VLAN Transition via Change of Authorization Message
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for transitioning a supplicant from one VLAN to another in a network interrupt network communications, particularly problematic in VOIP deployments where uninterrupted traffic is critical, as they require reauthentication and cause traffic disruptions.
Innovation Solution
The use of a Change of Authorization (COA) message to update the forwarding table of network devices, allowing a supplicant to be moved from one VLAN to another without reauthentication or port flapping, by associating the supplicant's MAC address with a new VLAN ID, ensuring continuous network access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If reauthentication is performed to change VLAN assignment, then VLAN transition is achieved, but network communications are interrupted
Solution Approach 1:
The system performs preliminary actions by establishing a secondary path through a different VLAN before disrupting the primary communication path. The authenticator proactively sets up alternative routing for the supplicant's traffic, ensuring that when VLAN reassignment occurs, communication continuity is maintained through the pre-established secondary path.
Solution Approach 2:
The patent introduces an intermediary mechanism where the authenticator acts as a mediator between the supplicant and the authentication server. The authenticator receives COA messages, processes VLAN reassignment locally, and manages the transition without requiring the supplicant to reauthenticate, thereby maintaining communication continuity while achieving VLAN transition.
2Adaptability or versatility
If reauthentication is performed to change VLAN assignment, then VLAN transition is achieved, but traffic disruptions occur
Solution Approach 1:
The system ensures continuity of useful action by maintaining active communication paths during VLAN transition. The authenticator processes COA messages and reassigns VLANs without interrupting the supplicant's traffic flow, allowing productive work to continue uninterrupted while the background reassignment occurs.
Solution Approach 2:
The authenticator performs preliminary routing setup before the actual VLAN change takes effect, ensuring that traffic can be seamlessly redirected to the new VLAN without disruption to ongoing communications or productivity-critical applications.
3Adaptability or versatility
If port flapping is used to transition VLAN, then VLAN change is achieved, but communication interruptions occur
Solution Approach 1:
The authenticator serves as an intermediary that handles VLAN reassignment through COA message processing rather than port flapping. This intermediary mechanism allows the supplicant to remain authenticated and connected while the authenticator silently performs the VLAN reassignment in the background, eliminating communication downtime.
Solution Approach 2:
The patent replaces the mechanical port flapping method with a software-based COA message processing mechanism. Instead of physically disrupting the connection through port flapping, the system uses authenticated communication channels to transmit reassignment commands, substituting a disruptive mechanical approach with a non-disruptive software-based approach.
Data Source
AI summary
Systems and methods are provided herein for transitioning a supplicant from one virtual local area network (VLAN) to another using a change of authorization (COA) message. This may be accomplished by an authentication server notifying a network device that a host should be granted access to the network, wherein the authentication server authenticates the host using MAC based authentication. Based on this notification and the MAC address of the host, the network device assigns the host to a first VLAN. If the authentication server determines that the host needs to change from the first VLAN to a second VLAN the authentication server generates a COA message, associated with the host, wherein the COA message comprises a VLAN identifier related to the second VLAN. The authentication server transmits the COA message to the network device causing the network device to route traffic to and from the host using the second VLAN.


