VLAN Tunneling for Wireless Security Segregation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless local area networks (WLANs) lack sufficient security mechanisms to segregate and restrict broadcast and multicast transmissions across different virtual local area networks (VLANs), as these transmissions are provided to all associated wireless stations without segregation.

Innovation Solution

The system establishes separate communication paths between Access Points (APs) and network switches using Open Systems Interconnection Layer 3 (OSI-L3) tunnels, each assigned to a specific VLAN, employing different encryption keys and segregating users via a single Basic Service Set Identifier (BSSID), thereby enhancing security and segregating broadcast and multicast coverage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If broadcast and multicast transmissions are provided to all wireless stations associated with the AP, then network coverage is maximized, but security is compromised as transmissions cannot be segregated across different VLANs

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication path structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the single wireless communication path into multiple separate communication paths, each corresponding to a different VLAN. The AP establishes distinct communication paths to different network switches for different VLANs, allowing broadcast and multicast transmissions to be segregated and restricted to specific VLANs, thereby improving security without requiring physical separation of wireless stations.

Inventive Principle:
Principle #1Segmentation

2Reliability

If separate communication paths are established for each VLAN, then security and segregation are improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication path structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary mechanism where the AP acts as a mediator that establishes separate communication paths to different network switches for different VLANs. This intermediary approach allows the system to maintain security through path segregation while the AP manages the complexity of establishing and maintaining multiple paths, rather than requiring each wireless station to have separate physical connections.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8161543B2VLAN tunneling
Publication Date: 2012.04.17 HEWLETT PACKARD ENTERPRISE DEV LP
  • US8161543B2 patent drawing
  • US8161543B2 patent drawing
  • US8161543B2 patent drawing

AI summary

According to one embodiment of the invention, a method for establishing multiple tunnels for each virtual local area network is described. Upon receiving information over a first tunnel associated with a first virtual local area network, a determination is made whether the information is from a network device assigned to a second virtual local area network, which differs from the first virtual local area network. If the network device is a member of the second virtual local area network, a second tunnel associated with the second virtual local area network is created.