LLDP Authentication Key for Lightweight Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security mechanisms, such as IEEE 802.1X, are complex and not suitable for light-weighted network devices, failing to prevent unauthorized connections and data breaches in local area networks, while IEEE 802.1ab lacks authentication and authorization features.
Innovation Solution
Incorporating an authentication key into LLDP packets transmitted under the 802.1ab communication protocol to periodically verify network devices, blocking unauthorized access by analyzing the legitimacy of the authentication key within the packets.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If IEEE 802.1X authentication protocol is used to provide security authentication mechanism, then network security is improved, but device complexity and computational overhead increase making it unsuitable for light-weighted network devices
Solution Approach 1:
The patent extracts the essential authentication function from the complex 802.1X protocol by incorporating an authentication key directly into the LLDP packet. This separation allows light-weighted devices to perform authentication without implementing the entire 802.1X protocol stack, reducing device complexity while maintaining security.
Solution Approach 2:
The authentication key embedded in the LLDP packet serves multiple functions: it provides authentication verification, device identification, and security validation simultaneously. This multi-functionality eliminates the need for separate authentication procedures, reducing computational overhead for light-weighted devices.
2Reliability
If IEEE 802.1X authentication protocol is used to prevent unauthorized connections, then network security is improved, but computational overhead increases making it unsuitable for light-weighted network devices
Solution Approach 1:
The authentication key is pre-configured in the LLDP packet before transmission. This preliminary action allows receiving devices to verify authentication without performing complex real-time computations, significantly reducing computational overhead and energy consumption for light-weighted devices.
Solution Approach 2:
Instead of implementing the full 802.1X authentication mechanism, the patent uses a simplified copy approach by embedding the authentication key directly in the LLDP packet. This copying method allows verification without the computational burden of the original protocol.
3Adaptability or versatility
If IEEE 802.1ab protocol is used for light-weighted network devices, then device compatibility is improved, but authentication and authorization capabilities are lost
Solution Approach 1:
The patent merges the authentication capability into the existing LLDP packet structure of the 802.1ab protocol. By combining authentication functionality with the familiar LLDP framework, light-weighted devices can maintain compatibility while gaining authentication capabilities without requiring separate protocols.
Solution Approach 2:
The modified LLDP packet serves dual purposes: it maintains the original link layer discovery functions of 802.1ab while simultaneously providing authentication and authorization capabilities. This multi-functionality allows light-weighted devices to use a single protocol for both discovery and security.
Data Source
AI summary
A method for preventing unauthorized connection in a network system mainly includes adding an authentication key in the LLDP (link layer discovery protocol) transmitted in accordance with the 802.1ab communication protocol so as to proceed with security mechanism under the structure of 802.1ab communication protocol. The method for preventing unauthorized connection includes receiving a LLDP packet satisfying the 802.1ab communication protocol transmitted from a second network device by a first network device in a network system; analyzing the LLDP packet and checking whether the LLDP packet contains a legitimate authentication key; and if the authentication key does not exist or is illegitimate, then block all packets transmitted from the second network device so as to prevent the unauthorized second network device from using the network transmission service provided by the first network device.


