Gateway Address Rotation for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Static IP addresses of gateways in networks make it easy for unauthorized access, as hackers can determine and exploit the gateway address, compromising network security.

Innovation Solution

Implementing a system where the gateway address rotates, synchronized with client devices, using multiple mapping devices to provide and update valid addresses, and incorporating authentication through protocol tunneling and MAC addresses, while allowing the network to switch operating systems to enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the gateway address is made static for easy access, then network accessibility is improved, but network security deteriorates as hackers can easily determine and exploit the gateway address

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The gateway address is transformed from a static value to a dynamic one that rotates periodically. The system implements address rotation where the gateway address changes at predetermined intervals, making it difficult for unauthorized users to maintain persistent access while allowing legitimate users to connect through the mapping service that tracks current address assignments

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

A mapping service is introduced as an intermediary between clients and the gateway. This mapping service maintains the relationship between rotating gateway addresses and client devices, allowing clients to discover and connect to the current gateway address through the mapping service without exposing the rotation mechanism to external users

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If the gateway address rotates frequently to enhance security, then network security is improved, but device complexity increases due to synchronization requirements between clients and gateway

Engineering Contradiction:
Improveunauthorized accessVSAvoidaddress synchronization
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The mapping service implements a feedback mechanism where clients query the mapping service for current gateway addresses. The mapping service responds with the current valid gateway address, automatically providing synchronization information to clients without requiring complex client-side address management or synchronization protocols

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system enables self-service address discovery where clients automatically obtain current gateway addresses by querying the mapping service. This eliminates the need for manual address configuration or complex synchronization logic in client devices, as the mapping service autonomously manages address distribution

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If different operating systems are associated with different gateway addresses to increase security, then network security is improved, but ease of operation deteriorates due to increased complexity in address management

Engineering Contradiction:
Improveunauthorized accessVSAvoidaddress management
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The mapping service is designed as a universal system that handles multiple operating systems and device types through a single interface. Clients from different operating systems all interact with the same mapping service using standard protocols, eliminating the need for OS-specific address management while maintaining security through the rotation mechanism

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2815552B1System and method for rotating a gateway address
Publication Date: 2019.04.10 THE BOEING CO
  • EP2815552B1 patent drawingFigure 1
  • EP2815552B1 patent drawingFigure 2
  • EP2815552B1 patent drawingFigure 3

AI summary

A client device, a gateway and a corresponding method are provided in order to increase the security of a network to which access is provided via a gateway. The address of the gateway may rotate, e.g., change, such that hackers or other individuals or devices that should not have access to the network will experience much greater difficulty in securing the address of the gateway and accessing the network, at least for any extended period of time. By ensuring that both the client device and the gateway are synchronized in regard to the rotation of the address of the gateway, however, the client device may still properly address the gateway and therefore access the network, even as the address of the gateway rotates. Different operating systems may also be associated with some of the different addresses of the gateway in order to increase the security of the network.