IPv6 Address Identity Encoding for In-Plane Network Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network policy enforcement in enterprise networks is complex due to reliance on virtual network and Endpoint ID Group identities, Deep Packet Inspection, and inconsistent use of VXLAN Network Identifiers and Scalable Group Tags, leading to interoperability issues and inefficient security measures.
Innovation Solution
Embedding user and application identities in IPv6 addresses for end-to-end communications, enabling finer-grained policy enforcement through unique identifiers that are independent of end terminals, using existing network primitives for routing, forwarding, and segmentation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If VXLAN and Scalable Group Tags are used for network segmentation and policy enforcement, then network security and segmentation are improved, but device complexity and interoperability issues worsen due to inconsistent VNI sizes and SGT propagation limitations
Solution Approach 1:
The patent combines multiple identity types (user identity, application identity, group identity) into a single unified IP address structure. This merging eliminates the need for separate VXLAN VNI and SGT mechanisms, reducing device complexity while maintaining security. The unified IP address carries all necessary identification information in its structure, allowing policy enforcement without multiple overlapping identity systems.
Solution Approach 2:
The IP address is designed to serve multiple functions simultaneously: it provides endpoint identification, application identification, user identification, and network segmentation all in one structure. This multi-functionality replaces the need for separate VXLAN and SGT systems, improving interoperability while maintaining security policies across diverse devices.
2Measurement precision
If Deep Packet Inspection and proxying are used for application identification, then policy enforcement accuracy is improved, but processing time and computational resources worsen
Solution Approach 1:
The application identity is embedded in the IP address structure before packets are transmitted across the network. This preliminary encoding of identification information eliminates the need for Deep Packet Inspection during packet processing. Routers and firewalls can perform fast lookups based on the pre-encoded IP address, significantly reducing processing time while maintaining accurate application identification.
3Measurement precision
If multiple identity types (user, application, group) are tracked separately, then policy enforcement granularity is improved, but system complexity and information loss worsen due to propagation limitations
Solution Approach 1:
The patent merges user identity, application identity, and group identity into a single hierarchical IP address structure. This unified structure propagates all identity information simultaneously across the network without the limitations of separate SGT propagation. Each IP address contains encoded information about the user, application, and group, ensuring complete information availability at all network points.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present disclosure provides a method of embedding finer grained information such as user identity and application identity in IPv6 addresses used for end-to-end communications within a network. The finer grained information can be used for improved policy enforcement within the network. In one aspect, generating an address for an end-to-end communication within a network, the address including a user identifier and an application identifier for network policy enforcement; assigning the address to an application used in the end-to-end communication; and performing network segmentation and the network policy enforcement within the network using the address.