IPv6 Gateway Dual-Prefix Addressing for Internal Topology Secrecy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current technologies, such as Network Address Translators (NATs), fail to effectively secure IPv6 addresses within Virtual Private Networks (VPNs) when accessing wide area networks, as they are not developed for IPv6 and cannot hide internal topology and addressing information, leading to security concerns and routing limitations.
Innovation Solution
A network architecture that assigns unique in-site and extra-site IPv6 addresses to nodes, with a gateway establishing secure connections and binding cache entries to maintain secrecy of in-site addresses, allowing secure communication and access to wide area networks without the need for NATs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If Network Address Translators (NATs) are deployed to hide IPv4 source addresses, then address secrecy is improved, but device complexity and loss of information increase
Solution Approach 1:
The invention segments the address space into two distinct prefixes: a first IPv6 address prefix for internal site communication and a second IPv6 address prefix for external wide area network communication. This segmentation eliminates the need for NAT by providing dedicated address spaces for different communication contexts, thereby maintaining address secrecy without requiring complex translation devices.
Solution Approach 2:
The invention transitions from the traditional single-address model to a dual-prefix address model, adding a dimensional aspect to IPv6 addressing. Nodes possess both a first prefix address for internal use and a second prefix address for external use, enabling direct routing without NAT while preserving internal address secrecy from external networks.
2Adaptability or versatility
If global source addresses are used for Internet communication, then network connectivity is improved, but address secrecy deteriorates
Solution Approach 1:
The invention applies local quality by assigning different address prefix characteristics to different communication contexts. The first IPv6 address prefix is designed specifically for internal site communication with secrecy properties, while the second IPv6 address prefix is designed for external WAN communication with global reachability. Each prefix has optimized properties suited to its specific communication domain.
Solution Approach 2:
The gateway acts as an intermediary that receives packets from external networks destined for the second prefix, performs address translation or routing to the appropriate node using the first prefix, and forwards packets to the internal node. This intermediary mechanism enables external communication while protecting internal address secrecy.
3Adaptability or versatility
If private routes are leaked to the global Internet, then routing connectivity is improved, but security deteriorates
Solution Approach 1:
The invention extracts the internal first IPv6 address prefix from the global Internet routing system, preventing it from being advertised or leaked to external networks. Only the second IPv6 address prefix is advertised externally. This extraction isolates internal addressing information from external networks, eliminating security risks associated with route leakage while maintaining connectivity through the gateway.
Data Source
AI summary
A network includes network nodes and a gateway. Each network node has a corresponding unique in-site IPv6 address for communication within a prescribed site, each in-site IPv6 address having a first IPv6 address prefix that is not advertised outside of the prescribed site. Network nodes can obtain from within the prescribed site a unique extra-site IPv6 address for mobile or extra-site communications. The extra-site IPv6 address has a second IPv6 address prefix, distinct from the first IPv6 address prefix, advertised by the gateway to the prescribed site and the wide area network. The gateway establishes a secure connection (e.g., tunnel) with each corresponding IPv6 node using its corresponding extra-site IPv6 address, and creates a corresponding binding cache entry specifying the corresponding extra-site IPv6 address and in-site IPv6 address. Hence, the gateway provides wide area network access while maintaining secrecy of the in-site IPv6 addresses.


