Layer 2 MAC-Based IPSEC Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IPSEC policies applied at Layer 3 in networks with Dynamic Host Configuration Protocol (DHCP) lead to administrative costs due to disruptions when dynamic IP addresses change, requiring frequent updates to match newly assigned addresses with correct security policies.

Innovation Solution

Applying security policies based on interface-specific MAC addresses at Layer 2, ensuring that security policies are applied to all traffic regardless of changes in dynamic IP addresses, by identifying and using second-level addresses for encryption and decryption processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IPSEC policies are applied at Layer 3 based on dynamic IP addresses, then network security is maintained, but administrative costs increase due to frequent policy updates required when DHCP assigns new addresses

Engineering Contradiction:
Improvenetwork securityVSAvoidpolicy management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent transitions from Layer 3 (IP address) based security policies to Layer 2 (MAC address) based security policies. By changing the dimensional level of address identification from network layer to data link layer, the system achieves stability in security policies despite dynamic IP address changes, as MAC addresses remain constant while IP addresses may change through DHCP renewal.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent introduces a mapping mechanism that acts as an intermediary between dynamic IP addresses and static MAC addresses. This mapping table correlates temporary IP assignments with permanent hardware addresses, allowing the security system to identify devices through their stable MAC addresses while still functioning with dynamic IP addressing schemes.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If static IP addresses are assigned to avoid DHCP, then IPSEC policies remain stable, but network flexibility and automation are reduced

Engineering Contradiction:
Improvepolicy management complexityVSAvoidnetwork flexibility
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent segments the address identification function into two layers: Layer 2 MAC address identification for stable security policy matching, and Layer 3 IP address for dynamic network allocation. This segmentation allows DHCP to continue providing network flexibility while MAC addresses provide the stability needed for security policies, effectively separating the concerns of address management and security enforcement.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11805094B2Dynamic IPSEC policies
Publication Date: 2023.10.31 VMWARE INC
  • US11805094B2 patent drawing
  • US11805094B2 patent drawing
  • US11805094B2 patent drawing

AI summary

Some embodiments provide a method for securing communication of data messages of a particular machine that includes a dynamic first level address. The method identifies a fixed second level address for a particular data. The fixed second level address is associated with an interface of the particular machine. Based on the fixed second level address, the method identifies a set of security policies for securing the communication of the particular data message. The method applies the set of security policies to the particular data message.