Automatic Network Provisioning via Magic Packets
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network provisioning methods require manual configuration and are vulnerable to security risks, especially when adding new devices or reconfiguring existing ones, as they often necessitate a separate machine connected to the local subnet and involve cumbersome processes like DHCP static assignment or IPv6 Link-Local Addressing, which are not suitable for heterogeneous environments.
Innovation Solution
A computer-implemented method and system for automatic network provisioning that broadcasts provisioning requests and configuration packets across a network environment, allowing devices to respond and receive configuration information without the need for a separate machine on the local subnet, using magic packets to manage network configuration and address provisioning.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Extent of automation
If DHCP is used for network provisioning, then address assignment is automated, but security vulnerabilities increase
Solution Approach 1:
The patent extracts the provisioning request and configuration delivery functions from the traditional DHCP client-server model and implements them directly at the device level using embedded provisioning agents. Devices autonomously broadcast provisioning requests and receive configuration packets without requiring external DHCP server intervention, thereby eliminating DHCP-related security vulnerabilities while maintaining automated address assignment.
Solution Approach 2:
The patent enables devices to self-provision by embedding provisioning agents that automatically broadcast provisioning requests, receive configuration packets, and configure network settings without human intervention or external DHCP server dependency. This self-service mechanism achieves automated address assignment while avoiding the security risks associated with DHCP protocols.
2Stability of the object's composition
If DHCP static assignment is used, then IP address fixation is achieved, but administrative burden increases due to manual MAC address discovery and configuration
Solution Approach 1:
The patent enables devices to automatically generate and include their unique identifiers (such as device IDs or MAC addresses) in provisioning requests. The provisioning server automatically binds IP addresses to these identifiers and delivers configured packets, eliminating the need for administrators to manually discover and configure MAC addresses while maintaining stable IP address assignment.
Solution Approach 2:
The patent implements preliminary binding of device identifiers to IP addresses in the provisioning server before configuration delivery. This pre-configuration approach ensures stable IP address fixation while automating the entire process, eliminating the need for subsequent manual administrative intervention.
3Extent of automation
If IPv6 Link-Local Addressing is used, then automatic address provisioning is achieved, but mutability is lost requiring a machine on the local subnet for configuration
Solution Approach 1:
The patent implements a dynamic provisioning system where devices can receive and update their network configuration packets at any time through broadcast communication. The provisioning server can deliver updated configuration packets to devices regardless of whether they are on the local subnet, enabling both automatic address provisioning and configuration mutability without requiring a machine physically present on the local subnet.
Solution Approach 2:
The patent creates a universal provisioning mechanism that works across different network topologies and subnets. The broadcast-based provisioning system can deliver configuration packets to any device in the network regardless of subnet boundaries, combining the automation benefits of link-local addressing with the flexibility to update configurations remotely.
4Object-affected harmful factors
If manual configuration is used, then security control is improved, but provisioning time and administrative effort increase significantly
Solution Approach 1:
The patent implements a self-service provisioning system where devices autonomously broadcast provisioning requests and automatically receive and apply configuration packets. This eliminates the need for manual administrator intervention in the provisioning process, dramatically reducing provisioning time while maintaining security through controlled configuration packet distribution from authorized provisioning servers.
Solution Approach 2:
The patent implements preliminary security controls in the provisioning server that validate and authorize configuration packets before delivery. This pre-validation approach maintains strong security control while enabling automated rapid provisioning, as devices can immediately receive pre-authorized configuration packets without waiting for manual administrator approval.
Data Source
AI summary
According to one embodiment, a method for automatic management network provisioning includes: broadcasting a provisioning request to one or more devices; receiving at least one provisioning reply from the device(s); and broadcasting a provisioning configuration packet to device(s) from which a provisioning reply was received. In another embodiment, a method for peer-based automatic management network provisioning includes broadcasting network configuration information corresponding to a particular device to one or more other devices of a network environment; determining, after the broadcast, whether such network configuration information was modified; and requesting, from one or more of the other devices, the network configuration information corresponding to the particular device. The request is made in response to determining the particular device network configuration information was modified after broadcasting the network configuration information to the one or more other devices. Corresponding systems and computer program products are also disclosed.


