DHCP Notification-Based Network Device Discovery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network device discovery and assessment methods are inefficient, leading to potential security risks and management difficulties due to the time-consuming nature of periodic scans in large networks, which can result in devices going undetected for hours or days.

Innovation Solution

Implementing a system that utilizes real-time notifications from Address Allocation Servers, such as DHCP servers, to provide instantaneous updates on network address and device identifier combinations, enabling immediate device discovery, assessment, and configuration through an IF-MAP server and client, facilitating dynamic network actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If periodic network scans are used to discover devices, then network device discovery can be performed, but the discovery process takes hours or days in large networks, allowing devices to go undetected

Engineering Contradiction:
Improvedevice detection accuracyVSAvoiddevice detection time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies preliminary action by having discovery sensors continuously monitor and maintain an up-to-date inventory of network devices before security policies need to be enforced. The Configuration Management Database (CMDB) is continuously updated with device information through ongoing discovery scans, so that when a new device connects or an existing device changes state, the information is already available in the CMDB without waiting for periodic full network scans. This eliminates the detection delay while maintaining accurate device inventory.

Inventive Principle:
Principle #10Preliminary action

2Speed

If discovery sensors continuously scan the network to detect devices in real-time, then device detection time is reduced, but the complexity and resource consumption of the discovery system increases

Engineering Contradiction:
Improvedevice detection speedVSAvoiddiscovery system complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent introduces the CMDB as an intermediary that centralizes device information management. Instead of having multiple discovery sensors independently scanning and managing device inventories, all discovery sensors report to a single CMDB, which maintains the authoritative device inventory. This intermediary approach simplifies the overall system architecture by providing a centralized coordination point, reducing the complexity of managing multiple distributed discovery systems while enabling real-time device detection capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If periodic discovery scans are performed, then network device inventory can be maintained, but devices may remain undetected between scans, creating security gaps

Engineering Contradiction:
Improvesecurity enforcement reliabilityVSAvoidnetwork management efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements continuity of useful action through continuous device discovery and CMDB updates. Discovery sensors continuously monitor the network and update the CMDB in real-time, ensuring that the device inventory is always current. This continuous operation eliminates gaps between periodic scans, ensuring that security policies can be immediately enforced when devices are detected or change state, thereby maintaining high security reliability without sacrificing network management efficiency.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS9621512B2Dynamic network action based on DHCP notification
Publication Date: 2017.04.11 INFOBLOX INC
  • US9621512B2 patent drawing
  • US9621512B2 patent drawing
  • US9621512B2 patent drawing

AI summary

Techniques for providing DHCP updates are provided. In various embodiments, a DHCP notification is received from a DHCP server, the notification includes a network address and a unique device identifier combination of a device. A second notification is generated in response to receiving the first notification, the second notification includes the network address and the unique device identifier combination.