Guest Access Management Server Using VLAN Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Providing guests with temporary access to network resources in an enterprise network is often costly and requires dedicated hardware and IT support, as existing solutions are complex and require significant administrative effort.

Innovation Solution

A system and method that uses a guest access management server to create and manage temporary guest user accounts, allowing access through existing network infrastructure using techniques such as scanning guest access cards, credit cards, or mobile phones, with VLAN technology to separate guest traffic from host traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If dedicated hardware and software solutions are used to provide guest access, then guest network access can be provided, but device complexity and cost increase

Engineering Contradiction:
Improveguest access provisionVSAvoiddedicated hardware and software
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent applies universality by enabling the existing enterprise network infrastructure to serve dual purposes: both host users and guest users access the network through the same infrastructure. The network infrastructure is configured to distinguish between host and guest users through authentication mechanisms and VLAN assignment, eliminating the need for separate dedicated hardware while maintaining secure guest access capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces a guest access management server as an intermediary component that mediates between the existing network infrastructure and guest users. This server handles guest authentication, credential generation, and traffic routing to appropriate VLANs, allowing the system to leverage existing infrastructure while providing specialized guest access control without requiring dedicated hardware throughout the network.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If dedicated hardware and software are installed, then guest access is enabled, but installation and maintenance costs increase

Engineering Contradiction:
Improveguest access provisionVSAvoidinstallation and maintenance
Core Design Contradiction:
Ease of operationVSEase of manufacture

Solution Approach 1:

The patent applies universality by enabling the existing enterprise network infrastructure to serve dual purposes: both host users and guest users access the network through the same infrastructure. The network infrastructure is configured to distinguish between host and guest users through authentication mechanisms and VLAN assignment, eliminating the need for separate dedicated hardware while maintaining secure guest access capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements self-service by allowing guests to independently obtain network access credentials through automated processes. Guests can scan their access cards, credit cards, or mobile phones to receive guest account credentials without requiring manual intervention from IT staff. The system automatically generates credentials, assigns VLANs, and manages access rights, significantly reducing the need for administrative assistance and lowering maintenance costs.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If traditional guest access solutions are used, then network access is provided, but IT support requirements increase

Engineering Contradiction:
Improveguest access provisionVSAvoidIT support and administrative assistance
Core Design Contradiction:
Ease of operationVSExtent of automation

Solution Approach 1:

The patent implements self-service by allowing guests to independently obtain network access credentials through automated processes. Guests can scan their access cards, credit cards, or mobile phones to receive guest account credentials without requiring manual intervention from IT staff. The system automatically generates credentials, assigns VLANs, and manages access rights, significantly reducing the need for administrative assistance and lowering maintenance costs.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent incorporates feedback mechanisms where the guest access management server continuously monitors guest access status, authentication results, and network traffic patterns. This feedback enables the system to dynamically adjust access rights, detect anomalies, and automatically resolve issues, reducing the need for manual IT support and administrative intervention while maintaining secure and flexible guest access.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS7874007B2Providing guest users access to network resources through an enterprise network
Publication Date: 2011.01.18 MICROSOFT TECHNOLOGY LICENSING LLC
  • US7874007B2 patent drawing
  • US7874007B2 patent drawing
  • US7874007B2 patent drawing

AI summary

Guest user are enabled to access network resources through an enterprise network using a guest user account. A guest user account may be created for a guest for a limited time. Guest account credentials of the guest account may be provided to the guest to use the guest account using any of a variety of techniques described herein, for example, by scanning a guest access card, credit card or mobile telephone of guest user, and providing the guest account credentials to the user based on the information obtained. A guest access management server may be configured to generate and maintain guest accounts, authenticate guest users, and track and log guest activity. A VLAN technology may be used to separate guest traffic from host enterprise traffic on the host enterprise network. After a guest user is authenticated, communications to and from the guest user may be routed to a guest VLAN.