WLAN Isolation Layer for Control Data Plane Separation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current WLAN management architectures, such as CAPWAP, are complex and difficult to manage, lacking mechanisms for virtual network provisioning and fine-grained control over data and control messages, which complicates the separation and distribution of control and data planes.
Innovation Solution
A system with a virtual access point (VAP) and physical access point (WTP) connected via an isolation layer, where the isolation layer handles data frames and control messages between them, allowing for seamless virtual network provisioning and compatibility with existing management software by using virtual WLAN interfaces and an isolation switch with a controller to manage traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a central AP controller manages several APs using CAPWAP protocol, then control plane tasks are centralized and AP complexity is reduced, but the system requires specialized management software and lacks mechanisms for virtual network provisioning
Solution Approach 1:
The system segments the control plane and data plane by introducing a Virtual Access Point (VAP) that runs on a virtual machine host, separating control functions from physical hardware management. The VAP virtualizes WLAN interfaces and exposes them through standard APIs, enabling virtual network provisioning without requiring specialized CAPWAP management software.
Solution Approach 2:
An isolation layer is introduced as an intermediary between the VAP and the Wireless Termination Point (WTP). This isolation layer handles data frames and control messages, allowing the VAP to provision virtual networks while maintaining compatibility with existing WTP hardware and management systems.
2Adaptability or versatility
If an AP comprises multiple wireless interface cards and a software stack managing radio parameters, then the AP can handle multiple wireless connections, but the architecture becomes complex and difficult to manage
Solution Approach 1:
The system creates virtual copies of WLAN interfaces through the VAP, which exposes virtual WLAN interfaces with the same API as real interfaces. This allows multiple virtual connections to be managed through a standardized interface, reducing architectural complexity while maintaining multi-connection capability.
Solution Approach 2:
The VAP provides universal management of wireless interfaces by exposing a common API that works across different physical wireless interface cards. The isolation layer handles the complexity of multi-card management, allowing the VAP to manage multiple wireless connections through a unified interface.
3Adaptability or versatility
If virtual machines are hosted on a physical AP through operating system virtualization, then multiple virtual access points can access the WLAN interfaces, but radio settings are controlled by the hypervisor and not within the virtual machine
Solution Approach 1:
The isolation layer acts as an intermediary that allows the VAP to control radio settings for virtual networks. Control messages are sent through the isolation layer to the WTP, enabling the VAP to manage radio parameters for its virtual networks while the WTP handles the actual radio hardware control.
4Reliability
If an isolation layer is introduced between VAPs and WTPs, then traffic and network virtualization are isolated, but additional system components are added
Solution Approach 1:
The isolation layer is designed as a streamlined intermediary that provides essential isolation functions without adding significant complexity. It handles data frames and control messages between the VAP and WTP, providing traffic isolation and network virtualization support with minimal additional components.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present invention provides a system for providing of control plane and data plane in a WLAN. The system comprises: a physical access point providing data connectivity for a user equipment, at least one virtual access point controlling the data connectivity, and an isolation layer connected with the physical access point and the virtual access point. The isolation layer is configured to handle data frames in the data plane and control messages in the control plane between the physical access point and the virtual access point. According to a further aspect, the present invention also provides a method for providing of control plane and data plane in a WLAN, preferably using the above described system.