IPv6 Address Delegation via Cryptographic Certificate

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing method of delegating responsibility for a Cryptographically Generated Address (CGA) requires a new certificate when the delegating node changes its IPv6 address, leading to inefficiencies due to the certificate being tied to a single CGA.

Innovation Solution

A delegation certificate is generated containing a public key, parameters or formulas for generating parameters, a specification of a range of IPv6 network routing prefixes, and a digital signature, allowing the delegated node to verify and use the CGA even when the address has not been generated, with the ability to generate new modifiers and extensions for increased security and flexibility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a certificate is tied to a single CGA address, then security verification is simplified, but the system cannot adapt when the delegating node changes its IPv6 address

Engineering Contradiction:
Improveadaptability to address changesVSAvoidcertificate management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies universality by designing a delegation certificate that is not tied to a single CGA address but can validate multiple CGA addresses generated by the delegating node. The certificate contains the delegating node's public key and authorization information that remains valid across address changes, allowing one certificate to serve multiple addressing scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent applies preliminary action by establishing the delegation relationship and issuing the certificate before the specific CGA address is determined or before address changes occur. This pre-established certificate structure allows the system to adapt to future address changes without requiring new certificates, as the certificate validates any CGA generated by the authorized node.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If a new certificate is provided whenever the delegating node changes its IPv6 address, then address ownership verification remains secure, but signaling overhead increases

Engineering Contradiction:
Improveaddress ownership verificationVSAvoidsignaling overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The delegation certificate is designed to be universal across multiple CGA addresses and address changes. Instead of creating new certificates for each address change, the same certificate structure validates any CGA generated by the delegating node within its authorization scope, eliminating repeated signaling for certificate updates.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent establishes continuous validity of the delegation certificate across address changes. The certificate maintains its authorization function continuously even as the delegating node's CGA address changes, eliminating the need for interrupting signaling exchanges to update certificates and maintaining uninterrupted service.

Inventive Principle:
Principle #20Continuity of useful action

3Adaptability or versatility

If the certificate contains all possible future parameters, then future address generations are covered, but the certificate size and initial complexity increase

Engineering Contradiction:
Improvecoverage of future addressesVSAvoidcertificate data size
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent segments the certificate structure into essential authorization elements (delegating node's public key, delegation authority) and dynamic address elements (CGA prefix, interface identifier). The certificate contains only the static authorization information needed to validate future CGAs, while the actual address details are determined later during CGA generation, keeping the certificate compact.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The certificate is prepared in advance with the delegating node's public key and authorization parameters, but does not pre-include specific CGA address details that would increase its size. Instead, it establishes the rules and authority for generating valid CGAs, allowing the system to cover future addresses without embedding all possible address data in the certificate.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8843751B2IP address delegation
Publication Date: 2014.09.23 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US8843751B2 patent drawing
  • US8843751B2 patent drawing
  • US8843751B2 patent drawing

AI summary

A method of verifying a request made in respect of an IPv6 address comprising a network routing prefix and a cryptographically generated Interface Identifier. The request includes a delegation certificate containing a public key of the host, one or more further parameters or a formula or formulae for generating one or more further parameters, a specification of a range or set of IPv6 network routing prefixes, an identity of a delegated host, and a digital signature taken over at least the identity and the specification of a range or set of IPv6 network routing prefixes using a private key associated with the public key. The method verifies that the network routing prefix of said IPv6 address is contained within the specification, verifying that the public key and the further parameter(s) can be used to generate the cryptographically generated Interface Identifier, and verifying said signature using the public key.