Switch Port Authenticator Dynamic Authentication Protocol

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network switches require IEEE 802.1X authentication support from clients to access resources, excluding clients that do not support this protocol, thereby limiting access to network resources.

Innovation Solution

Implementing a system that enables dynamic authentication using different protocols on the same port, allowing clients without 802.1X support to access resources by monitoring for authentication messages and switching to non-802.1X authentication mechanisms, such as name/passwords or digital certificates, if 802.1X authentication fails, and routing their traffic through a network device for quarantine and filtering.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IEEE 802.1X authentication is required for all clients, then security control is improved, but access availability deteriorates for clients without 802.1X support

Engineering Contradiction:
Improvesecurity controlVSAvoidaccess availability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically switches between 802.1X authentication mode and alternative authentication modes based on client capability detection. When a client does not support 802.1X, the system transitions to using alternative authentication mechanisms (such as MAC address filtering, VLAN-based authentication, or web-based authentication) to maintain both security and access availability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The switch port authenticator is designed to perform multiple authentication functions: it can handle 802.1X authentication for compliant clients, and simultaneously support alternative authentication methods for non-compliant clients. This multi-functionality ensures that all client types can access network resources while maintaining security control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Stability of the object's composition

If 802.1X authentication is enforced on all ports, then authentication consistency is improved, but device compatibility deteriorates

Engineering Contradiction:
Improveauthentication consistencyVSAvoiddevice compatibility
Core Design Contradiction:
Stability of the object's compositionVSAdaptability or versatility

Solution Approach 1:

The authentication approach is adapted locally based on the specific client device's capabilities. Each client connection is evaluated individually to determine the appropriate authentication method, allowing 802.1X authentication for compliant devices while using alternative methods for non-compliant devices, thus maintaining both consistency and compatibility.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts the authentication mechanism based on real-time client capability detection. When a client connects, the switch detects whether the client supports 802.1X and automatically selects the appropriate authentication method, ensuring compatibility across different device types while maintaining authentication consistency.

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If alternative authentication methods are added to support non-802.1X clients, then access availability is improved, but system complexity increases

Engineering Contradiction:
Improveaccess availabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

Multiple authentication methods are merged into a single unified authentication framework within the switch port authenticator. The system combines 802.1X authentication logic with alternative authentication mechanisms (such as MAC address filtering, VLAN-based authentication, or web-based authentication) so that they operate together through a common control plane, reducing the complexity that would otherwise arise from separate independent systems.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8522318B2Enabling dynamic authentication with different protocols on the same port for a switch
Publication Date: 2013.08.27 MCAFEE LLC
  • US8522318B2 patent drawing
  • US8522318B2 patent drawing
  • US8522318B2 patent drawing

AI summary

The invention enables a client device that does not support IEEE 802.1X authentication to access at least some resources provided through a switch that supports 802.1X authentication by using dynamic authentication with different protocols. When the client device attempts to join a network, the switch monitors for an 802.1X authentication message from the client device. In one embodiment, if the client fails to send an 802.1X authentication message, respond to an 802.1X request from the switch, or a predefined failure condition is detected the client may be deemed incapable of supporting 802.1X authentication. In one embodiment, the client may be initially placed on a quarantine VLAN after determination that the client fails to perform an 802.1X authentication within a backoff time limit. However, the client may still gain access to resources based on various non-802.1X authentication mechanisms, including name/passwords, digital certificates, or the like.