First Hop Security for IPv6 Neighbor Discovery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In multi-site and multi-vendor cloud environments, securing the software-defined access security perimeter against potential attacks from the trunk is challenging, especially when access switches or edge devices outside the security perimeter may introduce vulnerabilities, and existing solutions like RFC 8928 cannot validate IPv6 ND control packets on the fly without a challenge.

Innovation Solution

Implementing a first hop security system that uses Crypto-ID Parameters Option (CIPO) and Neighbor Discovery Protocol Signature Option (NDPSO) to validate and sign messages within the security perimeter, including a shared secret and timestamp, allowing trusted FHS devices to verify message authenticity and prevent attacks by intercepting and signing messages before they enter the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If access switches or edge devices outside the security perimeter are used to extend network coverage, then network scalability and flexibility are improved, but security vulnerabilities are introduced that compromise the security perimeter

Engineering Contradiction:
Improvenetwork scalabilityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces FHS devices as intermediary components between hosts and the network fabric. These devices perform security validation and message signing before traffic enters the network, acting as a mediator that allows external devices to connect while maintaining security boundaries. The FHS device validates IPv6 ND packets and signs them with cryptographic signatures, enabling secure communication without compromising the security perimeter.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary security validation and message signing at the FHS device before traffic enters the network fabric. By performing security checks and signing messages in advance, the system prevents potentially malicious traffic from entering the network, thus maintaining security while allowing network extension through external access switches and edge devices.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If message validation and signing is performed on all incoming traffic, then security against forged messages is improved, but processing time and operational overhead increase

Engineering Contradiction:
Improvemessage authenticityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies security validation and signing selectively at specific network boundary points (FHS devices) rather than uniformly across all network devices. This localized approach concentrates security processing where it is most needed (at the security perimeter) while allowing internal devices to operate without the overhead of repeated validation, thus balancing security with processing efficiency.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent performs message validation and signing in advance at the FHS device before traffic enters the network fabric. By completing security processing beforehand, subsequent devices within the network can forward and process signed messages without repeating the validation process, reducing overall processing time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If a challenge-based validation protocol like RFC 8928 is used, then security verification is improved, but compatibility and ease of operation deteriorate due to complex challenge-response mechanisms

Engineering Contradiction:
Improvesecurity verificationVSAvoidoperational complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces challenge-response validation with preliminary asymmetric cryptographic signing. The FHS device signs IPv6 ND packets with its private key before they enter the network. Receiving devices can then verify authenticity using the sender's public key without needing to engage in complex challenge-response exchanges, simplifying operation while maintaining security verification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent substitutes the mechanical challenge-response interaction model with an asymmetric cryptographic signing model. Instead of requiring back-and-forth challenge exchanges between validating and responding devices, the system uses cryptographic signatures that provide the same security verification function but without the operational complexity of interactive challenges.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11784970B2First hop security in multi-site multi-vendor cloud
Publication Date: 2023.10.10 CISCO TECHNOLOGY INC
  • US11784970B2 patent drawing
  • US11784970B2 patent drawing
  • US11784970B2 patent drawing

AI summary

The present disclosure is directed to systems and methods for first hop security in a multi-site and multi-vendor cloud. The method may include receiving, at a first hop security (FHS) device located within a defined security perimeter, a message from a first host; validating a security of the message; signing the message with a signature to prove validation of the message, the signature comprising at least a Crypto-ID Parameters Option (CIPO) and a Neighbor Discovery Protocol Signature Option (NDPSO); and transmitting the signed message to one or more network FHS devices within the security perimeter.