Secure Port Groups for MAC Address Movement Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing edge devices face challenges in securely managing MAC address moves between ports while maintaining network connectivity and security, particularly in preventing unauthorized MAC address movements that could lead to bridge forwarding loops and compromising network security.

Innovation Solution

Implementing secure port groups that restrict MAC address movements to specific VLANs and port groups, allowing moves only within designated secure port groups, and filtering or discarding packets attempting to move outside these groups, thereby enhancing security and preventing loop detection warnings.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If MAC address moves are allowed freely between ports, then network flexibility and adaptability are improved, but network security and stability deteriorate due to potential bridge forwarding loops and unauthorized access

Engineering Contradiction:
ImproveMAC address movement flexibilityVSAvoidnetwork stability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The network ports are segmented into different secure port groups (e.g., secure port group 34, secure port group 36), and MAC address moves are restricted within these segments. This segmentation allows MAC addresses to move freely within their designated group while preventing moves between groups, thus maintaining network stability and security while preserving flexibility within boundaries.

Inventive Principle:
Principle #1Segmentation

2Reliability

If strict security protocols are enforced to prevent unauthorized MAC moves, then network security is improved, but network flexibility and connectivity deteriorate

Engineering Contradiction:
Improvenetwork securityVSAvoidMAC address movement flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

Different security policies are applied to different secure port groups. Each group can have its own MAC address movement restrictions and security parameters. This allows the system to enforce strict security where needed while permitting greater flexibility in other areas, achieving local optimization of security and adaptability.

Inventive Principle:
Principle #3Local quality

3Reliability

If MAC lock down is implemented to prevent unauthorized MAC addresses, then network security is improved, but legitimate MAC address updates are blocked causing connectivity issues

Engineering Contradiction:
Improvenetwork securityVSAvoidMAC address update capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system continuously monitors MAC address movements within secure port groups and provides feedback by updating the MAC address table dynamically. When a MAC address moves within the same secure port group, the system automatically updates the forwarding table to reflect the new location, allowing legitimate updates while maintaining security boundaries.

Inventive Principle:
Principle #23Feedback

4Reliability

If the number of MAC moves is tracked to detect bridge forwarding loops, then loop detection capability is improved, but system complexity and processing overhead increase

Engineering Contradiction:
Improveloop detection capabilityVSAvoidMAC move tracking complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system pre-establishes secure port group memberships and MAC address bindings before MAC moves occur. By having the MAC address table pre-configured with secure port group associations, the system can quickly determine whether a MAC move is legitimate (within the same group) or suspicious (between groups) without complex real-time analysis, reducing processing overhead.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9148360B2Managing MAC moves with secure port groups
Publication Date: 2015.09.29 HEWLETT PACKARD ENTERPRISE DEV LP
  • US9148360B2 patent drawing
  • US9148360B2 patent drawing
  • US9148360B2 patent drawing

AI summary

A source MAC address is associated with a particular port that is a member of a secure group of ports of a network edge device. A move of the source MAC address to any port of the network edge device that is a member of the secure group of ports is allowed. Moves of the MAC address to any port of the network edge device that is outside the secure group of ports are disallowed.