ELI MAC Address Encoding for Multi-Vendor Group Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems struggle to enforce group identity and policy across multi-vendor environments due to differing operating mechanisms, leading to uncontrolled communication between devices belonging to different users.

Innovation Solution

Encoding a User Defined Network (UDN) Identifier and client ID within the source Media Access Control (MAC) address of a frame, enabling policy enforcement through a distributed architecture that allows group and client identity to traverse networks using an in-band assignment/encoding process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional systems are used in multi-vendor environments, then device compatibility and network coverage are improved, but group identity enforcement and policy control deteriorate due to differing operating mechanisms

Engineering Contradiction:
Improvedevice compatibilityVSAvoidpolicy enforcement
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies homogeneity by encoding group identity information in a standardized format within the MAC address structure that is universally recognized across all vendor devices. The ELI MAC address format provides a uniform method for representing group membership that works consistently across multi-vendor environments, eliminating the fragmentation caused by different vendor-specific implementations.

Inventive Principle:
Principle #33Homogeneity

Solution Approach 2:

The patent introduces an intermediary mechanism by using the ELI MAC address as a carrier that mediates between the physical device layer and the policy enforcement layer. This intermediary encoding structure allows group identity information to be transported through the network infrastructure without requiring vendor-specific protocol modifications, enabling centralized policy control across diverse devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If group identity enforcement is implemented across multi-vendor environments, then policy control and security are improved, but system complexity increases due to differing operating mechanisms

Engineering Contradiction:
Improvepolicy enforcementVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts group identity information from complex vendor-specific protocol stacks and consolidates it into a simple, standardized ELI MAC address format. By taking out the essential group identification function from the messy multi-vendor protocol environment and representing it in a clean, uniform structure, the system achieves policy enforcement without proportionally increasing complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The ELI MAC address structure serves multiple functions simultaneously: it provides standard device identification, encodes group membership information, and enables policy enforcement decisions. This multi-functionality reduces the need for separate complexity layers for each function, as the same encoded structure handles identification, grouping, and policy control across all vendor devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If vendor-specific solutions are used for group management, then policy control within single-vendor environments is improved, but adaptability to multi-vendor environments deteriorates

Engineering Contradiction:
Improvepolicy controlVSAvoidmulti-vendor compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent replaces heterogeneous vendor-specific group management approaches with a homogeneous ELI MAC address encoding scheme. This standardized format ensures that group identity information is represented consistently regardless of the device vendor, enabling uniform policy control across multi-vendor environments while maintaining the effectiveness originally achieved in single-vendor systems.

Inventive Principle:
Principle #33Homogeneity

Data Source

PatentUS12526282B2Group identity assignment and policy enforcement for devices within the same network
Publication Date: 2026.01.13 CISCO TECHNOLOGY INC
  • US12526282B2 patent drawing
  • US12526282B2 patent drawing
  • US12526282B2 patent drawing

AI summary

Group identity assignment and policy enforcement may be provided. A User Defined Network Identifier (UDN ID) defining a group of client devices may be received. Next, a client identifier (ID) associated with a source client device that is associated with the group of client devices may be received. The UDN ID and the client ID may be encoded in an Extended Local Identifier (ELI) Media Access Control (MAC) address associated with the source client device. A source MAC address of a packet received from the source client device may then be substituted with the ELI MAC address. Then the packet may be forwarded.