Dynamic Whitelist Update for DHCP-Managed IP Addresses

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing whitelisting technologies struggle to adapt to networks where IP addresses of terminals are dynamically changed using DHCP, as they rely on static whitelists and fail to effectively control suspicious behavior from authorized terminals.

Innovation Solution

A communication device with a protocol information table storing MAC addresses, IP addresses, and expiration times, and a processing unit that updates and generates entries for dynamically allocated IP addresses, allowing for real-time adaptation of whitelists to manage communications securely in DHCP environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a static whitelist is used for security control, then security level is improved, but adaptability to dynamic IP address changes deteriorates

Engineering Contradiction:
Improvesecurity levelVSAvoidadaptability to IP address changes
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a dynamic whitelist system that automatically updates authorized IP addresses based on DHCP lease information. The communication device monitors DHCP transactions, extracts authorized IP addresses and their validity periods from DHCP ACK packets, and dynamically adds them to the whitelist with time-based constraints. This allows the whitelist to adapt to changing network conditions while maintaining security, resolving the contradiction between static security control and dynamic adaptability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system establishes a feedback mechanism by continuously monitoring DHCP communication between servers and clients. When the communication device receives DHCP ACK packets, it extracts IP address allocation information and automatically updates the whitelist accordingly. This closed-loop feedback ensures the whitelist remains synchronized with actual network authorization states, maintaining both security and adaptability.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If manual whitelist management is used, then control precision is improved, but operation complexity deteriorates

Engineering Contradiction:
Improvecontrol precisionVSAvoidoperation complexity
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The communication device performs self-service by automatically monitoring DHCP transactions, extracting authorized IP address information, and updating the whitelist without manual intervention. The system autonomously manages the entire whitelist maintenance process, including adding new authorized addresses, updating existing entries, and removing expired addresses based on DHCP lease expiration. This eliminates the need for manual whitelist management while maintaining precise control over authorized communications.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces DHCP lease information as an intermediary mechanism that bridges manual configuration requirements and automatic updates. By leveraging the existing DHCP protocol's authorization information, the system automatically populates and updates the whitelist with precisely authorized IP addresses and their validity periods, eliminating manual entry while maintaining control precision.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If whitelist entries are permanently stored, then reliability is improved, but adaptability to IP address expiration deteriorates

Engineering Contradiction:
Improvewhitelist reliabilityVSAvoidadaptability to IP expiration
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system implements periodic action by associating each whitelist entry with a validity period derived from DHCP lease information. The communication device monitors the expiration of these time-based entries and automatically removes expired IP addresses from the whitelist. This ensures that authorized addresses remain in the whitelist only for their valid periods, maintaining reliability during their authorization window while adapting to expiration events, thus resolving the contradiction between permanent storage and expiration adaptability.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS10397111B2Communication device, communication system, and communication method
Publication Date: 2019.08.27 ALAXALA NETWORKS
  • US10397111B2 patent drawing
  • US10397111B2 patent drawing
  • US10397111B2 patent drawing

AI summary

A packet relay device automatically generates a whitelist including an authorized communication rule. The packet relay device snoops on communications between a DHCP server and a DHCP client in accordance with DHCP. When the IP address of a DHCP client is changed, the packet relay device also automatically changes IP address information included in a whitelist related to the DHCP client to IP address information newly allocated to the DHCP client.