System and method for advertising supplicants in a network
Provided are system, method, and device for enabling network entities to view authenticated supplicants in a network. According to embodiments, the system may include: a memory storage storing computer-executable instructions; and at least one processor communicatively coupled to the memory storage, wherein the at least one processor may be configured to execute the instructions to: create a first authentication list for a first network entity; receive a second authentication list from a second network entity; and create a trust list for the first network entity based on the first authentication list and the second authentication list, wherein the trust list for the first network entity specifies a trust level between the first network entity and one or more network entities in the first and second authentication lists.
1 . A system comprising:
at least one memory storage storing computer-executable instructions; and
at least one processor communicatively coupled to the at least one memory storage, wherein the at least one processor is configured to execute the instructions to:
create a first authentication list for a first network entity, wherein the first authentication list specifies one or more network entities that are authenticated with the first network entity;
receive a second authentication list from a second network entity, wherein the second authentication list specifies one or more network entities that are authenticated with the second network entity, and wherein the first network entity and the second network entity are authenticated with each other; and
create a trust list for the first network entity based on the first authentication list and the second authentication list, wherein the trust list for the first network entity specifies a trust level between the first network entity and one or more network entities in the first and second authentication lists,
wherein Zero Trust communication between the first network entity and the one or more network entities in the first and second authentication lists is performed based on trust relationships corresponding to the trust list and based on the first authentication list and the second authentication list, and
wherein the trust list comprises the trust level that is determined and specified in the trust list as either a direct trust or an indirect trust, as well as one or more medium access control (MAC) address of one or more ports of the first network entity and one or more MAC address of one or more ports of the one or more network entities in the first and second authentication lists that has a role of a supplicant.
2 . The system according to claim 1 , wherein:
the trust level is between the one or more ports of the first network entity and the one or more ports of the one or more network entities in the first and second authentication lists that has the role of the supplicant.
3 . The system according to claim 1 , wherein the at least one processor is configured to execute the instructions to create the trust list for the first network entity based on the first authentication list and the second authentication list by:
creating the trust list based on the first authentication list, such that the trust list specifies a first trust level between the first network entity and the one or more network entities in the first authentication list;
in response to receiving the second authentication list, updating the first authentication list to include the second authentication list; and
updating the trust list based on the updated first authentication list, such that the trust list further specifies an updated trust level between the first network entity and the one or more network entities in the second authentication list.
4 . The system according to claim 3 , wherein the at least one processor is further configured to execute the instructions to transmit the updated first authentication list to the one or more network entities that are authenticated with the first network entity.
5 . The system according to claim 1 , wherein:
the second authentication list further specifies one or more network entities that are authenticated with a third network entity; and
the third network entity is authenticated with the second network entity.
6 . The system according to claim 1 , wherein:
the first authentication list specifies one or more first medium access control (MAC) address of one or more ports of the first network entity, one or more third MAC address of one or more ports of one or more network entities authenticated with the one or more first MAC address, and a role of the one or more ports of the first network entity;
the second authentication list specifies one or more second MAC address of one or more ports of the second network entity, one or more fourth MAC address of one or more ports of one or more network entities authenticated with the one or more second MAC address, and a role of the one or more ports of the second network entity; and
the role comprises one of an authenticator and a supplicant.
7 . The system according to claim 1 , wherein an authentication between the first network entity, the second network entity, and the one or more network entities are based on a port-based network access control IEEE 802.1x.
8 . The system according to claim 1 , wherein the first network entity, the second network entity, and the one or more network entities comprise at least one of an Open Radio Access Network (O-RAN) Centralized Unit (O-CU), an O-RAN Distributed Unit (O-DU), an O-RAN Radio Unit (O-RU), and Transport Network elements.
9 . A system comprising:
at least one memory storage storing computer-executable instructions; and
at least one processor communicatively coupled to the at least one memory storage, wherein the at least one processor is configured to execute the instructions to:
receive a first authentication list from a first network entity, wherein the first authentication list specifies one or more network entities that are authenticated with the first network entity;
receive a second authentication list from the second network entity, wherein the second authentication list specifies one or more network entities that are authenticated with the second network entity, and wherein the first network entity and the second network entity are authenticated with each other; and
create a trust list for the first network entity based on the first authentication list and the second authentication list, wherein the trust list for the first network entity specifies a trust level between the first network entity and one or more network entities in the first and second authentication lists,
wherein Zero Trust communication between the first network entity and the one or more network entities in the first and second authentication lists is performed based on trust relationships corresponding to the trust list and based on the first authentication list and the second authentication list, and
wherein the trust list comprises the trust level that is determined and specified in the trust list as either a direct trust or an indirect trust, as well as one or more medium access control (MAC) address of one or more ports of the first network entity and one or more MAC address of one or more ports of the one or more network entities in the first and second authentication lists that has a role of a supplicant.
10 . A method comprising:
creating a first authentication list for a first network entity, wherein the first authentication list specifies one or more network entities that are authenticated with the first network entity;
receiving a second authentication list from a second network entity, wherein the second authentication list specifies one or more network entities that are authenticated with the second network entity, and wherein the first network entity and the second network entity are authenticated with each other; and
creating a trust list for the first network entity based on the first authentication list and the second authentication list, wherein the trust list for the first network entity specifies a trust level between the first network entity and one or more network entities in the first and second authentication lists,
wherein Zero Trust communication between the first network entity and the one or more network entities in the first and second authentication lists is performed based on trust relationships corresponding to the trust list and based on the first authentication list and the second authentication list, and
wherein the trust list comprises the trust level that is determined and specified in the trust list as either a direct trust or an indirect trust, as well as one or more medium access control (MAC) address of one or more ports of the first network entity and one or more MAC address of one or more ports of the one or more network entities in the first and second authentication lists that has a role of a supplicant.
11 . The method according to claim 10 , wherein:
the trust level is between the one or more ports of the first network entity and the one or more ports of the one or more network entities in the first and second authentication lists that has the role of the supplicant.
12 . The method according to claim 10 , wherein the creating the trust list for the first network entity based on the first authentication list and the second authentication list comprises:
creating the trust list based on the first authentication list, such that the trust list specifies a first trust level between the first network entity and the one or more network entities in the first authentication list;
in response to receiving the second authentication list, updating the first authentication list to include the second authentication list; and
updating the trust list based on the updated first authentication list, such that the trust list further specifies an updated trust level between the first network entity and the one or more network entities in the second authentication list.
13 . The method according to claim 12 , further comprising transmitting the updated first authentication list to the one or more network entities that are authenticated with the first network entity.
14 . The method according to claim 10 , wherein:
the second authentication list further specifies one or more network entities that are authenticated with a third network entity; and
the third network entity is authenticated with the second network entity.
15 . The method according to claim 10 , wherein:
the first authentication list specifies one or more first medium access control (MAC) address of one or more ports of the first network entity, one or more third MAC address of one or more ports of one or more network entities authenticated with the one or more first MAC address, and a role of the one or more ports of the first network entity;
the second authentication list specifies one or more second MAC address of one or more ports of the second network entity, one or more fourth MAC address of one or more ports of one or more network entities authenticated with the one or more second MAC address, and a role of the one or more ports of the second network entity; and
the role comprises one of an authenticator and a supplicant.
16 . The method according to claim 10 , wherein an authentication between the first network entity, the second network entity, and the one or more network entities are based on a port-based network access control IEEE 802.1x.
17 . The method according to claim 10 , wherein the first network entity, the second network entity, and the one or more network entities comprise at least one of an Open Radio Access Network (O-RAN) Centralized Unit (O-CU), an O-RAN Distributed Unit (O-DU), an O-RAN Radio Unit (O-RU), and Transport Network elements.
18 . A method comprising:
receiving a first authentication list from a first network entity, wherein the first authentication list specifies one or more network entities that are authenticated with the first network entity;
receiving a second authentication list from the second network entity, wherein the second authentication list specifies one or more network entities that are authenticated with the second network entity, and wherein the first network entity and the second network entity are authenticated with each other; and
creating a trust list for the first network entity based on the first authentication list and the second authentication list, wherein the trust list for the first network entity specifies a trust level between the first network entity and one or more network entities in the first and second authentication lists,
wherein Zero Trust communication between the first network entity and the one or more network entities in the first and second authentication lists is performed based on trust relationships corresponding to the trust list and based on the first authentication list and the second authentication list, and
wherein the trust list comprises the trust level that is determined and specified in the trust list as either a direct trust or an indirect trust, as well as one or more medium access control (MAC) address of one or more ports of the first network entity and one or more MAC address of one or more ports of the one or more network entities in the first and second authentication lists that has a role of a supplicant.