Virtual Visitor Network Gateway for Secure LAN Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in allowing visitor access to their private local area networks (LANs) due to security concerns, as existing solutions require managing user accounts and leave networks vulnerable to attacks when providing public access.

Innovation Solution

A virtual visitor network system that includes a visitor access point and a gateway to enable secure access to a public network from within a private LAN, using a virtual visitor network to isolate visitor traffic and protect the LAN from potential threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If visitor accounts are created to provide public network access, then visitor productivity is improved, but network security and management complexity deteriorate

Engineering Contradiction:
Improvevisitor productivityVSAvoidnetwork management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces a network address translator (NAT) device as an intermediary between the visitor's computer and the private LAN. The NAT device translates the visitor's private IP address to a public IP address for internet access, while preventing direct access to the private LAN. This intermediary solution enables visitor productivity without requiring account management or exposing the network to security risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If visitor accounts with limited access are created, then network security is improved, but visitor productivity deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoidvisitor productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the network access into two distinct paths: one for private LAN resources (restricted to authorized users only) and one for public internet resources (available to visitors). The NAT device creates a separate virtual interface for internet access that does not require visitor accounts or permissions, thereby maintaining network security while fully preserving visitor productivity for internet-related tasks.

Inventive Principle:
Principle #1Segmentation

3Reliability

If continuous management and monitoring of network accounts is performed, then network security is improved, but device complexity deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoidaccount management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The NAT device operates autonomously without requiring any account management, user authentication, or continuous monitoring. The device automatically translates IP addresses and manages network traffic based on predefined rules, eliminating the need for administrators to create, maintain, or monitor visitor accounts. This self-service approach maintains network security while completely removing account management complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8041824B1System, device, method and software for providing a visitor access to a public network
Publication Date: 2011.10.18 TP-LINK SYSTEMS INC
  • US8041824B1 patent drawing
  • US8041824B1 patent drawing
  • US8041824B1 patent drawing

AI summary

A system, device, method and software for providing a visitor access to a public network are disclosed. In one form, a virtual visitor enabled local area network includes a visitor access point operable to provide a visitor access to a public network while connected to a local area network (LAN). The visitor access point is operable to protect the LAN using a virtual visitor network established between the visitor access point and a virtual visitor network gateway.