MAC Address Priority Management for Switch FDB Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Ethernet switches are vulnerable to MAC flooding attacks, which consume limited Forwarding Database (FDB) resources, leading to service degradation and security issues, and face synchronization challenges in distributed architectures that can cause traffic loss and service disruption due to inefficient MAC address synchronization mechanisms.

Innovation Solution

Assigning priorities to MAC addresses to manage them efficiently in the FDB, ensuring important services are protected from MAC flooding and synchronizing MAC address changes among line cards based on these priorities, thereby preventing resource overload and ensuring timely synchronization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the FDB size is increased to accommodate more MAC addresses, then the resistance to MAC flooding attacks is improved, but the device complexity and resource consumption increase

Engineering Contradiction:
Improveresistance to MAC flooding attacksVSAvoidFDB size
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the parameter of MAC address management by introducing priority levels and aging time mechanisms. Instead of simply increasing FDB size, it dynamically manages MAC addresses based on their priority and activity status, allowing the system to maintain security with a more manageable database size.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The FDB learning process automatically learns MAC addresses from incoming frames and manages their lifecycles without manual intervention. The system self-regulates by adding learned MAC addresses with appropriate priorities and aging times, and automatically removing stale entries, reducing the need for manual FDB management.

Inventive Principle:
Principle #25Self-service

2Productivity

If the FDB learning process is activated to automatically learn MAC addresses, then the forwarding efficiency is improved, but the vulnerability to MAC flooding attacks increases

Engineering Contradiction:
Improveforwarding efficiencyVSAvoidvulnerability to MAC flooding attacks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent makes the FDB learning process dynamic by introducing priority-based management and configurable aging times. The system adaptively learns MAC addresses only when necessary, assigns them appropriate priorities based on source port configurations, and automatically ages them out after predetermined time periods, preventing the FDB from being overwhelmed by malicious traffic.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback mechanisms where the FDB learning process continuously monitors incoming traffic patterns, learns legitimate MAC addresses, and adjusts the forwarding behavior based on learned information. The aging mechanism provides feedback by removing stale entries, ensuring the FDB contains only currently active MAC addresses.

Inventive Principle:
Principle #23Feedback

3Speed

If MAC addresses are synchronized immediately upon change, then the synchronization speed is improved, but the system resource consumption and complexity increase

Engineering Contradiction:
Improvesynchronization speedVSAvoidsystem resource consumption
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

Instead of continuous or immediate synchronization, the patent implements periodic synchronization based on aging time intervals. MAC address changes are synchronized at predetermined intervals rather than instantly, reducing the frequency of synchronization operations while maintaining adequate synchronization speed for network operations.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The synchronization mechanism is made dynamic by adjusting the timing based on MAC address priority and activity status. High-priority MAC addresses may be synchronized more frequently, while low-priority or stale entries are synchronized less often or not at all, optimizing resource usage based on actual network needs.

Inventive Principle:
Principle #15Dynamics

4Quantity of substance

If the FDB is filled with numerous MAC addresses during an attack, then the attack effectiveness is improved, but the service quality for legitimate users deteriorates

Engineering Contradiction:
Improvenumber of MAC addresses in FDBVSAvoidservice quality
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent applies different quality attributes to different MAC addresses in the FDB through priority levels. Legitimate MAC addresses assigned to secure ports receive high priority and are protected from being displaced, while untrusted or learned MAC addresses receive lower priority. This ensures that even when the FDB is full, high-priority legitimate entries are preserved, maintaining service quality for authorized users.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes the parameter of MAC address retention by introducing priority-based differentiation. Instead of treating all MAC addresses equally, it assigns priority levels that determine which entries are retained when the FDB is full. High-priority entries are protected from aging out or being overwritten, ensuring continuous service quality for critical MAC addresses during attack conditions.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP2936764B1Method and apparatus for managing media access control addresses
Publication Date: 2020.03.25 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP2936764B1 patent drawingFigure 1~2
  • EP2936764B1 patent drawingFigure 3~5
  • EP2936764B1 patent drawingFigure 4

AI summary

A method and apparatus for managing a media access control address are provided. The method comprises assigning a priority to the MAC address. The method also comprises managing the MAC address in a forwarding database based on the priority. With the method and apparatus, a MAC flooding attack can be efficiently avoided and communication performance would be improved in a secure manner.