Distributed Zone-Based Security Architecture for Layer 2 Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Layer2 security zone architectures are inadequate for distributed network environments, as they fail to account for non-local hosts and lack the ability to define security policies across multiple devices, leading to insufficient security control and packet egress path determination.
Innovation Solution
A distributed zone-based security method that uses MAC addresses and unique keys to determine ingress and egress security zones across multiple network devices, enabling policy lookup and application to ensure secure packet transfer between devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional security zone architecture is used, then security gateway can perform zone securing screening on local traffic, but it cannot determine egress path for non-local hosts and cannot define policies across multiple devices
Solution Approach 1:
The patent segments the security zone into distributed components across multiple network devices. Each device maintains local security zone information while the system as a whole provides distributed security functionality. This allows the system to handle non-local hosts and inter-device traffic without requiring a single complex centralized controller.
Solution Approach 2:
The patent introduces a security zone database as an intermediary component that stores security zone information, packet egress paths, and policies. This intermediary enables different network devices to access consistent security information without direct peer-to-peer complexity, resolving the contradiction between adaptability and device complexity.
2Loss of information
If security zone operates within a single device, then implementation is simple, but user/administer cannot know host location and cannot define inter-device security policies
Solution Approach 1:
The patent performs preliminary actions by pre-establishing security zone mappings, packet egress paths, and policies in the security zone database before traffic flows. This allows the system to immediately know host locations and apply appropriate policies without requiring complex real-time discovery mechanisms, reducing information loss while avoiding implementation complexity.
Solution Approach 2:
The security zone database serves multiple functions: storing zone information, tracking host locations, determining egress paths, and defining policies. This multi-functionality consolidates what would otherwise require multiple separate systems into a single component, reducing overall system complexity while providing comprehensive information.
3Productivity
If distributed security zones are implemented, then scalability and uniform policy application are improved, but policy lookup and application complexity increases
Solution Approach 1:
The patent pre-computes and stores packet egress paths and security policies in the database before traffic arrives. When a packet needs processing, the system simply looks up the pre-determined path and applies the pre-defined policy, avoiding complex real-time calculations. This preliminary action significantly improves productivity while keeping the lookup mechanism simple.
Solution Approach 2:
The patent creates copies of security zone information and policies in the distributed database across multiple devices. This allows each device to independently perform policy lookups using local copies of the information, eliminating the need for complex inter-device coordination and centralization, thus improving efficiency without increasing operational complexity.
Data Source
AI summary
A method and apparatus is disclosed herein for distributed zone-based security. In one embodiment, the method comprises: determining an ingress security zone associated with an ingress of a first network device based on a first key and a media access control (MAC) address of a source of a packet; determining an egress security zone of a second network device based on a MAC address of a destination for the packet and a second key; performing a policy lookup based on the ingress security zone and the egress security zone to identify a policy to apply to the packet; and applying the policy to the packet.


