Frame Processing Apparatus for Home Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In home networks, Ethernet frames with broadcast or multicast addresses are inadvertently received by unauthorized terminals due to the lack of virtualization technology and special processing, leading to security breaches and inefficient data transmission.

Innovation Solution

A frame processing method and apparatus that convert data link layer frames with multiple addresses into unicast frames by replacing the destination address with predetermined unicast addresses, allowing only preauthorized terminals to receive and process the frames without virtualization technology or special terminal processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If broadcast or multicast addresses are used for frame transmission, then transmission efficiency is improved by sending to multiple terminals simultaneously, but security deteriorates because unauthorized terminals cannot be prevented from receiving the frames

Engineering Contradiction:
Improvetransmission efficiencyVSAvoidsecurity breach
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the frame transmission process by separating the destination address field into multiple components: a group identifier portion (for broadcast/multicast grouping) and a terminal-specific identifier portion. This allows the frame to be efficiently delivered to multiple terminals while enabling each terminal to determine whether it is an authorized recipient based on matching its identifier with the terminal-specific portion of the destination address.

Inventive Principle:
Principle #1Segmentation

2Reliability

If tunneling parts are provided in terminals for configuring communication tunnels, then security is improved by enabling authorized communication, but device complexity increases due to requiring special processing components in each terminal

Engineering Contradiction:
Improveauthorized communicationVSAvoidterminal processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent enables terminals to autonomously determine their authorization status by comparing their own terminal identifiers with the terminal-specific identifier portion embedded in the destination address of received frames. This self-service mechanism eliminates the need for complex tunneling parts or special processing components in each terminal, as the security verification is performed automatically using simple identifier matching.

Inventive Principle:
Principle #25Self-service

3Reliability

If VLAN virtualization technology is used for grouping terminals, then security is improved by isolating communication groups, but ease of operation deteriorates due to requiring virtualization configuration

Engineering Contradiction:
Improvecommunication isolationVSAvoidconfiguration simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent changes the addressing parameter structure by incorporating both group identification and terminal-specific identification within the destination address field itself. This parameter change enables communication grouping and security isolation similar to VLAN functionality, but without requiring separate virtualization configuration, as the grouping information is directly embedded in the frame address that terminals naturally process.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8102847B2Frame processing method and frame processing apparatus
Publication Date: 2012.01.24 NEC CORP
  • US8102847B2 patent drawing
  • US8102847B2 patent drawing
  • US8102847B2 patent drawing

AI summary

When a data link layer frame whose destination address has been designated as a multiple address is inputted from a tunneling source via a decapsulation unit 202, a destination processing unit 201 generates data link layer frames in which the destination address of the frame is replaced with each of one or more unicast addresses that are preset in a table unit 205 for a source address of the data link layer frame and outputs the generated frames to a local network 11.