Identity-Based Networking via VLAN Tunneling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users accessing a wide area network (WAN) from remote locations do not have the same IP address, network permissions, or access to local network resources due to the limitations of existing WAN connectivity methods, which restrict their experience and efficiency.

Innovation Solution

The implementation of identity-based networking through virtual LAN (VLAN) tunneling between mobility domains, utilizing a network database to authenticate and connect remote clients to their authorized VLANs, ensuring they have the same IP address and access to network resources as if they were locally connected, by using VLAN tunneling protocols and network domain seeds and members.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If users access the WAN from remote locations using traditional methods, then network connectivity is provided, but users do not have the same IP address, network permissions, or access to local network resources

Engineering Contradiction:
Improvenetwork access flexibilityVSAvoiduser experience consistency
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent introduces VLAN tunneling as an intermediary mechanism that creates a virtual connection between remote clients and their home VLAN. The tunnel acts as a mediator that transports network traffic through the WAN while preserving the client's original network identity and permissions, effectively bridging the gap between remote access needs and local network experience

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent adds a virtual dimension to the network architecture by creating VLAN tunnels that operate alongside physical network connections. This virtual layer allows clients to maintain their home network identity while physically located elsewhere, adding a dimension of network virtualization that decouples physical location from network identity

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Adaptability or versatility

If VLAN tunneling is implemented to provide consistent network experience, then remote users get the same IP address and permissions, but system complexity increases with network databases and domain seeds

Engineering Contradiction:
Improveremote access capabilityVSAvoidnetwork infrastructure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where the network database automatically authenticates clients and the system autonomously establishes appropriate VLAN tunnels based on client identity. The network infrastructure serves itself by automatically routing traffic and managing connections without manual intervention, reducing the operational burden despite the added complexity

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent pre-configures network databases with client authorization information and pre-establishes tunnel routing paths before remote access is needed. Network domain seeds are pre-distributed across the infrastructure, allowing the system to quickly authenticate and establish connections without real-time complex decision-making

Inventive Principle:
Principle #10Preliminary action

3Reliability

If network databases store VLAN information for authentication, then client authorization is verified, but information retrieval time increases during log-in

Engineering Contradiction:
Improveauthentication accuracyVSAvoidlog-in processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent pre-populates network databases with all necessary client authorization information and VLAN mapping data before authentication is needed. This preliminary preparation allows the authentication process to simply retrieve pre-processed information rather than performing complex real-time analysis, significantly reducing log-in time while maintaining security

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8270408B2Identity-based networking
Publication Date: 2012.09.18 TRAPEZE NETWORKS INC
  • US8270408B2 patent drawing
  • US8270408B2 patent drawing
  • US8270408B2 patent drawing

AI summary

A technique for identity based networking is disclosed. A system according to the technique can include a WAN, a first VLAN, a second VLAN, and a network database. The first VLAN and second VLAN can be coupled to the WAN. The network database can include VLAN information. In operation, a client that is authorized on the second VLAN can attempt to connect to the first VLAN. A switch in the WAN can perform a lookup in the network database and determine that the client is authorized on the second VLAN. Based on this information, the client can be connected to the second VLAN using VLAN tunneling.