LLDP Link Discovery Security and Efficiency
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network management technologies face issues with device information leakage and inefficient LLDP packet transmission, leading to potential security risks and operational issues due to the lack of secure authentication and inappropriate TLV exchange.
Innovation Solution
A method and apparatus for determining the security level of a directly connected device using authentication TLVs in LLDP packets, selectively sending TLVs based on device type, and encrypting packets to reduce information leakage and improve network efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If all TLVs are exchanged between directly connected devices, then complete device information is transmitted, but device information leakage risk increases
Solution Approach 1:
The patent segments TLVs into two categories: mandatory TLVs (Chassis ID, Port ID, Time to Live, End of LLDPDU) that are always exchanged, and optional TLVs that are conditionally exchanged based on security level. This segmentation allows the system to transmit essential device information while filtering out sensitive information to prevent leakage.
Solution Approach 2:
The patent applies different quality levels of information exchange to different communication contexts. Secure devices exchange complete TLV information including optional fields, while insecure devices exchange only mandatory TLVs. This local quality differentiation ensures information completeness where safe and minimizes exposure where risky.
2Reliability
If security authentication is implemented in LLDP packets, then network security is improved, but device complexity increases
Solution Approach 1:
The patent changes the security parameter from complex cryptographic authentication to a simple security level indicator in the LLDP packet. Devices transmit their security level (secure/insecure) through TLVs, and receiving devices adjust their information exchange accordingly. This parameter change maintains security reliability while avoiding the complexity of cryptographic protocols.
3Productivity
If selective TLV exchange based on device type is implemented, then network efficiency is improved, but protocol complexity increases
Solution Approach 1:
The patent performs preliminary device type identification using mandatory TLVs (Chassis ID, Port ID) before deciding on optional TLV exchange. Devices pre-determine whether to exchange additional information based on the identified device type and security level, avoiding unnecessary protocol processing and improving network efficiency.
Data Source
AI summary
The present application discloses a link discovery method and apparatus. The method includes: when a network device receives a first LLDP packet sent by a directly connected device, determining a security level of the directly connected device according to an authentication TLV; if the security level of the directly connected device is secure, determining a device type of the directly connected device, and sending a second LLDP packet to the directly connected device according to a correspondence between the device type of the directly connected device and a TLV. In the present application, a corresponding TLV is selected according to the device type and sent, which avoids that all types of TLVs are sent to a directly connected device every time, and reduces a possibility of device information leakage. It is ensured that a sent LLDP packet is more proper, and a link overhead is reduced.


