Defending Router for Rogue IPv6 Neighbor Discovery
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional IPv6 networks lack effective mechanisms to authenticate and defend against rogue routers that advertise unauthorized address prefixes, posing a threat to host nodes, especially those not configured for Secure Neighbor Discovery (SEND) protocol.
Innovation Solution
A defending router is implemented to monitor and authenticate router advertisement messages, determining authorization of routers and address prefixes, and initiating defensive operations against unauthorized routers by outputting alerts, denying access, and impersonating the rogue router to prevent host nodes from using unauthorized prefixes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If SEND protocol mechanisms are implemented to secure IPv6 nodes, then network security against rogue routers is improved, but device complexity and configuration requirements increase
Solution Approach 1:
The patent introduces a defending router as an intermediary entity that performs SEND protocol validation on behalf of host nodes. This mediator router authenticates router advertisement messages and protects hosts that cannot perform self-authentication, thereby maintaining security while reducing configuration complexity for end devices
Solution Approach 2:
The defending router implements automatic detection and response mechanisms that operate without manual intervention. The router autonomously monitors router advertisements, validates cryptographic signatures, identifies rogue routers, and initiates defensive operations, eliminating the need for complex manual configuration and maintenance
2Reliability
If all host nodes are configured with SEND protocol and trust anchors, then authentication capability is improved, but ease of operation and deployment are worsened
Solution Approach 1:
The defending router serves as a mediation layer between unconfigured host nodes and the SEND protocol infrastructure. It performs authentication functions centrally, allowing hosts to operate without direct SEND configuration while still benefiting from cryptographic verification of router advertisements
Solution Approach 2:
The patent segments the authentication function from the host nodes and concentrates it in the defending router. This separation allows hosts to remain simple endpoints while the router handles the complex authentication logic, making deployment easier without sacrificing security
3Stability of the object's composition
If conventional routers ignore unauthorized router advertisements, then network stability is maintained, but security against rogue routers deteriorates
Solution Approach 1:
The defending router applies preliminary anti-action by proactively authenticating router advertisements before they can affect network stability. It preemptively identifies and neutralizes rogue routers through cryptographic verification and defensive operations, preventing potential disruptions rather than merely reacting to them
Solution Approach 2:
The system implements feedback mechanisms where the defending router continuously monitors router advertisements, validates them against trust anchors, and dynamically adjusts network protection based on detected threats. This closed-loop approach maintains both stability and security by adapting to changing network conditions
Data Source
AI summary
In one embodiment, a method comprises receiving, by a router in a network, a router advertisement message on a network link of the network; detecting within the router advertisement message, by the router, an advertised address prefix and an identified router having transmitted the router advertisement message within the network; determining, by the router, whether the identified router is authorized to at least one of advertise itself as a router, or advertise the advertised address prefix on the network link; and selectively initiating, by the router, a defensive operation against the identified router based on the router determining the identified router is not authorized to advertise itself as a router, or advertise the advertised address prefix on the network link.


