Layer 2 MAC-Based IPSEC Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
IPSEC policies applied at Layer 3 in networks with Dynamic Host Configuration Protocol (DHCP) lead to administrative costs due to disruptions when dynamic IP addresses change, requiring frequent updates to match newly assigned addresses with correct security policies.
Innovation Solution
Applying security policies based on interface-specific MAC addresses at Layer 2, ensuring that security policies are applied to all traffic regardless of changes in dynamic IP addresses, by identifying and using second-level addresses for encryption and decryption processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If IPSEC policies are applied at Layer 3 based on dynamic IP addresses, then network security is maintained, but administrative costs increase due to frequent policy updates required when DHCP assigns new addresses
Solution Approach 1:
The patent transitions from Layer 3 (IP address) based security policies to Layer 2 (MAC address) based security policies. By changing the dimensional level of address identification from network layer to data link layer, the system achieves stability in security policies despite dynamic IP address changes, as MAC addresses remain constant while IP addresses may change through DHCP renewal.
Solution Approach 2:
The patent introduces a mapping mechanism that acts as an intermediary between dynamic IP addresses and static MAC addresses. This mapping table correlates temporary IP assignments with permanent hardware addresses, allowing the security system to identify devices through their stable MAC addresses while still functioning with dynamic IP addressing schemes.
2Device complexity
If static IP addresses are assigned to avoid DHCP, then IPSEC policies remain stable, but network flexibility and automation are reduced
Solution Approach 1:
The patent segments the address identification function into two layers: Layer 2 MAC address identification for stable security policy matching, and Layer 3 IP address for dynamic network allocation. This segmentation allows DHCP to continue providing network flexibility while MAC addresses provide the stability needed for security policies, effectively separating the concerns of address management and security enforcement.
Data Source
AI summary
Some embodiments provide a method for securing communication of data messages of a particular machine that includes a dynamic first level address. The method identifies a fixed second level address for a particular data. The fixed second level address is associated with an interface of the particular machine. Based on the fixed second level address, the method identifies a set of security policies for securing the communication of the particular data message. The method applies the set of security policies to the particular data message.


