Dynamic User Private Networks Logical Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current packet switching network technologies face challenges in dynamically modifying logical segmentation of shared virtual networks to efficiently migrate user entities among dynamic user private networks without disconnecting them from the shared virtual network, requiring manual intervention and lacking efficient security and scalability.

Innovation Solution

A network control system that automatically modifies dynamic logical segmentation in real-time based on user requests, using User Private Network Identifiers (UPN-IDs) to encapsulate and filter packets, allowing seamless movement of user entities between dynamic user private networks within a shared virtual network, while maintaining connectivity and enhancing security through micro-segmentation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual intervention is used to modify logical segmentation of shared virtual networks, then network security can be maintained, but network efficiency and scalability are reduced

Engineering Contradiction:
Improvenetwork efficiencyVSAvoidmanual intervention requirement
Core Design Contradiction:
ProductivityVSExtent of automation

Solution Approach 1:

The system enables self-service by allowing users to automatically request and receive network segmentation modifications through a control system. Users can initiate requests to join or leave dynamic user private networks without manual network administrator intervention, and the system automatically processes these requests by modifying logical segmentation and migrating user entities as needed.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements dynamic logical segmentation where network configurations can be automatically modified in real-time based on user requests. The system transitions from static manual configuration to dynamic automated adjustment, allowing the network topology to adapt automatically when users need to be transferred between different dynamic user private networks.

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If user entities are migrated between dynamic user private networks, then network adaptability is improved, but connectivity stability may be compromised

Engineering Contradiction:
Improvenetwork adaptabilityVSAvoidconnectivity stability
Core Design Contradiction:
Adaptability or versatilityVSStability of the object's composition

Solution Approach 1:

The system performs preliminary actions by maintaining the user entity's association with the shared virtual network before and during the migration process. The control system ensures that the logical segmentation is modified in a way that preserves connectivity, allowing the user entity to remain connected to both the source and destination networks during the transition, thus avoiding disruption.

Inventive Principle:
Principle #10Preliminary action

3Speed

If dynamic logical segmentation is modified in real-time, then network responsiveness is improved, but system complexity increases

Engineering Contradiction:
Improvenetwork responsivenessVSAvoidsystem complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent introduces a control system as an intermediary that manages the complexity of real-time logical segmentation modifications. This control system acts as a mediator between user requests and the actual network configuration changes, automatically processing requests, modifying logical segmentation, and coordinating entity migrations while hiding the underlying complexity from end users.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12107721B2Dynamic user private networks of a shared virtual network
Publication Date: 2024.10.01 CISCO TECHNOLOGY INC
  • US12107721B2 patent drawing
  • US12107721B2 patent drawing
  • US12107721B2 patent drawing

AI summary

In one embodiment, dynamic user private networks are virtually segmented within a shared virtual network. A network control system maintains the dynamic logical segmentation of the shared virtual network. User entities (e.g., user devices and/or services) are communicatively coupled to respective personal virtual networks via endpoints of access devices. Each of these endpoints is associated with a corresponding user private network. Responsive in real-time to automated processing of a received electronic particular user request, the network control system automatically modifies the dynamic logical segmentation of the shared virtual network to move a particular user entity on the shared virtual network to newly being on the first dynamic user private network without being disconnected from the shared virtual network. One embodiment uses different user private network identifiers (UPN-IDs) associated with endpoints and received packets to identify their respective user private network.