First Hop Switch IPv6 NDP Interception for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IPv6 network traffic is vulnerable to security threats due to shared layer-2 physical networks, where rogue users can intercept and exploit Neighbor Discovery Protocol (NDP) exchanges, leading to attacks like man-in-the-middle and denial-of-service attacks.

Innovation Solution

A first hop switch intercepts NDP messages, compares address information with a local device tracking cache, and performs end node discovery and tracking, creating bindings between Link Layer Addresses (LLA) and IPv6 addresses to verify identities and prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a shared layer-2 physical network infrastructure is used to transport IPv6 traffic, then network resource utilization and user mobility are improved, but network security deteriorates due to vulnerability to rogue users and attacks

Engineering Contradiction:
Improveuser mobility and network resource utilizationVSAvoidnetwork security vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary security mechanism at the first-hop switch that mediates NDP message exchanges between end hosts and routers. This intermediary validates address bindings, monitors neighbor discovery processes, and filters malicious traffic, thereby protecting the shared layer-2 network from rogue users while maintaining its resource utilization benefits

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary security actions by pre-establishing address bindings between link layer addresses and IPv6 addresses before actual data transmission occurs. The first-hop switch performs advance validation of neighbor discovery messages and proactively identifies rogue devices, preventing attacks before they can compromise network security

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If NDP exchanges are allowed to proceed without interception, then network protocol functionality and ease of operation are maintained, but security against spoofing and man-in-the-middle attacks deteriorates

Engineering Contradiction:
ImproveNDP protocol functionalityVSAvoidspoofing and man-in-the-middle attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The first-hop switch acts as an intermediary that transparently intercepts and validates NDP messages without disrupting the normal neighbor discovery process. It maintains protocol functionality by allowing legitimate NDP exchanges while filtering out spoofed messages, thus preserving ease of operation while enhancing security

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements feedback mechanisms where the first-hop switch monitors NDP message exchanges, validates address bindings, and provides real-time security enforcement. The switch uses feedback from intercepted messages to dynamically update its security state and block malicious traffic, maintaining protocol functionality while preventing attacks

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8893271B1End node discovery and tracking in layer-2 of an internet protocol version 6 network
Publication Date: 2014.11.18 CISCO TECHNOLOGY INC
  • US8893271B1 patent drawing
  • US8893271B1 patent drawing
  • US8893271B1 patent drawing

AI summary

Network security and tracking techniques are provided for intercepting at a first hop switch a neighbor discovery protocol (NDP) message sent from an end node of an Internet Protocol Version 6 (IPV6) network. Address information contained in the NDP message are compared to values stored in a local device tracking cache. As a result of the comparing, end node discovery and learning are performed.