IPv6 Address Delegation via Cryptographic Certificate
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing method of delegating responsibility for a Cryptographically Generated Address (CGA) requires a new certificate when the delegating node changes its IPv6 address, leading to inefficiencies due to the certificate being tied to a single CGA.
Innovation Solution
A delegation certificate is generated containing a public key, parameters or formulas for generating parameters, a specification of a range of IPv6 network routing prefixes, and a digital signature, allowing the delegated node to verify and use the CGA even when the address has not been generated, with the ability to generate new modifiers and extensions for increased security and flexibility.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a certificate is tied to a single CGA address, then security verification is simplified, but the system cannot adapt when the delegating node changes its IPv6 address
Solution Approach 1:
The patent applies universality by designing a delegation certificate that is not tied to a single CGA address but can validate multiple CGA addresses generated by the delegating node. The certificate contains the delegating node's public key and authorization information that remains valid across address changes, allowing one certificate to serve multiple addressing scenarios.
Solution Approach 2:
The patent applies preliminary action by establishing the delegation relationship and issuing the certificate before the specific CGA address is determined or before address changes occur. This pre-established certificate structure allows the system to adapt to future address changes without requiring new certificates, as the certificate validates any CGA generated by the authorized node.
2Reliability
If a new certificate is provided whenever the delegating node changes its IPv6 address, then address ownership verification remains secure, but signaling overhead increases
Solution Approach 1:
The delegation certificate is designed to be universal across multiple CGA addresses and address changes. Instead of creating new certificates for each address change, the same certificate structure validates any CGA generated by the delegating node within its authorization scope, eliminating repeated signaling for certificate updates.
Solution Approach 2:
The patent establishes continuous validity of the delegation certificate across address changes. The certificate maintains its authorization function continuously even as the delegating node's CGA address changes, eliminating the need for interrupting signaling exchanges to update certificates and maintaining uninterrupted service.
3Adaptability or versatility
If the certificate contains all possible future parameters, then future address generations are covered, but the certificate size and initial complexity increase
Solution Approach 1:
The patent segments the certificate structure into essential authorization elements (delegating node's public key, delegation authority) and dynamic address elements (CGA prefix, interface identifier). The certificate contains only the static authorization information needed to validate future CGAs, while the actual address details are determined later during CGA generation, keeping the certificate compact.
Solution Approach 2:
The certificate is prepared in advance with the delegating node's public key and authorization parameters, but does not pre-include specific CGA address details that would increase its size. Instead, it establishes the rules and authority for generating valid CGAs, allowing the system to cover future addresses without embedding all possible address data in the certificate.
Data Source
AI summary
A method of verifying a request made in respect of an IPv6 address comprising a network routing prefix and a cryptographically generated Interface Identifier. The request includes a delegation certificate containing a public key of the host, one or more further parameters or a formula or formulae for generating one or more further parameters, a specification of a range or set of IPv6 network routing prefixes, an identity of a delegated host, and a digital signature taken over at least the identity and the specification of a range or set of IPv6 network routing prefixes using a private key associated with the public key. The method verifies that the network routing prefix of said IPv6 address is contained within the specification, verifying that the public key and the further parameter(s) can be used to generate the cryptographically generated Interface Identifier, and verifying said signature using the public key.


