Network Device O&M Access Security with Dynamic Settings
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network device access security methods are vulnerable to unauthorized access by malicious users who can bypass authentication and encryption, obtain a valid IP address, or spoof their MAC address, posing a risk to network operations and maintenance.
Innovation Solution
Implement a method where network devices dynamically change access settings such as IP addresses, serial communication parameters, access protocols, and authentication methods upon receiving a trigger, and communicate these changes to a service terminal using audio or light signals.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If authentication and encryption methods are used for O&M interface access, then security against unauthorized access is improved, but vulnerability to determined attackers who can bypass authentication or obtain credentials remains
Solution Approach 1:
The patent implements dynamic IP address assignment for O&M interfaces, where the IP address changes periodically or upon trigger events. This dynamic behavior prevents static configuration attacks and makes it difficult for attackers to maintain persistent unauthorized access, directly addressing the security vulnerability where attackers could obtain valid credentials and maintain access.
Solution Approach 2:
The system performs preliminary security validation by checking whether the accessing device is an authorized service terminal before granting O&M interface access. This preliminary action occurs before authentication, preventing attackers from even attempting to use stolen credentials, thereby addressing the vulnerability where determined attackers could bypass authentication.
2Ease of operation
If static IP address configuration is used for O&M access, then ease of operation is improved, but security against IP spoofing and unauthorized access deteriorates
Solution Approach 1:
The patent implements dynamic IP address assignment where the O&M interface IP address changes periodically or upon trigger events. This eliminates the security vulnerability of static IP configuration while maintaining ease of operation through automated assignment and service terminal recognition, resolving the contradiction between operational simplicity and security.
3Reliability
If MAC address filtering is used for access control, then security against unauthorized devices is improved, but vulnerability to MAC address spoofing remains
Solution Approach 1:
The patent implements dynamic IP address assignment combined with service terminal identification, where the authorized service terminal is recognized through multiple parameters including but not limited to MAC address. This dynamic multi-parameter authentication approach prevents MAC spoofing attacks while maintaining access control security.
4Ease of manufacture
If default IP addresses are used for network nodes, then ease of deployment is improved, but security against unauthorized access deteriorates
Solution Approach 1:
The patent implements dynamic IP address assignment that automatically assigns secure, changing IP addresses to network nodes during deployment and operation. This eliminates the security vulnerability of default IP addresses while maintaining deployment simplicity through automated configuration, resolving the contradiction between ease of deployment and security.
Data Source
AI summary
The present disclosure relates to a service terminal, a network device and a method for access security at Operation and Maintenance, O&M, support of the network device. The network device (100) and the service terminal (20) are configured to establish a communication using at least one access setting for establishing a communication. The at least one access setting comprising one of the following: an IP address, one or several serial communication parameters, access protocol, authentication method. The method comprises to receive a trigger for changing the at least one access setting for establishing a communication with the service terminal, and to change the at least one access setting for establishing the communication with the service terminal to at least one new access setting.


