Wireless Access Point Group Isolation via Single SSID

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless networks lack the ability to efficiently isolate groups of client devices regarding permissions, leading to potential security and privacy issues within the network.

Innovation Solution

Implementing a system that uses a controller and access points (APs) to manage wireless networks by aggregating client devices into isolation groups, assigning specific permission sets, and routing communications through a single Service Set Identification (SSID) and Virtual Local Area Network (VLAN), allowing communication within groups while isolating them from other devices on the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If wireless networks allow all client devices to communicate freely, then network simplicity and ease of operation are improved, but security and privacy are worsened due to inability to isolate groups

Engineering Contradiction:
Improvenetwork simplicityVSAvoidsecurity and privacy
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the wireless network into multiple isolation groups, where each group can communicate freely within itself but is isolated from other groups. This is achieved by assigning different isolation group identifiers to different sets of client devices, allowing the network to maintain simplicity while providing security through logical segmentation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The access point acts as an intermediary that controls communication between client devices. It receives data packets from transmitting devices, determines the isolation groups of both transmitting and receiving devices, and selectively forwards or blocks packets based on group membership, thereby enabling security without complicating the network architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If wireless networks implement group isolation to improve security, then security and privacy are improved, but device complexity and network management complexity increase

Engineering Contradiction:
Improvesecurity and privacyVSAvoidnetwork management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the isolation group management functionality into the existing access point and network infrastructure. Instead of requiring separate management systems, the access point integrates isolation group identification, packet inspection, and selective forwarding capabilities, thereby improving security without significantly increasing overall system complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system enables self-service isolation group management by automatically assigning isolation group identifiers to client devices based on their association with the access point. This automated assignment reduces manual configuration complexity while maintaining security boundaries.

Inventive Principle:
Principle #25Self-service

3Reliability

If wireless networks use multiple SSIDs and VLANs to isolate groups, then security is improved, but network complexity and ease of operation are worsened

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the access point universal by enabling it to handle both isolated and non-isolated communication within a single network infrastructure. The same access point can simultaneously serve clients in different isolation groups while maintaining a single SSID and VLAN structure, eliminating the need for multiple network infrastructures and reducing overall complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11038761B2Group isolation in wireless networks
Publication Date: 2021.06.15 RUCKUS IP HOLDINGS LLC
  • US11038761B2 patent drawing
  • US11038761B2 patent drawing
  • US11038761B2 patent drawing

AI summary

Methods and Systems here may be used for managing a wireless network including associating a first and second wireless access device to an access point (AP), assigning the first and second wireless access device to respective first and second isolation groups, providing local communication via the AP within the isolation group, and prohibiting local communication via the AP between the first and second isolation groups.