IPv6 Gateway Dual-Prefix Addressing for Internal Topology Secrecy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies, such as Network Address Translators (NATs), fail to effectively secure IPv6 addresses within Virtual Private Networks (VPNs) when accessing wide area networks, as they are not developed for IPv6 and cannot hide internal topology and addressing information, leading to security concerns and routing limitations.

Innovation Solution

A network architecture that assigns unique in-site and extra-site IPv6 addresses to nodes, with a gateway establishing secure connections and binding cache entries to maintain secrecy of in-site addresses, allowing secure communication and access to wide area networks without the need for NATs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If Network Address Translators (NATs) are deployed to hide IPv4 source addresses, then address secrecy is improved, but device complexity and loss of information increase

Engineering Contradiction:
Improveaddress secrecyVSAvoidNAT deployment complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The invention segments the address space into two distinct prefixes: a first IPv6 address prefix for internal site communication and a second IPv6 address prefix for external wide area network communication. This segmentation eliminates the need for NAT by providing dedicated address spaces for different communication contexts, thereby maintaining address secrecy without requiring complex translation devices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The invention transitions from the traditional single-address model to a dual-prefix address model, adding a dimensional aspect to IPv6 addressing. Nodes possess both a first prefix address for internal use and a second prefix address for external use, enabling direct routing without NAT while preserving internal address secrecy from external networks.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Adaptability or versatility

If global source addresses are used for Internet communication, then network connectivity is improved, but address secrecy deteriorates

Engineering Contradiction:
Improvenetwork connectivityVSAvoidaddress secrecy
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The invention applies local quality by assigning different address prefix characteristics to different communication contexts. The first IPv6 address prefix is designed specifically for internal site communication with secrecy properties, while the second IPv6 address prefix is designed for external WAN communication with global reachability. Each prefix has optimized properties suited to its specific communication domain.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The gateway acts as an intermediary that receives packets from external networks destined for the second prefix, performs address translation or routing to the appropriate node using the first prefix, and forwards packets to the internal node. This intermediary mechanism enables external communication while protecting internal address secrecy.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If private routes are leaked to the global Internet, then routing connectivity is improved, but security deteriorates

Engineering Contradiction:
Improverouting connectivityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The invention extracts the internal first IPv6 address prefix from the global Internet routing system, preventing it from being advertised or leaked to external networks. Only the second IPv6 address prefix is advertised externally. This extraction isolates internal addressing information from external networks, eliminating security risks associated with route leakage while maintaining connectivity through the gateway.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS7539202B2Maintaining secrecy of assigned unique local addresses for IPv6 nodes within a prescribed site during access of a wide area network
Publication Date: 2009.05.26 CISCO TECHNOLOGY INC
  • US7539202B2 patent drawing
  • US7539202B2 patent drawing
  • US7539202B2 patent drawing

AI summary

A network includes network nodes and a gateway. Each network node has a corresponding unique in-site IPv6 address for communication within a prescribed site, each in-site IPv6 address having a first IPv6 address prefix that is not advertised outside of the prescribed site. Network nodes can obtain from within the prescribed site a unique extra-site IPv6 address for mobile or extra-site communications. The extra-site IPv6 address has a second IPv6 address prefix, distinct from the first IPv6 address prefix, advertised by the gateway to the prescribed site and the wide area network. The gateway establishes a secure connection (e.g., tunnel) with each corresponding IPv6 node using its corresponding extra-site IPv6 address, and creates a corresponding binding cache entry specifying the corresponding extra-site IPv6 address and in-site IPv6 address. Hence, the gateway provides wide area network access while maintaining secrecy of the in-site IPv6 addresses.