VLAN Tunneling for Wireless Security Segregation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wireless local area networks (WLANs) lack sufficient security mechanisms to segregate and restrict broadcast and multicast transmissions across different virtual local area networks (VLANs), as these transmissions are provided to all associated wireless stations without segregation.
Innovation Solution
The system establishes separate communication paths between Access Points (APs) and network switches using Open Systems Interconnection Layer 3 (OSI-L3) tunnels, each assigned to a specific VLAN, employing different encryption keys and segregating users via a single Basic Service Set Identifier (BSSID), thereby enhancing security and segregating broadcast and multicast coverage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If broadcast and multicast transmissions are provided to all wireless stations associated with the AP, then network coverage is maximized, but security is compromised as transmissions cannot be segregated across different VLANs
Solution Approach 1:
The patent segments the single wireless communication path into multiple separate communication paths, each corresponding to a different VLAN. The AP establishes distinct communication paths to different network switches for different VLANs, allowing broadcast and multicast transmissions to be segregated and restricted to specific VLANs, thereby improving security without requiring physical separation of wireless stations.
2Reliability
If separate communication paths are established for each VLAN, then security and segregation are improved, but device complexity increases
Solution Approach 1:
The patent introduces an intermediary mechanism where the AP acts as a mediator that establishes separate communication paths to different network switches for different VLANs. This intermediary approach allows the system to maintain security through path segregation while the AP manages the complexity of establishing and maintaining multiple paths, rather than requiring each wireless station to have separate physical connections.
Data Source
AI summary
According to one embodiment of the invention, a method for establishing multiple tunnels for each virtual local area network is described. Upon receiving information over a first tunnel associated with a first virtual local area network, a determination is made whether the information is from a network device assigned to a second virtual local area network, which differs from the first virtual local area network. If the network device is a member of the second virtual local area network, a second tunnel associated with the second virtual local area network is created.


