Network Tunnel Connection for Secure Enterprise Communications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Communications between devices in enterprise campus networks can be cumbersome and prone to security compromises due to the dynamic nature of business operations and the presence of various interconnected devices.

Innovation Solution

Establishing a tunnel connection between a switch and a gateway in a network, and conducting data traffic, including DHCP and ARP messages, through this tunnel connection to ensure secure and efficient communication between devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data traffic is conducted directly between devices in the network, then communication efficiency is improved, but network security deteriorates due to exposure to security compromises from various interconnected devices

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidnetwork security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a tunnel connection as an intermediary layer between the switch and gateway, encapsulating data traffic within protected channels. This tunnel acts as a mediator that allows direct communication efficiency while maintaining security boundaries, preventing unauthorized access and security compromises from propagating through the network.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If broadcast or multicast traffic is allowed to flow freely in the network, then device discovery and communication setup are improved, but network stability deteriorates due to traffic flooding and potential outages

Engineering Contradiction:
Improvedevice discoveryVSAvoidnetwork stability
Core Design Contradiction:
Ease of operationVSStability of the object's composition

Solution Approach 1:

The patent segments broadcast and multicast traffic handling by implementing tunnel-specific configurations that control traffic flow. The tunnel connection divides the network into controlled segments where broadcast/multicast traffic can be selectively permitted or blocked, preventing flooding while allowing necessary device discovery protocols to function within defined boundaries.

Inventive Principle:
Principle #1Segmentation

3Reliability

If a tunnel connection is established between switch and gateway, then network security is improved by filtering traffic, but device complexity increases due to additional connection management

Engineering Contradiction:
Improvenetwork securityVSAvoidconnection management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The tunnel connection is designed to perform multiple functions simultaneously: it provides security filtering, enables controlled traffic flow management, supports both unicast and broadcast/multicast traffic types, and facilitates device discovery protocols. This multi-functionality reduces the need for separate security mechanisms and simplifies overall network management despite the added tunnel layer.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12289290B2Methods and systems for communications
Publication Date: 2025.04.29 NILE GLOBAL INC
  • US12289290B2 patent drawing
  • US12289290B2 patent drawing
  • US12289290B2 patent drawing

AI summary

Embodiments of a device and method are disclosed. In an embodiment, a method for communications involves establishing a tunnel connection between a switch of a network and a gateway of the network and in response to a communications device connecting to a network port of the switch, conducting data traffic involving the communications device through the tunnel connection between the switch and the gateway.