发明名称 Authentication survivability for assigning role and VLAN based on cached radius attributes
摘要 A system and method is described that allows the assignment of roles and/or VLANs to an authenticated client device even when an external remote authentication dial in user service (RADIUS) server is inaccessible. In particular, using RADIUS key-reply attributes stored locally after a previous successful authentication using the external RADIUS server, an internal RADIUS server may perform authentication and pass the stored RADIUS key-reply attributes to an authentication module for assignment of a role and/or VLAN to the client device. Accordingly, roles and/or VLANs may be assigned to enforce access privileges of the client device even when an external RADIUS server is inaccessible.
申请公布号 US9531700(B2) 申请公布日期 2016.12.27
申请号 US201514610033 申请日期 2015.01.30
申请人 Aruba Networks, Inc. 发明人 Yuan Liang-Chih;Limaye Vikram;Nasikkar Ashutosh
分类号 G06F21/30;H04L29/06 主分类号 G06F21/30
代理机构 Hewlett Packard Enterprise Patent Department 代理人 Hewlett Packard Enterprise Patent Department
主权项 1. A method for authenticating a client device in a network system, comprising: receiving, by an authentication module implemented by one or more hardware processors of a network controller within a local network of the network system, an authentication success message from an external remote authentication dial in user service (RADIUS) server located external to the local network; storing RADIUS attributes from the authentication success message when the authentication success message includes RADIUS attributes for the client device and; determining, at a later time by the network controller, whether the external RADIUS server, is accessible; and in response to determining that the external RADIUS server is inaccessible, an internal RADIUS server of the network controller: attempting to authenticate the client device within the local network based on credentials of the client device, andin response to successfully authenticating the client device, attempting to locate the RADIUS attributes stored locally within the local network; and in response to locating the locally stored RADIUS attributes, the authentication module assigning a role or virtual local area network (VLAN) to the client device based on the locally stored RADIUS attributes, in response to the authentication success message failing to include RADIUS attributes, assigning, by the authentication module, a default role or a default VLAN to the client device.
地址 Sunnyvale CA US