Dynamic VLAN Provisioning via Random Tag Association

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional enterprise networks require static configuration of virtual local area networks (VLANs), which leads to resource consumption, security concerns, and ongoing management duties, as devices need to be aware of pre-defined VLANs and their settings, limiting flexibility and increasing overhead.

Innovation Solution

A dynamic network interfaces system that uses a computer system, configuration database, and dynamic network interfaces application to authenticate client devices and dynamically provision VLANs by assigning configuration information, including subnet interface information and virtual local area network tags, to access devices and firewall components, allowing on-demand creation and management of VLANs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static VLAN configuration is used, then network devices can be formally designated with predetermined VLAN settings, but this consumes device resources, creates security vulnerabilities, and requires ongoing management duties

Engineering Contradiction:
Improvenetwork securityVSAvoidconfiguration management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic VLAN configuration where VLAN settings are not statically predefined but are automatically generated and assigned to client devices in real-time based on authentication and policy requirements. This transforms the static configuration model into a dynamic one, eliminating the need for manual VLAN management and reducing security risks associated with predetermined configurations.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system enables self-service automated VLAN provisioning where the network infrastructure automatically creates and assigns VLAN configurations to authenticated devices without requiring manual intervention from network administrators. The system self-manages the entire VLAN configuration lifecycle including creation, assignment, and cleanup based on device authentication status.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If static VLAN designations are predetermined, then network access can be controlled through formal device configuration, but this limits flexibility and increases overhead for managing VLAN creation and dismantling

Engineering Contradiction:
ImproveVLAN provisioning flexibilityVSAvoidmanagement time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-establishing VLAN configuration templates and policies in advance, but the actual VLAN instantiation is deferred until needed during device authentication. This allows the system to have VLAN configurations ready to be rapidly deployed when required, providing both preparation efficiency and on-demand flexibility.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent dynamically changes VLAN configuration parameters such as VLAN ID, subnet mask, and gateway address based on device authentication results and policy requirements. Instead of using fixed static parameters, the system generates and assigns unique parameter sets for each authenticated device, enabling flexible adaptation to different network access scenarios.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If devices are configured with predetermined VLAN identifiers and settings, then network access control can be implemented, but this creates potential security concerns and resource consumption

Engineering Contradiction:
Improvenetwork access controlVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary authentication system that acts as a mediator between the client device and the network infrastructure. This intermediary verifies device credentials, determines appropriate VLAN assignments based on policies, and then provisions the VLAN configuration. This intermediary layer eliminates the need for devices to have predetermined VLAN knowledge while maintaining secure access control through centralized authentication and authorization.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8752160B1Dynamic firewall and dynamic host configuration protocol configuration
Publication Date: 2014.06.10 T MOBILE INNOVATIONS LLC
  • US8752160B1 patent drawing
  • US8752160B1 patent drawing
  • US8752160B1 patent drawing

AI summary

A system is provided comprising a computer system and a dynamic network interfaces application that executes on the computer system. The dynamic network interfaces application activates a virtual local area network (VLAN) by associating subnet interface information and a virtual local area network tag, wherein the virtual local area network tag is unrelated to and randomly combined with the subnet interface information, and by transmitting the association of the subnet interface information and the virtual local area network tag to a firewall component and to a network access component.