MAC Address Modification for Local Bridge Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In networks with separate hardware devices for security functions and wireless access point capability, communications between client devices are hindered by the formation of local bridges, which prevent data from traversing through the network security device, thereby obstructing the application of security policies.

Innovation Solution

Implementing MAC address modification and management techniques that authenticate clients and modify packet MAC addresses to route them through a security device for deep packet inspection, firewall operations, and content filtering, using an address resolution table to ensure accurate MAC address updates and routing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If separate hardware devices are used for security functions and wireless access point capability, then cost is reduced and wireless coverage is extended, but security policies cannot be effectively applied to communications between client devices

Engineering Contradiction:
Improvecost reductionVSAvoidsecurity policy enforcement
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent introduces a local bridge as an intermediary component that connects client devices associated with the same access point. This local bridge intercepts traffic between clients before it reaches the security device, allowing the security device to inspect and enforce security policies on local traffic while maintaining the cost benefits of separate hardware devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of time

If a local bridge is created by the shared access point device, then latency is reduced for local communications, but data is not filtered through the network security device

Engineering Contradiction:
Improvelatency reductionVSAvoidunfiltered data transmission
Core Design Contradiction:
Loss of timeVSObject-affected harmful factors

Solution Approach 1:

The local bridge acts as a mediator that forwards traffic between local clients while also routing copies of this traffic to the security device for inspection. This allows low-latency local communication to continue while simultaneously enabling security filtering of the same data flow.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network traffic handling into two paths: a direct local bridge path for low-latency communication and a security inspection path for filtered communication. This segmentation allows both low latency and security filtering to coexist by processing traffic through different routes.

Inventive Principle:
Principle #1Segmentation

3Productivity

If an intermediary device creates a local bridge between client devices, then communication efficiency is improved, but the network administrator cannot apply security policies

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidsecurity policy applicability
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The local bridge serves as an intermediary that maintains efficient local communication while also acting as a forwarding point to the security device. This dual role allows the system to achieve both communication efficiency and security policy applicability by routing traffic through multiple intermediaries with different functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7996894B1MAC address modification of otherwise locally bridged client devices to provide security
Publication Date: 2011.08.09 QUEST SOFTWARE INC
  • US7996894B1 patent drawing
  • US7996894B1 patent drawing
  • US7996894B1 patent drawing

AI summary

A method is disclosed for providing security to a client-to-client communication. The method includes authenticating a first client and a second client with an access point device, transmitting the packet to the security device and modifying a destination media access control (MAC) address of a packet from the first client to a MAC address of a security device for a first network. The packet contains a destination internet protocol (IP) address of the second client. The access point device and the first and second clients belong to the first network. The security device is located between the first network and a second network.