SDN-Based Virtual Guest Network Segmentation on Wired LAN
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless communication systems face challenges in efficiently and flexibly setting up guest networks, leading to reduced business readiness and limited flexibility due to the need for separate networks and cumbersome security settings.
Innovation Solution
A communication apparatus utilizing Software-Defined Networking (SDN) and tunneling protocols to establish a virtual network on an existing wired LAN, allowing guest devices to connect without pre-registered authentication information, enabling flexible control and higher use efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a separate guest network is established with security settings, then security is improved, but device complexity and setup time increase
Solution Approach 1:
The patent segments the network into a usual network and a virtual guest network. The virtual guest network is created as a separate logical entity within the existing physical network infrastructure, allowing security policies to be applied specifically to guest traffic without reconfiguring the entire network. This segmentation enables security enhancement for guest access while maintaining the existing usual network configuration.
Solution Approach 2:
The patent introduces a controller as an intermediary that manages the virtual guest network. The controller handles authentication, authorization, and network policy enforcement for guest devices. By placing security management functions in the controller rather than requiring manual configuration on each access point or switch, the system achieves enhanced security with reduced configuration complexity.
2Reliability
If a separate guest network is established, then security is improved, but productivity and use efficiency decrease
Solution Approach 1:
The patent merges the guest network functionality with the existing usual network infrastructure. Instead of creating physically separate networks, the virtual guest network shares the same physical network resources (switches, access points, cables) as the usual network. This merging approach allows security to be enhanced for guest access while maintaining high resource utilization, as both guest and usual network traffic flow through the same infrastructure.
Solution Approach 2:
The patent makes the usual network infrastructure universal by enabling it to serve dual purposes: handling both usual network traffic and virtual guest network traffic simultaneously. The access points and switches in the usual network can authenticate and route traffic for both registered usual devices and unregistered guest devices, eliminating the need for dedicated guest network hardware and improving overall resource efficiency.
3Reliability
If MAC address registration is required for authentication, then security is improved, but adaptability and flexibility decrease
Solution Approach 1:
The patent implements dynamic authentication for the virtual guest network. Unlike the static MAC address registration required for the usual network, the guest network uses dynamic authentication methods where devices can connect without pre-registration. The controller dynamically authenticates guest devices, assigns network permissions, and manages session lifecycles, allowing the system to adapt to varying guest access requirements while maintaining security through policy-based control.
Data Source
Figure 1
Figure 2
Figure 3A~3B
AI summary
A communication apparatus which communicates with one or more other communication apparatuses via a network, includes: one or more communication interfaces being used for communication with the one or more other communication terminals; a selection unit connected to the one or more communication interfaces and selecting at least one communication interface that is used in accordance with an instruction from a control device which controls communications; and a network establish unit establishing a virtual network by forming a virtual communication path which directly connects between the at least one communication interface selected by the selection unit and a communication interface included in at least one communication apparatus among the one or more other communication apparatuses.