical and time-consuming, especially in dynamic and large-scale networks, and do not effectively restrict access to specific types or brands of devices.
Innovation Solution
A method and system that compares device attributes with access policies to control switch port access, allowing or denying access based on policy matches, using a network device to receive authentication requests, compare device attributes, and transmit authorization instructions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If MAC address lists are used to control switch port access, then network security is improved, but system complexity and maintenance burden increase significantly
Solution Approach 1:
The patent introduces an intermediary system that acts as a bridge between the switch port and end devices. This intermediary automatically manages access control by intercepting authentication requests, comparing device attributes against stored policies, and dynamically generating authorization instructions. This eliminates the need for administrators to manually maintain complex MAC address lists, as the intermediary automatically handles the matching and authorization process based on device characteristics.
Solution Approach 2:
The system enables self-service automation where the access control mechanism automatically performs authentication and authorization without human intervention. When an end device connects to a switch port, the system autonomously retrieves device attributes, compares them with stored access policies, and determines authorization status. This self-service capability eliminates manual configuration and maintenance of access control lists, reducing administrative burden while maintaining security.
2Reliability
If MAC address lists are maintained for all devices, then access control is achieved, but time consumption and operational efficiency deteriorate
Solution Approach 1:
The patent implements preliminary action by pre-storing access policies and device attribute criteria in the system before actual authentication occurs. The system maintains a database of authorized device types, brands, and characteristics along with their corresponding access policies. When a device connects, the system performs rapid matching against these pre-configured policies, eliminating the need for real-time manual verification or dynamic list updates during authentication events.
Solution Approach 2:
The automated authentication system performs self-service by independently completing the entire access control process without administrator intervention. The system automatically captures device attributes upon connection, retrieves relevant access policies, performs comparison operations, and generates authorization decisions. This automated workflow eliminates manual time consumption associated with maintaining and updating MAC address lists, allowing the system to scale efficiently with increasing device counts.
3Reliability
If conventional port security systems are used, then basic access control is provided, but adaptability to different device types and brands is reduced
Solution Approach 1:
The patent applies parameter changes by transitioning from fixed MAC address-based control to flexible attribute-based control. Instead of relying on static MAC address lists, the system evaluates multiple device parameters including device type, brand, model, and other characteristics. Access policies are defined in terms of these parameters, allowing the system to adapt to various device types and brands by matching their attributes against stored policy criteria. This parameter-based approach enables granular control over different device categories while maintaining comprehensive access security.
Data Source
AI summary
A method, device, and system for controlling access to switch ports in communication networks is disclosed. The method may include receiving an authentication request associated with an end-device requesting access to a switch port of a switch within a communication network; comparing at least one device attribute associated with the end-device with an access policy associated with an access policy associated with the switch port; transmitting an authentication instruction associated with the end-device and the switch port to the switch based on a result of comparing. The authentication instruction comprises one of allowing the end-device access to the switch port based on the access policy and denying the end-device access to the switch port based on the access policy.


