DHCP Processing for Layer Two Access Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security techniques fail to effectively prevent MAC collisions caused by configuration errors or MAC spoofing attempts, leading to unauthorized traffic redirection and potential network disruption.

Innovation Solution

Modifying access nodes and Dynamic Host Configuration Protocol (DHCP) servers to authorize only legitimate subscriber devices, storing associations between layer two and layer three addresses, and using layer three relay treatment to isolate DHCP data units, thereby preventing MAC collisions without disabling ports or requiring manual configuration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If MAC address-based switching is used to direct traffic, then network traffic can be directed to the correct subscriber device, but MAC collisions occur when the same MAC address is observed on multiple ports

Engineering Contradiction:
Improveautomatic traffic directionVSAvoidMAC address uniqueness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary verification mechanism where the access node checks MAC addresses against a database of authorized MAC addresses for each port before forwarding traffic. This intermediary layer prevents MAC collisions by blocking unauthorized MAC addresses while allowing legitimate traffic to pass through, thus maintaining reliability without compromising automatic traffic direction.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback by continuously monitoring MAC addresses on each port and comparing them against the authorized database. When a MAC collision is detected, the system provides feedback by disabling the affected port or generating alerts, enabling automatic correction of MAC address conflicts without manual intervention.

Inventive Principle:
Principle #23Feedback

2Reliability

If port disabling is used to prevent MAC collisions, then unauthorized traffic redirection is prevented, but network availability is reduced due to disabled ports

Engineering Contradiction:
ImproveMAC collision preventionVSAvoidnetwork availability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies dynamics by making port states adaptive rather than static. Ports are dynamically enabled or disabled based on real-time MAC address verification results. This allows the system to maintain high network availability by keeping ports active when no collisions are detected, while automatically disabling them only when necessary to prevent MAC collisions, thus balancing reliability and productivity.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary verification of MAC addresses against the authorized database before allowing traffic through the port. This preliminary action prevents MAC collisions from occurring in the first place, reducing the need for reactive port disabling and thereby maintaining higher network availability while ensuring reliability.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If manual configuration is used to resolve MAC collisions, then precise control over MAC address assignments is achieved, but operational complexity and time consumption increase

Engineering Contradiction:
ImproveMAC address assignment accuracyVSAvoidmanual configuration requirements
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling the access node to automatically detect MAC collisions, verify MAC addresses against the authorized database, and resolve conflicts without human intervention. The system autonomously disables affected ports or generates alerts, eliminating the need for manual configuration while maintaining precise MAC address assignment accuracy through automated verification processes.

Inventive Principle:
Principle #25Self-service

4Adaptability or versatility

If DHCP servers assign IP addresses without MAC collision detection, then device mobility is supported, but MAC spoofing attempts cannot be prevented

Engineering Contradiction:
Improvedevice mobilityVSAvoidMAC spoofing vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by implementing MAC address verification at the access node before devices can access the network, even before DHCP IP address assignment. This preemptive measure prevents MAC spoofing attempts by blocking devices with unauthorized MAC addresses at the point of entry, while still allowing legitimate mobile devices to obtain IP addresses through DHCP after their MAC addresses are verified as authorized.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS8862705B2Secure DHCP processing for layer two access networks
Publication Date: 2014.10.14 CALIX INC
  • US8862705B2 patent drawing
  • US8862705B2 patent drawing
  • US8862705B2 patent drawing

AI summary

In general, this disclosure describes network security techniques that may accommodate legitimate movement of a subscriber device while preventing MAC collisions that may result from configuration errors or MAC spoofing attempts. MAC spoofing may result in packets directed to one subscriber device being sent instead to another subscriber device. By modifying an access node or a Dynamic Host Configuration Protocol (DHCP) server to allow only authorized subscriber devices on the access network, layer two collisions (“MAC collisions”) may be prevented.