DHCP Server Network Filter for Dynamic Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network infrastructure lacks efficient methods for selectively blocking network packets based on endpoint assessments, leading to laborious and non-dynamic filtering processes that require undesirable changes in infrastructure.

Innovation Solution

Implementing a network filter associated with a DHCP server that modifies DHCP option parameters to assign endpoints to either a restricted or less-restricted subnet based on assessment results, using access control lists and relay IP addresses to control access, without requiring changes to physical topology or additional servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If selective blocking of network packets is implemented using traditional filtering methods, then network access control is achieved, but the process becomes laborious and non-dynamic, requiring changes in infrastructure

Engineering Contradiction:
Improvenetwork access controlVSAvoidfiltering management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the DHCP server functionality with network access control capabilities. The DHCP server is modified to include an assessment module that evaluates endpoints and dynamically assigns IP addresses from different scopes based on assessment results. This merging eliminates the need for separate filtering management infrastructure and makes the access control process automatic and dynamic.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system implements dynamic access control by continuously assessing endpoints and automatically reassigning IP addresses based on current security status. The DHCP server monitors endpoint behavior and can move endpoints between restricted and unrestricted scopes in real-time, transforming static filtering into a dynamic, adaptive system.

Inventive Principle:
Principle #15Dynamics

2Reliability

If traditional packet filtering is used to control network access, then security assessment is possible, but administrative overhead and configuration complexity increase

Engineering Contradiction:
Improvesecurity assessment capabilityVSAvoidadministrative overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables self-service access control where the DHCP server automatically performs security assessments, evaluates endpoint compliance, and assigns IP addresses without administrative intervention. The assessment module autonomously determines which scope each endpoint should receive, eliminating manual configuration and reducing administrative overhead significantly.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The DHCP server performs security assessments and IP address assignments in advance, before endpoints attempt to access restricted resources. By pre-evaluating endpoints and assigning appropriate IP addresses from the correct scopes, the system prevents unauthorized access before it occurs, reducing the need for reactive administrative management.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If multiple subnets are created for restricted and less-restricted access, then access control is achieved, but infrastructure changes and configuration complexity increase

Engineering Contradiction:
Improveaccess control separationVSAvoidinfrastructure flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the IP address space into multiple scopes within the DHCP server, where each scope represents a different access level (restricted or unrestricted). This logical segmentation allows the DHCP server to assign IP addresses from appropriate scopes based on endpoint assessment, achieving access control separation without requiring separate physical subnets or infrastructure changes.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The modified DHCP server becomes a universal device that handles both IP address assignment and security assessment functions. By making the DHCP server multi-functional, the system achieves access control without adding specialized filtering hardware or modifying the physical network topology, maintaining infrastructure flexibility while providing robust access control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7590733B2Dynamic address assignment for access control on DHCP networks
Publication Date: 2009.09.15 INFOEXPRESS
  • US7590733B2 patent drawing
  • US7590733B2 patent drawing
  • US7590733B2 patent drawing

AI summary

Systems and methods of managing security on a computer network are disclosed. The computer network includes a restricted subnet and a less-restricted subnet. Access to the restricted subnet is controlled by a network filter, optionally inserted as a software shim on a DHCP server. In some embodiments, the network filter is configured to manipulate relay IP addresses to control whether the DHCP server provides, in a DHCPOFFER packet, an IP address that can be used to access the restricted subset. In some embodiments, configuration information is communicated between the DHCP server and the network filter via DHCPOFFER packets.