Multi-Layer Address Security in Routed Access Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In routed access networks, pushing Layer 3 routing to the access layer breaks Layer 2 protection security protocols and eliminates the ability of network infrastructure devices to validate the binding of source MAC and IP addresses, leading to vulnerabilities such as IP address spoofing.
Innovation Solution
Implementing a system where switches in the network maintain a database of host information, including both MAC and IP addresses, which is synchronously updated upon topology changes, allowing for multi-layer address security by verifying the authenticity of hosts and preventing unauthorized access through both Layer 2 and Layer 3 security measures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If Layer 3 routing is pushed to the access layer, then routing functionality is improved, but Layer 2 protection security protocols are broken
Solution Approach 1:
The patent combines Layer 2 MAC address security with Layer 3 IP address security into a unified multi-layer security framework. By merging these two security layers and validating both MAC and IP addresses together, the system maintains security effectiveness even when routing is pushed to the access layer.
Solution Approach 2:
The patent introduces a database as an intermediary component that stores and validates the binding between MAC addresses and IP addresses. This database acts as a mediator that enables security validation across Layer 2 and Layer 3 boundaries, allowing switches to verify address bindings even in routed access networks.
2Productivity
If routing is pushed to the access layer, then routing efficiency is improved, but the ability to validate MAC and IP address binding is eliminated
Solution Approach 1:
The patent performs preliminary actions by pre-establishing and storing the binding relationships between MAC addresses and IP addresses in a database before routing decisions are made. This allows validation to occur in advance, enabling efficient routing while maintaining the capability to verify address authenticity.
Solution Approach 2:
The patent replaces the traditional mechanical validation process (where switches directly validated MAC/IP bindings through Layer 2 switching) with a database-driven validation system. This substitution allows validation functionality to be maintained even when routing operations are decoupled from the access layer switches.
3Reliability
If port security is implemented at Layer 2, then MAC address security is improved, but IP address spoofing protection is insufficient
Solution Approach 1:
The patent extends security from a single Layer 2 dimension to multiple dimensions by incorporating both Layer 2 MAC address validation and Layer 3 IP address validation. This multi-dimensional approach creates a more comprehensive security framework that addresses both MAC address security and IP address spoofing protection simultaneously.
Data Source
AI summary
In one embodiment, providing multi-layer address security incorporating Layer 2 Media Access Control (MAC) addresses and corresponding Layer 3 Internet Protocol (IP) addresses for host machines on a routed access network is provided.


