Aggregated Networking Station Move Control via Static MAC Entries

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional station move control functionality in aggregated networking device subsystems, such as those using the Virtual Link Trunking (VLT) protocol, is limited to a single switch device and fails to provide secure MAC address management across multiple nodes, leading to reduced security as 'orphan' ports are not recognized, allowing unauthorized MAC address moves.

Innovation Solution

An Information Handling System (IHS) with a processing system and memory that includes instructions to generate a static MAC address entry associating learned MAC addresses with an Inter-Chassis Link (ICL) and program rules to manage MAC address associations on non-ICL ports, ensuring secure MAC address movement control across aggregated networking devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If station move control functionality is implemented in a single switch device, then MAC address security is improved on that device, but security is weakened across aggregated networking device subsystems due to orphan port recognition failures

Engineering Contradiction:
ImproveMAC address securityVSAvoidcross-device security management
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent merges station move control functionality across multiple switch devices in an aggregated networking subsystem. The first switch device shares MAC address information with the second switch device through inter-chassis links, enabling coordinated security enforcement. When a MAC address is learned on a port-security-enabled port at the first switch device, this information is propagated to the second switch device, which then enforces the same security policy on its non-ICL ports, effectively extending station move control across the aggregated subsystem.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces an intermediary information sharing mechanism between aggregated switch devices. The first switch device acts as the primary controller that learns MAC addresses and generates security policies, while the second switch device acts as a follower that receives and enforces these policies. This intermediary communication through shared memory or messaging protocols enables coordinated security enforcement without requiring complex peer-to-peer coordination between all devices in the aggregate.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If port security is enabled on all ports to prevent unauthorized MAC moves, then security is improved, but network flexibility deteriorates as legitimate MAC address movements are blocked

Engineering Contradiction:
Improvenetwork securityVSAvoidMAC address mobility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies different security policies to different ports based on their security requirements. Port-security-enabled ports enforce strict station move control to prevent unauthorized MAC address movements and potential security threats. In contrast, ports with port security disabled allow legitimate MAC address movements for devices that need to move between ports. This localized quality approach ensures that security is enforced only where necessary, maintaining both security and network flexibility.

Inventive Principle:
Principle #3Local quality

3Reliability

If static MAC address entries are created for all learned MAC addresses, then MAC move control is improved, but system performance deteriorates due to increased memory and processing requirements

Engineering Contradiction:
ImproveMAC address control accuracyVSAvoidswitching performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements partial station move control by creating static MAC address entries only for MAC addresses learned on port-security-enabled ports, rather than for all learned MAC addresses. This selective approach ensures that security-critical MAC addresses are controlled while avoiding the performance penalty of creating static entries for every MAC address in the network. The system applies the computationally intensive static entry creation only where security requirements demand it.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11985171B2Aggregated networking subsystem station move control system
Publication Date: 2024.05.14 DELL PROD LP
  • US11985171B2 patent drawing
  • US11985171B2 patent drawing
  • US11985171B2 patent drawing

AI summary

An aggregated networking device subsystem station move control system includes first and second aggregated networking devices connected via an ICL. The first aggregated networking device receives a MAC address from the second aggregated networking device that was learned on an orphan port that has port security enabled and a station-move-deny configuration, and generates a static MAC address entry in its MAC address table that associates the MAC address with the ICL. The static MAC address entry causes data packets received on non-ICL ports on the first aggregated networking device that include the MAC address to generate a static MAC move violation. The first aggregated networking device also programs rule(s) that, in response to data packets being received on its non-ICL ports that have port security disabled and generating a static MAC move violation, causes the association of the MAC address with that non-ICL port.