IPv6 Prefix Subnetting for Residential Gateway Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The exhaustion of IPv4 address space necessitates the development of techniques to efficiently manage and allocate IP addresses, particularly in residential and small business networks, where existing solutions like NAT are cumbersome and inefficient.

Innovation Solution

Implementing prefix subnetting methods, where a delegated IPv6 prefix is divided into lower and higher-numbered portions, allocated to multiple networks, and further subdivided for use in prefix delegation to routers, eliminating the need for network address translation (NAT) and enhancing security by creating segmented security realms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If NAT is used to manage IPv4 address exhaustion, then address space utilization is improved, but network complexity and security are worsened

Engineering Contradiction:
Improveaddress space utilizationVSAvoidnetwork complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent segments the IPv6 address space by dividing the delegated prefix into multiple subnets (first subnet, second subnet, third subnet, fourth subnet) with different trust values. This segmentation allows each subnet to be managed independently with appropriate security policies, eliminating the need for NAT while providing structured address management.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a trust value parameter associated with each subnet to differentiate security requirements. By changing the trust value parameter for different subnets, the system can apply appropriate security measures without requiring NAT, thus simplifying the network architecture while maintaining security.

Inventive Principle:
Principle #35Parameter changes

2Quantity of substance

If NAT is used to manage IPv4 address exhaustion, then address space utilization is improved, but security is worsened

Engineering Contradiction:
Improveaddress space utilizationVSAvoidsecurity
Core Design Contradiction:
Quantity of substanceVSObject-affected harmful factors

Solution Approach 1:

The patent segments networks into multiple subnets with different trust values, allowing security policies to be applied at the subnet level. This segmentation provides finer-grained security control compared to NAT, enabling trusted and untrusted subnets to be differentiated and protected appropriately without compromising overall network security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

By introducing trust values as a parameter for each subnet, the patent enables differentiated security measures. Trusted subnets can have enhanced security policies while untrusted subnets can be isolated or monitored, providing robust security without the need for NAT and its associated vulnerabilities.

Inventive Principle:
Principle #35Parameter changes

3Quantity of substance

If a single public IPv4 address is used for multiple private addresses, then address exhaustion is addressed, but network management complexity is worsened

Engineering Contradiction:
Improveaddress exhaustionVSAvoidnetwork management complexity
Core Design Contradiction:
Quantity of substanceVSEase of operation

Solution Approach 1:

The patent segments the address space into multiple subnets with distinct trust values, making network management more straightforward. Each subnet can be independently configured and managed, and the trust value parameter provides clear guidance for security policies, reducing the complexity of managing multiple addresses and devices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The trust value parameter simplifies network management by providing a clear classification mechanism for subnets. Administrators can easily identify which subnets require enhanced security measures and which can be more permissive, making network management simpler and more systematic compared to traditional NAT approaches.

Inventive Principle:
Principle #35Parameter changes

4Object-affected harmful factors

If prefix subnetting is implemented, then network security is improved through segmentation, but address allocation complexity is worsened

Engineering Contradiction:
Improvenetwork securityVSAvoidaddress allocation complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent segments the delegated prefix into multiple subnets with different trust values, providing structured security segmentation. The segmentation follows a systematic pattern (first, second, third, fourth subnets) that simplifies the allocation process while maintaining security benefits.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The trust value parameter provides a clear framework for address allocation that simplifies complexity. By assigning trust values to subnets, the system creates a straightforward allocation methodology that balances security requirements with ease of deployment and management.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8995360B2Techniques for prefix subnetting
Publication Date: 2015.03.31 TIME WARNER CABLE ENTERPRISES LLC
  • US8995360B2 patent drawing
  • US8995360B2 patent drawing
  • US8995360B2 patent drawing

AI summary

A delegated internet protocol version six prefix, which is assigned to a gateway device which is interposed between an internet and a premises, is divided into a lower-numbered portion and a higher-numbered portion. One of the portions is allocated to a plurality of networks associated with the premises. The other is broken into a plurality of blocks for use in prefix delegation for allocation to routers associated with the premises requesting the prefix delegation. The gateway device is operated in accordance with the dividing, allocating, and breaking steps. Optionally, at least some of the plurality of networks associated with the premises are pre-categorized into at least first and second trust zones, and the operating step further includes operating the gateway device in accordance with the pre-categorizing step. Apparatuses, devices, computer program products, and internet protocol version four embodiments are also provided.