Network Device IP Address Segment ID Mapping via ARP Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network segmentation methods face challenges in mapping Internet Protocol (IP) addresses to segment identifications without API integration, particularly in authentication systems like RADIUS-based servers, which are unaware of client device IP addresses due to security protocols that only share MAC addresses, leading to interoperability issues between network devices and authentication systems.
Innovation Solution
A mechanism that enables IP address to segment ID mapping without requiring API integration, where network devices interact with authentication systems to obtain MAC address-segment ID mappings, and then generate IP address-segment ID mappings using address locking or ARP tables, with a Network Management System (NMS) collecting and distributing these mappings to ensure compatibility with various security-based authentication systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If authentication systems use security protocols like RADIUS that only share MAC addresses, then network security is maintained, but IP address-segment ID mapping cannot be effected
Solution Approach 1:
The patent introduces a network device (switch) as an intermediary that receives both MAC address-segment ID mappings from the authentication system and IP address-MAC address mappings from ARP tables. The switch then performs the function of creating IP address-segment ID mappings by correlating these two mappings, thereby enabling segmentation without requiring the authentication system to have direct knowledge of IP addresses.
Solution Approach 2:
The patent segments the functionality into distinct components: the authentication system handles MAC address-segment ID mapping, the network device handles IP address-MAC address mapping via ARP tables, and the network device correlates these to produce IP address-segment ID mappings. This segmentation allows each component to operate within its security constraints while achieving the overall mapping objective.
2Adaptability or versatility
If API integration is implemented to enable IP address-segment ID mapping, then mapping capability is improved, but device complexity and integration cost increase
Solution Approach 1:
The network device performs self-service by autonomously creating IP address-segment ID mappings using its own ARP table data and the MAC address-segment ID mappings received from the authentication system. No external API integration or additional feature development on the authentication system is required, as the network device independently correlates the available information to achieve the mapping.
Solution Approach 2:
The network device performs multiple functions: it acts as an authentication client receiving MAC address-segment ID mappings, maintains an ARP table for IP address-MAC address mappings, and correlates these to create IP address-segment ID mappings. This multi-functionality eliminates the need for specialized API integration while achieving the mapping capability.
3Adaptability or versatility
If MAC address-based authentication is used, then authentication compatibility is maintained, but IP address awareness is lost
Solution Approach 1:
The network device performs preliminary action by maintaining an ARP table that maps IP addresses to MAC addresses before the segmentation mapping is needed. When MAC address-segment ID mappings are received from the authentication system, the network device already has the IP address-MAC address mappings ready to correlate, enabling immediate creation of IP address-segment ID mappings without requiring the authentication system to provide IP address information.
Data Source
AI summary
In general, the disclosure relates to a method for creating segment mapping in a network, by a network device. The method includes receiving a segment identification (ID) for a client device of the network from an authentication system. The segment ID identifies a segment of the network including the client device and the network device wherein the segment ID is associated with a media access control (MAC) address of the client device. The network device or a network management system (NMS) determines an internet protocol (IP) address of the client device and the network device creates an IP address to segment ID mapping for the client device using the IP address. The IP address to segment ID mapping is provided to the NMS for distribution to remaining network devices of the network. At least one packet of the client device is processed using the IP address to segment ID mapping.


