Network Security System for Secure DHCP and TFTP File Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems using secure DHCP protocols are costly and require separate servers and terminals, lacking cost-effectiveness while providing enhanced security.

Innovation Solution

A network security system that includes a communication interface to request and receive preset option field values from a DHCP server, and a processor to designate a preset location and file from a TFTP server based on these values, enabling secure file management and firmware updates without additional equipment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a secure DHCP system is developed using separate servers and terminals, then security is improved, but cost increases

Engineering Contradiction:
ImprovesecurityVSAvoidcost
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the secure DHCP server functionality and secure terminal functionality into a single network security system. The system integrates the DHCP server that provides preset option field values, the TFTP server that stores preset files, and the terminal that requests and validates these values, eliminating the need for separate secure servers and terminals while maintaining security through encrypted option field value transmission and validation mechanisms

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The network security system performs multiple functions within a single device: it acts as a DHCP server providing option field values, a TFTP server providing preset files, and a terminal validating received values. This multi-functionality reduces system cost while maintaining the security benefits of a separate secure DHCP architecture

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If traditional DHCP is used for automatic IP allocation, then ease of operation is improved, but security deteriorates due to spoofing attacks

Engineering Contradiction:
Improveautomatic IP allocationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system applies preliminary anti-action by encrypting the preset option field values (including IP address information and file identification information) before transmission from the DHCP server to the terminal. This pre-encryption prevents spoofing terminals from intercepting and using valid option field values, addressing the security vulnerability of traditional DHCP while maintaining automatic IP allocation functionality

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The terminal validates the received preset option field values by comparing them against expected values and provides feedback to the DHCP server about whether the values are valid or invalid. This feedback mechanism ensures that only authorized terminals receive valid IP address assignments, preventing spoofing attacks while maintaining automatic allocation

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11201910B2Network security system and method for operating same
Publication Date: 2021.12.14 HANWHA VISION CO LTD
  • US11201910B2 patent drawing
  • US11201910B2 patent drawing
  • US11201910B2 patent drawing

AI summary

Provided is a network security system including a communication interface that transmits a request for a preset option field value to a Dynamic Host Configuration Protocol (DHCP) server, receives a preset option field value corresponding to the request for the preset option field value from the DHCP server, transmits a request for a preset file to a Trivial File Transfer Protocol (TFTP) server, and receives a preset file corresponding to the request for the preset file from the TFTP server, and a processor that designates a preset location and the preset file of the TFTP server based on the preset option field value, wherein the preset file includes a file different from a file specified in the preset option field value by the DHCP.