VLAN Communication Control Using Edge Identification for Duplicate IPs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication control systems face challenges in managing information efficiently and cost-effectively, particularly when dealing with duplicate IP addresses and high-quality traffic in networks with logically divided VLANs, leading to communication interruptions and high operational costs.
Innovation Solution
A communication control device that detects unauthorized communication within VLANs, identifies edge devices using DHCP or router advertisements, and instructs them to control communication, eliminating the need for constant database updates and manual management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of energy
If centralized deployment of quality control functions is implemented, then cost is reduced, but flexible control between subscriber terminals and quality control functions becomes impossible
Solution Approach 1:
The system segments the network into multiple VLANs with edge devices distributed at different locations. Each edge device independently performs quality control functions for its local VLAN, eliminating the need for centralized deployment while maintaining cost efficiency. This segmentation allows flexible control within each VLAN while reducing overall system costs.
2Adaptability or versatility
If distributed deployment of quality control functions is implemented, then flexible control is enabled, but cost increases due to distributed deployment
Solution Approach 1:
Edge devices are equipped with autonomous capabilities to detect unauthorized communication, identify themselves through publicity mechanisms, and control communication without requiring centralized management. This self-service approach enables flexible control while reducing operational costs by eliminating the need for centralized deployment and manual management.
3Measurement precision
If security devices constantly update and manage information to identify IP addresses and communication devices, then communication control accuracy is improved, but information management cost increases
Solution Approach 1:
The system performs preliminary identification of edge devices through publicity mechanisms before unauthorized communication occurs. Edge devices publicly advertise their presence and identity in advance, so when unauthorized communication is detected, the system can immediately identify and control the communication without requiring constant information updates or manual management, maintaining accuracy while reducing costs.
4Ease of operation
If IP address-based blocking is used to counter unauthorized communication, then communication control is simplified, but it becomes ineffective when duplicate IP addresses are used with VLANs
Solution Approach 1:
The system implements a feedback mechanism where edge devices respond to publicity signals with their unique device identifiers. When unauthorized communication is detected, the system uses this pre-established feedback information to accurately identify and block the specific edge device responsible, rather than relying solely on IP addresses. This maintains blocking effectiveness even when duplicate IP addresses are used across different VLANs.
Data Source
AI summary
A security device (10) detects unauthorized communication in each of VLANs in a network in which each edge device (20) is logically divided into different VLANs. Also, when detecting unauthorized communication, the security device (10) publicizes predetermined data in the VLAN in which the unauthorized communication is detected and identifies the edge device (20) in the VLAN based on the response to the publicity. Subsequently, the security device (10) instructs the identified edge device (20) to control communication against unauthorized communications.


