Private VLAN Edge Across Switch Modules

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional networks, including those with multiple switches, lack the ability to implement a protected port feature that controls data transmission between endpoints, making it difficult to isolate or restrict information flow between different endpoints.

Innovation Solution

The implementation of a protected port feature in a Virtual Local Area Network (VLAN) using switches with protected port logic, where a central processing unit or other processor provides protected port status information through vendor-specific tags, allowing for controlled data transmission protocols based on port status, enabling isolation of endpoints and restricting information flow.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Object-affected harmful factors

If conventional switches are used in a LAN or VLAN with two or more switches, then network connectivity between endpoints is maintained, but the protected port feature cannot be implemented and information flow cannot be restricted

Engineering Contradiction:
Improveunrestricted information flowVSAvoidswitch configuration complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent segments the VLAN into multiple Private VLANs (PVLANs) where endpoints are assigned to specific PVLANs. This segmentation restricts information flow between different PVLANs while maintaining connectivity within each PVLAN, solving the contradiction by dividing the network into isolated segments that prevent unrestricted information flow without requiring complex configuration on each individual switch.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a bridge or router as an intermediary device that enforces PVLAN policies. This intermediary handles the complex policy enforcement and information flow restriction logic, allowing conventional switches to maintain simple connectivity functions while the intermediary manages the restricted information flow between PVLANs.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If protected port logic is implemented in each switch to control data transmission, then information flow can be restricted between endpoints, but the device complexity and configuration difficulty increase

Engineering Contradiction:
Improveinformation flow controlVSAvoidswitch and system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the protected port logic into the bridge or router rather than implementing it in each switch. This consolidation ensures consistent information flow control across the network while reducing overall system complexity, as the policy enforcement is centralized in one device rather than distributed across multiple switches.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The bridge or router is designed to handle multiple functions including PVLAN policy enforcement, information flow restriction, and data forwarding. This multi-functional approach ensures reliable information flow control while avoiding the need for separate dedicated devices for each function, thereby reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If vendor-specific tags are used to provide protected port status information, then controlled data transmission protocols can be implemented, but compatibility and ease of operation may be reduced

Engineering Contradiction:
Improvedata transmission controlVSAvoidnetwork configuration and operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies vendor-specific tags only where needed - specifically at the bridge or router where PVLAN policy enforcement occurs. This localized use of specialized tagging maintains data transmission control reliability while minimizing the impact on overall network operation, as conventional switches continue to operate with standard tagging and only the intermediary device requires the enhanced functionality.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS7710959B2Private VLAN edge across multiple switch modules
Publication Date: 2010.05.04 CISCO TECHNOLOGY INC
  • US7710959B2 patent drawing
  • US7710959B2 patent drawing
  • US7710959B2 patent drawing

AI summary

A source endpoint connected via a Virtual Local Area Network to a first access port and a destination endpoint connected to a second access port. Two or more network processing devices indirectly connected through a backplane interconnect to transmit data between the source and destination endpoints according to a protected port status of the first and second access ports.