Whitelist Generation in Dynamic IP Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In networks with dynamically changing terminal IP addresses, existing whitelist functions struggle to effectively differentiate between normal and abnormal communication, leading to security vulnerabilities, especially in flexible office environments where physical terminal connections are dynamic.

Innovation Solution

A communication apparatus that includes a protocol information table, a whitelist generating unit, and a whitelist generation possibility/impossibility determination unit, which extracts MAC and IP addresses from communication content and determines whitelist generation based on matching entries in the table, ensuring only legitimate communication is permitted.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a whitelist function is automatically generated from communication contents in a dynamic IP address network, then the ease of operation is improved, but the reliability deteriorates because abnormal terminal communication is incorrectly registered in the whitelist

Engineering Contradiction:
Improveease of operationVSAvoidreliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary registration of MAC addresses and IP addresses in the protocol information table before whitelist generation. This preliminary action ensures that only communication from registered devices is included in the whitelist, preventing abnormal terminals from being incorrectly registered while maintaining automatic whitelist generation functionality.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The protocol information table serves as an intermediary between DHCP communication and whitelist generation. It stores and validates the correspondence between MAC addresses and IP addresses, acting as a mediator that ensures only legitimate communication is included in the whitelist, thereby resolving the contradiction between automatic generation and reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If port filtering is performed based on IP address matching in DHCP network, then the reliability is improved, but the adaptability deteriorates because it cannot handle dynamic IP address assignments effectively

Engineering Contradiction:
ImprovereliabilityVSAvoidadaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically updates the protocol information table based on DHCP communication, automatically adapting to changing IP address assignments. This dynamic approach maintains reliable security control by continuously validating MAC address and IP address correspondences while effectively handling dynamic network environments.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameter validation approach by checking both MAC address and IP address correspondences in the protocol information table rather than relying solely on IP address matching. This parameter change enables the system to adapt to dynamic IP assignments while maintaining reliability through dual-validation.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If whitelist is generated without distinction between normal and abnormal communication, then the productivity is improved, but the security deteriorates because abnormal terminal communication is registered in the whitelist

Engineering Contradiction:
ImproveproductivityVSAvoidsecurity
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary registration of legitimate devices in the protocol information table before whitelist generation. This preliminary action ensures that only communication from pre-registered, legitimate devices is included in the whitelist, maintaining high productivity through automatic generation while preventing security compromises by excluding abnormal terminals.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses feedback from DHCP communication to continuously update and validate the protocol information table. This feedback mechanism ensures that the whitelist generation process receives accurate information about legitimate devices, maintaining both productivity through automation and security by excluding abnormal terminals based on validated correspondence data.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11108738B2Communication apparatus and communication system
Publication Date: 2021.08.31 ALAXALA NETWORKS
  • US11108738B2 patent drawing
  • US11108738B2 patent drawing
  • US11108738B2 patent drawing

AI summary

A whitelist generation possibility/impossibility determination unit transmits a signal for permitting generation of a whitelist to a whitelist generating unit, in a case where an IP address corresponding to a source MAC address stored in a protocol information table matches the extracted source IP address, and in a case where an IP address corresponding to a destination MAC address stored in the protocol information table matches the extracted destination IP address.