Policy Server L2 Network Assignment and L3 IP Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network access control systems face challenges in ensuring continuous and secure communication between endpoint devices and policy servers across multiple layer two (L2) networks, particularly when endpoint devices are assigned to different L2 networks based on varying characteristics, as they require distinct IP addresses and secure access control channels.

Innovation Solution

The implementation of a policy server that assigns endpoint devices to specific L2 networks and provides them with corresponding layer three (L3) IP addresses for secure communication, allowing dynamic reassignment to different VLANs based on compliance with access policies, without requiring IP routing across all L2 networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a policy server assigns endpoint devices to different L2 networks based on characteristics, then access control flexibility is improved, but the complexity of maintaining continuous communication and IP address management increases

Engineering Contradiction:
Improveaccess control flexibilityVSAvoidcommunication maintenance complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the communication channel into L2 network assignment and L3 IP address assignment components. The policy server assigns endpoint devices to specific L2 networks (VLANs) and provides corresponding L3 IP addresses, separating these functions to manage complexity while maintaining flexibility in access control across multiple networks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a trunk link as an intermediary mechanism that connects the policy server to multiple L2 networks. This trunk link carries traffic for multiple VLANs, enabling the policy server to communicate with endpoint devices across different L2 networks without requiring direct routing configurations on each network segment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If distinct IP addresses are provided for each L2 network, then secure communication is improved, but the configuration and management overhead increases

Engineering Contradiction:
Improvesecure communicationVSAvoidconfiguration overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the IP address assignment function with the L2 network assignment function. When the policy server assigns an endpoint device to a specific L2 network, it simultaneously provides the corresponding L3 IP address through the same negotiation process, eliminating the need for separate IP configuration steps and reducing management overhead while maintaining secure communication.

Inventive Principle:
Principle #5Merging (Combining)

3Object-affected harmful factors

If the policy server maintains separate configurations for each L2 network, then network security is improved, but the system complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements a universal negotiation framework that handles both L2 network assignment and L3 IP address assignment through a single process. The policy server uses a trunk link that can carry traffic for multiple VLANs, allowing it to maintain separate security configurations for each L2 network while using a unified communication mechanism, thereby reducing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Adaptability or versatility

If dynamic reassignment to different VLANs is enabled, then access control adaptability is improved, but the complexity of maintaining continuous L3 communication channels increases

Engineering Contradiction:
Improveaccess control adaptabilityVSAvoidL3 communication maintenance complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic reassignment capability where the policy server can assign endpoint devices to different L2 networks and provide different L3 IP addresses based on changing access control requirements. The negotiation framework supports dynamic updates, allowing the system to adapt to changing policies while maintaining continuous communication through coordinated L2 and L3 reconfiguration.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8966075B1Accessing a policy server from multiple layer two networks
Publication Date: 2015.02.24 PULSE SECURE LLC
  • US8966075B1 patent drawing
  • US8966075B1 patent drawing
  • US8966075B1 patent drawing

AI summary

A network device, such as a policy server, supports a plurality of different layer two (L2) networks. The network device receives a request to initiate a communication session from an endpoint device, selects an L2 network to which to assign the endpoint device, and assigns the endpoint device to the selected L2 network, selects one of a plurality of L3 network addresses for the policy server based on the selected L2 network, and sends the L3 network address to the endpoint device. The network device also includes a monitoring module that monitors activities of the endpoint device, and a plurality of L2 network interfaces, wherein each L2 network interface is associated with at least one L2 network. The L2 networks may be virtual local area networks.