Switch Port VLAN Assignment for Unauthorized Client Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network access security systems, such as those using IEEE 802.1X, often deny access to new clients lacking IEEE 802.1X supplicant software, even if they are authorized, as they cannot initiate an authentication session, leading to undesirable access denial for properly registered devices with older operating systems.

Innovation Solution

A method and apparatus that temporarily assign a switch port to an unauthorized-client VLAN, providing initialization services and allowing access for new clients to download necessary software and authenticate, then switching to authorized VLAN access upon successful authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IEEE 802.1X port access control is implemented to secure network access, then network security is improved, but clients without IEEE 802.1X supplicant software are denied access even if they are authorized

Engineering Contradiction:
Improvenetwork securityVSAvoidaccess compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an intermediary mechanism (captive portal or authentication redirect) that mediates between clients without supplicant software and the IEEE 802.1X authentication system. When a client without supplicant software connects, the system intercepts their traffic and redirects it to a web-based authentication interface, allowing them to authenticate through a browser instead of requiring native supplicant software. This resolves the contradiction by maintaining security through IEEE 802.1X while enabling access compatibility for clients without the required software.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If strict IEEE 802.1X authentication is enforced to prevent unauthorized access, then network security is improved, but legitimate clients with older operating systems cannot access network resources

Engineering Contradiction:
Improveaccess control securityVSAvoidclient access ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies parameter changes by dynamically adjusting authentication requirements based on client capabilities. The system detects whether a client has IEEE 802.1X supplicant software and automatically switches between authentication modes: enforcing strict IEEE 802.1X authentication for compliant clients while providing alternative web-based authentication for non-compliant clients. This resolves the contradiction by maintaining security through parameter-based authentication policy adaptation rather than rigid enforcement.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If all clients are required to have IEEE 802.1X supplicant software for authentication, then authentication security is improved, but device compatibility and ease of deployment are reduced

Engineering Contradiction:
Improveauthentication securityVSAvoidclient software requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent inverts the traditional authentication approach by making web-based authentication the default for clients without supplicant software, rather than requiring supplicant software as the primary method. Instead of forcing all clients to install and configure IEEE 802.1X supplicant software, the system allows them to authenticate through standard web browsers using cached credentials or simple web forms. This resolves the contradiction by maintaining authentication security while dramatically reducing device complexity and software requirements.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS8826385B2Method and apparatus for access security services
Publication Date: 2014.09.02 HEWLETT PACKARD ENTERPRISE DEV LP
  • US8826385B2 patent drawing
  • US8826385B2 patent drawing
  • US8826385B2 patent drawing

AI summary

One embodiment disclosed relates to a method for a switch to respond to a new client. A new client is detected at a port of the switch. The switch temporarily assigns the port to be an untagged member of a virtual local area network (VLAN) which is configured for unauthorized clients. Initialization services are provided to the new client via the unauthorized-client VLAN. The new client may be authenticated by way of an authentication session using the unauthorized-client VLAN. If the new client is authenticated, then the untagged membership of the port in the unauthorized-client VLAN is dropped, and the port is assigned to be an untagged member of a specified VLAN.