SDA Fabric Access Switch Address Resolution for IoT Endpoint Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network access control solutions for IoT devices in Software Defined Access (SDA) fabrics face challenges in managing unmanaged devices and scaling with large numbers of IoT devices, particularly when broadcast messages are filtered out and replaced by layer-2 unicast.
Innovation Solution
The system converts address resolution requests into two unicast messages, one sent to a sensor and the other to the target device, allowing the sensor to determine if a device is a 'bad' endpoint and prompting it to resolve issues, while maintaining network access control within an SDA fabric.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If broadcast messages are filtered out and replaced by layer-2 unicast, then network security and control are improved, but device detection and management capabilities deteriorate
Solution Approach 1:
The patent introduces a sensor as an intermediary component between the access switch and the target device. The access switch sends unicast messages to the sensor, which then determines whether the target device is a 'bad endpoint'. This intermediary enables secure unicast communication while maintaining device detection and classification capabilities that would otherwise be lost without broadcast messages.
2Ease of operation
If unicast messages are used instead of broadcast, then network traffic control is improved, but message delivery efficiency deteriorates
Solution Approach 1:
The patent extracts the device detection and classification function from the broadcast message mechanism and places it in a dedicated sensor component. This allows the access switch to send targeted unicast messages only to the sensor for evaluation, rather than flooding all devices with broadcast messages. The sensor then provides selective responses only for devices requiring attention, improving overall message delivery efficiency while maintaining tight traffic control.
3Reliability
If sensor evaluation is added to the address resolution process, then device security assessment is improved, but processing time increases
Solution Approach 1:
The patent implements preliminary action by having the sensor pre-evaluate target devices during the address resolution process. The access switch sends unicast messages to the sensor with target device identifiers, and the sensor determines in advance whether these devices are 'bad endpoints' before actual communication attempts. This preliminary assessment prevents time-wasting communication with malicious or compromised devices, thereby reducing overall processing time despite adding an evaluation step.
Data Source
AI summary
A first address resolution request may be received by a first access switch from a first device and the address resolution request may be resolved by the first access switch with a central database of a network. Then a second address resolution request may be sent to a sensor by the first access switch in response to resolving the first address resolution request. An address resolution response may then be sent by the sensor to the first device in response to the sensor determining that the first device is a bad endpoint. A session may then be established between the sensor and the first device in response to the sensor sending the address resolution response. The first device may then be prompted by the sensor via the established session to resolve issues that lead the sensor to determine that the first device is a bad endpoint.


