Dynamic Network Device Access Settings for Secure O&M Support
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network devices are vulnerable to unauthorized access by malicious users who can bypass authentication and encryption methods, obtaining a valid IP address or impersonating a legitimate device, posing a security risk during Operations and Maintenance (O&M) procedures.
Innovation Solution
The network device and service terminal employ additional security measures by dynamically changing access settings, such as IP addresses and authentication methods, and utilize existing hardware components like fans and LEDs to communicate these changes to the service terminal through audio and light signals, ensuring secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If authentication and encryption methods are used for O&M access, then security against unauthorized access is improved, but malicious users may still bypass these methods by obtaining valid IP addresses or compromising credentials
Solution Approach 1:
The patent applies preliminary action by pre-configuring multiple access settings (IP addresses, authentication methods, ports) in the network device before an access attempt occurs. When a service terminal needs to connect, the device dynamically selects and switches to an appropriate access setting from the pre-configured options, rather than using a single static configuration. This allows the system to prepare multiple security layers in advance and switch between them based on the connection request, making it harder for malicious users to bypass security through predetermined attack vectors.
Solution Approach 2:
The patent implements dynamics by enabling the network device to dynamically change access settings during operation. Instead of maintaining fixed IP addresses and authentication credentials, the device can switch between multiple configured access settings based on connection requests, time, or security conditions. This dynamic behavior means that even if a malicious user obtains one set of credentials or IP address, the access settings may have changed by the time the connection is attempted, rendering the stolen credentials ineffective.
2Reliability
If dynamic access setting changes are implemented, then unauthorized access is prevented, but additional security mechanisms increase system complexity
Solution Approach 1:
The patent applies universality by making existing hardware components (fans, LEDs, displays) perform multiple functions. These components originally serve specific purposes (cooling, indication, user interface), but the patent enables them to additionally communicate access setting information and security status. For example, fan rotation speeds or LED blinking patterns convey authentication state or connection status. This eliminates the need for dedicated communication hardware, reducing overall system complexity while maintaining the dynamic security functionality.
Solution Approach 2:
The patent implements self-service by enabling the network device to autonomously manage access setting changes and communicate them to service terminals without requiring external security management systems. The device automatically switches between pre-configured access settings based on connection requests and uses its existing hardware interfaces to notify terminals of the current access configuration. This self-managed approach avoids the complexity of external security infrastructure while maintaining robust dynamic security control.
3Ease of manufacture
If existing hardware components are utilized for communication, then additional hardware costs are reduced, but the reliability of communication through non-standard interfaces may be compromised
Solution Approach 1:
The patent applies universality by repurposing existing hardware components (fans, LEDs, displays) to serve dual functions: their original purposes plus communication of access setting information. This eliminates the need for additional dedicated communication hardware, reducing manufacturing costs. The patent ensures reliability by using these components in a controlled manner where their communication function supplements rather than replaces primary communication channels, creating a redundant information path that enhances overall system reliability without requiring expensive new hardware.
Data Source
Figure 1~2
Figure 3
Figure 4A~4B
AI summary
The present disclosure relates to a service terminal, a network device and a method for access security at Operation and Maintenance, O&M, support of the network device. The network device (100) and the service terminal (20) are configured to establish a communication using at least one access setting for establishing a communication. The at least one access setting comprising one of the following: an IP address, one or several serial communication parameters, access protocol, authentication method. The method comprises to receive a trigger for changing the at least one access setting for establishing a communication with the service terminal, and to change the at least one access setting for establishing the communication with the service terminal to at least one new access setting.