IP Packet Identification for Spoofing Traceability
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The expansion of Internet networks from SS7 to IP protocols has increased fraud scenarios due to lower security measures, particularly in tracing Internet Protocol addresses, as IPv4 and IPv6 protocols do not effectively improve user security against fraud, making it difficult to track the origin of IP packets.
Innovation Solution
A method is introduced where identification information is added to IP data packets by a first network node and verified by a neighboring node, ensuring only authorized nodes forward the packets, using additional nodes with hop information to maintain low testing effort and resource usage, without altering existing RFC or IP protocol characteristics.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If identification information is added to every IP data packet to improve traceability, then security and fraud tracking improve, but device complexity and processing overhead increase
Solution Approach 1:
The patent applies preliminary action by pre-assigning identification information to network nodes before data transmission occurs. Each network node is configured with unique identification data that will be attached to outgoing packets, eliminating the need for complex real-time generation or verification mechanisms during packet processing.
Solution Approach 2:
The patent extracts the security verification function from the complex IP routing process by separating identification information attachment and verification into distinct, simple operations. The sending node simply attaches its ID, and the receiving node simply verifies it, removing security checks from the main data path processing.
2Reliability
If existing IP protocols are modified to include security fields, then fraud prevention improves, but compatibility and ease of operation deteriorate
Solution Approach 1:
The patent introduces an intermediary approach by using existing IP header fields (such as Type of Service or unused reserved fields) to carry identification information, rather than creating new mandatory fields. This intermediary use of existing structures maintains compatibility while enabling security functionality.
Solution Approach 2:
The patent changes parameters of existing IP protocol fields to serve dual purposes - using previously unused or optional fields for identification purposes. This allows the same protocol structures to support both traditional IP functionality and new security requirements without breaking compatibility.
3Reliability
If comprehensive verification is performed at every network node, then security improves, but processing time and energy consumption increase
Solution Approach 1:
The patent applies partial action by having network nodes perform only the necessary minimum verification - checking whether the identification information matches the expected sender - rather than conducting comprehensive security analysis. This partial verification is sufficient for fraud prevention without requiring excessive processing time.
Data Source
AI summary
A method for increasing the security of packet-oriented data exchange in a telecommunications network is disclosed. The method enables the traceability of messages even if a fictitious source IP address is entered in the message header data (spoofing). The telecommunications network (100) has a first (11) and a second (12) network node, the second network node (12) being a neighbor of the first network node (11). The first network node is assigned identification information. First, the first network node (11) adds its identification information to an Internet Protocol (IP) data packet and transmits the packet to the second network node (12). There, the identification information of the Internet Protocol (IP) data packet is checked.The Internet Protocol data packet is discarded by the second network node (12) if the identification information of the Internet Protocol data packet does not match the identification information assigned to the first network node.
