WLAN Traffic Partitioning via MAC Layer Switching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless digital networks face challenges in partitioning traffic without relying on VLAN creation, particularly in enterprise networks where configuring and managing VLANs can be complex and prone to security vulnerabilities due to native VLANs.

Innovation Solution

A network device receives packets associated with pre-configured VLANs and transmits them to a MAC layer switching device without configuring the VLAN on the device, using techniques like DHCP relay and ARP proxy services to manage traffic on native VLANs, allowing for traffic separation without explicit VLAN setup.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If VLANs are configured on switches and routers to separate network traffic, then network security and traffic isolation are improved, but device complexity and administrative configuration burden increase

Engineering Contradiction:
Improvenetwork securityVSAvoidVLAN configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a wireless access point as an intermediary device that performs VLAN-like traffic separation functions without requiring VLAN configuration on downstream switches and routers. The access point acts as a mediator that segments traffic at the wireless interface level, allowing network administrators to achieve traffic isolation without the complexity of end-to-end VLAN configuration across all network devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments network traffic at the wireless access point level by creating separate virtual interfaces or SSIDs that correspond to different logical networks. This segmentation approach allows traffic from different departments or security zones to be separated at the point of wireless connection, eliminating the need for VLAN configuration on every switch and router in the network.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If native VLANs are used to maintain backward compatibility with legacy devices, then compatibility is improved, but security vulnerabilities increase due to untagged traffic

Engineering Contradiction:
Improvebackward compatibilityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent creates virtual copies of network interfaces at the wireless access point that emulate VLAN behavior for modern devices while presenting a unified untagged interface to legacy devices. This copying approach allows the system to maintain backward compatibility with legacy devices that don't understand VLAN tags, while simultaneously providing VLAN-like security isolation for devices that do support it.

Inventive Principle:
Principle #26Copying

3Reliability

If VLANs are configured to separate trust domains, then security isolation is improved, but ease of operation deteriorates due to complex DHCP and subnet configuration

Engineering Contradiction:
Improvesecurity isolationVSAvoidnetwork configuration ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges multiple VLAN configuration functions into a single wireless access point interface. By consolidating traffic separation, DHCP relay, and subnet management capabilities at the access point, the system eliminates the need for complex coordinated configuration across multiple switches and routers, significantly simplifying network administration while maintaining security isolation.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9756682B2Method and system for partitioning wireless local area network
Publication Date: 2017.09.05 HEWLETT PACKARD ENTERPRISE DEV LP
  • US9756682B2 patent drawing
  • US9756682B2 patent drawing
  • US9756682B2 patent drawing

AI summary

The present disclosure discloses a method and system for partitioning WLAN in order to separate network traffic from different WLANs. Specifically, a network device receives a packet from a client connected to a first network device on an access network. The network device then determines that the received packet is associated with a VLAN that is pre-configured on the first network device based on the access network to which the client is connected. Furthermore, the network device transmits the packet to a MAC layer switching device, which is not configured with the VLAN that is pre-configured on the network device. The packet includes one of a DHCP discovery message, an ARP request message, a unicast message, a multicast message, and a broadcast message. The unicast message will be transmitted to the second network device on the pre-configured VLAN prior to being transmitted to another network device outside the pre-configured VLAN.