Embedding Credentials in IPv6 Network Addresses

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The transmission of account identifiers in the data payload of network packets poses a security threat due to interception risks, and existing solutions do not effectively address the need for secure credential transmission across networks.

Innovation Solution

Embedding credentials within network addresses, such as in the network interface identifier field of IPv6 packets, allows for secure transmission by eliminating the need for credentials in the data payload and enhancing network efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If credentials are transmitted in the data payload of network packets, then account identification is achieved, but data security deteriorates due to interception risks

Engineering Contradiction:
Improvedata securityVSAvoidcredential interception
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the credential information from the data payload and relocates it to the network address (specifically the interface identifier field in IPv6). This separation removes the harmful exposure of credentials in the payload while maintaining their identification function, directly resolving the security issue without sacrificing account identification capability

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The network address serves as an intermediary carrier for credentials. Instead of directly placing credentials in the payload (vulnerable) or using separate authentication mechanisms (complex), the patent uses the network address as an intermediate structure that embeds credential information in a protected location, balancing security and functionality

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If credentials are embedded in network addresses, then data security improves by reducing interception risk, but network address structure complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidnetwork address structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the network address multi-functional: it simultaneously serves routing purposes (source/destination identification) and credential carrying purposes (account identification). By embedding credentials in the interface identifier field, the address structure performs multiple functions without requiring separate dedicated fields, thus avoiding additional complexity while achieving security improvements

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If credentials are placed in data payload, then account identification is simplified, but network efficiency deteriorates due to increased data transmission

Engineering Contradiction:
Improvenetwork efficiencyVSAvoiddata transmission volume
Core Design Contradiction:
ProductivityVSQuantity of substance

Solution Approach 1:

The patent merges the credential carrying function with the existing network address structure. Instead of adding separate credential fields in the payload, the interface identifier field of the network address is reused to embed credentials. This consolidation reduces redundant data transmission while maintaining account identification capability, directly improving network efficiency

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20240348609A1Embedding credentials in network addresses
Publication Date: 2024.10.17 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US20240348609A1 patent drawing
  • US20240348609A1 patent drawing
  • US20240348609A1 patent drawing

AI summary

A technique for embedding and utilizing credentials in a network address may include requesting a network address for a client device by providing an account identifier to a server computer associated with a service provider. A network address that is mapped to the account identifier can be assigned to the client device. The network address may include a routing prefix field and a network interface identifier field. The routing prefix field may include an issuer identifier of an issuer of the account, and the network interface identifier field may include an interface identifier that maps to the account identifier. By embedding credentials such as an account identifier in the network address, the actual account identifier need not be transmitted to perform actions on the account.