Hidden Virtual Access Point for Quarantine Station Traffic Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Rogue devices in WLANs can still transmit and receive multicast and broadcast traffic across VLANs, leading to reduced network performance and security concerns, as existing methods fail to effectively isolate such traffic.
Innovation Solution
Creating a hidden virtual access point with a distinct SSID for quarantine stations, using different GTK keys for encryption to segregate broadcast and multicast traffic from non-quarantine stations, thereby isolating and securing quarantine traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If rogue devices are isolated from the WLAN by placing them on a separate VLAN, then device isolation is improved, but multicast and broadcast traffic can still be transmitted and received across VLANs reducing network performance
Solution Approach 1:
The patent segments the network traffic by creating separate virtual access points (VAPs) for different traffic types. Multicast traffic is directed to a dedicated multicast VAP while broadcast traffic for quarantine devices is directed to a separate quarantine VAP. This segmentation prevents multicast and broadcast traffic from propagating across VLAN boundaries, resolving the contradiction by maintaining device isolation while preserving network performance through targeted traffic separation.
Solution Approach 2:
The patent introduces a multicast router as an intermediary component that receives multicast traffic on one interface and forwards it only to the appropriate multicast VAP interface. This intermediary prevents multicast traffic from leaking into other VLANs while maintaining the isolation of rogue devices, thus improving both device isolation reliability and overall network performance by controlling traffic flow paths.
2Reliability
If a hidden virtual access point with distinct SSID is created for quarantine stations, then traffic separation is improved, but device complexity increases
Solution Approach 1:
The patent implements a universal quarantine mechanism that works across multiple SSIDs and VAPs through centralized configuration. The hidden quarantine VAP with distinct SSID serves as a universal destination for all broadcast traffic destined for quarantine devices, regardless of which SSID they originally connected to. This multi-functional approach improves traffic separation reliability while managing device complexity through a standardized quarantine process that can be applied consistently across the network.
Data Source
AI summary
Quarantine stations are steered to a hidden virtual access point for quarantining multicast and broadcast traffic from other traffic on an access point, or other device. The hidden virtual access point can be spawned, with the same configurations as a non-quarantine virtual access point, for on demand traffic containment. The data stream transmitted over Wi-Fi to the quarantine client using a different GTK key generated under virtual access point of hidden SSID for encryption of the multicast or broadcast transmission, and the data packet stream transmitted over wi-fi to the non-quarantine station using different GTK key generated under virtual access point SSID of regular SSID for encryption of the multicast or broadcast transmission.


