CPE Configuration via MAC-Embedded IP and Dynamic Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for configuring Customer Premise Equipment (CPE) are insecure and difficult to manage, particularly for ISPs with strict security policies, as they rely on unencrypted protocols and static credentials, which are prone to security threats and logistical challenges.

Innovation Solution

A method that embeds a Media Access Control (MAC) address into the IP address leased to CPE, generates a pair of public and private keys based on the MAC address for secure key exchange, and establishes a secure connection using temporary and permanent encryption keys to transfer a configuration file, enabling secure configuration of CPE.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If unencrypted protocols such as TFTP are used for downloading configuration files, then the configuration process is simple and compatible with security policies allowing unencrypted protocols, but the security of the configuration process is compromised

Engineering Contradiction:
Improveconfiguration process simplicityVSAvoidconfiguration security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary mechanism where the MAC address embedded in the IP address serves as a key identifier. The configuration server uses this embedded MAC address to dynamically generate and provide encryption keys to the CPE, enabling secure encrypted file transfers while maintaining automated provisioning. This intermediary key management system resolves the contradiction by allowing security without compromising operational simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the parameter of file transfer protocol from unencrypted (TFTP) to encrypted (SFTP or similar), and dynamically changes encryption keys based on the CPE's MAC address embedded in its IP address. This parameter change enables secure configurations while maintaining automated provisioning through dynamic key generation rather than static credential management.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If encrypted file transfer protocols such as SFTP are used, then the security of the configuration process is improved, but the management of credentials becomes complex and logistically challenging

Engineering Contradiction:
Improveconfiguration securityVSAvoidcredential management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling the CPE to automatically obtain encryption keys without manual credential management. The MAC address embedded in the IP address serves as a unique identifier that allows the CPE to autonomously receive its encryption keys from the configuration server, eliminating the need for ISPs to manually manage credentials for large numbers of installations.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The embedded MAC address in the IP address acts as an intermediary that links the CPE to its specific encryption keys. This intermediary mechanism simplifies credential management by using the already-assigned IP address (which contains the MAC address) as the basis for key distribution, rather than requiring separate credential management systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If static credentials are used for encrypted file transfer, then the credential management is simplified, but the system becomes prone to security threats

Engineering Contradiction:
Improvecredential management simplicityVSAvoidsecurity resistance
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent transitions from static credentials to dynamic encryption keys that are generated and distributed based on the CPE's MAC address embedded in its IP address. This dynamic approach ensures that each CPE has unique, time-varying encryption credentials, significantly improving security resistance while maintaining automated key distribution that doesn't increase management complexity.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the credential parameter from static to dynamic, where encryption keys are generated based on the CPE's MAC address and can be updated or rotated. This parameter change enables each CPE to have unique security credentials without requiring complex manual management, as the keys are automatically derived from the embedded MAC address in the IP address.

Inventive Principle:
Principle #35Parameter changes

4Extent of automation

If Low-Touch-Provisioning with DHCP and TFTP is used, then the automated configuration capability is achieved, but the compatibility with strict security policies is lost

Engineering Contradiction:
Improveautomated configuration capabilityVSAvoidsecurity policy compliance
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The patent introduces an intermediary key management layer between DHCP and the file transfer protocol. The MAC address embedded in the IP address serves as the intermediary that enables the configuration server to provide dynamic encryption keys to the CPE, allowing encrypted file transfers while maintaining automated provisioning capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent performs preliminary action by embedding the MAC address in the IP address during the DHCP process before the actual configuration file transfer. This preliminary embedding of identification information enables subsequent automated key distribution and encrypted file transfers without requiring manual intervention, thus maintaining automation while achieving security compliance.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10069802B2Method for securely configuring customer premise equipment
Publication Date: 2018.09.04 CIENA CORP
  • US10069802B2 patent drawing
  • US10069802B2 patent drawing
  • US10069802B2 patent drawing

AI summary

A method for securely configuring a customer premise equipment in a network. The network including a configuration server, a DHCP server, and the customer premise equipment. The method includes receiving a request from the customer premise equipment for leasing an Internet Protocol (IP) address to the customer premise equipment. The method further includes embedding at least a portion of a Media Access Control (MAC) address of the customer premise equipment into the IP address leased to the customer premise equipment. The method includes leasing the IP address to the customer premise equipment. Further, the method enables authentication of customer premise equipment, before providing configuration to the customer premise equipment. The method includes use of characteristic attributes of the customer premise equipment to generate cryptographic keys for secure connection. Moreover, the method includes establishing a secure connection between the configuration server and the customer premise equipment for transfer of a configuration file and a set of encryption keys. The configuration file and the set of encryption keys are used to securely configure the customer premise equipment.