Autonomic Neighbor Discovery for Dynamic Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Securing computer networks is operationally difficult due to the complexity and variety of attacks, requiring manual configuration of defense mechanisms that need frequent adaptation, leading to high operational loads and costs.

Innovation Solution

Implementing autonomic neighbor discovery to automate security configuration by establishing a trust database and dynamic security barriers, allowing network devices to self-manage and adapt to changes without centralized servers, using protocols like IPv6 SEND for credential validation and trust information generation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual configuration of security features is implemented, then network protection against attacks is improved, but operational complexity and cost increase

Engineering Contradiction:
Improvenetwork protectionVSAvoidoperational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network devices automatically perform security configuration tasks including generating access control lists, validating credentials, and establishing security policies without requiring manual administrator intervention. The system self-manages security operations by autonomously responding to neighbor discovery events and dynamically adjusting security parameters.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Security parameters such as access control lists and policy configurations are dynamically changed based on real-time neighbor discovery results. The system automatically adjusts security parameters in response to detected neighbors and their validated credentials, transitioning from static manual configuration to dynamic adaptive security settings.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If manual configuration of security policies is implemented, then network security is improved, but time consumption increases

Engineering Contradiction:
Improvenetwork securityVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Security configurations and access control lists are generated and prepared in advance based on pre-configured security policies and templates. When neighbor discovery occurs, the system can quickly apply pre-prepared security measures rather than creating configurations from scratch, significantly reducing response time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system automatically generates and applies security configurations without requiring administrator time for manual setup. Network devices autonomously perform credential validation, generate access control lists, and enforce security policies, eliminating the time-consuming manual configuration process.

Inventive Principle:
Principle #25Self-service

3Productivity

If default security configuration is applied, then setup time is reduced, but security restrictiveness increases

Engineering Contradiction:
Improvesetup speedVSAvoidtraffic flow
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The security configuration transitions from a static default state to a dynamic adaptive state based on neighbor discovery. Initially, default restrictive security is applied for quick setup, but the system then dynamically adjusts security levels by validating neighbor credentials and generating appropriate access control lists, optimizing both security and traffic flow.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

Security parameters are automatically adjusted from restrictive default values to optimized values based on validated neighbor relationships. The system changes access control list parameters and policy settings dynamically, allowing legitimate internal traffic to flow freely while maintaining protection against external threats.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9043884B2Autonomic network protection based on neighbor discovery
Publication Date: 2015.05.26 CISCO TECHNOLOGY INC
  • US9043884B2 patent drawing
  • US9043884B2 patent drawing
  • US9043884B2 patent drawing

AI summary

In one implementation, security configuration is automated based on information gathered using autonomic neighbor discovery. The neighbor discovery establishes a realm of trust between neighbors, such as determining that some neighbors may be trusted and others may not be trusted. A dynamic security barrier is created using the trust where devices on the network border protect the entire network. Differences in trust result in differential security configuration.