CGA Generation Using Network Traffic Hashes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security systems fail to effectively identify and mitigate unauthorized computing devices within a network environment, as they rely on randomly generated cryptographically generated addresses (CGA) that can be exploited by rogue devices, leading to potential disruptions and data compromise.
Innovation Solution
A system that monitors network traffic to generate and validate CGA using a cryptographic hash of network data, ensuring that only authorized devices with correct modifiers can generate valid CGA, thereby detecting and remediating unauthorized devices by blocking them from the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If randomly generated CGA are used for device identification, then device authorization is simplified, but network security is compromised allowing unauthorized devices to infiltrate
Solution Approach 1:
The patent changes the parameter used in CGA generation from random values to cryptographic hashes of observed network traffic. This transformation maintains the ease of CGA generation while significantly improving security, as the hash-based modifier is deterministic and verifiable against actual network traffic patterns
Solution Approach 2:
The system implements feedback by continuously monitoring network traffic and using this observed data to generate the modifier for CGA. This feedback loop ensures that CGA are based on actual network characteristics rather than random values, enabling verification of device authenticity while maintaining operational simplicity
2Reliability
If CGA validation using network traffic monitoring is implemented, then network security is improved, but system complexity increases
Solution Approach 1:
The validation system leverages the device's own network traffic and public key to generate and validate its CGA. The device essentially validates itself by demonstrating that its CGA could have been generated from the observed network traffic and its public key, reducing the need for complex external validation infrastructure
Solution Approach 2:
The system performs preliminary monitoring of network traffic before CGA validation is needed. By collecting and hashing network traffic data in advance, the system prepares the modifier that will be used for CGA generation and validation, simplifying the actual validation process when a device needs to be authorized
Data Source
AI summary
A system is provided for generating and signing cryptographically generated addresses (“CGA”) using computing network traffic. In particular, the system, as well as any authorized computing systems within the network, may monitor network traffic during a specified time window for designated types of data or information during the time window. Based on monitoring the network traffic, the system may generate a cryptographic hash output of the data or information collected. The hash output may then subsequently be used, in part or whole, as the modifier in a CGA algorithm to generate a CGA. The system may then selective authorize devices which have generated the CGA using the correct modifier.

