Identity-Based Networking via VLAN Tunneling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users accessing a wide area network (WAN) from remote locations do not have the same IP address, network permissions, or access to local network resources due to the limitations of existing WAN connectivity methods, which restrict their experience and efficiency.
Innovation Solution
The implementation of identity-based networking through virtual LAN (VLAN) tunneling between mobility domains, utilizing a network database to authenticate and connect remote clients to their authorized VLANs, ensuring they have the same IP address and access to network resources as if they were locally connected, by using VLAN tunneling protocols and network domain seeds and members.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If users access the WAN from remote locations using traditional methods, then network connectivity is provided, but users do not have the same IP address, network permissions, or access to local network resources
Solution Approach 1:
The patent introduces VLAN tunneling as an intermediary mechanism that creates a virtual connection between remote clients and their home VLAN. The tunnel acts as a mediator that transports network traffic through the WAN while preserving the client's original network identity and permissions, effectively bridging the gap between remote access needs and local network experience
Solution Approach 2:
The patent adds a virtual dimension to the network architecture by creating VLAN tunnels that operate alongside physical network connections. This virtual layer allows clients to maintain their home network identity while physically located elsewhere, adding a dimension of network virtualization that decouples physical location from network identity
2Adaptability or versatility
If VLAN tunneling is implemented to provide consistent network experience, then remote users get the same IP address and permissions, but system complexity increases with network databases and domain seeds
Solution Approach 1:
The patent implements self-service mechanisms where the network database automatically authenticates clients and the system autonomously establishes appropriate VLAN tunnels based on client identity. The network infrastructure serves itself by automatically routing traffic and managing connections without manual intervention, reducing the operational burden despite the added complexity
Solution Approach 2:
The patent pre-configures network databases with client authorization information and pre-establishes tunnel routing paths before remote access is needed. Network domain seeds are pre-distributed across the infrastructure, allowing the system to quickly authenticate and establish connections without real-time complex decision-making
3Reliability
If network databases store VLAN information for authentication, then client authorization is verified, but information retrieval time increases during log-in
Solution Approach 1:
The patent pre-populates network databases with all necessary client authorization information and VLAN mapping data before authentication is needed. This preliminary preparation allows the authentication process to simply retrieve pre-processed information rather than performing complex real-time analysis, significantly reducing log-in time while maintaining security
Data Source
AI summary
A technique for identity based networking is disclosed. A system according to the technique can include a WAN, a first VLAN, a second VLAN, and a network database. The first VLAN and second VLAN can be coupled to the WAN. The network database can include VLAN information. In operation, a client that is authorized on the second VLAN can attempt to connect to the first VLAN. A switch in the WAN can perform a lookup in the network database and determine that the client is authorized on the second VLAN. Based on this information, the client can be connected to the second VLAN using VLAN tunneling.


