VLAN Assignment via DHCP Token for Secure Network Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network environments face security exposure when a portable storage device is used to boot a PC, allowing unauthorized access to intranet resources, especially in scenarios where the PC is temporarily under external control, such as with a guest user, and traditional VLAN configurations require manual operations and are not dynamic enough to ensure isolation.

Innovation Solution

Implementing a system that automatically configures client access to a network by using DHCP for IP-level configurations and combining it with a VLAN configuration scheme, where a client stack carries a token identifying its trustworthiness, allowing the DHCP server to invoke a VLAN configuration routine to assign the port to a suitable VLAN based on security policies, thereby isolating machines and maintaining network security across multiple layers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual VLAN configuration is used to isolate network resources, then network security is improved, but device complexity and operational difficulty increase

Engineering Contradiction:
Improvenetwork securityVSAvoidVLAN configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs self-service by automatically detecting the portable device's identity and credentials, then autonomously configuring the appropriate VLAN assignment without requiring manual network administrator intervention. The portable device itself provides the necessary authentication information that triggers the automated VLAN configuration process.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary action by pre-configuring multiple VLAN options and security policies in advance, then automatically selecting and applying the appropriate configuration based on the portable device's authentication results. This eliminates the need for manual real-time configuration decisions.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual VLAN configuration operations are required before machine allocation, then network security is ensured, but productivity and ease of operation decrease

Engineering Contradiction:
Improvenetwork securityVSAvoidmachine allocation speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system enables self-service by automatically performing VLAN configuration as the portable device boots and authenticates, eliminating the need for pre-allocation manual setup. The entire security configuration process occurs automatically during the device's initial connection, maintaining security while dramatically improving productivity.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If the PC is trusted based on wall port connection, then ease of operation is improved, but security exposure increases

Engineering Contradiction:
Improvenetwork access convenienceVSAvoidsecurity exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system applies local quality by providing different network access permissions to different portable devices based on their specific authentication credentials. Instead of a blanket trust policy for all devices on a wall port, each device receives a customized VLAN assignment that grants only the appropriate level of access, maintaining convenience while eliminating security exposure.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system segments the network into multiple VLANs with different security levels, separating trusted devices from untrusted ones. This segmentation allows the PC to maintain ease of operation for authorized users while preventing security exposure by isolating unauthenticated portable devices in restricted VLANs.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8973098B2System and method for virtualized resource configuration
Publication Date: 2015.03.03 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US8973098B2 patent drawing
  • US8973098B2 patent drawing
  • US8973098B2 patent drawing

AI summary

A system and method for configuring client access to a network includes at a first port, accessing a first server on a first local area network associated with the first port. An authorized local area network other than the first local area network is determined to which an authorized connection can be properly made based on information in a client request. The first port is assigned to the authorized local area network. Communications are handled with a new client configuration in the authorized local area network.