W-01PUBLIC / EVIDENCE-CONTROLLEDREV 2026.08.24
SSWork
W-01FULL / ACADEMIC

Layer-2 Ethernet security firewall in hardware

A seventeen-rule Ethernet security firewall implemented on Xilinx Zynq-7000.

← Work ledger

Problem

The project asked whether a useful Layer-2 security rule set could be evaluated in hardware with bounded latency and a resource footprint small enough to coexist with the rest of the SoC fabric.

My contribution

I designed the hardware rule path, parser/control structure, subsystem integration and validation flow used for the M.E. thesis.

ARCHITECTURE / PUBLIC VIEW

System boundary

Public Layer-2 security firewall datapathStreaming Ethernet input flows to header parsing, parallel policy engines, a decision stage and output flow control, with control and status on a separate side path.AXI-S INPUTPARSERPOLICYENGINESDECIDEAXI4-LITE C/S

A streaming input feeds Ethernet field extraction and policy logic. The public diagram is a simplified redraw of the functional boundary; it does not reproduce a Vivado block-design screenshot.

Measurement metadata remains intentionally incomplete rather than invented.

VERIFICATION / LIMIT

What the record proves

The owner-cleared academic record establishes hardware implementation and traffic-level validation. The numeric figures are shown because they were explicitly cleared in the content pack; tool-version/date metadata is not fabricated and will be attached when the artifact ledger is normalized.

EVIDENCE
  • M.E. thesis / academic record — privately held
  • Owner-cleared thesis figures listed in the content pack
  • Source/repository link remains withheld until provenance audit
Discuss this record ↗