Hidden Virtual Access Point for Quarantine Station Traffic Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Rogue devices in WLANs can still transmit and receive multicast and broadcast traffic across VLANs, leading to reduced network performance and security concerns, as existing methods fail to effectively isolate such traffic.

Innovation Solution

Creating a hidden virtual access point with a distinct SSID for quarantine stations, using different GTK keys for encryption to segregate broadcast and multicast traffic from non-quarantine stations, thereby isolating and securing quarantine traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If rogue devices are isolated from the WLAN by placing them on a separate VLAN, then device isolation is improved, but multicast and broadcast traffic can still be transmitted and received across VLANs reducing network performance

Engineering Contradiction:
Improvedevice isolationVSAvoidnetwork performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the network traffic by creating separate virtual access points (VAPs) for different traffic types. Multicast traffic is directed to a dedicated multicast VAP while broadcast traffic for quarantine devices is directed to a separate quarantine VAP. This segmentation prevents multicast and broadcast traffic from propagating across VLAN boundaries, resolving the contradiction by maintaining device isolation while preserving network performance through targeted traffic separation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a multicast router as an intermediary component that receives multicast traffic on one interface and forwards it only to the appropriate multicast VAP interface. This intermediary prevents multicast traffic from leaking into other VLANs while maintaining the isolation of rogue devices, thus improving both device isolation reliability and overall network performance by controlling traffic flow paths.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a hidden virtual access point with distinct SSID is created for quarantine stations, then traffic separation is improved, but device complexity increases

Engineering Contradiction:
Improvetraffic separationVSAvoidaccess point configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal quarantine mechanism that works across multiple SSIDs and VAPs through centralized configuration. The hidden quarantine VAP with distinct SSID serves as a universal destination for all broadcast traffic destined for quarantine devices, regardless of which SSID they originally connected to. This multi-functional approach improves traffic separation reliability while managing device complexity through a standardized quarantine process that can be applied consistently across the network.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11184741B1Separating broadcast and multicast wireless traffic in WLANs (wireless local access networks) for quarantine stations
Publication Date: 2021.11.23 FORTINET INC
  • US11184741B1 patent drawing
  • US11184741B1 patent drawing
  • US11184741B1 patent drawing

AI summary

Quarantine stations are steered to a hidden virtual access point for quarantining multicast and broadcast traffic from other traffic on an access point, or other device. The hidden virtual access point can be spawned, with the same configurations as a non-quarantine virtual access point, for on demand traffic containment. The data stream transmitted over Wi-Fi to the quarantine client using a different GTK key generated under virtual access point of hidden SSID for encryption of the multicast or broadcast transmission, and the data packet stream transmitted over wi-fi to the non-quarantine station using different GTK key generated under virtual access point SSID of regular SSID for encryption of the multicast or broadcast transmission.