Switch Port Security with LLDP MAC Association for Uplink Failover

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The conflict between port security mechanisms and redundancy mechanisms in network devices, such as access points (APs) and switches, leads to undesired interface shutdowns due to violations when multiple uplinks are used for failover, as port security rules restrict multiple MAC addresses on a single interface.

Innovation Solution

Utilizing organizationally specific TLV fields in LLDP control packets to associate and recognize multiple MAC addresses of a bonded interface as connected to a single AP, allowing these addresses to move between secure interfaces without triggering security violations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If port security mechanism is implemented to restrict MAC addresses on interfaces, then security is improved, but failover capability between multiple uplinks deteriorates due to interface shutdowns

Engineering Contradiction:
Improveport securityVSAvoidfailover capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces LLDP control packets as an intermediary mechanism between the AP and switch. These packets carry MAC address association information that mediates the conflict between port security (which needs to identify legitimate devices) and failover capability (which requires MAC addresses to move between interfaces). The LLDP packets enable the switch to understand that multiple MAC addresses belong to the same AP, allowing failover without security violations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary action by establishing MAC address associations through LLDP control packets before failover occurs. The switch learns and stores the relationships between multiple MAC addresses and the single AP in advance. When failover happens, the switch already has this information and can immediately allow the MAC addresses to move to different interfaces without triggering security violations, thus preventing interface shutdowns.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If multiple MAC addresses are allowed on a single interface for redundancy, then failover is improved, but port security rules are violated leading to interface shutdowns

Engineering Contradiction:
ImproveredundancyVSAvoidinterface stability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

LLDP control packets serve as the intermediary that resolves the conflict between redundancy requirements (multiple MAC addresses on interfaces) and port security rules. The packets provide the switch with information about which MAC addresses belong to the same AP, enabling the switch to make informed decisions about allowing multiple MAC addresses without violating security policies, thus preventing unnecessary interface shutdowns while maintaining redundancy.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system establishes MAC address associations through LLDP packets in advance, before any failover or security violation events occur. This preliminary action populates the switch's knowledge base with the relationships between MAC addresses and the AP. When redundancy operations occur (such as moving MAC addresses between interfaces during failover), the switch can immediately proceed without triggering security violations because the associations were already established, ensuring interface stability while maintaining redundancy capability.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If port security restricts MAC address movement between interfaces, then security control is improved, but seamless failover deteriorates due to security violations

Engineering Contradiction:
Improvesecurity controlVSAvoiddata transmission continuity
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

LLDP control packets act as the intermediary mechanism that enables seamless coordination between security control and failover operations. The packets carry association information that allows the switch to maintain security control (by knowing which MAC addresses belong to the same AP) while permitting MAC address movement between interfaces during failover. This eliminates security violations that would otherwise interrupt data transmission, ensuring continuity while maintaining security oversight.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary action by establishing MAC address associations through LLDP packets before failover events. This advance preparation enables the switch to recognize legitimate MAC address movements as part of normal failover operations rather than security threats. When failover occurs, the switch can immediately allow MAC addresses to move between interfaces without triggering security violations, thus maintaining data transmission continuity while preserving security control through the pre-established associations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12452202B2Method to support multiple uplinks failover between switch interfaces with port security
Publication Date: 2025.10.21 HEWLETT PACKARD ENTERPRISE DEV LP
  • US12452202B2 patent drawing
  • US12452202B2 patent drawing
  • US12452202B2 patent drawing

AI summary

A first switch port receives a first control packet, a header having a source media access control (MAC) address of a first MAC of a first interface of a sending device and a payload containing a second MAC of a second interface of the same sending device. The first and second interfaces form a bonded interface for failover purposes on the sending device. A second switch port receives a second control packet, a header having the second MAC as its source MAC and a payload containing the first MAC. The switch associates the first and second MAC addresses as related MAC addresses associated with the bonded interface. The switch facilitates failover between the secure interfaces via multiple uplinks while maintaining the port security on the switch by allowing transmission of data from either the first or second MAC address, associated as related MAC addresses, without triggering a port security violation.