Dynamic VLAN Assignment for MDU Tenant Network Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In multiple dwelling unit (MDU) networks, devices connected to a shared WiFi or wired network cannot communicate directly with each other for privacy reasons, preventing tasks like file sharing or printer access, even among devices owned by the same entity, due to the network's design that isolates all devices from each other for privacy across multiple unrelated tenants.

Innovation Solution

The implementation of dynamic Virtual Local Area Network (VLAN) assignment using IEEE 802.1x and MAC authentication bypass creates personal networks for each tenant, allowing their devices to intercommunicate while remaining hidden from other tenants, using a captive portal and property ID, enabling onboarding and secure access across the MDU property.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Object-affected harmful factors

If devices are isolated on a shared MDU network for privacy reasons, then privacy protection across multiple tenants is improved, but device intercommunication capability deteriorates

Engineering Contradiction:
Improveprivacy protectionVSAvoiddevice intercommunication
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The network is segmented into multiple Virtual Local Area Networks (VLANs), where each tenant's devices are assigned to a dedicated VLAN. This segmentation allows devices within the same tenant's VLAN to communicate freely while maintaining isolation from other tenants' devices, thus resolving the contradiction between privacy protection and device intercommunication capability

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A network controller acts as an intermediary that manages VLAN assignments and device onboarding. The controller receives onboarding requests, authenticates devices, and dynamically assigns them to appropriate VLANs, enabling seamless communication within tenant networks while maintaining privacy across the broader MDU network

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If dynamic VLAN assignment is implemented to enable personal networks, then device intercommunication within tenant networks is improved, but network complexity increases

Engineering Contradiction:
Improvedevice intercommunicationVSAvoidnetwork complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system implements self-service onboarding where devices automatically authenticate and receive VLAN assignments through the network controller without manual configuration. This automation reduces the operational complexity that would otherwise result from dynamic VLAN assignment, as the system manages itself rather than requiring manual intervention

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The network controller provides multiple functions including authentication, VLAN assignment, and device management through a single unified system. This multi-functionality consolidates what would otherwise be separate complex systems into one manageable component, reducing overall network complexity while enabling dynamic VLAN assignment

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12058514B2Virtual tenant for multiple dwelling unit
Publication Date: 2024.08.06 RUCKUS IP HOLDINGS LLC
  • US12058514B2 patent drawing
  • US12058514B2 patent drawing
  • US12058514B2 patent drawing

AI summary

An apparatus and method provide personal networks to a plurality of tenant entities on a property network, which has a captive portal and a property identification (ID). Virtual Local Area Network (VLAN) are assigned to each of the plurality of tenant entities to define a plurality of personal networks on the property network using dynamic VLAN assignment. Onboarding requests are received from one or more user devices on a specific personal network of the plurality of personal networks. The onboarding requests are processed in a manner permitting intercommunication among the one or more user devices within the specific personal network, to take place across the property network.