Browse > Article

Performance of an Authentication Proxy for Port Based Security Systems  

이동현 ((주)이오넥스)
이현우 (한국전자통신연구원 네트워크연구소)
정해원 (한국전자통신연구원 네트워크연구소)
윤종호 (한국항공대학교 전자·정보통신·컴퓨터공학부)
Abstract
In this paper, we present an efficient authentication proxy for IEEE 802.1x systems based on the port-based access control mechanism. An IEEE 802.1x system consists of PC supplicants, a bridge with authentication client functions, and an authentication server. For the network security and user authentication purposes, a supplicant who wants to access Internet should be authorized to access the bridge port using the Extended Authentication Protocol (EAP) over LAN. The frame of EAP over LAN is then relayed to the authentication server by the bridge. After several transactions between the supplicant and the server via the bridge, the supplicant may be either authorized or not. Noting that the transactions between the relaying bridge and the server will be increased as the number of supplicants grows in public networks, we propose a scheme for reducing the transactions by employing an authentication proxy function at the bridge. The proxy is allowed to cache the supplicant's user ID and password during his first transaction with the server. For the next authentication procedure of the same supplicant, the proxy function of the bridge handles the authentication transactions using its cache on behalf of the authentication server. Since the main authentication server handles only the first authentication transaction of each supplicant, the processing load of the server can be reduced. Also, the authentication transaction delay experienced by a supplicant can be decreased compared with the conventional 802.1x system.
Keywords
Citations & Related Records
연도 인용수 순위
  • Reference
1 /
[ W.Stallings ] / Crytography and Network Security
2 PPP Extensible Authentication Protocol /
[ Blink;Vollbrecht ] / RFC 2284
3 RADIUS extension /
[ C.Rigney;W.Willats ] / RFC 2869
4 Remoto Authentication Dial In User Service(RADIUS) /
[ C.Rigney(et al.) ] / RFC 2058
5 /
[] / SIMULA web site
6 PPP EAP Authentication Protocol /
[ B.Aboba;D.Simon ] / RFC 2716
7 Standards for Local and Metropolitan Area Network, Standard for port based Network Acess Control /
[] / IEEE Std 802.1x