Multi-Layer Address Security in Routed Access Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In routed access networks, pushing Layer 3 routing to the access layer breaks Layer 2 protection security protocols and eliminates the ability of network infrastructure devices to validate the binding of source MAC and IP addresses, leading to vulnerabilities such as IP address spoofing.

Innovation Solution

Implementing a system where switches in the network maintain a database of host information, including both MAC and IP addresses, which is synchronously updated upon topology changes, allowing for multi-layer address security by verifying the authenticity of hosts and preventing unauthorized access through both Layer 2 and Layer 3 security measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If Layer 3 routing is pushed to the access layer, then routing functionality is improved, but Layer 2 protection security protocols are broken

Engineering Contradiction:
Improverouting functionalityVSAvoidLayer 2 protection security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent combines Layer 2 MAC address security with Layer 3 IP address security into a unified multi-layer security framework. By merging these two security layers and validating both MAC and IP addresses together, the system maintains security effectiveness even when routing is pushed to the access layer.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a database as an intermediary component that stores and validates the binding between MAC addresses and IP addresses. This database acts as a mediator that enables security validation across Layer 2 and Layer 3 boundaries, allowing switches to verify address bindings even in routed access networks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If routing is pushed to the access layer, then routing efficiency is improved, but the ability to validate MAC and IP address binding is eliminated

Engineering Contradiction:
Improverouting efficiencyVSAvoidaddress validation capability
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent performs preliminary actions by pre-establishing and storing the binding relationships between MAC addresses and IP addresses in a database before routing decisions are made. This allows validation to occur in advance, enabling efficient routing while maintaining the capability to verify address authenticity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces the traditional mechanical validation process (where switches directly validated MAC/IP bindings through Layer 2 switching) with a database-driven validation system. This substitution allows validation functionality to be maintained even when routing operations are decoupled from the access layer switches.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If port security is implemented at Layer 2, then MAC address security is improved, but IP address spoofing protection is insufficient

Engineering Contradiction:
ImproveMAC address securityVSAvoidIP address spoofing
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extends security from a single Layer 2 dimension to multiple dimensions by incorporating both Layer 2 MAC address validation and Layer 3 IP address validation. This multi-dimensional approach creates a more comprehensive security framework that addresses both MAC address security and IP address spoofing protection simultaneously.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS8200798B2Address security in a routed access network
Publication Date: 2012.06.12 CISCO TECHNOLOGY INC
  • US8200798B2 patent drawing
  • US8200798B2 patent drawing
  • US8200798B2 patent drawing

AI summary

In one embodiment, providing multi-layer address security incorporating Layer 2 Media Access Control (MAC) addresses and corresponding Layer 3 Internet Protocol (IP) addresses for host machines on a routed access network is provided.