Network Security System for Secure DHCP and TFTP File Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security systems using secure DHCP protocols are costly and require separate servers and terminals, lacking cost-effectiveness while providing enhanced security.
Innovation Solution
A network security system that includes a communication interface to request and receive preset option field values from a DHCP server, and a processor to designate a preset location and file from a TFTP server based on these values, enabling secure file management and firmware updates without additional equipment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a secure DHCP system is developed using separate servers and terminals, then security is improved, but cost increases
Solution Approach 1:
The patent combines the secure DHCP server functionality and secure terminal functionality into a single network security system. The system integrates the DHCP server that provides preset option field values, the TFTP server that stores preset files, and the terminal that requests and validates these values, eliminating the need for separate secure servers and terminals while maintaining security through encrypted option field value transmission and validation mechanisms
Solution Approach 2:
The network security system performs multiple functions within a single device: it acts as a DHCP server providing option field values, a TFTP server providing preset files, and a terminal validating received values. This multi-functionality reduces system cost while maintaining the security benefits of a separate secure DHCP architecture
2Ease of operation
If traditional DHCP is used for automatic IP allocation, then ease of operation is improved, but security deteriorates due to spoofing attacks
Solution Approach 1:
The system applies preliminary anti-action by encrypting the preset option field values (including IP address information and file identification information) before transmission from the DHCP server to the terminal. This pre-encryption prevents spoofing terminals from intercepting and using valid option field values, addressing the security vulnerability of traditional DHCP while maintaining automatic IP allocation functionality
Solution Approach 2:
The terminal validates the received preset option field values by comparing them against expected values and provides feedback to the DHCP server about whether the values are valid or invalid. This feedback mechanism ensures that only authorized terminals receive valid IP address assignments, preventing spoofing attacks while maintaining automatic allocation
Data Source
AI summary
Provided is a network security system including a communication interface that transmits a request for a preset option field value to a Dynamic Host Configuration Protocol (DHCP) server, receives a preset option field value corresponding to the request for the preset option field value from the DHCP server, transmits a request for a preset file to a Trivial File Transfer Protocol (TFTP) server, and receives a preset file corresponding to the request for the preset file from the TFTP server, and a processor that designates a preset location and the preset file of the TFTP server based on the preset option field value, wherein the preset file includes a file different from a file specified in the preset option field value by the DHCP.


