IPv6 Zero Touch Provisioning via Management Port Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network devices with IPv6 disabled by default cannot perform zero touch provisioning over IPv6 networks due to security concerns associated with enabling IPv6 on data ports, which poses risks such as host-scanning attacks.
Innovation Solution
Utilizing a Dynamic Host Configuration Protocol (DHCP) server to assign an IPv6 address to the management port of a network device, allowing it to communicate with the network management system via an IPv6 network for zero touch provisioning while maintaining security by separating the management plane from the data plane.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Extent of automation
If IPv6 is enabled on data ports to allow zero touch provisioning, then network device can be automatically configured over IPv6 network, but security risks increase due to host-scanning attacks
Solution Approach 1:
The patent segments the network device into two distinct planes: a management plane that handles provisioning and configuration traffic, and a data plane that handles user data traffic. By enabling IPv6 only on the management plane (specifically on the management port), the system allows zero touch provisioning while preventing exposure of the data plane to IPv6-based host-scanning attacks. This segmentation isolates the automated provisioning function from security threats.
Solution Approach 2:
The patent introduces a management port as an intermediary component that facilitates communication between the network device and the network management system over IPv6. This management port acts as a dedicated channel that mediates all provisioning traffic, preventing direct exposure of the data plane to potential attackers while still enabling the desired automated configuration functionality.
2Object-affected harmful factors
If IPv6 is disabled by default for security reasons, then security risks are reduced, but zero touch provisioning over IPv6 networks cannot be performed
Solution Approach 1:
The patent applies local quality by enabling IPv6 selectively and locally on the management port rather than globally across all interfaces. This allows the network device to have IPv6 capability where it is needed (for management and provisioning) while maintaining IPv6-disabled state on data ports for security. The DHCP server similarly applies local quality by providing IPv6 configuration specifically for the management interface.
3Adaptability or versatility
If IPv6 is enabled on all ports for full functionality, then network versatility is improved, but attack surface increases exposing management interfaces
Solution Approach 1:
The patent segments IPv6 functionality into distinct operational domains: the management plane where IPv6 is enabled for provisioning and the data plane where IPv6 remains disabled for security. This segmentation allows the system to achieve protocol versatility where needed while minimizing exposure to attacks by restricting IPv6 to the managed environment rather than enabling it universally across all interfaces.
Data Source
AI summary
A network device may send, to a Dynamic Host Configuration Protocol (DHCP) server, a request for an Internet Protocol version 6 (IPv6) address to be assigned to a management port of the network device, wherein IPv6 is disabled at the network device, and may receive a message that includes information associated with a network management system (NMS) and IPv6 configuration information for enabling IPv6 processing on the management port. In response to receiving the IPv6 configuration information, the network device may enable IPv6 processing on the management port of the network device and may register with the NMS based at least in part on the information associated with the NMS. The network device may, in response to receiving one or more configuration commands sent from the NMS to the management port of the network device, configure the network device according to the one or more configuration commands.


