28th Annual IEEE International Conference on Local Computer Networks (LCN'03)
Thinking Outside the Box: Extending 802.1x Authentication to Remote "Splitter" Ports by Combining Physical and Data Link Layer Techniques
Bonn/K?nigswinter, Germany
October 20-October 24
ISBN: 0-7695-2037-5
We present a novel switched full-duplex LAN architecture which can greatly simplify the cabling requirements in areas that must support high port densities and/or are subject to frequent changes. Instead of providing a separate cable to connect each host to a dedicated port on a monolithic switch behind the wall, we emulate the shared bus topology from the early days of Ethernet by daisy-chaining a series of small network-powered "slave" bridge modules called Ethernet Splitters from a single port on the "master" switch. Our partitioned switch architecture enforces network privacy throughout the entire splitter chain, so no host can view any traffic belonging to another host. The splitters also authenticate the point of origin for every frame, independent of the value contained in its source address field thus providing the same level of security as a monolithic switch under the 802.1x Port Based Access Control protocol.
Citation:
Arun Saha, Mart Molle, "Thinking Outside the Box: Extending 802.1x Authentication to Remote "Splitter" Ports by Combining Physical and Data Link Layer Techniques," lcn, pp.324, 28th Annual IEEE International Conference on Local Computer Networks (LCN'03), 2003