Private VLAN Edge Across Switch Modules
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional networks, including those with multiple switches, lack the ability to implement a protected port feature that controls data transmission between endpoints, making it difficult to isolate or restrict information flow between different endpoints.
Innovation Solution
The implementation of a protected port feature in a Virtual Local Area Network (VLAN) using switches with protected port logic, where a central processing unit or other processor provides protected port status information through vendor-specific tags, allowing for controlled data transmission protocols based on port status, enabling isolation of endpoints and restricting information flow.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Object-affected harmful factors
If conventional switches are used in a LAN or VLAN with two or more switches, then network connectivity between endpoints is maintained, but the protected port feature cannot be implemented and information flow cannot be restricted
Solution Approach 1:
The patent segments the VLAN into multiple Private VLANs (PVLANs) where endpoints are assigned to specific PVLANs. This segmentation restricts information flow between different PVLANs while maintaining connectivity within each PVLAN, solving the contradiction by dividing the network into isolated segments that prevent unrestricted information flow without requiring complex configuration on each individual switch.
Solution Approach 2:
The patent introduces a bridge or router as an intermediary device that enforces PVLAN policies. This intermediary handles the complex policy enforcement and information flow restriction logic, allowing conventional switches to maintain simple connectivity functions while the intermediary manages the restricted information flow between PVLANs.
2Reliability
If protected port logic is implemented in each switch to control data transmission, then information flow can be restricted between endpoints, but the device complexity and configuration difficulty increase
Solution Approach 1:
The patent merges the protected port logic into the bridge or router rather than implementing it in each switch. This consolidation ensures consistent information flow control across the network while reducing overall system complexity, as the policy enforcement is centralized in one device rather than distributed across multiple switches.
Solution Approach 2:
The bridge or router is designed to handle multiple functions including PVLAN policy enforcement, information flow restriction, and data forwarding. This multi-functional approach ensures reliable information flow control while avoiding the need for separate dedicated devices for each function, thereby reducing overall system complexity.
3Reliability
If vendor-specific tags are used to provide protected port status information, then controlled data transmission protocols can be implemented, but compatibility and ease of operation may be reduced
Solution Approach 1:
The patent applies vendor-specific tags only where needed - specifically at the bridge or router where PVLAN policy enforcement occurs. This localized use of specialized tagging maintains data transmission control reliability while minimizing the impact on overall network operation, as conventional switches continue to operate with standard tagging and only the intermediary device requires the enhanced functionality.
Data Source
AI summary
A source endpoint connected via a Virtual Local Area Network to a first access port and a destination endpoint connected to a second access port. Two or more network processing devices indirectly connected through a backplane interconnect to transmit data between the source and destination endpoints according to a protected port status of the first and second access ports.


