Trusted DHCP Server for Secure IP Allocation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network protocols, such as DHCP, face risks of fraudulent IP address allocation and unauthorized access due to the lack of trusted communication channels, which can lead to security breaches and unauthorized access to sensitive networks.

Innovation Solution

Implementing a trusted dynamic host configuration protocol (DHCPT) and trusted domain name system (DNS) that operate within trusted security zones, using trust tokens to verify continuity of trust and ensuring that IP addresses and routing information are allocated and transmitted over trusted end-to-end communication links, thereby preventing unauthorized access and ensuring secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional DHCP protocol is used for IP address allocation, then network connectivity is established quickly and simply, but security risks increase due to lack of trusted communication channels

Engineering Contradiction:
Improvesecurity of IP address allocationVSAvoidcomplexity of communication protocol
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a trusted server as an intermediary between the client and the DHCP server. This trusted server verifies the authenticity of DHCP requests and responses, ensuring that only authorized devices can obtain IP addresses. The intermediary validates cryptographic credentials and ensures secure communication throughout the DHCP process, resolving the security issue without requiring fundamental changes to the DHCP protocol structure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary authentication before IP address allocation. The client must first prove its identity and authorization to the trusted server before receiving DHCP responses. This preliminary verification step prevents unauthorized devices from obtaining IP addresses, enhancing security while maintaining the simplicity of the overall DHCP process by placing authentication requirements at the beginning rather than throughout the entire protocol.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If domain name translation is performed without trusted verification, then translation speed is fast, but fraudulent translation responses can be transmitted

Engineering Contradiction:
Improvetrustworthiness of domain name translationVSAvoidspeed of domain name translation
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The trusted server acts as an intermediary in domain name translation by verifying the authenticity of translation requests and responses. The server uses cryptographic credentials to ensure that only authorized clients can perform translations and that the translation responses are genuine. This intermediary approach maintains translation speed while preventing fraudulent responses, as the verification process occurs efficiently at the server level without blocking legitimate requests.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If trusted security zones are implemented for all network operations, then security and integrity are enhanced, but system complexity and configuration requirements increase

Engineering Contradiction:
Improveintegrity of network communicationVSAvoidcomplexity of security zone configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The trusted server serves as a central intermediary that manages security zone configuration and verification. Instead of requiring each client to independently configure and manage security zones, the trusted server handles authentication, credential verification, and security policy enforcement. This approach enhances the integrity of network communication while reducing the complexity at the client level, as security configuration is centralized and automated.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements self-service authentication where clients automatically provide cryptographic credentials and prove their authorization to the trusted server. The system handles security verification automatically without requiring manual configuration or complex setup at the client end. This self-service approach enhances security integrity while minimizing configuration complexity, as the authentication process is transparent and automated.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8752140B1System and methods for trusted internet domain networking
Publication Date: 2014.06.10 T MOBILE INNOVATIONS LLC
  • US8752140B1 patent drawing
  • US8752140B1 patent drawing
  • US8752140B1 patent drawing

AI summary

A method of performing a trusted dynamic host configuration protocol (DHCPT). The method comprises receiving a trusted dynamic host configuration protocol request message, wherein the request message was created in and transmitted from a trusted security zone of a computing device, and wherein the request message requests an internet protocol (IP) address and routing information for the computing device, allocating an internet protocol address and determining routing information for the computing device, wherein the allocating and determining are performed by a dynamic host configuration protocol server while executing in a trusted security zone of the server, and transmitting the internet protocol address and routing information to the computing device over a trusted end-to-end communication link.