Dynamic VLAN Assignment for MDU Tenant Network Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In multiple dwelling unit (MDU) networks, devices connected to a shared WiFi or wired network cannot communicate directly with each other for privacy reasons, preventing tasks like file sharing or printer access, even among devices owned by the same entity, due to the network's design that isolates all devices from each other for privacy across multiple unrelated tenants.
Innovation Solution
The implementation of dynamic Virtual Local Area Network (VLAN) assignment using IEEE 802.1x and MAC authentication bypass creates personal networks for each tenant, allowing their devices to intercommunicate while remaining hidden from other tenants, using a captive portal and property ID, enabling onboarding and secure access across the MDU property.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Object-affected harmful factors
If devices are isolated on a shared MDU network for privacy reasons, then privacy protection across multiple tenants is improved, but device intercommunication capability deteriorates
Solution Approach 1:
The network is segmented into multiple Virtual Local Area Networks (VLANs), where each tenant's devices are assigned to a dedicated VLAN. This segmentation allows devices within the same tenant's VLAN to communicate freely while maintaining isolation from other tenants' devices, thus resolving the contradiction between privacy protection and device intercommunication capability
Solution Approach 2:
A network controller acts as an intermediary that manages VLAN assignments and device onboarding. The controller receives onboarding requests, authenticates devices, and dynamically assigns them to appropriate VLANs, enabling seamless communication within tenant networks while maintaining privacy across the broader MDU network
2Ease of operation
If dynamic VLAN assignment is implemented to enable personal networks, then device intercommunication within tenant networks is improved, but network complexity increases
Solution Approach 1:
The system implements self-service onboarding where devices automatically authenticate and receive VLAN assignments through the network controller without manual configuration. This automation reduces the operational complexity that would otherwise result from dynamic VLAN assignment, as the system manages itself rather than requiring manual intervention
Solution Approach 2:
The network controller provides multiple functions including authentication, VLAN assignment, and device management through a single unified system. This multi-functionality consolidates what would otherwise be separate complex systems into one manageable component, reducing overall network complexity while enabling dynamic VLAN assignment
Data Source
AI summary
An apparatus and method provide personal networks to a plurality of tenant entities on a property network, which has a captive portal and a property identification (ID). Virtual Local Area Network (VLAN) are assigned to each of the plurality of tenant entities to define a plurality of personal networks on the property network using dynamic VLAN assignment. Onboarding requests are received from one or more user devices on a specific personal network of the plurality of personal networks. The onboarding requests are processed in a manner permitting intercommunication among the one or more user devices within the specific personal network, to take place across the property network.


