L2 Secure Network Overlay via Platform AP Simulation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing remote access solutions for secure network connections, such as VPNs and browser-based approaches, face challenges in providing comprehensive security and ease of use, especially when connecting to enterprise networks from untrusted environments, and often require complex setup and specialized hardware.

Innovation Solution

A Layer 2 (L2)-based secured network solution that uses the computer platform to connect the operating system to a secured backend overlay network, simulating an Access Point (AP) or access switch, and leveraging cloud authenticators to establish end-to-end L2 encryption without altering the operating system or network infrastructure, providing a virtual network indistinguishable from local networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If VPN agents are installed on end-user devices to provide secure remote access, then network security is improved, but device complexity and administrative overhead increase significantly

Engineering Contradiction:
Improvenetwork securityVSAvoidadministrative complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a network-level intermediary (proxy server or gateway) that mediates between end-user devices and enterprise resources. Instead of installing VPN agents on each device, the intermediary handles security functions at the network layer, allowing devices to access resources through the proxy without requiring local security software installation or configuration.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If specialized CPE hardware is deployed to provide secure remote access, then network security is improved, but device cost and accessibility worsen

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice accessibility
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent creates a universal access solution that works across multiple device types and operating systems without requiring specialized hardware. The proxy server approach provides consistent security functionality whether accessed from smartphones, tablets, laptops, or desktops, eliminating the need for device-specific CPE hardware and making the solution universally accessible.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If browser-based application-level access is used, then ease of operation is improved, but security coverage deteriorates as only web applications are protected

Engineering Contradiction:
Improveease of useVSAvoidsecurity coverage
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent transitions from application-layer (Layer 7) security to network-layer (Layer 3/4) security by deploying proxies at the network level. This dimensional shift allows the solution to protect all traffic types (web, email, file transfers, custom protocols) simultaneously while maintaining ease of use, as the security function operates transparently at the network level rather than requiring application-specific configuration.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS20220264299A1Virtual enterprise secure networking
Publication Date: 2022.08.18 INTEL CORP
  • US20220264299A1 patent drawing
  • US20220264299A1 patent drawing
  • US20220264299A1 patent drawing

AI summary

Methods and apparatus for virtual enterprise secure networking. A Layer 2 (L2)-based secured network solution is provided using resources of a computer platform to connect an operating system to a secured backend overlay network (e.g., enterprise, service provider or ‘zero trust network service’) in a way that does not require changes in the operating system and connection manager or alteration of network infrastructure (e.g., wireless access point) in the location where a client may reside. Under an aspect of the solution, the computer platform itself (e.g., platform hardware/Firmware/drivers) provides part of the role of the authenticator in an Institute of Electrical and Electronics Engineers (IEEE) 802.1X scheme either directly by simulation of an Access Point (AP) or as a pass through to the overlay network core. This replaces the traditional access point/switch authenticator role.