First Hop Security for IPv6 Neighbor Discovery
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In multi-site and multi-vendor cloud environments, securing the software-defined access security perimeter against potential attacks from the trunk is challenging, especially when access switches or edge devices outside the security perimeter may introduce vulnerabilities, and existing solutions like RFC 8928 cannot validate IPv6 ND control packets on the fly without a challenge.
Innovation Solution
Implementing a first hop security system that uses Crypto-ID Parameters Option (CIPO) and Neighbor Discovery Protocol Signature Option (NDPSO) to validate and sign messages within the security perimeter, including a shared secret and timestamp, allowing trusted FHS devices to verify message authenticity and prevent attacks by intercepting and signing messages before they enter the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If access switches or edge devices outside the security perimeter are used to extend network coverage, then network scalability and flexibility are improved, but security vulnerabilities are introduced that compromise the security perimeter
Solution Approach 1:
The patent introduces FHS devices as intermediary components between hosts and the network fabric. These devices perform security validation and message signing before traffic enters the network, acting as a mediator that allows external devices to connect while maintaining security boundaries. The FHS device validates IPv6 ND packets and signs them with cryptographic signatures, enabling secure communication without compromising the security perimeter.
Solution Approach 2:
The patent implements preliminary security validation and message signing at the FHS device before traffic enters the network fabric. By performing security checks and signing messages in advance, the system prevents potentially malicious traffic from entering the network, thus maintaining security while allowing network extension through external access switches and edge devices.
2Reliability
If message validation and signing is performed on all incoming traffic, then security against forged messages is improved, but processing time and operational overhead increase
Solution Approach 1:
The patent applies security validation and signing selectively at specific network boundary points (FHS devices) rather than uniformly across all network devices. This localized approach concentrates security processing where it is most needed (at the security perimeter) while allowing internal devices to operate without the overhead of repeated validation, thus balancing security with processing efficiency.
Solution Approach 2:
The patent performs message validation and signing in advance at the FHS device before traffic enters the network fabric. By completing security processing beforehand, subsequent devices within the network can forward and process signed messages without repeating the validation process, reducing overall processing time while maintaining security.
3Reliability
If a challenge-based validation protocol like RFC 8928 is used, then security verification is improved, but compatibility and ease of operation deteriorate due to complex challenge-response mechanisms
Solution Approach 1:
The patent replaces challenge-response validation with preliminary asymmetric cryptographic signing. The FHS device signs IPv6 ND packets with its private key before they enter the network. Receiving devices can then verify authenticity using the sender's public key without needing to engage in complex challenge-response exchanges, simplifying operation while maintaining security verification.
Solution Approach 2:
The patent substitutes the mechanical challenge-response interaction model with an asymmetric cryptographic signing model. Instead of requiring back-and-forth challenge exchanges between validating and responding devices, the system uses cryptographic signatures that provide the same security verification function but without the operational complexity of interactive challenges.
Data Source
AI summary
The present disclosure is directed to systems and methods for first hop security in a multi-site and multi-vendor cloud. The method may include receiving, at a first hop security (FHS) device located within a defined security perimeter, a message from a first host; validating a security of the message; signing the message with a signature to prove validation of the message, the signature comprising at least a Crypto-ID Parameters Option (CIPO) and a Neighbor Discovery Protocol Signature Option (NDPSO); and transmitting the signed message to one or more network FHS devices within the security perimeter.


