IPv6 Host Portion Authentication for Secure IoT Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The growth of the Internet and increased use of devices have led to address exhaustion issues, and existing security methods for transactions over untrusted networks, such as passwords, are vulnerable to theft and guessing, making secure communication challenging.

Innovation Solution

A token generator creates a cryptographically secure token using a device's source address to prevent impersonation and predictability, with a token-retrieval engine ensuring the correct destination address is used, and an optional security monitor blocks repeated invalid authentication attempts, utilizing the host portion of an IPv6 destination address for authentication and policy mapping.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If passwords are used for authentication, then security can be implemented, but the passwords are vulnerable to theft, reuse, and cryptographic guessing

Engineering Contradiction:
Improveauthentication securityVSAvoidpassword theft and guessing vulnerabilities
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication mechanism from traditional password-based systems and implements it directly within the IP address structure itself. The host portion of the IPv6 address serves as the authentication token, eliminating the need for separate password storage and transmission, thereby removing the vulnerabilities associated with password theft and reuse.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an authentication server as an intermediary that issues and manages cryptographic authentication tokens (the host portion of IPv6 addresses). This server mediates between clients and services, providing secure authentication without requiring clients to store or transmit passwords, thus eliminating password-related security vulnerabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If IPv6 addresses are used to provide device-specific responses and security policies, then secure communication is enabled, but the system complexity increases

Engineering Contradiction:
Improvesecure communicationVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the IPv6 address structure multi-functional by using it simultaneously for network routing identification and authentication. The host portion of the address serves dual purposes: identifying the device on the network and providing cryptographic authentication credentials. This eliminates the need for separate authentication protocols and reduces overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The authentication mechanism is designed to be self-service, where the client device automatically uses its assigned IPv6 host address as its authentication credential without requiring additional configuration or manual intervention. The authentication server automatically recognizes and validates the host portion of incoming connection requests, simplifying the authentication process.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20230239283A1Destination-based policy selection and authentication
Publication Date: 2023.07.27 THREATSTOP
  • US20230239283A1 patent drawing
  • US20230239283A1 patent drawing
  • US20230239283A1 patent drawing

AI summary

Techniques for allowing client devices to securely request services from remote servers without using a reproducible token on the client are disclosed. In an embodiment, the host-portion of a destination address, in whole or in part, is used as an authentication token to identify an end-user, to be a selector to retrieve a security or other policy, or to provide device-specific or user-specific content. In an embodiment, repeated unauthorized attempts to access services are monitored to allow a human or artificial network agent to take appropriate defensive action against attacks.