Wireless Client Group Isolation via Key-Based L2 Forwarding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network configurations face challenges in providing scalable and manageable Layer 2 (L2) isolation between devices of different users within a single VLAN domain, especially as the number of users exceeds a certain threshold, as traditional VLAN-based solutions become difficult to deploy and manage.

Innovation Solution

Implementing user-group-to-user-group isolation by processing L2 traffic based on user-specific keys (Pre-Shared Keys, PSKs) and hardware addresses, allowing network devices to forward traffic within the same user group while dropping traffic between different user groups, using device group information stored in network devices to enforce forwarding policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional VLAN-based isolation is used to separate devices of different users, then network security and isolation are improved, but device complexity and difficulty of deployment increase significantly when the number of users exceeds a certain threshold

Engineering Contradiction:
Improvenetwork isolationVSAvoidVLAN configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the network isolation problem by introducing a key identifier field that groups devices into different user groups. Instead of creating separate VLANs for each user (which becomes complex at scale), devices are segmented into logical groups using a simplified key-based mechanism that maintains isolation while reducing configuration complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the isolation parameter from VLAN ID-based segmentation to key identifier-based segmentation. This parameter change allows the network to maintain isolation properties while using a more scalable approach where the key identifier field in frame headers determines group membership, enabling thousands of user groups without proportional increases in complexity.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If VLAN-based isolation is implemented to prevent communication between different users, then network security is improved, but ease of operation and management deteriorate as the number of users increases

Engineering Contradiction:
Improveuser isolationVSAvoidnetwork manageability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent makes the key identifier mechanism universal by applying it to all user groups in the network. A single key identifier field in the frame header serves multiple functions: it identifies user group membership, determines forwarding decisions, and enables isolation policies. This universal approach simplifies management compared to individual VLAN configurations for each user.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces a key identifier as an intermediary element that mediates between the physical network infrastructure and the logical isolation requirements. This intermediary key field acts as a simplified interface that translates complex user group relationships into straightforward forwarding rules, improving ease of operation and management.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If L2 traffic is forwarded based on traditional MAC address routing, then network connectivity within VLANs is maintained, but unauthorized communication between different user groups occurs

Engineering Contradiction:
Improvenetwork connectivityVSAvoidunauthorized communication
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by embedding the key identifier in the frame header at the point of frame generation or ingress into the network. This key identifier is prepared in advance and attached to each frame, enabling network devices to perform preliminary checks and enforce isolation policies before forwarding decisions are made, preventing unauthorized communication proactively rather than reactively.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback by using the key identifier field to continuously inform forwarding decisions. Each frame carries its key identifier feedback, which network devices use to determine whether to forward or drop the frame based on the destination's group membership. This feedback mechanism ensures that connectivity is maintained within groups while blocking unauthorized cross-group communication.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20240214802A1Wireless client group isolation within a network
Publication Date: 2024.06.27 ARISTA NETWORKS INC
  • US20240214802A1 patent drawing
  • US20240214802A1 patent drawing
  • US20240214802A1 patent drawing

AI summary

A network device can be configured to access device group information organizing host devices into different user or user-specific key groups. The network device may perform data link layer (L2) forwarding based on the accessible device group information.