IPv6 Host Blocking via Neighbor Discovery Protocol

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The exhaustion of IPv4 addresses and the need for efficient management and security in IPv6 networks, where automatic IP address assignment poses risks of unauthorized access.

Innovation Solution

A method utilizing the Neighbor Discovery Protocol (NDP) in IPv6 networks to search for and block hosts by sending Neighbor Solicitation and Router Solicitation packets, determining packet types, and generating modified Neighbor Advertisement packets to manage and block access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If automatic IP address assignment is implemented in IPv6 network, then network configuration efficiency is improved, but security control capability deteriorates

Engineering Contradiction:
Improvenetwork configuration efficiencyVSAvoidsecurity control capability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a Neighbor Discovery Protocol packet capturing and analyzing system as an intermediary between automatic IP assignment and security control. The system captures NDP packets, extracts host information, and enables centralized management and blocking of unauthorized devices, thus maintaining both automatic configuration efficiency and security control capability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a feedback mechanism where the system continuously monitors NDP packets in the network, automatically detects unauthorized hosts, and responds by generating blocking decisions. This closed-loop feedback enables dynamic security control without manual intervention, resolving the contradiction between automation and security

Inventive Principle:
Principle #23Feedback

2Reliability

If host blocking is implemented in IPv6 network, then security environment is improved, but network management complexity increases

Engineering Contradiction:
Improvesecurity environmentVSAvoidnetwork management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent utilizes existing Neighbor Discovery Protocol packet structures and formats for capturing, analyzing, and responding to host blocking scenarios. By copying and adapting proven IPv6 protocol mechanisms rather than creating new complex systems, the patent achieves effective security control while minimizing management complexity

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent designs a multi-functional system that can capture NDP packets, extract host information, identify unauthorized devices, and implement blocking decisions using standard IPv6 protocols. This universal approach handles multiple security scenarios through a single integrated mechanism, reducing overall management complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8189580B2Method for blocking host in IPv6 network
Publication Date: 2012.05.29 NETMAN
  • US8189580B2 patent drawing
  • US8189580B2 patent drawing
  • US8189580B2 patent drawing

AI summary

Disclosed herein are methods of searching for a host in a network using IPv4 and of blocking and searching a host in an IPv6 network which blocking access to an unauthorized network. The present invention provides a method of searching for a host in an IPv6 network, including the steps of requesting host information, including link-layer address information and IP address information about an IP to be searched for, by sending a Neighbor Solicitation (NS) packet in which the IP to be searched for is set in an ICMPv6 target address to the network, after sending the NS packet, waiting for a predetermined time by taking a processing speed of a host and a transfer rate according to a network environment and state into consideration, after the predetermined time of waiting, determining whether a Neighbor Advertisement (NA) packet of the IP to be searched for has been received, and if, as a result of the determination, the NA packet of the IP to be searched for is determined to have been received, acquiring the host information from the NA packet.