Encoding Security Rankings in IP Addresses via VLSM

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network protection systems (NPS) limit security information accessibility to third-party applications and systems, as security rankings are typically only available and used within the NPS operating environment.

Innovation Solution

The NPS is augmented to encode security information into the IP address using variable-length subnet masking (VLSM) notation, allowing third-party systems to retrieve and utilize security rankings by applying a bitmask to the IP address, enabling secure and efficient propagation across the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security information is stored only within the NPS operating environment, then security ranking accuracy is maintained, but accessibility to third-party applications is limited

Engineering Contradiction:
Improvesecurity ranking accuracyVSAvoidaccessibility to third-party applications
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent uses the IP address as an intermediary carrier to transmit security ranking information from the NPS to third-party applications. The security rank is encoded into the IP address structure itself, allowing third parties to access security information without direct NPS interaction while maintaining data integrity through the standardized IP addressing protocol

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The IP address is given dual functionality: it serves both as the standard network identifier and as a carrier for security ranking information. By encoding the security rank within the IP address structure using VLSM notation, the same data structure performs both traditional networking functions and security information dissemination

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If security information is encoded in IP address using VLSM notation, then accessibility and propagation efficiency are improved, but IP address structure complexity increases

Engineering Contradiction:
Improvesecurity information propagation efficiencyVSAvoidIP address structure complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent modifies the IP address parameter structure by utilizing VLSM (Variable Length Subnet Masking) notation to allocate specific bit portions for security rank encoding. This changes the traditional IP address parameters to include security information without fundamentally altering the underlying networking protocols, allowing efficient propagation while managing complexity through standardized parameter expansion

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If third-party applications can access security rankings independently, then network security monitoring capability is enhanced, but compatibility with existing infrastructure may be compromised

Engineering Contradiction:
Improvenetwork security monitoring capabilityVSAvoidcompatibility with existing infrastructure
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The security ranking information is pre-encoded into the IP address structure before network communication occurs. This preliminary encoding ensures that third-party applications can immediately access and utilize security information without requiring real-time NPS connections, while the use of standardized IP address formats maintains compatibility with existing network infrastructure

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11303615B2Security information propagation in a network protection system
Publication Date: 2022.04.12 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11303615B2 patent drawing
  • US11303615B2 patent drawing
  • US11303615B2 patent drawing

AI summary

A network protection system (NPS) is augmented to determine and apply security information for a host on a network. The NPS is configured to monitor the host. In response to an occurrence, e.g., the host requesting a network host address, the NPS dynamically determines the security information and encodes it in a portion of the IP address that is assigned. The particular portion of the IP address that is configured for the security information is identified according to variable-length subnet masking (VLSM) notation and, in particular, by including an additional host identifier subdivision that identifies the portion that carries the relevant security data. The security information (e.g., a rank) is encoded in a bitmask. An IP address that has been extended in this manner is then provided on the network, where it is readily-evaluated by other applications and systems that recover the security information by simply applying the bitmask to the IP address.