Network Management Apparatus for Shared VLAN Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current techniques for setting up communication in shared networks, such as VLANs, are complex and prone to errors, leading to potential unauthorized access and security risks due to the lack of effective methods to ensure that only authorized systems communicate with each other.

Innovation Solution

A management apparatus that receives and compares identifiers from connected information processing apparatuses to determine user coincidence, applying specific settings to enable or disable communication, thereby preventing errors and ensuring secure communication within shared networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If VLAN settings are used to prevent communication between servers of different customers in a shared network, then communication security is improved, but the complexity of settings increases and errors are more likely to occur

Engineering Contradiction:
Improvecommunication securityVSAvoidsettings complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a management server as an intermediary between the control server and network switches. This management server automatically generates and manages VLAN settings based on customer information, acting as a mediator that translates high-level customer identification requirements into specific network configuration parameters, thereby reducing the complexity of direct VLAN management while maintaining security

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service automation where the management server automatically generates VLAN settings, assigns VLAN IDs, and configures network switches without requiring manual intervention. The system serves itself by automatically detecting customer connections, retrieving customer information, and applying appropriate network settings, eliminating the need for complex manual VLAN configuration

Inventive Principle:
Principle #25Self-service

2Ease of operation

If manual VLAN settings are configured to enable communication between specific servers, then communication control is improved, but the time and effort required for configuration increases

Engineering Contradiction:
Improvecommunication controlVSAvoidconfiguration time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-storing customer information and server identification data in the management server before actual network connections are made. When a server connects to the network, the management server already has the necessary customer information ready, allowing immediate automatic configuration of VLAN settings without requiring manual lookup or configuration at the time of connection

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system employs feedback mechanisms where the management server continuously monitors network connections, receives information about connected servers, and automatically adjusts VLAN settings based on this feedback. The control server provides feedback about customer connections, and the management server uses this feedback to dynamically generate and update network configurations, creating a closed-loop system that adapts to changing network conditions

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10574516B2Management apparatus and shared network system
Publication Date: 2020.02.25 FUJITSU LTD
  • US10574516B2 patent drawing
  • US10574516B2 patent drawing
  • US10574516B2 patent drawing

AI summary

A disclosed management apparatus that manages communication in a network shared by information processing apparatuses of plural users includes: a memory and a processor coupled to the memory. And the processor is configured to: receive, from a first information processing apparatus connected to the network, a first identifier assigned to the first information processing apparatus; receive, from a second information processing apparatus connected to the network, a second identifier assigned to the second information processing apparatus; determine whether a user of the first information processing apparatus coincides with a user of the second information processing apparatus based on the received first identifier and second identifier; and apply first settings to permit communication between the first information processing apparatus and the second information processing apparatus, upon determining that the user of the first information processing apparatus coincides with the user of the second information processing apparatus.