LLDP-Based Automatic DHCP Key Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current DHCP key management lacks an automatic solution for secure key exchange, making networks vulnerable to attacks like Man-in-the-Middle (MitM) attacks, and hindering the widespread adoption of DHCP message authentication.

Innovation Solution

The proposed solution utilizes Link Layer Discovery Protocol (LLDP) security extensions to enable automatic key exchange for DHCP clients, where an upstream neighbor node securely provides DHCP keys via LLDP extensions before any DHCP message transmission, ensuring authenticated DHCP communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual key exchange is used for DHCP authentication, then network security is improved, but operational complexity and time consumption increase

Engineering Contradiction:
Improvenetwork securityVSAvoidkey exchange process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies preliminary action by pre-configuring the DHCP server with a secret key and implementing an automatic key distribution mechanism that distributes this key to authorized DHCP clients before actual DHCP authentication occurs. This eliminates manual key exchange operations while maintaining security, as the key distribution happens automatically as a preliminary step in the DHCP initialization process.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If DHCP message authentication is implemented, then security against MitM attacks is improved, but system complexity increases

Engineering Contradiction:
Improveprotection against MitM attacksVSAvoidDHCP system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary authentication mechanism where a pre-shared secret key acts as a mediator between the DHCP server and authorized clients. This secret key enables automatic authentication without requiring complex cryptographic handshakes or certificate verification processes, thus providing MitM protection while keeping the system relatively simple.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Extent of automation

If automatic key distribution is implemented, then ease of deployment is improved, but security requirements increase

Engineering Contradiction:
Improvekey distribution processVSAvoidsecurity infrastructure
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-configuring the secret key in the DHCP server and establishing authorization rules beforehand. This allows automatic key distribution to occur seamlessly during DHCP initialization without requiring complex real-time security decisions, thereby achieving high automation while keeping the security infrastructure manageable through advance preparation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12278905B2Automatic distribution of dynamic host configuration protocol (DHCP) keys via link layer discovery protocol (LLDP)
Publication Date: 2025.04.15 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US12278905B2 patent drawing
  • US12278905B2 patent drawing
  • US12278905B2 patent drawing

AI summary

A method for obtaining information from a server. The method includes a client device receiving a link layer message transmitted by a network node, the link layer message comprising authentication information; and the client device using the authentication information to obtain information from the server.