Encoding Security Rankings in IP Addresses via VLSM
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network protection systems (NPS) limit security information accessibility to third-party applications and systems, as security rankings are typically only available and used within the NPS operating environment.
Innovation Solution
The NPS is augmented to encode security information into the IP address using variable-length subnet masking (VLSM) notation, allowing third-party systems to retrieve and utilize security rankings by applying a bitmask to the IP address, enabling secure and efficient propagation across the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security information is stored only within the NPS operating environment, then security ranking accuracy is maintained, but accessibility to third-party applications is limited
Solution Approach 1:
The patent uses the IP address as an intermediary carrier to transmit security ranking information from the NPS to third-party applications. The security rank is encoded into the IP address structure itself, allowing third parties to access security information without direct NPS interaction while maintaining data integrity through the standardized IP addressing protocol
Solution Approach 2:
The IP address is given dual functionality: it serves both as the standard network identifier and as a carrier for security ranking information. By encoding the security rank within the IP address structure using VLSM notation, the same data structure performs both traditional networking functions and security information dissemination
2Productivity
If security information is encoded in IP address using VLSM notation, then accessibility and propagation efficiency are improved, but IP address structure complexity increases
Solution Approach 1:
The patent modifies the IP address parameter structure by utilizing VLSM (Variable Length Subnet Masking) notation to allocate specific bit portions for security rank encoding. This changes the traditional IP address parameters to include security information without fundamentally altering the underlying networking protocols, allowing efficient propagation while managing complexity through standardized parameter expansion
3Adaptability or versatility
If third-party applications can access security rankings independently, then network security monitoring capability is enhanced, but compatibility with existing infrastructure may be compromised
Solution Approach 1:
The security ranking information is pre-encoded into the IP address structure before network communication occurs. This preliminary encoding ensures that third-party applications can immediately access and utilize security information without requiring real-time NPS connections, while the use of standardized IP address formats maintains compatibility with existing network infrastructure
Data Source
AI summary
A network protection system (NPS) is augmented to determine and apply security information for a host on a network. The NPS is configured to monitor the host. In response to an occurrence, e.g., the host requesting a network host address, the NPS dynamically determines the security information and encodes it in a portion of the IP address that is assigned. The particular portion of the IP address that is configured for the security information is identified according to variable-length subnet masking (VLSM) notation and, in particular, by including an additional host identifier subdivision that identifies the portion that carries the relevant security data. The security information (e.g., a rank) is encoded in a bitmask. An IP address that has been extended in this manner is then provided on the network, where it is readily-evaluated by other applications and systems that recover the security information by simply applying the bitmask to the IP address.


