Dynamic VLAN Provisioning via Random Tag Association
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional enterprise networks require static configuration of virtual local area networks (VLANs), which leads to resource consumption, security concerns, and ongoing management duties, as devices need to be aware of pre-defined VLANs and their settings, limiting flexibility and increasing overhead.
Innovation Solution
A dynamic network interfaces system that uses a computer system, configuration database, and dynamic network interfaces application to authenticate client devices and dynamically provision VLANs by assigning configuration information, including subnet interface information and virtual local area network tags, to access devices and firewall components, allowing on-demand creation and management of VLANs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If static VLAN configuration is used, then network devices can be formally designated with predetermined VLAN settings, but this consumes device resources, creates security vulnerabilities, and requires ongoing management duties
Solution Approach 1:
The patent implements dynamic VLAN configuration where VLAN settings are not statically predefined but are automatically generated and assigned to client devices in real-time based on authentication and policy requirements. This transforms the static configuration model into a dynamic one, eliminating the need for manual VLAN management and reducing security risks associated with predetermined configurations.
Solution Approach 2:
The system enables self-service automated VLAN provisioning where the network infrastructure automatically creates and assigns VLAN configurations to authenticated devices without requiring manual intervention from network administrators. The system self-manages the entire VLAN configuration lifecycle including creation, assignment, and cleanup based on device authentication status.
2Adaptability or versatility
If static VLAN designations are predetermined, then network access can be controlled through formal device configuration, but this limits flexibility and increases overhead for managing VLAN creation and dismantling
Solution Approach 1:
The system performs preliminary actions by pre-establishing VLAN configuration templates and policies in advance, but the actual VLAN instantiation is deferred until needed during device authentication. This allows the system to have VLAN configurations ready to be rapidly deployed when required, providing both preparation efficiency and on-demand flexibility.
Solution Approach 2:
The patent dynamically changes VLAN configuration parameters such as VLAN ID, subnet mask, and gateway address based on device authentication results and policy requirements. Instead of using fixed static parameters, the system generates and assigns unique parameter sets for each authenticated device, enabling flexible adaptation to different network access scenarios.
3Ease of operation
If devices are configured with predetermined VLAN identifiers and settings, then network access control can be implemented, but this creates potential security concerns and resource consumption
Solution Approach 1:
The patent introduces an intermediary authentication system that acts as a mediator between the client device and the network infrastructure. This intermediary verifies device credentials, determines appropriate VLAN assignments based on policies, and then provisions the VLAN configuration. This intermediary layer eliminates the need for devices to have predetermined VLAN knowledge while maintaining secure access control through centralized authentication and authorization.
Data Source
AI summary
A system is provided comprising a computer system and a dynamic network interfaces application that executes on the computer system. The dynamic network interfaces application activates a virtual local area network (VLAN) by associating subnet interface information and a virtual local area network tag, wherein the virtual local area network tag is unrelated to and randomly combined with the subnet interface information, and by transmitting the association of the subnet interface information and the virtual local area network tag to a firewall component and to a network access component.


