Secure VLANs via Router-Mediated Intra-Subnet Traffic Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing VLANs are vulnerable to security breaches and destabilizing loops due to local switching of traffic between member devices on the same IP subnet, which is not subjected to security measures and can lead to uncontrolled Layer 2 flooding.

Innovation Solution

Implementing a logical hub and spoke topology where all traffic, including intra-subnet communication, is routed through a hub device, such as a router, with only a single logical broadcast uplink port and point-to-point downlink ports, ensuring all traffic is processed by the router for security and service provision, and disabling bridging functions in Layer 2 switches.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If local switching is implemented for intra-subnet traffic, then network efficiency is improved, but security is worsened

Engineering Contradiction:
Improvenetwork efficiencyVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a router as an intermediary device that all intra-subnet traffic must pass through. The router acts as a mediator between member devices, performing security inspections, protocol enforcement, and service provisioning on all traffic flows. This resolves the contradiction by maintaining network efficiency through centralized processing while dramatically improving security through mandatory router involvement in all traffic paths.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If local switching is implemented for intra-subnet traffic, then network efficiency is improved, but network stability is worsened

Engineering Contradiction:
Improvenetwork efficiencyVSAvoidnetwork stability
Core Design Contradiction:
ProductivityVSStability of the object's composition

Solution Approach 1:

The router serves as a stabilizing intermediary that prevents destabilizing loops by controlling and regulating all traffic flows. The router enforces protocol compliance and manages traffic forwarding decisions, eliminating the loop formation problems that occur with distributed Layer 2 switching. This maintains network stability while still allowing efficient traffic handling through the centralized router.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If an enforcement point is implemented at the network access level, then security is improved, but device complexity and cost are worsened

Engineering Contradiction:
ImprovesecurityVSAvoidequipment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the existing router universal by enabling it to handle both inter-subnet and intra-subnet traffic. Instead of adding specialized enforcement devices at network access points, the router is configured to perform security enforcement, protocol validation, and service provisioning for all traffic types. This eliminates the need for additional complex equipment while maintaining improved security through centralized router-based enforcement.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9660829B2Secure VLANs
Publication Date: 2017.05.23 PULSELINK SYSTEMS LLC
  • US9660829B2 patent drawing
  • US9660829B2 patent drawing
  • US9660829B2 patent drawing

AI summary

A VLAN is implemented with a logical hub and spoke topology that obviates local switching. Member devices are connected to a hub device such as a router via intermediate devices such as Layer 2 switches that support individual IP subnets within the VLAN. The Layer 2 switch does not allow bridging, so there is no IP subnet broadcast domain. Further, the Layer 2 switch implements only a single logical broadcast uplink port which is connected to the router. The Layer 2 switch also implements only point-to-point downlink ports, i.e., to individual member devices. Consequently, all traffic is forced to flow through the router, e.g., broadcast traffic, multicast traffic and traffic of unknown destination received by the Layer 2 switch from a member device is only flooded to the router, and the router performs intra-subnet routing in addition to routing between subnets and between VLANs. The router subjects all traffic to security measures and provide services including packet inspection, firewall, policing, metering, accounting, anti-virus, marking, filtering and encryption, and thereby reduce or eliminate the drawbacks associated with local switching.