Policy Server L2 Network Assignment and L3 IP Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network access control systems face challenges in ensuring continuous and secure communication between endpoint devices and policy servers across multiple layer two (L2) networks, particularly when endpoint devices are assigned to different L2 networks based on varying characteristics, as they require distinct IP addresses and secure access control channels.
Innovation Solution
The implementation of a policy server that assigns endpoint devices to specific L2 networks and provides them with corresponding layer three (L3) IP addresses for secure communication, allowing dynamic reassignment to different VLANs based on compliance with access policies, without requiring IP routing across all L2 networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a policy server assigns endpoint devices to different L2 networks based on characteristics, then access control flexibility is improved, but the complexity of maintaining continuous communication and IP address management increases
Solution Approach 1:
The patent segments the communication channel into L2 network assignment and L3 IP address assignment components. The policy server assigns endpoint devices to specific L2 networks (VLANs) and provides corresponding L3 IP addresses, separating these functions to manage complexity while maintaining flexibility in access control across multiple networks.
Solution Approach 2:
The patent introduces a trunk link as an intermediary mechanism that connects the policy server to multiple L2 networks. This trunk link carries traffic for multiple VLANs, enabling the policy server to communicate with endpoint devices across different L2 networks without requiring direct routing configurations on each network segment.
2Reliability
If distinct IP addresses are provided for each L2 network, then secure communication is improved, but the configuration and management overhead increases
Solution Approach 1:
The patent merges the IP address assignment function with the L2 network assignment function. When the policy server assigns an endpoint device to a specific L2 network, it simultaneously provides the corresponding L3 IP address through the same negotiation process, eliminating the need for separate IP configuration steps and reducing management overhead while maintaining secure communication.
3Object-affected harmful factors
If the policy server maintains separate configurations for each L2 network, then network security is improved, but the system complexity increases
Solution Approach 1:
The patent implements a universal negotiation framework that handles both L2 network assignment and L3 IP address assignment through a single process. The policy server uses a trunk link that can carry traffic for multiple VLANs, allowing it to maintain separate security configurations for each L2 network while using a unified communication mechanism, thereby reducing system complexity.
4Adaptability or versatility
If dynamic reassignment to different VLANs is enabled, then access control adaptability is improved, but the complexity of maintaining continuous L3 communication channels increases
Solution Approach 1:
The patent implements dynamic reassignment capability where the policy server can assign endpoint devices to different L2 networks and provide different L3 IP addresses based on changing access control requirements. The negotiation framework supports dynamic updates, allowing the system to adapt to changing policies while maintaining continuous communication through coordinated L2 and L3 reconfiguration.
Data Source
AI summary
A network device, such as a policy server, supports a plurality of different layer two (L2) networks. The network device receives a request to initiate a communication session from an endpoint device, selects an L2 network to which to assign the endpoint device, and assigns the endpoint device to the selected L2 network, selects one of a plurality of L3 network addresses for the policy server based on the selected L2 network, and sends the L3 network address to the endpoint device. The network device also includes a monitoring module that monitors activities of the endpoint device, and a plurality of L2 network interfaces, wherein each L2 network interface is associated with at least one L2 network. The L2 networks may be virtual local area networks.


