vCPE Network Segment Allocation via Authentication Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication systems using vCPE technology face challenges in separating network segments between subscriber terminals and other party terminals due to shared network connectivity, posing security risks from potential malicious software or vulnerabilities.

Innovation Solution

A communication system that includes first and second vCPEs and an authentication server, which determines and manages network segment allocation based on connection permission conditions, allowing flexible establishment of identical or different network segments for connections between terminals and vCPEs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a common network segment is established for subscriber terminal and other party terminal through other party vCPE, then connection flexibility is improved, but security is worsened due to inability to separate network segments

Engineering Contradiction:
Improveconnection flexibilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the network segment into separate virtual network segments (VLANs) for the subscriber terminal and other party terminal, even though they connect through the same other party vCPE. This allows physical connectivity while maintaining logical separation, thus improving security without sacrificing connection flexibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces the authentication server as an intermediary that manages and controls the network segment allocation. The authentication server determines whether to allocate the same or different network segments based on connection permission conditions, acting as a mediator between the need for connectivity and the need for security isolation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If network segment separation is implemented for security, then security is improved, but connection flexibility is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidconnection flexibility
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic network segment allocation where the authentication server can determine at connection time whether to allocate the same or different network segments based on connection permission conditions. This dynamic approach allows the system to adapt to different security requirements while maintaining connection flexibility, rather than using a static separation approach.

Inventive Principle:
Principle #15Dynamics

3Object-affected harmful factors

If dynamic network segment allocation is implemented, then security control is improved, but system complexity is worsened

Engineering Contradiction:
Improvesecurity controlVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The authentication server serves as a centralized intermediary that handles the complex logic of determining network segment allocation. By concentrating the decision-making functionality in one component, the patent simplifies the overall system architecture while still providing dynamic security control, rather than distributing complex logic across multiple components.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11374793B2Network segment allocation system and method
Publication Date: 2022.06.28 NIPPON TELEGRAPH & TELEPHONE CORP
  • US11374793B2 patent drawing
  • US11374793B2 patent drawing
  • US11374793B2 patent drawing

AI summary

When a subscriber terminal (100A) connects to the other party vCPE (310B), a communication system (1) determines whether a connection between the other party terminal (100B) and the other party vCPE (310B) and a connection between the subscriber terminal (100A) and the other party vCPE (310B) are to be established through the same network segment based on connection permission conditions of the other party vCPE (310B) and the subscriber terminal (100A), and the other party vCPE (310B) allocates a network segment, which is the same as or different from a network segment allocated to the other party terminal (100B), to the subscriber terminal (100A) according to the determination.