Community Identifiers for Automated Client Network Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The manual configuration of group identifiers in network devices for virtual network segmentation in VXLAN environments is complex and cumbersome, especially with large numbers of client devices, increasing setup complexity.

Innovation Solution

Automated segmentation of virtual networks using community identifiers, such as PAN IDs, assigned during authentication procedures based on shared secrets or user information, to group client devices and restrict interactions within defined communities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual configuration of group identifiers is used for virtual network segmentation, then network security and isolation are achieved, but setup complexity and configuration overhead increase significantly

Engineering Contradiction:
Improvenetwork securityVSAvoidsetup complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically assigns community identifiers to client devices based on their authentication credentials without requiring manual configuration. The network device autonomously groups devices into communities and enforces isolation policies, eliminating the need for administrators to manually configure group identifiers for each device while maintaining security requirements.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual configuration of group identifiers is used for virtual network segmentation, then network security and isolation are achieved, but configuration time and operational overhead increase

Engineering Contradiction:
Improvenetwork securityVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Community identifiers are assigned to client devices during the authentication phase before the devices join the virtual network. This preliminary assignment ensures that devices are pre-grouped into appropriate communities with proper security policies applied, eliminating the need for subsequent manual configuration and reducing overall setup time while maintaining security requirements.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If automated segmentation using community identifiers is implemented, then setup complexity and configuration overhead are reduced, but network isolation and security may be compromised

Engineering Contradiction:
Improvesetup easeVSAvoidnetwork isolation
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The network device continuously monitors community identifier assignments and enforces isolation policies by examining community identifiers in packet headers. When packets are received, the system automatically determines whether to forward or drop them based on community matching rules, providing real-time feedback that ensures network isolation is maintained despite automated assignment processes.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250240186A1Community identifier of a group of client devices
Publication Date: 2025.07.24 HEWLETT PACKARD ENTERPRISE DEV LP
  • US20250240186A1 patent drawing
  • US20250240186A1 patent drawing
  • US20250240186A1 patent drawing

AI summary

In some examples, a system initiates an authentication procedure for a client device, and determines a group of client devices including the client device based on information associated with the client devices. The system assigns, to the client device, a community identifier as part of the authentication procedure, where the community identifier identifies the group of client devices that are able to communicate with one another over a virtual network.