Defending Router for Rogue IPv6 Neighbor Discovery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional IPv6 networks lack effective mechanisms to authenticate and defend against rogue routers that advertise unauthorized address prefixes, posing a threat to host nodes, especially those not configured for Secure Neighbor Discovery (SEND) protocol.

Innovation Solution

A defending router is implemented to monitor and authenticate router advertisement messages, determining authorization of routers and address prefixes, and initiating defensive operations against unauthorized routers by outputting alerts, denying access, and impersonating the rogue router to prevent host nodes from using unauthorized prefixes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If SEND protocol mechanisms are implemented to secure IPv6 nodes, then network security against rogue routers is improved, but device complexity and configuration requirements increase

Engineering Contradiction:
Improvenetwork securityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a defending router as an intermediary entity that performs SEND protocol validation on behalf of host nodes. This mediator router authenticates router advertisement messages and protects hosts that cannot perform self-authentication, thereby maintaining security while reducing configuration complexity for end devices

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The defending router implements automatic detection and response mechanisms that operate without manual intervention. The router autonomously monitors router advertisements, validates cryptographic signatures, identifies rogue routers, and initiates defensive operations, eliminating the need for complex manual configuration and maintenance

Inventive Principle:
Principle #25Self-service

2Reliability

If all host nodes are configured with SEND protocol and trust anchors, then authentication capability is improved, but ease of operation and deployment are worsened

Engineering Contradiction:
Improveauthentication capabilityVSAvoiddeployment simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The defending router serves as a mediation layer between unconfigured host nodes and the SEND protocol infrastructure. It performs authentication functions centrally, allowing hosts to operate without direct SEND configuration while still benefiting from cryptographic verification of router advertisements

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the authentication function from the host nodes and concentrates it in the defending router. This separation allows hosts to remain simple endpoints while the router handles the complex authentication logic, making deployment easier without sacrificing security

Inventive Principle:
Principle #1Segmentation

3Stability of the object's composition

If conventional routers ignore unauthorized router advertisements, then network stability is maintained, but security against rogue routers deteriorates

Engineering Contradiction:
Improvenetwork stabilityVSAvoidsecurity defense
Core Design Contradiction:
Stability of the object's compositionVSReliability

Solution Approach 1:

The defending router applies preliminary anti-action by proactively authenticating router advertisements before they can affect network stability. It preemptively identifies and neutralizes rogue routers through cryptographic verification and defensive operations, preventing potential disruptions rather than merely reacting to them

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The system implements feedback mechanisms where the defending router continuously monitors router advertisements, validates them against trust anchors, and dynamically adjusts network protection based on detected threats. This closed-loop approach maintains both stability and security by adapting to changing network conditions

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8219800B2Secure neighbor discovery router for defending host nodes from rogue routers
Publication Date: 2012.07.10 CISCO TECHNOLOGY INC
  • US8219800B2 patent drawing
  • US8219800B2 patent drawing
  • US8219800B2 patent drawing

AI summary

In one embodiment, a method comprises receiving, by a router in a network, a router advertisement message on a network link of the network; detecting within the router advertisement message, by the router, an advertised address prefix and an identified router having transmitted the router advertisement message within the network; determining, by the router, whether the identified router is authorized to at least one of advertise itself as a router, or advertise the advertised address prefix on the network link; and selectively initiating, by the router, a defensive operation against the identified router based on the router determining the identified router is not authorized to advertise itself as a router, or advertise the advertised address prefix on the network link.