IPv6 Address Identity Encoding for In-Plane Network Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network policy enforcement in enterprise networks is complex due to reliance on virtual network and Endpoint ID Group identities, Deep Packet Inspection, and inconsistent use of VXLAN Network Identifiers and Scalable Group Tags, leading to interoperability issues and inefficient security measures.

Innovation Solution

Embedding user and application identities in IPv6 addresses for end-to-end communications, enabling finer-grained policy enforcement through unique identifiers that are independent of end terminals, using existing network primitives for routing, forwarding, and segmentation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If VXLAN and Scalable Group Tags are used for network segmentation and policy enforcement, then network security and segmentation are improved, but device complexity and interoperability issues worsen due to inconsistent VNI sizes and SGT propagation limitations

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple identity types (user identity, application identity, group identity) into a single unified IP address structure. This merging eliminates the need for separate VXLAN VNI and SGT mechanisms, reducing device complexity while maintaining security. The unified IP address carries all necessary identification information in its structure, allowing policy enforcement without multiple overlapping identity systems.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The IP address is designed to serve multiple functions simultaneously: it provides endpoint identification, application identification, user identification, and network segmentation all in one structure. This multi-functionality replaces the need for separate VXLAN and SGT systems, improving interoperability while maintaining security policies across diverse devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If Deep Packet Inspection and proxying are used for application identification, then policy enforcement accuracy is improved, but processing time and computational resources worsen

Engineering Contradiction:
Improveapplication identification accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The application identity is embedded in the IP address structure before packets are transmitted across the network. This preliminary encoding of identification information eliminates the need for Deep Packet Inspection during packet processing. Routers and firewalls can perform fast lookups based on the pre-encoded IP address, significantly reducing processing time while maintaining accurate application identification.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If multiple identity types (user, application, group) are tracked separately, then policy enforcement granularity is improved, but system complexity and information loss worsen due to propagation limitations

Engineering Contradiction:
Improvepolicy enforcement granularityVSAvoidinformation propagation
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent merges user identity, application identity, and group identity into a single hierarchical IP address structure. This unified structure propagates all identity information simultaneously across the network without the limitations of separate SGT propagation. Each IP address contains encoded information about the user, application, and group, ensuring complete information availability at all network points.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP3981137B1In-data-plane network policy enforcement using IP addresses
Publication Date: 2026.01.07 CISCO TECHNOLOGY INC
  • EP3981137B1 patent drawingFigure 1
  • EP3981137B1 patent drawingFigure 2
  • EP3981137B1 patent drawingFigure 3

AI summary

The present disclosure provides a method of embedding finer grained information such as user identity and application identity in IPv6 addresses used for end-to-end communications within a network. The finer grained information can be used for improved policy enforcement within the network. In one aspect, generating an address for an end-to-end communication within a network, the address including a user identifier and an application identifier for network policy enforcement; assigning the address to an application used in the end-to-end communication; and performing network segmentation and the network policy enforcement within the network using the address.