Switching Hub VLAN Segmentation for Quarantine Network Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In quarantine network systems, virus-infected terminals are isolated in the same network as terminals not complying with security policies, allowing potential infection of non-compliant terminals.

Innovation Solution

A switching hub with VLAN functionality that connects terminals with sufficient security to a business network and those with insufficient security to an isolation network, using packet processing to restrict communication within the isolation network, preventing cross-infection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If virus-infected terminals are isolated in the same isolation network as terminals not complying with security policies, then network control is simplified, but cross-infection between terminals occurs

Engineering Contradiction:
Improvenetwork control complexityVSAvoidcross-infection risk
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the isolation network into multiple segments using VLAN technology. Terminals not complying with security policies are placed in one VLAN, while virus-infected terminals are placed in a separate VLAN. This segmentation prevents cross-infection while maintaining simplified network control through centralized VLAN management.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different network access policies to different terminal groups within the isolation network. Compliant terminals receive certain network services while non-compliant terminals have restricted access. This local quality differentiation allows simplified overall control while preventing harmful interactions between specific terminal groups.

Inventive Principle:
Principle #3Local quality

2Reliability

If terminals with insufficient security levels are connected to the isolation network, then security policy enforcement is achieved, but communication between isolated terminals may spread infections

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidvirus spread within isolation network
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent segments the isolation network into multiple VLANs based on security compliance status. Terminals with insufficient security levels are further divided into subgroups (e.g., non-compliant terminals vs. virus-infected terminals) placed in different VLANs. This ensures security policy enforcement while preventing virus spread through inter-terminal communication restrictions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a network switch with VLAN capabilities as an intermediary device that controls communication between isolated terminals. The switch enforces VLAN-based isolation policies, allowing security policy enforcement while blocking direct communication between virus-infected terminals and non-compliant terminals, thus preventing virus spread.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If a single isolation network is used for all non-compliant terminals, then network management is simplified, but security isolation effectiveness is reduced

Engineering Contradiction:
Improvenetwork management simplicityVSAvoidsecurity isolation effectiveness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent makes the network switch universal by enabling it to perform multiple functions: basic network switching, VLAN segmentation, security policy enforcement, and isolation management. This multi-functionality allows the system to maintain simplified management through a single device while achieving effective security isolation through VLAN-based segmentation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements dynamic VLAN assignment where terminals are automatically placed into appropriate VLANs based on their security compliance status and infection state. This dynamic adjustment maintains security isolation effectiveness while simplifying management through automated policy-based assignment rather than manual configuration.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8732817B2Switching hub, a system, a method of the switching hub and a program thereof
Publication Date: 2014.05.20 NEC CORP
  • US8732817B2 patent drawing
  • US8732817B2 patent drawing
  • US8732817B2 patent drawing

AI summary

A switching hub, system and method for restricting a communication between terminals within a second network isolated form a first network. The terminals are connected to the first network or the second network, wherein a terminal with sufficient security level is connected to the first network and a terminal with insufficient security level is connected to the second network. And a communication between the terminals within the second network is restricted.