Distributed Zone-Based Security Architecture for Layer 2 Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Layer2 security zone architectures are inadequate for distributed network environments, as they fail to account for non-local hosts and lack the ability to define security policies across multiple devices, leading to insufficient security control and packet egress path determination.

Innovation Solution

A distributed zone-based security method that uses MAC addresses and unique keys to determine ingress and egress security zones across multiple network devices, enabling policy lookup and application to ensure secure packet transfer between devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional security zone architecture is used, then security gateway can perform zone securing screening on local traffic, but it cannot determine egress path for non-local hosts and cannot define policies across multiple devices

Engineering Contradiction:
Improveability to handle distributed network trafficVSAvoidsecurity zone architecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the security zone into distributed components across multiple network devices. Each device maintains local security zone information while the system as a whole provides distributed security functionality. This allows the system to handle non-local hosts and inter-device traffic without requiring a single complex centralized controller.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a security zone database as an intermediary component that stores security zone information, packet egress paths, and policies. This intermediary enables different network devices to access consistent security information without direct peer-to-peer complexity, resolving the contradiction between adaptability and device complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If security zone operates within a single device, then implementation is simple, but user/administer cannot know host location and cannot define inter-device security policies

Engineering Contradiction:
Improvehost location informationVSAvoiddistributed security zone implementation
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent performs preliminary actions by pre-establishing security zone mappings, packet egress paths, and policies in the security zone database before traffic flows. This allows the system to immediately know host locations and apply appropriate policies without requiring complex real-time discovery mechanisms, reducing information loss while avoiding implementation complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security zone database serves multiple functions: storing zone information, tracking host locations, determining egress paths, and defining policies. This multi-functionality consolidates what would otherwise require multiple separate systems into a single component, reducing overall system complexity while providing comprehensive information.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If distributed security zones are implemented, then scalability and uniform policy application are improved, but policy lookup and application complexity increases

Engineering Contradiction:
Improvesecurity policy application efficiencyVSAvoidpolicy lookup mechanism
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent pre-computes and stores packet egress paths and security policies in the database before traffic arrives. When a packet needs processing, the system simply looks up the pre-determined path and applies the pre-defined policy, avoiding complex real-time calculations. This preliminary action significantly improves productivity while keeping the lookup mechanism simple.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates copies of security zone information and policies in the distributed database across multiple devices. This allows each device to independently perform policy lookups using local copies of the information, eliminating the need for complex inter-device coordination and centralization, thus improving efficiency without increasing operational complexity.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9419941B2Distributed computer network zone based security architecture
Publication Date: 2016.08.16 GRYPHO5 LLC
  • US9419941B2 patent drawing
  • US9419941B2 patent drawing
  • US9419941B2 patent drawing

AI summary

A method and apparatus is disclosed herein for distributed zone-based security. In one embodiment, the method comprises: determining an ingress security zone associated with an ingress of a first network device based on a first key and a media access control (MAC) address of a source of a packet; determining an egress security zone of a second network device based on a MAC address of a destination for the packet and a second key; performing a policy lookup based on the ingress security zone and the egress security zone to identify a policy to apply to the packet; and applying the policy to the packet.