BIOS-Based LLDP Service for Data Switch Port Learning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for configuring data switches in data centers face challenges, particularly when servers do not support Link Layer Discovery Protocol (LLDP, as they require OS customization and are insecure, making it difficult to manage network access policies and detect changes in network ports.
Innovation Solution
Incorporating the LLDP service into the BIOS rather than the operating system, allowing LLDP functionality to be executed without OS customization, and using detection circuits or management controllers to trigger LLDP packet generation for data switches, ensuring secure and reliable communication of NIC card changes without relying on OS-based solutions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Difficulty of detecting and measuring
If LLDP service is incorporated into the operating system, then network topology discovery capability is improved, but system security deteriorates and OS customization is required
Solution Approach 1:
The LLDP service is extracted from the operating system and relocated to the BIOS layer. This extraction eliminates the security vulnerabilities associated with OS-based LLDP implementations while maintaining the network topology discovery capability. The BIOS-based approach removes the dependency on OS customization and enhances system security by operating at a lower, more secure system layer.
Solution Approach 2:
A management controller is introduced as an intermediary component to facilitate LLDP packet generation and transmission. The management controller receives triggers from detection circuits and autonomously generates LLDP packets, acting as a mediator between the hardware detection layer and the network communication layer. This intermediary approach enables secure LLDP operation without requiring OS involvement.
2Difficulty of detecting and measuring
If LLDP service is incorporated into the operating system, then network port change detection is improved, but system complexity increases due to OS customization requirements
Solution Approach 1:
The system implements self-service through detection circuits that automatically monitor network port changes and trigger LLDP packet generation without requiring OS intervention. The management controller autonomously processes these triggers and generates appropriate LLDP packets, eliminating the need for complex OS customization and reducing overall system complexity.
Solution Approach 2:
LLDP packets are generated proactively in response to detected network port changes, before the system needs to query topology information. This preliminary action ensures that the data switch already has updated topology information when needed, improving detection capability while simplifying the system architecture by avoiding post-change investigation complexities.
3Ease of operation
If manual mapping table maintenance is used, then network access policy application is simplified, but labor intensity and error probability increase
Solution Approach 1:
The system implements automated feedback loops where detection circuits continuously monitor network port changes, trigger LLDP packet generation, and update topology information in real-time. This automated feedback mechanism eliminates manual mapping table maintenance, reducing labor intensity and error probability while keeping network access policies current without requiring manual intervention.
Solution Approach 2:
The manual mechanical process of maintaining mapping tables is replaced with an automated electronic system. Detection circuits electronically monitor port changes, and the management controller automatically generates LLDP packets to update topology information, substituting the manual mechanical maintenance process with an automated electronic solution that reduces time loss and errors.
4Difficulty of detecting and measuring
If LLDP is used for topology discovery, then network topology information acquisition is improved, but compatibility deteriorates when servers do not support LLDP
Solution Approach 1:
The management controller serves as an intermediary that enables LLDP functionality on servers regardless of OS support. By implementing LLDP packet generation at the BIOS/firmware level rather than requiring OS-based LLDP support, the system achieves protocol compatibility across diverse server platforms. The management controller mediates between hardware detection capabilities and network protocol requirements, ensuring broad adaptability.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Apparatus and methods are described for configuring data switches with server data port information. In a first embodiment of the invention, a computing device is provided. The computing device includes a network interface controller (NIC) card coupled to a data network, a central processing unit (CPU), and a basic input/output system (BIOS) with a link layer discovery protocol (LLDP) service. In the computing device, the CPU is configured for receiving a signal indicating a change at the NIC card and configuring the CPU to initiate a BIOS session in response to the signal. Further, the BIOS session is configured to allow the BIOS to perform, via the CPU, operations for the LLDP service including transmitting to a data switch of the data network via the NIC card a LLDP packet including information for the NIC card based on the change.