Virtual Network Assigner Resolves VLAN Address Reassignment Bottleneck

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional technologies for authenticating devices connecting to virtual networks require devices to obtain an IP address before authentication, which can lead to cumbersome reassignment of network addresses and technical challenges due to the inability to determine the virtual network access until after IP-based authentication is completed.

Innovation Solution

A system that includes a virtual network assigner and a packet director, allowing devices to communicate using a shared pool of VLAN addresses, where an address is assigned first and then authenticated, enabling the device to be exclusively assigned to a VLAN based on authentication, with routers maintaining separate VRF information for each VLAN, ensuring correct routing and address management across multiple VLANs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If an IP address is assigned to a device before authentication, then HTTP/Web Portal based authentication can be performed, but the device may be assigned to an incorrect VLAN and require cumbersome address reassignment

Engineering Contradiction:
Improveauthentication processVSAvoidaddress reassignment
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent assigns a temporary IP address from a shared pool to the device before authentication occurs. This preliminary address assignment enables HTTP/Web Portal authentication to proceed without requiring the device to be pre-configured with a permanent address or pre-assigned to a specific VLAN. After authentication determines the correct VLAN, the temporary address is then permanently assigned to the appropriate VLAN, eliminating the need for cumbersome reassignment procedures.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a shared pool of IP addresses that acts as an intermediary between the authentication process and the VLAN assignment. These temporary addresses serve as a bridge, allowing devices to participate in HTTP authentication before their final VLAN membership is determined. The shared pool isolates the authentication process from the VLAN addressing structure, enabling flexible authentication without compromising network segmentation integrity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If a device is statically or dynamically assigned to a VLAN before authentication, then the device can communicate on the network, but the virtual network access cannot be determined until after authentication is completed

Engineering Contradiction:
Improvenetwork communicationVSAvoidVLAN determination
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system performs preliminary IP address assignment from a shared pool before authentication, allowing the device to immediately communicate on the network. This preliminary action decouples the authentication process from VLAN determination, enabling the device to be productive during authentication while the system simultaneously determines the appropriate VLAN assignment based on authentication credentials.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a dynamic addressing system where IP addresses are temporarily assigned from a shared pool and then dynamically moved to the appropriate VLAN after authentication. This dynamic approach allows the system to maintain network communication continuity while flexibly adapting the device's VLAN assignment based on authentication results, eliminating delays associated with static pre-assignment.

Inventive Principle:
Principle #15Dynamics

3Ease of manufacture

If multiple VLANs share a pool of commonly usable addresses, then address assignment is simplified, but address management becomes more complex with exclusive assignment requirements

Engineering Contradiction:
Improveaddress assignmentVSAvoidaddress management
Core Design Contradiction:
Ease of manufactureVSDevice complexity

Solution Approach 1:

The system pre-configures a shared pool of IP addresses that can be temporarily assigned to any device requiring network access. This preliminary preparation simplifies the authentication process by ensuring addresses are available without complex real-time allocation logic. The shared pool acts as a pre-prepared resource that can be quickly assigned and later transferred to appropriate VLANs based on authentication outcomes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the state of IP address assignment from permanent VLAN-specific assignment to temporary shared pool assignment during authentication, then transitions to permanent VLAN-specific assignment after authentication. This parameter change allows the system to simplify address assignment during the critical authentication phase while maintaining proper VLAN segmentation for long-term network operation. The system dynamically adjusts the assignment parameters based on the authentication state.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS7869436B1Methods and apparatus for connecting to virtual networks using non supplicant authentication
Publication Date: 2011.01.11 CISCO TECHNOLOGY INC
  • US7869436B1 patent drawing
  • US7869436B1 patent drawing
  • US7869436B1 patent drawing

AI summary

A system allows a device to communicate using a virtual network the method by assigning a network address to the device. The network address is selected from a plurality of network addresses that can be assigned to any of a plurality of virtual networks. The system receives a request to authenticate the device, and then determines a virtual network on which to assign the device. The virtual network is selected from the plurality of virtual networks. The system identifies the device as authenticated based on the assigning of the network address and the virtual network.