Network Management Server for Unauthorized Device Cutoff
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for managing information processing devices connected to a network struggle to distinguish between devices with the same identifier, making it difficult to determine whether a device is authorized or unauthorized, especially when unauthorized devices spoof the identifier of authorized devices.
Innovation Solution
A management server and communication cutoff device system that acquires and accumulates device and segment identifying information to determine if communication cutoff is required, and notifies a communication cutoff device to disconnect unauthorized devices, using ARP spoofing and MAC address manipulation to manage network segments effectively.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a whitelist or blacklist method is used to manage information processing devices by recording their identifiers, then it is simple to implement and operate, but it becomes impossible to distinguish between multiple devices having the same identifier, making authorization determination difficult
Solution Approach 1:
The patent segments the identifier into two distinct parts: a common identifier (shared by multiple devices) and a unique identifier (specific to each device). This segmentation allows the system to first group devices by common identifier and then differentiate them using unique identifiers, resolving the contradiction between simple management and accurate identification.
Solution Approach 2:
The patent adds an additional dimension to device identification by introducing unique identifiers beyond the common identifier. Instead of relying solely on a single identifier dimension, the system now operates in a two-dimensional identifier space, enabling precise distinction between devices that share the same common identifier.
2Adaptability or versatility
If multiple devices with the same identifier are connected to the network, then resource sharing and flexibility are improved, but the ability to determine whether a specific device is authorized or unauthorized deteriorates
Solution Approach 1:
By segmenting the identifier system into common and unique components, the patent maintains network flexibility (devices can share common identifiers) while ensuring authorization reliability (each device is uniquely identified for accurate authorization checks).
Solution Approach 2:
The system uses the unique identifier as feedback information to distinguish between multiple devices sharing the same common identifier. When an ARP request is received, the system retrieves the unique identifier corresponding to the common identifier and uses it to accurately determine whether the specific device is authorized, preventing unauthorized access while allowing legitimate devices to communicate.
3Ease of operation
If ARP spoofing is used to establish connections for not-yet-authorized devices, then connection establishment becomes easier, but the ability to distinguish between authorized and unauthorized devices deteriorates
Solution Approach 1:
The patent performs preliminary action by pre-registering both common identifiers and unique identifiers for authorized devices in the management server before they connect to the network. When devices attempt to connect via ARP spoofing, the system can immediately retrieve the pre-registered unique identifier and verify authorization, making detection of unauthorized devices straightforward despite the ease of connection establishment.
Data Source
AI summary
An inspection system 1 having a plurality of network segments 2 includes: a management information acquiring unit 34 which acquires a node ID that a node 90 belonging to the network segment 2 can be identified and a segment ID that the network segment 2 to which the node 90 belongs can be identified; a management information accumulating unit 35 which accumulates the acquired node ID and segment ID in the way of being associated with each other; a cutoff determining unit 36 which determines whether the cutoff of the communications of the node 90 specified by the accumulated node ID and segment ID is required or not; and a communication cutoff unit 21 which cuts off the communications of the node 90 specified by the node ID in the case of determining that the cutoff of the communications of the node 90 is required.


