Virtual Network Assigner Resolves VLAN Address Reassignment Bottleneck
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional technologies for authenticating devices connecting to virtual networks require devices to obtain an IP address before authentication, which can lead to cumbersome reassignment of network addresses and technical challenges due to the inability to determine the virtual network access until after IP-based authentication is completed.
Innovation Solution
A system that includes a virtual network assigner and a packet director, allowing devices to communicate using a shared pool of VLAN addresses, where an address is assigned first and then authenticated, enabling the device to be exclusively assigned to a VLAN based on authentication, with routers maintaining separate VRF information for each VLAN, ensuring correct routing and address management across multiple VLANs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If an IP address is assigned to a device before authentication, then HTTP/Web Portal based authentication can be performed, but the device may be assigned to an incorrect VLAN and require cumbersome address reassignment
Solution Approach 1:
The patent assigns a temporary IP address from a shared pool to the device before authentication occurs. This preliminary address assignment enables HTTP/Web Portal authentication to proceed without requiring the device to be pre-configured with a permanent address or pre-assigned to a specific VLAN. After authentication determines the correct VLAN, the temporary address is then permanently assigned to the appropriate VLAN, eliminating the need for cumbersome reassignment procedures.
Solution Approach 2:
The patent introduces a shared pool of IP addresses that acts as an intermediary between the authentication process and the VLAN assignment. These temporary addresses serve as a bridge, allowing devices to participate in HTTP authentication before their final VLAN membership is determined. The shared pool isolates the authentication process from the VLAN addressing structure, enabling flexible authentication without compromising network segmentation integrity.
2Productivity
If a device is statically or dynamically assigned to a VLAN before authentication, then the device can communicate on the network, but the virtual network access cannot be determined until after authentication is completed
Solution Approach 1:
The system performs preliminary IP address assignment from a shared pool before authentication, allowing the device to immediately communicate on the network. This preliminary action decouples the authentication process from VLAN determination, enabling the device to be productive during authentication while the system simultaneously determines the appropriate VLAN assignment based on authentication credentials.
Solution Approach 2:
The patent implements a dynamic addressing system where IP addresses are temporarily assigned from a shared pool and then dynamically moved to the appropriate VLAN after authentication. This dynamic approach allows the system to maintain network communication continuity while flexibly adapting the device's VLAN assignment based on authentication results, eliminating delays associated with static pre-assignment.
3Ease of manufacture
If multiple VLANs share a pool of commonly usable addresses, then address assignment is simplified, but address management becomes more complex with exclusive assignment requirements
Solution Approach 1:
The system pre-configures a shared pool of IP addresses that can be temporarily assigned to any device requiring network access. This preliminary preparation simplifies the authentication process by ensuring addresses are available without complex real-time allocation logic. The shared pool acts as a pre-prepared resource that can be quickly assigned and later transferred to appropriate VLANs based on authentication outcomes.
Solution Approach 2:
The patent changes the state of IP address assignment from permanent VLAN-specific assignment to temporary shared pool assignment during authentication, then transitions to permanent VLAN-specific assignment after authentication. This parameter change allows the system to simplify address assignment during the critical authentication phase while maintaining proper VLAN segmentation for long-term network operation. The system dynamically adjusts the assignment parameters based on the authentication state.
Data Source
AI summary
A system allows a device to communicate using a virtual network the method by assigning a network address to the device. The network address is selected from a plurality of network addresses that can be assigned to any of a plurality of virtual networks. The system receives a request to authenticate the device, and then determines a virtual network on which to assign the device. The virtual network is selected from the plurality of virtual networks. The system identifies the device as authenticated based on the assigning of the network address and the virtual network.


