Network Interface Segmentation for Subscriber Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for isolating subscribers in computer networks, such as ring topologies, fail to effectively prevent communication between subscribers across multiple network devices, despite isolating them on the same device, due to limitations in hardware configurations and the lack of appropriate mechanisms for subscriber isolation across devices.
Innovation Solution
The introduction of a novel interface type, NNI-ALT, which is identified based on its role in forwarding upstream traffic, allows for user isolation by denying traffic forwarding between UNIs and NNI-ALTs, and between NNI-ALTs, while permitting forwarding between NNIs and NNI-ALTs, thereby extending the UNI/NNI forwarding principle to isolate subscribers across multiple devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If UNI/NNI functionality is implemented to forward traffic from UNI to NNI, then subscriber isolation on the same network device is achieved, but subscriber isolation across multiple network devices is not provided
Solution Approach 1:
The patent segments network interfaces into four distinct types: UNI, NNI, NNI-ALT, and protected ports. This segmentation allows traffic forwarding rules to be applied differently to each interface type, enabling subscriber isolation to extend across multiple network devices by blocking traffic between UNIs on different devices while maintaining necessary connectivity through NNIs and NNI-ALTs.
2Reliability
If Private VLAN functionality is configured to provide traffic control across multiple devices, then subscriber isolation across devices is achieved, but hardware configuration limitations prevent its use in certain scenarios
Solution Approach 1:
The patent changes the parameter of interface classification by introducing NNI-ALT as a distinct interface type with specific forwarding rules. Instead of relying on PVLAN hardware features that may not be available in all configurations, the solution uses software-configurable interface types and associated forwarding rules that can be implemented on any standard switch, thereby achieving hardware compatibility while maintaining subscriber isolation.
3Reliability
If protected port forwarding rules are applied to block traffic between protected ports, then subscriber isolation is improved, but network topology adaptability and dynamic adjustment capability are reduced
Solution Approach 1:
The patent implements dynamic configuration flexibility by allowing the NNI-ALT interface type and its associated forwarding rules to be dynamically adjusted based on network topology changes. The system can adapt to different ring topologies and reconfigure forwarding behavior as needed, maintaining both subscriber isolation and configuration flexibility through programmable switching logic rather than static hardware constraints.
Data Source
AI summary
In one embodiment, a network device may have its network interfaces identified as either network-to-network interfaces (NNIs) configured to communicate with other network devices in a first computer network, or user-to-network interfaces (UNIs) configured to provide service to the first computer network for user devices. Based on determining at least one NNI for forwarding upstream traffic to an aggregation device of the first network that connects the first network to a second network, any NNI that is not used for forwarding upstream traffic is deemed a novel "NNI alternate" (NNI-ALT). The forwarding of traffic at the network device may be controlled to provide user isolation between network devices by denying traffic forwarding between UNIs and NNI-ALTs as well as between NNI-ALTs and NNI-ALTs, while permitting traffic forwarding between NNIs and NNI-ALTs.


