IP Router Cache Entry for Authenticated Link Identifier Tracking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems fail to reliably track and identify the source of IP addresses used in network attacks, such as Denial of Service, due to the lack of preserved network state and untraceable network addresses, making it difficult to correlate IP addresses with user identities and preventing effective enforcement against abuse.

Innovation Solution

A method where link layer authentication information is supplied to an IP router to track IP address usage by creating a cache entry with authenticated client and link identifiers, allowing for the maintenance of an audit trail that associates IP addresses with their corresponding authenticated link identifiers and client identifiers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If link layer authentication is implemented, then user identity can be correlated with network address, but device complexity increases

Engineering Contradiction:
Improvetraceability of network addressVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an authentication server as an intermediary component that mediates between the link layer authentication and IP address assignment. The authentication server receives authentication requests, verifies credentials, and returns authentication results, thereby enabling reliable traceability without requiring complex authentication logic distributed across multiple network devices. This centralized intermediary approach resolves the technical contradiction by consolidating complexity in a dedicated component while improving overall system reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If IP address assignment is monitored, then usage tracking is possible, but unassigned addresses can still be used by malicious users

Engineering Contradiction:
Improveaudit trail preservationVSAvoidenforcement against abuse
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The patent implements preliminary authentication at the link layer before IP address assignment occurs. By requiring authentication and creating audit trail entries before the user receives an IP address, the system ensures that even unassigned or dynamically allocated addresses are pre-associated with authenticated user identities. This preliminary action prevents malicious users from exploiting unassigned addresses, as authentication must occur first, thereby resolving the contradiction between audit trail preservation and enforcement reliability.

Inventive Principle:
Principle #10Preliminary action

3Difficulty of detecting and measuring

If link layer addresses are monitored, then attack origin can be identified, but addresses can be spoofed and do not scale well

Engineering Contradiction:
Improveattack source identificationVSAvoidaddress authenticity
Core Design Contradiction:
Difficulty of detecting and measuringVSReliability

Solution Approach 1:

The patent replaces reliance on physical link layer address monitoring with an authentication-based identification system. Instead of depending on the mechanical properties of link layer addresses (MAC addresses) which can be spoofed, the system substitutes authentication credentials and cryptographic verification mechanisms. The authentication server verifies user identities through authenticated exchange of credentials, making address spoofing ineffective. This substitution resolves the contradiction by maintaining attack source identification capability while eliminating the reliability issues associated with link layer address spoofing.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS8068414B2Arrangement for tracking IP address usage based on authenticated link identifier
Publication Date: 2011.11.29 CISCO TECHNOLOGY INC
  • US8068414B2 patent drawing
  • US8068414B2 patent drawing
  • US8068414B2 patent drawing

AI summary

Link layer authentication information is supplied by a link layer authentication device to an access router for tracking IP address usage by a client device. The authentication information supplied to the access router includes an authenticated client identifier and a corresponding authenticated link identifier for the client device that attached to the network based on the authenticated link identifier. The access router, in response to receiving a message that specifies the authenticated link identifier and a source IP address, adds the source IP address to a cache entry that specifies the authenticated client identifier and the corresponding authenticated link identifier, and outputs to an audit resource a record that specifies the source IP address and the authenticated link identifier.