Wireless Network User Isolation via VLAN Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless network deployment methods in multi-unit buildings face issues with signal interference and privacy/security concerns due to overlapping coverage areas, leading to compromised user privacy and security, as well as limitations in controlling wireless devices outside the primary access point range.

Innovation Solution

The method involves strategically placing access points on non-adjacent channels and power levels, using configurable antenna beam patterns, and employing VLANs and access control lists to isolate users and devices, allowing secure and private access to authorized networks and devices from any location within the building.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a wireless router is placed in each individual unit to provide coverage, then each user can access wireless devices within their unit, but signal bleed over into neighboring units compromises privacy and security and causes interference between routers

Engineering Contradiction:
Improvewireless device control reliabilityVSAvoidsignal interference and privacy compromise
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The network is segmented into multiple Virtual Local Area Networks (VLANs), with each VLAN assigned to a specific unit. This logical segmentation isolates traffic between units, preventing signal bleed over from compromising privacy and security while allowing each unit to maintain its own wireless network for reliable device control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A central wireless controller or access point acts as an intermediary that manages communication between units. Instead of direct peer-to-peer communication that causes interference, the intermediary routes and isolates traffic, eliminating harmful signal bleed over while maintaining network functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If a unit's access point coverage area is expanded to allow control of wireless devices outside the unit, then users can control devices from remote locations, but this expands the coverage area and increases signal bleed over into neighboring units

Engineering Contradiction:
Improvewireless device control flexibilityVSAvoidaccess point coverage area
Core Design Contradiction:
Adaptability or versatilityVSArea of stationary object

Solution Approach 1:

The wireless network is divided into unit-specific VLANs that logically segment traffic. Users can roam throughout the building and connect to any access point, gaining flexibility to control devices from any location, while the VLAN segmentation ensures that expanded physical coverage does not result in harmful signal bleed over affecting neighboring units' privacy.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If users are allowed to access authorized networks and devices, then network functionality is maintained, but users may access unauthorized networks or devices in neighboring units

Engineering Contradiction:
Improvenetwork access convenienceVSAvoidunauthorized access and security risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The network is segmented into multiple VLANs, one for each unit, with access control policies that permit users to access only their authorized networks and devices. This segmentation maintains ease of operation within each unit while preventing unauthorized access to neighboring units, eliminating security risks associated with blanket network access.

Inventive Principle:
Principle #1Segmentation

4Adaptability or versatility

If the building owner operates a separate network to access internet and servers, then building owner network control is maintained, but this creates network complexity and potential interference with user networks

Engineering Contradiction:
Improvenetwork isolation capabilityVSAvoidnetwork configuration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The building owner's network is segmented into a separate VLAN, isolating it from user networks while maintaining the ability to access internet and servers. This logical segmentation provides network isolation capability without requiring physically separate infrastructure, thereby reducing complexity compared to completely separate networks while preventing interference between owner and user networks.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9544831B2System and method for network user isolation
Publication Date: 2017.01.10 SPOT ON NETWORKS LLC
  • US9544831B2 patent drawing
  • US9544831B2 patent drawing
  • US9544831B2 patent drawing

AI summary

A communications network for providing communications for Group 1 Users, Group 2 Users and a plurality of digitally-controlled appliances is disclosed. Said communications network includes a first switch operatively connected to a server, a router, a second switch, and a third switch. Said second switch is operatively connected to a first access point and a second access point. Said third switch is operatively connected to a third access point and a fourth access point. Said first access point is wirelessly connected to Device A, said second access point is wirelessly connected to Device B, said third access point is wirelessly connected to Device C. Said fourth access point is programmed to allow communications between User F wirelessly connected to said fourth access point and any said Group 1 Users, any said Group 2 Users, any of said plural appliances, said server, and said router.