Wireless Client Group Isolation via Key-Based L2 Forwarding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network configurations face challenges in providing scalable and manageable Layer 2 (L2) isolation between devices of different users within a single VLAN domain, especially as the number of users exceeds a certain threshold, as traditional VLAN-based solutions become difficult to deploy and manage.
Innovation Solution
Implementing user-group-to-user-group isolation by processing L2 traffic based on user-specific keys (Pre-Shared Keys, PSKs) and hardware addresses, allowing network devices to forward traffic within the same user group while dropping traffic between different user groups, using device group information stored in network devices to enforce forwarding policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional VLAN-based isolation is used to separate devices of different users, then network security and isolation are improved, but device complexity and difficulty of deployment increase significantly when the number of users exceeds a certain threshold
Solution Approach 1:
The patent segments the network isolation problem by introducing a key identifier field that groups devices into different user groups. Instead of creating separate VLANs for each user (which becomes complex at scale), devices are segmented into logical groups using a simplified key-based mechanism that maintains isolation while reducing configuration complexity.
Solution Approach 2:
The patent changes the isolation parameter from VLAN ID-based segmentation to key identifier-based segmentation. This parameter change allows the network to maintain isolation properties while using a more scalable approach where the key identifier field in frame headers determines group membership, enabling thousands of user groups without proportional increases in complexity.
2Reliability
If VLAN-based isolation is implemented to prevent communication between different users, then network security is improved, but ease of operation and management deteriorate as the number of users increases
Solution Approach 1:
The patent makes the key identifier mechanism universal by applying it to all user groups in the network. A single key identifier field in the frame header serves multiple functions: it identifies user group membership, determines forwarding decisions, and enables isolation policies. This universal approach simplifies management compared to individual VLAN configurations for each user.
Solution Approach 2:
The patent introduces a key identifier as an intermediary element that mediates between the physical network infrastructure and the logical isolation requirements. This intermediary key field acts as a simplified interface that translates complex user group relationships into straightforward forwarding rules, improving ease of operation and management.
3Productivity
If L2 traffic is forwarded based on traditional MAC address routing, then network connectivity within VLANs is maintained, but unauthorized communication between different user groups occurs
Solution Approach 1:
The patent applies preliminary action by embedding the key identifier in the frame header at the point of frame generation or ingress into the network. This key identifier is prepared in advance and attached to each frame, enabling network devices to perform preliminary checks and enforce isolation policies before forwarding decisions are made, preventing unauthorized communication proactively rather than reactively.
Solution Approach 2:
The patent implements feedback by using the key identifier field to continuously inform forwarding decisions. Each frame carries its key identifier feedback, which network devices use to determine whether to forward or drop the frame based on the destination's group membership. This feedback mechanism ensures that connectivity is maintained within groups while blocking unauthorized cross-group communication.
Data Source
AI summary
A network device can be configured to access device group information organizing host devices into different user or user-specific key groups. The network device may perform data link layer (L2) forwarding based on the accessible device group information.


