LLDP Security Status Verification in SDN Topology Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing Link Layer Discovery Protocol (LLDP) in Ethernet networks lacks security mechanisms, making it vulnerable to attacks and inefficient, particularly in Software Defined Networks (SDNs) where authentication and message integrity are crucial for trusted topology databases.
Innovation Solution
Incorporating security status information into LLDP messages to verify authenticity and integrity of neighboring nodes, using cryptographic keys and encryption to secure communication, allowing management nodes to differentiate between authenticated and unauthenticated nodes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security verification mechanisms are added to LLDP messages, then network security and authenticity verification are improved, but message processing complexity and energy consumption increase
Solution Approach 1:
The patent segments the LLDP message into multiple components: basic LLDP fields and separate security verification fields (authentication data, integrity check values). This segmentation allows the verification mechanism to be added without fundamentally changing the existing LLDP message structure, reducing processing complexity while improving security.
Solution Approach 2:
The patent introduces cryptographic hash functions and authentication mechanisms as intermediary layers that verify message integrity without requiring the receiving node to perform complex validation of the entire message. The intermediary verification process simplifies the overall complexity by providing a dedicated security layer.
2Reliability
If security verification mechanisms are added to LLDP messages, then network security and authenticity verification are improved, but energy consumption increases
Solution Approach 1:
The patent performs preliminary cryptographic hashing and authentication data generation at the message source before transmission. This preliminary action ensures that security verification is already partially completed, reducing the energy consumption at receiving nodes while maintaining strong security verification.
Solution Approach 2:
The patent uses computationally efficient cryptographic hash functions that provide strong security verification with minimal energy consumption. These hash-based verification mechanisms are designed to be computationally lightweight compared to more complex authentication protocols, reducing energy consumption while maintaining security.
3Reliability
If security status information is included in LLDP messages, then topology database trustworthiness is improved, but message size and processing overhead increase
Solution Approach 1:
The patent adds security status information locally to each LLDP message and each discovered topology entry, rather than requiring global security validation. This local quality approach allows the management node to verify security status of individual messages and nodes independently, improving topology database trustworthiness without requiring processing of the entire topology database.
Solution Approach 2:
The patent changes the parameter of security verification from binary (verified/not verified) to a structured set of parameters including authentication status, integrity verification results, and security level indicators. This parameter change allows for more nuanced security tracking while maintaining efficient processing through standardized parameter formats.
4Reliability
If security verification is performed on all LLDP messages, then network security is improved, but processing time and system performance decrease
Solution Approach 1:
The patent implements partial verification by performing security checks selectively based on message type, node importance, and network conditions. Critical topology changes and messages from unverified nodes receive full security verification, while routine messages use simplified verification. This partial action approach maintains network security while reducing overall processing time.
Solution Approach 2:
The patent enables nodes to perform self-verification of received LLDP messages using pre-shared cryptographic keys and local authentication databases. This self-service verification reduces the burden on central management nodes and distributes processing time, improving overall system performance while maintaining security verification on all messages.
Data Source
Figure 1
Figure 2
Figure 3~4
AI summary
Embodiments support management of network nodes (120-123; 124-127) comprised in a communication network (100). A management node (130; 131) receives (501a-b; 601), from at least some of said network nodes (120, 121), LLDP information based on one or more LLDP messages received from neighboring network nodes (120-124) that are neighbouring said at least some network nodes (120, 121). The LLDP information comprises security status information regarding said neighbouring network nodes (120-124), indicating if a neighbouring network node (120) has been verified to be authentic and indicates if the neighbouring network node (120) has been verified to be not authentic.