Dynamic User Private Networks Logical Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current packet switching network technologies face challenges in dynamically modifying logical segmentation of shared virtual networks to efficiently migrate user entities among dynamic user private networks without disconnecting them from the shared virtual network, requiring manual intervention and lacking efficient security and scalability.
Innovation Solution
A network control system that automatically modifies dynamic logical segmentation in real-time based on user requests, using User Private Network Identifiers (UPN-IDs) to encapsulate and filter packets, allowing seamless movement of user entities between dynamic user private networks within a shared virtual network, while maintaining connectivity and enhancing security through micro-segmentation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If manual intervention is used to modify logical segmentation of shared virtual networks, then network security can be maintained, but network efficiency and scalability are reduced
Solution Approach 1:
The system enables self-service by allowing users to automatically request and receive network segmentation modifications through a control system. Users can initiate requests to join or leave dynamic user private networks without manual network administrator intervention, and the system automatically processes these requests by modifying logical segmentation and migrating user entities as needed.
Solution Approach 2:
The patent implements dynamic logical segmentation where network configurations can be automatically modified in real-time based on user requests. The system transitions from static manual configuration to dynamic automated adjustment, allowing the network topology to adapt automatically when users need to be transferred between different dynamic user private networks.
2Adaptability or versatility
If user entities are migrated between dynamic user private networks, then network adaptability is improved, but connectivity stability may be compromised
Solution Approach 1:
The system performs preliminary actions by maintaining the user entity's association with the shared virtual network before and during the migration process. The control system ensures that the logical segmentation is modified in a way that preserves connectivity, allowing the user entity to remain connected to both the source and destination networks during the transition, thus avoiding disruption.
3Speed
If dynamic logical segmentation is modified in real-time, then network responsiveness is improved, but system complexity increases
Solution Approach 1:
The patent introduces a control system as an intermediary that manages the complexity of real-time logical segmentation modifications. This control system acts as a mediator between user requests and the actual network configuration changes, automatically processing requests, modifying logical segmentation, and coordinating entity migrations while hiding the underlying complexity from end users.
Data Source
AI summary
In one embodiment, dynamic user private networks are virtually segmented within a shared virtual network. A network control system maintains the dynamic logical segmentation of the shared virtual network. User entities (e.g., user devices and/or services) are communicatively coupled to respective personal virtual networks via endpoints of access devices. Each of these endpoints is associated with a corresponding user private network. Responsive in real-time to automated processing of a received electronic particular user request, the network control system automatically modifies the dynamic logical segmentation of the shared virtual network to move a particular user entity on the shared virtual network to newly being on the first dynamic user private network without being disconnected from the shared virtual network. One embodiment uses different user private network identifiers (UPN-IDs) associated with endpoints and received packets to identify their respective user private network.


