Hardware Interface for IPv6 Direct Access and Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The transition from IPv4 to IPv6 poses challenges due to the need for extensive network upgrades, security vulnerabilities in proxy gateways, and complexity in DNS infrastructure, especially during the coexistence period when both protocols are used within the same infrastructure.

Innovation Solution

A hardware interface that enables native IPv6 capabilities in IPv4 networks through Direct Access models, supporting IPv4 to IPv6 translation and IPsec termination, while also providing Network Access Protection (NAP) and Enterprise Security Assessment Sharing (ESAS) functionalities, allowing non-Direct Access-ready devices to be upgraded with enhanced security without software modifications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If proxy gateways are used for IPv4 to IPv6 translation, then IPv6 capability can be provided to IPv4 networks, but security vulnerabilities arise due to the need for IPsec termination and DNS confusion

Engineering Contradiction:
ImproveIPv6 capability provisionVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent extracts the IPv6 translation functionality from software-based proxy gateways and implements it directly in hardware network interface cards. This eliminates the need for complex software proxy gateways that terminate IPsec connections, thereby resolving the security vulnerability while maintaining IPv6 capability provision to IPv4 networks

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The hardware network interface card acts as an intermediary device that natively supports both IPv4 and IPv6 protocols. It provides direct translation and routing capabilities without requiring higher-level software proxies, thus eliminating DNS confusion and security termination issues while enabling seamless IPv6 access

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If extensive network upgrades are performed for IPv6 transition, then native IPv6 capabilities can be achieved, but cost and complexity increase significantly

Engineering Contradiction:
Improvenative IPv6 capabilityVSAvoidnetwork upgrade scope
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts IPv6 translation and routing functionality from the core network infrastructure and embeds it directly into end-user network interface cards. This eliminates the need for extensive centralized network upgrades and allows devices to obtain native IPv6 capabilities independently, significantly reducing overall network upgrade scope and cost

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The hardware network interface card provides self-contained IPv6 support with built-in translation and routing capabilities. Devices can autonomously configure and communicate using IPv6 without requiring complex network-wide reconfiguration or centralized management, thereby reducing implementation complexity while achieving native IPv6 capability

Inventive Principle:
Principle #25Self-service

3Quantity of substance

If NATs are used to extend IPv4 lifetime, then multiple systems can share public IPv4 addresses, but existing applications are broken and flexibility to deploy new applications is restricted

Engineering Contradiction:
Improvepublic IPv4 address sharingVSAvoidapplication flexibility
Core Design Contradiction:
Quantity of substanceVSAdaptability or versatility

Solution Approach 1:

The patent introduces IPv6 as an additional address dimension that coexists with IPv4. Network interface cards provide dual-stack capability, allowing systems to simultaneously use both IPv4 (for compatibility with existing applications) and IPv6 (for enhanced flexibility and end-to-end connectivity). This dimensional expansion resolves the contradiction by maintaining address sharing benefits while enabling new application deployment flexibility

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS8739289B2Hardware interface for enabling direct access and security assessment sharing
Publication Date: 2014.05.27 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8739289B2 patent drawing
  • US8739289B2 patent drawing
  • US8739289B2 patent drawing

AI summary

Native IPv6 capabilities are provided to an IPv4 network node, device, or endpoint using a hardware interface that supports network communication under a Direct Access model. The Direct Access model supports IPv6 communication with IPsec and enforces Network Access Protection (“NAP”) health requirement policies for endpoints that are network clients. A Direct Access-ready server is enabled using a hardware interface that implements IPv4 to IPv6 translation and optionally IPsec termination capability. A Direct Access-ready client is enabled using a hardware interface that implements IPv4 to IPv6 translation, IPsec termination capability, and which optionally provides NAP (Network Access Protection) capabilities for Direct Access-ready clients that are configured as mobile information appliances. The hardware interface may be implemented as a network interface card (“NIC”) or as a chipset.