LLDP Authentication Key for Lightweight Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security mechanisms, such as IEEE 802.1X, are complex and not suitable for light-weighted network devices, failing to prevent unauthorized connections and data breaches in local area networks, while IEEE 802.1ab lacks authentication and authorization features.

Innovation Solution

Incorporating an authentication key into LLDP packets transmitted under the 802.1ab communication protocol to periodically verify network devices, blocking unauthorized access by analyzing the legitimacy of the authentication key within the packets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IEEE 802.1X authentication protocol is used to provide security authentication mechanism, then network security is improved, but device complexity and computational overhead increase making it unsuitable for light-weighted network devices

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication procedure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the essential authentication function from the complex 802.1X protocol by incorporating an authentication key directly into the LLDP packet. This separation allows light-weighted devices to perform authentication without implementing the entire 802.1X protocol stack, reducing device complexity while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The authentication key embedded in the LLDP packet serves multiple functions: it provides authentication verification, device identification, and security validation simultaneously. This multi-functionality eliminates the need for separate authentication procedures, reducing computational overhead for light-weighted devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If IEEE 802.1X authentication protocol is used to prevent unauthorized connections, then network security is improved, but computational overhead increases making it unsuitable for light-weighted network devices

Engineering Contradiction:
Improveunauthorized connection preventionVSAvoidcomputational overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The authentication key is pre-configured in the LLDP packet before transmission. This preliminary action allows receiving devices to verify authentication without performing complex real-time computations, significantly reducing computational overhead and energy consumption for light-weighted devices.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Instead of implementing the full 802.1X authentication mechanism, the patent uses a simplified copy approach by embedding the authentication key directly in the LLDP packet. This copying method allows verification without the computational burden of the original protocol.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If IEEE 802.1ab protocol is used for light-weighted network devices, then device compatibility is improved, but authentication and authorization capabilities are lost

Engineering Contradiction:
Improvelight-weighted device compatibilityVSAvoidauthentication capability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent merges the authentication capability into the existing LLDP packet structure of the 802.1ab protocol. By combining authentication functionality with the familiar LLDP framework, light-weighted devices can maintain compatibility while gaining authentication capabilities without requiring separate protocols.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The modified LLDP packet serves dual purposes: it maintains the original link layer discovery functions of 802.1ab while simultaneously providing authentication and authorization capabilities. This multi-functionality allows light-weighted devices to use a single protocol for both discovery and security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7926100B2Method for preventing unauthorized connection in network system
Publication Date: 2011.04.12 CAMEO COMM
  • US7926100B2 patent drawing
  • US7926100B2 patent drawing
  • US7926100B2 patent drawing

AI summary

A method for preventing unauthorized connection in a network system mainly includes adding an authentication key in the LLDP (link layer discovery protocol) transmitted in accordance with the 802.1ab communication protocol so as to proceed with security mechanism under the structure of 802.1ab communication protocol. The method for preventing unauthorized connection includes receiving a LLDP packet satisfying the 802.1ab communication protocol transmitted from a second network device by a first network device in a network system; analyzing the LLDP packet and checking whether the LLDP packet contains a legitimate authentication key; and if the authentication key does not exist or is illegitimate, then block all packets transmitted from the second network device so as to prevent the unauthorized second network device from using the network transmission service provided by the first network device.