Gateway VLAN Tagging for Secure Remote Device Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems struggle to integrate remote devices into a domestic VLAN securely, as existing Digital Rights Management (DRM) policies restrict multimedia content access based on geographical location, limiting its distribution beyond local networks.

Innovation Solution

A method and system that utilize a gateway network device to establish secure connections with remote devices via L2TP/IPSec tunneling and implement double VLAN-tagging, allowing multimedia content to be distributed securely beyond geographical restrictions by preserving content provider VLAN identifiers and adding additional tags for remote device access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If DRM policies restrict multimedia content access based on geographical location, then content security is improved, but content distribution capability deteriorates

Engineering Contradiction:
Improvecontent securityVSAvoidcontent distribution capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the VLAN identification into two layers: outer VLAN tag for remote network identification and inner VLAN tag for content provider identification. This segmentation allows the system to maintain content security restrictions while enabling distribution to remote devices by separating the functions of network routing and content protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The gateway network device acts as an intermediary between content providers and remote devices. It establishes secure L2TP/IPSec tunnel connections, performs double VLAN-tagging, and manages the distribution of multimedia content while maintaining DRM policy compliance. The gateway mediates between the conflicting requirements of content security and distribution capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If secure connections are established using L2TP/IPSec tunneling, then connection security is improved, but system complexity deteriorates

Engineering Contradiction:
Improveconnection securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The gateway network device performs multiple functions: establishing L2TP/IPSec tunnel connections, implementing double VLAN-tagging, managing remote device integration, and enforcing DRM policies. By consolidating these functions into a single multi-functional device, the patent reduces overall system complexity while maintaining connection security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If double VLAN-tagging is implemented for remote device integration, then network adaptability is improved, but processing complexity deteriorates

Engineering Contradiction:
Improvenetwork adaptabilityVSAvoidprocessing complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent adds another dimension to VLAN tagging by implementing double VLAN-tags (outer and inner tags) instead of traditional single tagging. This dimensional expansion allows the system to simultaneously maintain content provider network segmentation and integrate remote devices, achieving network adaptability while the gateway handles the processing complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS8707456B2Method and system for integrating remote devices into a domestic VLAN
Publication Date: 2014.04.22 AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE LTD
  • US8707456B2 patent drawing
  • US8707456B2 patent drawing
  • US8707456B2 patent drawing

AI summary

A gateway network device may establish secure connections to a plurality of remote network devices using tunneling protocols to distribute to the remote network devices multimedia content received from one or more content providers. The consumption of the multimedia content may originally be restricted to local network associated with the gateway network device. The secure connections may be set up using L2TP protocol, and the L2TP tunneling connections may be secured using IPSec protocol. Use of multimedia content may be restricted based on DRM policies of the content provider. DRM policies may be implemented using DTCP protocol, which may restrict use of the multimedia content based on roundtrip times and/or IP subnetting. Each content provider may use one or more VLAN identifiers during communication of the multimedia content to the gateway network device, and the gateway network device may associate an additional VLAN identifier with each secure connection.