SD-WAN Controller Location Verification for CPE Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current SD-WAN configurations are vulnerable to information leakage due to incorrect or tampered two-dimensional codes, allowing unauthorized access to enterprise branch sites.
Innovation Solution
A method and device configuration that verifies the location of a customer-premises equipment (CPE) by sending a verification request based on indicator or sound responses, ensuring that configuration information is only sent if the CPE is correctly located, thereby preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a two-dimensional code or bar code is used to identify CPE devices for configuration, then the deployment process is simplified and automated, but the system becomes vulnerable to incorrect pasting or malicious tampering, leading to information leakage
Solution Approach 1:
The patent applies preliminary action by performing location verification before sending configuration information. The SDN controller sends a verification request to the CPE device to confirm its location matches the expected deployment site before proceeding with configuration delivery, preventing unauthorized access from the outset
Solution Approach 2:
The patent implements feedback by requiring the CPE device to respond to location verification requests from the SDN controller. The device must confirm its identity and location through a verification response, creating a closed-loop validation process that ensures configuration information is only sent to authorized devices
2Productivity
If configuration information is sent to CPE devices based on scanned codes, then deployment efficiency is improved, but unauthorized devices may receive configuration information and access enterprise sites
Solution Approach 1:
The patent applies preliminary action by performing location verification before sending configuration information. The SDN controller sends a verification request to the CPE device to confirm its location matches the expected deployment site before proceeding with configuration delivery, preventing unauthorized access from the outset
Solution Approach 2:
The patent applies preliminary anti-action by proactively preventing unauthorized access through location verification. By validating the CPE device's location and identity before configuration delivery, the system counteracts the potential harm of code tampering or incorrect pasting before it can result in information leakage
3Device complexity
If the SDN controller sends configuration information to any CPE device that connects, then system simplicity is maintained, but security vulnerabilities arise from code tampering or misplacement
Solution Approach 1:
The patent applies preliminary action by performing location verification before sending configuration information. The SDN controller sends a verification request to the CPE device to confirm its location matches the expected deployment site before proceeding with configuration delivery, preventing unauthorized access from the outset
Solution Approach 2:
The patent introduces an intermediary verification mechanism between the SDN controller and CPE device. The location verification process acts as a mediator that validates the device's authenticity and location, adding a security layer without fundamentally changing the overall system architecture
Data Source
AI summary
Embodiments of this application disclose a configuration method that may be applied to a software-defined wide area network (SD-WAN). The method includes: receiving a correspondence between a device identifier of a first device and a first location; sending, to the first device, a verification request related to verifying whether the first device is located at the first location; receiving a verification response to the verification request; and determining, based on the verification response, whether to send configuration information corresponding to the first location to the first device. The methods in the embodiments of this application may be implemented by a software-defined network (SDN) controller.


