VLAN Communication Control Using Edge Identification for Duplicate IPs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication control systems face challenges in managing information efficiently and cost-effectively, particularly when dealing with duplicate IP addresses and high-quality traffic in networks with logically divided VLANs, leading to communication interruptions and high operational costs.

Innovation Solution

A communication control device that detects unauthorized communication within VLANs, identifies edge devices using DHCP or router advertisements, and instructs them to control communication, eliminating the need for constant database updates and manual management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of energy

If centralized deployment of quality control functions is implemented, then cost is reduced, but flexible control between subscriber terminals and quality control functions becomes impossible

Engineering Contradiction:
ImprovecostVSAvoidflexible control
Core Design Contradiction:
Loss of energyVSAdaptability or versatility

Solution Approach 1:

The system segments the network into multiple VLANs with edge devices distributed at different locations. Each edge device independently performs quality control functions for its local VLAN, eliminating the need for centralized deployment while maintaining cost efficiency. This segmentation allows flexible control within each VLAN while reducing overall system costs.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If distributed deployment of quality control functions is implemented, then flexible control is enabled, but cost increases due to distributed deployment

Engineering Contradiction:
Improveflexible controlVSAvoidcost
Core Design Contradiction:
Adaptability or versatilityVSLoss of energy

Solution Approach 1:

Edge devices are equipped with autonomous capabilities to detect unauthorized communication, identify themselves through publicity mechanisms, and control communication without requiring centralized management. This self-service approach enables flexible control while reducing operational costs by eliminating the need for centralized deployment and manual management.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If security devices constantly update and manage information to identify IP addresses and communication devices, then communication control accuracy is improved, but information management cost increases

Engineering Contradiction:
Improvecommunication control accuracyVSAvoidinformation management cost
Core Design Contradiction:
Measurement precisionVSLoss of energy

Solution Approach 1:

The system performs preliminary identification of edge devices through publicity mechanisms before unauthorized communication occurs. Edge devices publicly advertise their presence and identity in advance, so when unauthorized communication is detected, the system can immediately identify and control the communication without requiring constant information updates or manual management, maintaining accuracy while reducing costs.

Inventive Principle:
Principle #10Preliminary action

4Ease of operation

If IP address-based blocking is used to counter unauthorized communication, then communication control is simplified, but it becomes ineffective when duplicate IP addresses are used with VLANs

Engineering Contradiction:
Improvecommunication control simplicityVSAvoidblocking effectiveness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system implements a feedback mechanism where edge devices respond to publicity signals with their unique device identifiers. When unauthorized communication is detected, the system uses this pre-established feedback information to accurately identify and block the specific edge device responsible, rather than relying solely on IP addresses. This maintains blocking effectiveness even when duplicate IP addresses are used across different VLANs.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250219994A1Communication control device, communication control method, and communication control program
Publication Date: 2025.07.03 NIPPON TELEGRAPH & TELEPHONE CORP
  • US20250219994A1 patent drawing
  • US20250219994A1 patent drawing
  • US20250219994A1 patent drawing

AI summary

A security device (10) detects unauthorized communication in each of VLANs in a network in which each edge device (20) is logically divided into different VLANs. Also, when detecting unauthorized communication, the security device (10) publicizes predetermined data in the VLAN in which the unauthorized communication is detected and identifies the edge device (20) in the VLAN based on the response to the publicity. Subsequently, the security device (10) instructs the identified edge device (20) to control communication against unauthorized communications.