DHCP Snooping Switch for Network Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large networks face challenges in controlling unauthorized access and ensuring quality of service, particularly with devices like IP phones requiring specific service types, and existing methods struggle to efficiently manage IP address allocation and traffic direction.

Innovation Solution

Implementing DHCP snooping in network switches to monitor and manage edge devices by determining MAC addresses, IP addresses, VLANs, and ports, using dynamic tables and protocols like RADIUS and IEEE 802.1x for authentication and access control, allowing for real-time management and quality of service optimization without altering traffic signals.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If DHCP snooping is implemented to monitor and control network traffic, then network security and access control are improved, but device complexity and processing overhead increase

Engineering Contradiction:
Improvenetwork securityVSAvoidswitch complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The switch performs preliminary binding of MAC addresses to IP addresses through DHCP snooping before actual network access occurs. This pre-establishes a trusted binding table that the switch can use for rapid authentication and access control decisions, preventing unauthorized devices from gaining network access without requiring complex real-time analysis of every packet.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication mechanism where the switch acts as a mediator between DHCP servers and network resources. By implementing DHCP snooping, the switch creates an intermediate layer that monitors and validates DHCP transactions, binding MAC addresses to IP addresses before allowing full network access, thus simplifying the overall security architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If dynamic binding tables are maintained to track MAC addresses and IP addresses, then unauthorized access detection is improved, but memory usage and processing time increase

Engineering Contradiction:
Improveaccess control accuracyVSAvoidauthentication time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The binding table is implemented as a dynamic structure that automatically updates in real-time as devices join and leave the network through DHCP transactions. This dynamic approach allows the switch to maintain precise tracking of MAC-to-IP bindings without manual intervention, improving access control accuracy while the automated nature reduces processing overhead compared to static table management.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The DHCP snooping mechanism enables the binding table to self-update automatically through DHCP transaction monitoring. The switch autonomously extracts MAC and IP address pairs from DHCP packets and populates the binding table without requiring external configuration or manual updates, reducing the time and resources needed for table maintenance while maintaining high measurement precision.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If DHCP snooping monitors all traffic to determine device information, then network control capability is improved, but processing load and energy consumption increase

Engineering Contradiction:
Improvenetwork control capabilityVSAvoidprocessing energy
Core Design Contradiction:
Adaptability or versatilityVSUse of energy by moving object

Solution Approach 1:

The switch extracts only the essential information needed for access control from DHCP traffic - specifically the MAC address and IP address pairs - rather than analyzing all packet contents. This selective extraction approach maintains comprehensive network control capability by capturing the critical binding information while minimizing processing load and energy consumption by ignoring irrelevant packet data.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The DHCP snooping implementation performs partial monitoring focused specifically on DHCP protocol transactions rather than all network traffic. By concentrating monitoring efforts on the DHCP protocol where MAC-to-IP bindings are established, the system achieves versatile network control capability while avoiding the excessive energy consumption that would result from deep inspection of all traffic types.

Inventive Principle:
Principle #16Partial or excessive action

4Reliability

If authentication protocols like IEEE 802.1x and RADA are integrated, then access security is improved, but device complexity and configuration difficulty increase

Engineering Contradiction:
Improveaccess securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple authentication mechanisms - DHCP snooping, IEEE 802.1x port-based authentication, and RADA MAC address-based authentication - into a unified access control framework. This integration allows the switch to leverage the strengths of each protocol: DHCP snooping for IP address validation, 802.1x for user credential verification, and RADA for MAC address authentication, thereby improving overall access security while presenting a consolidated system rather than separate complex components.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS7596614B2Network including snooping
Publication Date: 2009.09.29 HEWLETT PACKARD ENTERPRISE DEV LP
  • US7596614B2 patent drawing
  • US7596614B2 patent drawing
  • US7596614B2 patent drawing

AI summary

A computer network including:at least one switch connecting at least one edge device to the remainder of the network, said at least one switch including:snooping apparatus using DHCP to monitor the signal traffic through the switch to or from the each edge device to determine, without changing the traffic signals, for each edge device, the MAC address, the IP address, and the port of the switch to which it is connected, anda dynamic table within said switch of, for each edge device, the MAC address, the IP address, and the port which it is connected, the contents of the table being provided by said snooping apparatus.