DHCP Processing for Layer Two Access Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security techniques fail to effectively prevent MAC collisions caused by configuration errors or MAC spoofing attempts, leading to unauthorized traffic redirection and potential network disruption.
Innovation Solution
Modifying access nodes and Dynamic Host Configuration Protocol (DHCP) servers to authorize only legitimate subscriber devices, storing associations between layer two and layer three addresses, and using layer three relay treatment to isolate DHCP data units, thereby preventing MAC collisions without disabling ports or requiring manual configuration.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If MAC address-based switching is used to direct traffic, then network traffic can be directed to the correct subscriber device, but MAC collisions occur when the same MAC address is observed on multiple ports
Solution Approach 1:
The patent introduces an intermediary verification mechanism where the access node checks MAC addresses against a database of authorized MAC addresses for each port before forwarding traffic. This intermediary layer prevents MAC collisions by blocking unauthorized MAC addresses while allowing legitimate traffic to pass through, thus maintaining reliability without compromising automatic traffic direction.
Solution Approach 2:
The system implements feedback by continuously monitoring MAC addresses on each port and comparing them against the authorized database. When a MAC collision is detected, the system provides feedback by disabling the affected port or generating alerts, enabling automatic correction of MAC address conflicts without manual intervention.
2Reliability
If port disabling is used to prevent MAC collisions, then unauthorized traffic redirection is prevented, but network availability is reduced due to disabled ports
Solution Approach 1:
The patent applies dynamics by making port states adaptive rather than static. Ports are dynamically enabled or disabled based on real-time MAC address verification results. This allows the system to maintain high network availability by keeping ports active when no collisions are detected, while automatically disabling them only when necessary to prevent MAC collisions, thus balancing reliability and productivity.
Solution Approach 2:
The system performs preliminary verification of MAC addresses against the authorized database before allowing traffic through the port. This preliminary action prevents MAC collisions from occurring in the first place, reducing the need for reactive port disabling and thereby maintaining higher network availability while ensuring reliability.
3Measurement precision
If manual configuration is used to resolve MAC collisions, then precise control over MAC address assignments is achieved, but operational complexity and time consumption increase
Solution Approach 1:
The patent implements self-service by enabling the access node to automatically detect MAC collisions, verify MAC addresses against the authorized database, and resolve conflicts without human intervention. The system autonomously disables affected ports or generates alerts, eliminating the need for manual configuration while maintaining precise MAC address assignment accuracy through automated verification processes.
4Adaptability or versatility
If DHCP servers assign IP addresses without MAC collision detection, then device mobility is supported, but MAC spoofing attempts cannot be prevented
Solution Approach 1:
The patent applies preliminary anti-action by implementing MAC address verification at the access node before devices can access the network, even before DHCP IP address assignment. This preemptive measure prevents MAC spoofing attempts by blocking devices with unauthorized MAC addresses at the point of entry, while still allowing legitimate mobile devices to obtain IP addresses through DHCP after their MAC addresses are verified as authorized.
Data Source
AI summary
In general, this disclosure describes network security techniques that may accommodate legitimate movement of a subscriber device while preventing MAC collisions that may result from configuration errors or MAC spoofing attempts. MAC spoofing may result in packets directed to one subscriber device being sent instead to another subscriber device. By modifying an access node or a Dynamic Host Configuration Protocol (DHCP) server to allow only authorized subscriber devices on the access network, layer two collisions (“MAC collisions”) may be prevented.


