LISP Control Plane for Cross-Subnetwork BYOD Service Discovery
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing campus-wide networks struggle to provide secure and privileged access to Bring Your Own Device (BYOD) services as users move across subnetworks, as consumer discovery protocols like Apple Bonjour are not routable and typically limited to local area networks, making it difficult to access services such as printers and scanners across different subnetworks.
Innovation Solution
The implementation of the Locator/Identifier Separation Protocol (LISP) control plane allows for the extension of BYOD services across subnetworks by separating the identity of devices from their physical location, enabling continuous internet access and secure service availability through a LISP map server that manages enterprise service advertisements and user access based on user roles and locations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If consumer discovery protocols (e.g., Apple Bonjour) are used for BYOD services, then local area network service discovery is enabled, but service accessibility across subnetworks is limited
Solution Approach 1:
The patent introduces a LISP map server as an intermediary component that mediates between BYOD services on one subnetwork and users on other subnetworks. The map server stores binding information between endpoint identifiers and routing locators, enabling service discovery traffic to be routed across subnetwork boundaries while maintaining the original discovery protocol functionality within each subnetwork.
2Adaptability or versatility
If BYOD services are made available across all subnetworks, then service accessibility is improved, but network security is compromised
Solution Approach 1:
The patent implements role-based access control where different user roles (e.g., students, faculty, staff) have different levels of access to BYOD services. The LISP map server evaluates user credentials and role information to determine which services each user can access, allowing fine-grained security policies to be applied locally to each user-service interaction while enabling broad cross-subnetwork service availability.
3Reliability
If static IP addressing is used, then network security and predictability are maintained, but user mobility across subnetworks is limited
Solution Approach 1:
The patent segments the network identity system into two independent components: endpoint identifiers (EIDs) that remain constant for each device regardless of location, and routing locators (RLOCs) that change based on the device's current subnetwork location. This segmentation allows devices to maintain stable identities for security purposes while enabling seamless mobility across different subnetworks through dynamic locator updates in the LISP map server.
Data Source
AI summary
A method, system, and computer readable medium is disclosed which utilizes the LISP control plane to increase communications and access to enterprise resources in a network with multiple subnetworks, such as a university setting. As a result, the various embodiments of the present invention provide a routing and services dimension to enterprise discovery protocol traffic, such as Apple Bonjour traffic. A LISP instance ID, which is carried in the LISP header, is used to associate one or more end user devices with specific enterprise resources in a particular subnetwork or a service domain, wherein these resources may be accessed by the end user device even if the end user device migrates to another subnetwork. Another embodiment of the invention limits routing services advertisements from enterprise services to a subset of end user devices associated with particular user EIDs by using L2-LISP multicast techniques.


