Programmable Switch Ports for East-West Traffic Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network security systems, particularly in enterprise networks, face challenges in managing complex firewall rules, allowing unauthorized access and data leakage due to the lack of effective control over East-West traffic within LANs, and the difficulty in securing Operational Technology (OT) and Internet of Things (IoT) devices.
Innovation Solution
A programmable switching device with individually programmable ports that enforce security controls at each switch port, utilizing Software-Defined Networking (SDN) to dynamically manage and enforce access rules, allowing only authorized traffic and preventing unauthorized access or data leakage, with features like automated traffic pattern learning and whitelisting.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional firewall systems are used to control network access, then basic network security is provided, but complex rule management becomes difficult and unauthorized access within LANs cannot be effectively prevented
Solution Approach 1:
The patent segments the network into multiple Virtual LANs (VLANs) with isolated broadcast domains, allowing granular control of traffic flows between different network segments. Each VLAN acts as an independent security zone with its own access control policies, replacing monolithic firewall rules with distributed, manageable segment policies.
Solution Approach 2:
The patent implements port-based access control where each switch port can be independently configured with specific security policies, VLAN assignments, and traffic filtering rules. This allows local customization of security parameters at each port level rather than applying uniform rules across the entire network.
2Ease of operation
If traditional switches are used to link computers in a network, then basic connectivity is provided, but control over data flow to or from individual systems is lost
Solution Approach 1:
The patent implements dynamic VLAN assignment and port configuration where switch ports can be programmatically reconfigured based on traffic patterns, security policies, or administrative commands. The system dynamically adjusts data flow control parameters without requiring physical reconfiguration or network downtime.
Solution Approach 2:
The patent combines multiple functions into a single network switch device, including routing, switching, VLAN management, access control, and traffic filtering capabilities. This multi-functional approach eliminates the need for separate devices for each function while maintaining ease of operation through unified management.
3Reliability
If dedicated firewalls are deployed to block unauthorized access, then network security is improved, but East-West traffic control within LANs remains insufficient
Solution Approach 1:
The patent adds a new dimension of control by implementing Layer 2 (data link layer) filtering and VLAN-based isolation, complementing traditional Layer 3 (network layer) firewall rules. This enables control of traffic flows at multiple protocol levels, particularly effective for preventing lateral movement within the LAN while maintaining perimeter security.
4Device complexity
If network switches operate without individual port programming, then device simplicity is maintained, but security controls at each switch port cannot be enforced
Solution Approach 1:
The patent implements automated port security features where the switch automatically detects unauthorized devices, learns MAC addresses, and enforces access policies without manual intervention. The system self-configures VLAN memberships and applies security rules based on pre-defined policies, reducing the burden of manual port programming while maintaining strong security controls.
Data Source
AI summary
A programmable switching device within a network infrastructure that includes at least one port; and at least one programmable filter communicatively coupled to the at least one port, wherein the at least one programmable filter is configured to permit/deny data packets being transmitted to or from a networked device connected to the at least one port based on a set of defined rules.


