WLAN Traffic Partitioning via MAC Layer Switching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless digital networks face challenges in partitioning traffic without relying on VLAN creation, particularly in enterprise networks where configuring and managing VLANs can be complex and prone to security vulnerabilities due to native VLANs.
Innovation Solution
A network device receives packets associated with pre-configured VLANs and transmits them to a MAC layer switching device without configuring the VLAN on the device, using techniques like DHCP relay and ARP proxy services to manage traffic on native VLANs, allowing for traffic separation without explicit VLAN setup.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If VLANs are configured on switches and routers to separate network traffic, then network security and traffic isolation are improved, but device complexity and administrative configuration burden increase
Solution Approach 1:
The patent introduces a wireless access point as an intermediary device that performs VLAN-like traffic separation functions without requiring VLAN configuration on downstream switches and routers. The access point acts as a mediator that segments traffic at the wireless interface level, allowing network administrators to achieve traffic isolation without the complexity of end-to-end VLAN configuration across all network devices.
Solution Approach 2:
The patent segments network traffic at the wireless access point level by creating separate virtual interfaces or SSIDs that correspond to different logical networks. This segmentation approach allows traffic from different departments or security zones to be separated at the point of wireless connection, eliminating the need for VLAN configuration on every switch and router in the network.
2Adaptability or versatility
If native VLANs are used to maintain backward compatibility with legacy devices, then compatibility is improved, but security vulnerabilities increase due to untagged traffic
Solution Approach 1:
The patent creates virtual copies of network interfaces at the wireless access point that emulate VLAN behavior for modern devices while presenting a unified untagged interface to legacy devices. This copying approach allows the system to maintain backward compatibility with legacy devices that don't understand VLAN tags, while simultaneously providing VLAN-like security isolation for devices that do support it.
3Reliability
If VLANs are configured to separate trust domains, then security isolation is improved, but ease of operation deteriorates due to complex DHCP and subnet configuration
Solution Approach 1:
The patent merges multiple VLAN configuration functions into a single wireless access point interface. By consolidating traffic separation, DHCP relay, and subnet management capabilities at the access point, the system eliminates the need for complex coordinated configuration across multiple switches and routers, significantly simplifying network administration while maintaining security isolation.
Data Source
AI summary
The present disclosure discloses a method and system for partitioning WLAN in order to separate network traffic from different WLANs. Specifically, a network device receives a packet from a client connected to a first network device on an access network. The network device then determines that the received packet is associated with a VLAN that is pre-configured on the first network device based on the access network to which the client is connected. Furthermore, the network device transmits the packet to a MAC layer switching device, which is not configured with the VLAN that is pre-configured on the network device. The packet includes one of a DHCP discovery message, an ARP request message, a unicast message, a multicast message, and a broadcast message. The unicast message will be transmitted to the second network device on the pre-configured VLAN prior to being transmitted to another network device outside the pre-configured VLAN.


