SDN-Based WLAN Slice for Low-Latency Enterprise VPN Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional VPN connections result in significant latency and inefficient use of resources when multiple employees working off-site communicate with each other, as all traffic must travel through the enterprise network, even when they are located at the same remote location and connected to the same wireless network.

Innovation Solution

Establishing a private wireless local area network (WLAN) slice at a wireless access point, which creates a VPN connection to the enterprise network, allowing traffic between co-located users to be routed directly without going through the enterprise network, using software-defined networking (SDN) to manage and secure this communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional VPN connections are used for off-site employees, then enterprise network security is maintained, but communication latency increases and bandwidth resources are inefficiently utilized

Engineering Contradiction:
Improveenterprise network securityVSAvoidcommunication latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the network traffic into two categories: local traffic between co-located employees and remote traffic to the enterprise network. A private WLAN slice is created to handle local traffic independently, while the VPN connection handles only remote traffic. This segmentation allows local communications to bypass the enterprise network entirely, reducing latency while maintaining security for enterprise-bound traffic.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a private WLAN slice as an intermediary network layer between employees' devices and the enterprise network. This slice acts as a mediator that enables direct local communications without requiring traffic to traverse the enterprise network, while still providing controlled access to enterprise resources when needed.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If conventional VPN connections are used for off-site employees, then enterprise network security is maintained, but bandwidth resources are inefficiently utilized

Engineering Contradiction:
Improveenterprise network securityVSAvoidbandwidth usage
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent segments network traffic to distinguish between local communications and enterprise-bound traffic. By creating a private WLAN slice, local traffic is isolated and routed directly between devices without consuming enterprise bandwidth. Only traffic requiring enterprise resources traverses the VPN connection, significantly reducing unnecessary bandwidth consumption.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts local traffic from the enterprise network path entirely. By establishing a separate private WLAN slice for local communications, the system removes the need for local traffic to traverse the enterprise network infrastructure, thereby conserving enterprise bandwidth resources for actual enterprise business needs.

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If a private WLAN slice is created for local traffic, then communication efficiency is improved, but network complexity increases

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidnetwork complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces a private WLAN slice as an intermediary layer that simplifies the overall network architecture. Rather than requiring complex peer-to-peer VPN configurations between multiple devices, the slice acts as a centralized mediator that automatically handles local routing, reducing configuration complexity while improving communication efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Loss of time

If traffic is routed directly between co-located users, then latency is reduced, but network security control is challenged

Engineering Contradiction:
Improvecommunication latencyVSAvoidnetwork security control
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The patent applies different security and routing characteristics to different parts of the network. The private WLAN slice provides direct, low-latency routing for local traffic, while the VPN connection maintains strict security controls for enterprise-bound traffic. This local quality approach allows optimized performance for local communications without compromising enterprise security policies.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent segments network traffic into local and enterprise-bound categories with different routing paths. Local traffic within the private WLAN slice enjoys direct routing for low latency, while enterprise traffic maintains security control through the VPN connection. This segmentation enables simultaneous optimization for both performance and security based on traffic type.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9985799B2Collaborative software-defined networking (SDN) based virtual private network (VPN)
Publication Date: 2018.05.29 NOKIA OF AMERICA CORP
  • US9985799B2 patent drawing
  • US9985799B2 patent drawing
  • US9985799B2 patent drawing

AI summary

A collaborative software-defined networking (SDN) based virtual private network (VPN) communication method includes: establishing, at a wireless access point, a private wireless local area network (WLAN) slice within a first wireless network in response to a request from a first user, wireless resources for the first wireless network being provided by the wireless access point; creating a VPN connection between the private WLAN slice and a second network; granting users access to the private WLAN slice and the VPN connection between the private WLAN slice and the second network; and routing traffic between the users granted access to the private WLAN slice and the VPN connection without transmission of the traffic to the second network through the VPN connection.