L2 Secure Network Overlay via Platform AP Simulation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing remote access solutions for secure network connections, such as VPNs and browser-based approaches, face challenges in providing comprehensive security and ease of use, especially when connecting to enterprise networks from untrusted environments, and often require complex setup and specialized hardware.
Innovation Solution
A Layer 2 (L2)-based secured network solution that uses the computer platform to connect the operating system to a secured backend overlay network, simulating an Access Point (AP) or access switch, and leveraging cloud authenticators to establish end-to-end L2 encryption without altering the operating system or network infrastructure, providing a virtual network indistinguishable from local networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If VPN agents are installed on end-user devices to provide secure remote access, then network security is improved, but device complexity and administrative overhead increase significantly
Solution Approach 1:
The patent introduces a network-level intermediary (proxy server or gateway) that mediates between end-user devices and enterprise resources. Instead of installing VPN agents on each device, the intermediary handles security functions at the network layer, allowing devices to access resources through the proxy without requiring local security software installation or configuration.
2Reliability
If specialized CPE hardware is deployed to provide secure remote access, then network security is improved, but device cost and accessibility worsen
Solution Approach 1:
The patent creates a universal access solution that works across multiple device types and operating systems without requiring specialized hardware. The proxy server approach provides consistent security functionality whether accessed from smartphones, tablets, laptops, or desktops, eliminating the need for device-specific CPE hardware and making the solution universally accessible.
3Ease of operation
If browser-based application-level access is used, then ease of operation is improved, but security coverage deteriorates as only web applications are protected
Solution Approach 1:
The patent transitions from application-layer (Layer 7) security to network-layer (Layer 3/4) security by deploying proxies at the network level. This dimensional shift allows the solution to protect all traffic types (web, email, file transfers, custom protocols) simultaneously while maintaining ease of use, as the security function operates transparently at the network level rather than requiring application-specific configuration.
Data Source
AI summary
Methods and apparatus for virtual enterprise secure networking. A Layer 2 (L2)-based secured network solution is provided using resources of a computer platform to connect an operating system to a secured backend overlay network (e.g., enterprise, service provider or ‘zero trust network service’) in a way that does not require changes in the operating system and connection manager or alteration of network infrastructure (e.g., wireless access point) in the location where a client may reside. Under an aspect of the solution, the computer platform itself (e.g., platform hardware/Firmware/drivers) provides part of the role of the authenticator in an Institute of Electrical and Electronics Engineers (IEEE) 802.1X scheme either directly by simulation of an Access Point (AP) or as a pass through to the overlay network core. This replaces the traditional access point/switch authenticator role.


