Virtual Wireless LANs via Single Access Point Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless local area networks struggle to accommodate multiple systems within the same physical space without requiring duplicate access points, particularly in environments like airports or corporate reorganizations where multiple users and networks need to share data communications efficiently.

Innovation Solution

A method and system that utilize a common distribution system with portals and access points to manage multiple virtual wireless networks by associating mobile units with service set identifications or realm identifications, allowing data to be relayed through the appropriate local area network using tags, enabling communication through a single access point.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple access points are installed to serve multiple systems in the same physical space, then each system can have dedicated communication infrastructure, but the device complexity and installation cost increase significantly

Engineering Contradiction:
Improvededicated communication infrastructureVSAvoidmultiple access points installation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple virtual wireless networks into a single physical access point infrastructure. The access point maintains separate virtual interfaces for each network (e.g., Airport operations, Police/Security, Airlines), allowing multiple systems to share the same hardware while maintaining logical separation and dedicated communication channels through virtualization.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The access point is designed with multi-functionality to serve multiple networks simultaneously. It can handle different service set identifications (SSIDs) and route traffic to different distribution systems based on the virtual network interface being used, making a single device perform the function of multiple dedicated access points.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Device complexity

If a single access point is used to serve multiple systems, then device complexity is reduced, but network security and data isolation between systems may be compromised

Engineering Contradiction:
Improvesingle access point infrastructureVSAvoidnetwork security and data isolation
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The access point segments network traffic into separate virtual interfaces, each corresponding to a specific network (Airport operations, Police/Security, Airlines). This segmentation ensures that data from one network remains isolated from others, maintaining security boundaries while using shared physical hardware. Each virtual interface processes and routes traffic independently.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The access point acts as an intermediary between mobile units and the distribution system. It receives data from mobile units, identifies the appropriate virtual network interface based on the service set identification, and routes the data to the corresponding distribution system. This intermediary function ensures proper data isolation and security while enabling efficient routing.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If duplicate access points are installed for each system, then network security is maintained, but the loss of substance (hardware resources) and installation cost increase

Engineering Contradiction:
Improvenetwork securityVSAvoidhardware resources and installation cost
Core Design Contradiction:
ReliabilityVSLoss of substance

Solution Approach 1:

The patent combines multiple access point functions into a single physical device. Instead of installing separate access points for Airport operations, Police/Security, and Airlines networks, the system uses one access point with multiple virtual interfaces, thereby reducing hardware consumption and installation costs while maintaining network security through virtualization.

Inventive Principle:
Principle #5Merging (Combining)

4Ease of operation

If multiple virtual networks share a common distribution system, then ease of operation and network management is improved, but the difficulty of detecting and measuring network-specific data may increase

Engineering Contradiction:
Improvenetwork managementVSAvoidnetwork-specific data routing
Core Design Contradiction:
Ease of operationVSDifficulty of detecting and measuring

Solution Approach 1:

The access point serves as an intermediary that maintains clear mapping between service set identifications and distribution system addresses. It processes incoming data by examining the service set identification, looking up the corresponding distribution system address in its memory, and routing the data appropriately. This intermediary function simplifies network management while maintaining clear data routing paths.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the access point continuously maintains and updates the mapping between service set identifications and distribution system addresses in its memory. This feedback loop ensures that network management operations can efficiently route data by simply providing the service set identification, and the system automatically determines the correct routing path.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS7280520B2Virtual wireless local area networks
Publication Date: 2007.10.09 EXTREME NETWORKS INC
  • US7280520B2 patent drawing
  • US7280520B2 patent drawing
  • US7280520B2 patent drawing

AI summary

A method of operating multiple virtual wireless networks using a common distribution system. Multiple radio frequency side networks are attached to multiple wired networks through a single access point. In this way messages may be sent between a mobile unit and a local area network. The mobile units and the local area networks are associated with identifiers which are used to route a sent message. The messages are sent from a mobile unit to a corresponding access point, which compares the identifier of the mobile unit with stored identifiers in its memory and assigns tags to the messages according to the intended local area network. The tagged messages are then sent from the access point to the distribution system that routes the message to the corresponding portal and to the local area network.