Asset Repository Management for IPv6 Network Discovery
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional network discovery methods, such as brute force scanning, become impractical with the advent of IPv6 due to the vast address space, making it difficult to efficiently map devices and monitor security within modern networks.
Innovation Solution
An asset management system that employs passive and active discovery sensors, including latent, event-based, and indirect discovery types, to identify system entities and assign security policies based on attributes, allowing for targeted analysis and efficient management of IPv6 networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If brute force scanning is used to discover network devices, then all possible IPv4 addresses can be scanned in a reasonable amount of time, but the method becomes impractical with IPv6 due to the vast address space
Solution Approach 1:
The patent segments the network discovery process into multiple specialized sensor types (latent, event-based, indirect,, and direct sensors) that work together to divide the vast IPv6 address space into manageable segments for efficient discovery. Each sensor type handles specific aspects of device identification, breaking down the overwhelming task of scanning all IPv6 addresses into coordinated sub-tasks.
Solution Approach 2:
The patent introduces an intermediary asset management system that coordinates between multiple discovery sensors and the final device identification process. This intermediary layer manages the complex interactions between different sensor types and filters results to identify actual devices without requiring exhaustive scanning of the entire IPv6 address space.
2Reliability
If manual configuration of IP address ranges is used for network sweeping, then security policies can be enforced against identified devices, but the process requires significant human intervention and time
Solution Approach 1:
The patent implements self-service through automated discovery sensors that actively identify network devices and their attributes without requiring manual IP address range configuration. The system autonomously performs network sweeping, device identification, and attribute collection, then automatically tags devices with discovered information for subsequent security policy enforcement.
Solution Approach 2:
The patent applies preliminary action by performing automated device discovery, attribute collection, and tagging operations before security policy enforcement is needed. This preliminary identification and classification of devices prepares the network infrastructure for reliable security policy application without requiring manual intervention at the time of enforcement.
3Measurement precision
If comprehensive device identification and attribute collection is performed, then accurate security policies can be assigned, but the complexity of managing and processing device information increases
Solution Approach 1:
The patent extracts only the essential device attributes and information needed for security policy enforcement from the comprehensive device identification process. By selecting and tagging only the most relevant attributes (such as device type, network role, and security characteristics), the system maintains high measurement precision while reducing the complexity of information management and processing.
4Productivity
If multiple types of discovery sensors are deployed, then efficient identification of IPv6 devices is achieved, but the system complexity increases
Solution Approach 1:
The patent applies universality by designing a multi-functional asset management system that coordinates multiple specialized discovery sensors through a unified interface. The system performs multiple functions (latent device detection, event-based monitoring, indirect identification, and direct scanning) through a single integrated platform, reducing operational complexity while maintaining high discovery efficiency.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A plurality of system entities described in an asset repository are identified, the asset repository defining a particular hierarchical organization of the plurality of system entities within a computing environment. A particular system entity in the plurality of system entities is tagged with a particular tag. The particular system entity is associated with a particular security policy based on the particular system entity being tagged with the particular tag. The particular security policy is applied to system entities in the asset repository tagged with one or more tags in a particular set of tags including the particular tag.