Asset Repository Management for IPv6 Network Discovery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional network discovery methods, such as brute force scanning, become impractical with the advent of IPv6 due to the vast address space, making it difficult to efficiently map devices and monitor security within modern networks.

Innovation Solution

An asset management system that employs passive and active discovery sensors, including latent, event-based, and indirect discovery types, to identify system entities and assign security policies based on attributes, allowing for targeted analysis and efficient management of IPv6 networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If brute force scanning is used to discover network devices, then all possible IPv4 addresses can be scanned in a reasonable amount of time, but the method becomes impractical with IPv6 due to the vast address space

Engineering Contradiction:
Improvenetwork device discovery efficiencyVSAvoidaddress space size
Core Design Contradiction:
ProductivityVSQuantity of substance

Solution Approach 1:

The patent segments the network discovery process into multiple specialized sensor types (latent, event-based, indirect,, and direct sensors) that work together to divide the vast IPv6 address space into manageable segments for efficient discovery. Each sensor type handles specific aspects of device identification, breaking down the overwhelming task of scanning all IPv6 addresses into coordinated sub-tasks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary asset management system that coordinates between multiple discovery sensors and the final device identification process. This intermediary layer manages the complex interactions between different sensor types and filters results to identify actual devices without requiring exhaustive scanning of the entire IPv6 address space.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual configuration of IP address ranges is used for network sweeping, then security policies can be enforced against identified devices, but the process requires significant human intervention and time

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidmanual configuration requirement
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service through automated discovery sensors that actively identify network devices and their attributes without requiring manual IP address range configuration. The system autonomously performs network sweeping, device identification, and attribute collection, then automatically tags devices with discovered information for subsequent security policy enforcement.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies preliminary action by performing automated device discovery, attribute collection, and tagging operations before security policy enforcement is needed. This preliminary identification and classification of devices prepares the network infrastructure for reliable security policy application without requiring manual intervention at the time of enforcement.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If comprehensive device identification and attribute collection is performed, then accurate security policies can be assigned, but the complexity of managing and processing device information increases

Engineering Contradiction:
Improvedevice attribute accuracyVSAvoidinformation management complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts only the essential device attributes and information needed for security policy enforcement from the comprehensive device identification process. By selecting and tagging only the most relevant attributes (such as device type, network role, and security characteristics), the system maintains high measurement precision while reducing the complexity of information management and processing.

Inventive Principle:
Principle #2Taking out (Extraction)

4Productivity

If multiple types of discovery sensors are deployed, then efficient identification of IPv6 devices is achieved, but the system complexity increases

Engineering Contradiction:
Improvedevice discovery efficiencyVSAvoidsensor system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent applies universality by designing a multi-functional asset management system that coordinates multiple specialized discovery sensors through a unified interface. The system performs multiple functions (latent device detection, event-based monitoring, indirect identification, and direct scanning) through a single integrated platform, reducing operational complexity while maintaining high discovery efficiency.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2837159B1System asset repository management
Publication Date: 2018.11.28 MCAFEE LLC
  • EP2837159B1 patent drawingFigure 1
  • EP2837159B1 patent drawingFigure 2
  • EP2837159B1 patent drawingFigure 3

AI summary

A plurality of system entities described in an asset repository are identified, the asset repository defining a particular hierarchical organization of the plurality of system entities within a computing environment. A particular system entity in the plurality of system entities is tagged with a particular tag. The particular system entity is associated with a particular security policy based on the particular system entity being tagged with the particular tag. The particular security policy is applied to system entities in the asset repository tagged with one or more tags in a particular set of tags including the particular tag.