Dynamic Whitelist Update for DHCP-Managed IP Addresses
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing whitelisting technologies struggle to adapt to networks where IP addresses of terminals are dynamically changed using DHCP, as they rely on static whitelists and fail to effectively control suspicious behavior from authorized terminals.
Innovation Solution
A communication device with a protocol information table storing MAC addresses, IP addresses, and expiration times, and a processing unit that updates and generates entries for dynamically allocated IP addresses, allowing for real-time adaptation of whitelists to manage communications securely in DHCP environments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a static whitelist is used for security control, then security level is improved, but adaptability to dynamic IP address changes deteriorates
Solution Approach 1:
The patent implements a dynamic whitelist system that automatically updates authorized IP addresses based on DHCP lease information. The communication device monitors DHCP transactions, extracts authorized IP addresses and their validity periods from DHCP ACK packets, and dynamically adds them to the whitelist with time-based constraints. This allows the whitelist to adapt to changing network conditions while maintaining security, resolving the contradiction between static security control and dynamic adaptability.
Solution Approach 2:
The system establishes a feedback mechanism by continuously monitoring DHCP communication between servers and clients. When the communication device receives DHCP ACK packets, it extracts IP address allocation information and automatically updates the whitelist accordingly. This closed-loop feedback ensures the whitelist remains synchronized with actual network authorization states, maintaining both security and adaptability.
2Measurement precision
If manual whitelist management is used, then control precision is improved, but operation complexity deteriorates
Solution Approach 1:
The communication device performs self-service by automatically monitoring DHCP transactions, extracting authorized IP address information, and updating the whitelist without manual intervention. The system autonomously manages the entire whitelist maintenance process, including adding new authorized addresses, updating existing entries, and removing expired addresses based on DHCP lease expiration. This eliminates the need for manual whitelist management while maintaining precise control over authorized communications.
Solution Approach 2:
The patent introduces DHCP lease information as an intermediary mechanism that bridges manual configuration requirements and automatic updates. By leveraging the existing DHCP protocol's authorization information, the system automatically populates and updates the whitelist with precisely authorized IP addresses and their validity periods, eliminating manual entry while maintaining control precision.
3Reliability
If whitelist entries are permanently stored, then reliability is improved, but adaptability to IP address expiration deteriorates
Solution Approach 1:
The system implements periodic action by associating each whitelist entry with a validity period derived from DHCP lease information. The communication device monitors the expiration of these time-based entries and automatically removes expired IP addresses from the whitelist. This ensures that authorized addresses remain in the whitelist only for their valid periods, maintaining reliability during their authorization window while adapting to expiration events, thus resolving the contradiction between permanent storage and expiration adaptability.
Data Source
AI summary
A packet relay device automatically generates a whitelist including an authorized communication rule. The packet relay device snoops on communications between a DHCP server and a DHCP client in accordance with DHCP. When the IP address of a DHCP client is changed, the packet relay device also automatically changes IP address information included in a whitelist related to the DHCP client to IP address information newly allocated to the DHCP client.


