Virtual AP LAN Configuration via Segmented Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The setup and configuration of secure communication channels between wireless local area network (WLAN) access points and client devices are complex, requiring manual steps and often necessitate temporary insecurity or unavailability of the network, with existing methods offering inadequate security and user-friendliness.

Innovation Solution

The implementation of virtual AP technology to create a configuration LAN and an operational LAN on a single access point, using distinct service set identifiers (SSIDs) to facilitate easy setup and secure data communication, where the configuration LAN is less secure and easier to access for initial setup and modifications, while the operational LAN is more secure and handles normal data communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a secure communication channel is configured between AP and client device, then security is improved, but setup complexity and manual configuration steps increase

Engineering Contradiction:
ImprovesecurityVSAvoidsetup complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a configuration network as an intermediary communication channel between the AP and client device. This separate configuration network handles setup and security provisioning, allowing the operational network to maintain security without requiring complex manual configuration. The configuration network acts as a mediator that simplifies the setup process while the operational network ensures secure data communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual setup steps are required for secure configuration, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of setup
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the network communication into two distinct networks: a configuration network for setup activities and an operational network for secure data communication. This segmentation allows the configuration network to be more accessible and easier to connect to, while the operational network maintains strong security. Users can easily set up the connection through the configuration network without needing to manually configure security parameters, as the segmentation handles security provisioning automatically.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If network modifications are made after secure configuration, then adaptability is improved, but security deteriorates due to temporary insecurity requirements

Engineering Contradiction:
Improvenetwork modification capabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The configuration network serves as a permanent intermediary that enables network modifications without compromising the security of the operational network. When modifications are needed, they can be performed through the configuration network, which is designed to handle setup and modification tasks. This eliminates the need to temporarily disable security on the operational network, as the configuration network provides a safe channel for all configuration activities including modifications.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of operation

If separate configuration and operational networks are provided, then ease of setup and security are improved, but device complexity increases

Engineering Contradiction:
Improveease of setupVSAvoidnetwork architecture complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent merges the configuration network and operational network within a single access point device. Although two separate logical networks are provided for different purposes (configuration and secure operation), they share the same physical infrastructure and management system. This merging approach provides the benefits of separate networks (ease of setup and security) while avoiding the hardware complexity of completely separate devices. The single AP manages both networks, reducing overall system complexity.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS7974249B2Virtual access point for configuration of a LAN
Publication Date: 2011.07.05 DELL PROD LP
  • US7974249B2 patent drawing
  • US7974249B2 patent drawing
  • US7974249B2 patent drawing

AI summary

A technique is disclosed for setting up and configuring a LAN. More particularly, secure communications may be configured between an access point (AP) and a client device. Virtual AP technology is utilized to assist the configuration of the network. In particular, at least two wireless networks are provided in a single A, a configuration LAN and an operational LAN, by utilizing virtual AP technology. The configuration LAN is utilized to provide communication between the AP and the client devices that is related to network setup, configuration, modification, etc. and the operational LAN provides normal LAN data communication. The configuration LAN may be provided in a relatively insecure manner that eases setup of that communication channel and the operational LAN may be provided in a more fully secure communication channel. Different types of service set identifiers (SSIDs) may be provided for configuration LANs and operational LANs so as to more easily identify the type of LAN through its SSID.