IPv6 Resource Allocation by Originating Entity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The transition from IPv4 to IPv6 networks poses challenges in managing network device resources, as IPv6 addresses allow subscribers to use multiple valid addresses, potentially leading to resource depletion and malicious denial-of-service attacks, especially during protocol translation between IPv4 and IPv6.

Innovation Solution

Implementing a method to determine the originating entity of IPv6 packets and allocate network device resources based on this entity rather than individual IPv6 addresses, using techniques like Network Address Translation (NAT) and prefix management to control resource usage and prevent overconsumption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network device resources are allocated per individual IPv6 address, then each subscriber can use multiple valid IPv6 addresses, but resource depletion and denial-of-service attacks occur

Engineering Contradiction:
ImproveIPv6 address usage flexibilityVSAvoidnetwork resource management security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the allocation of network device resources from individual IPv6 addresses to originating entities (subscribers). Instead of allocating resources per address, the system identifies the originating entity through the first received packet and allocates a limited group of resources to that entity, preventing resource exhaustion while allowing multiple address usage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism that maps IPv6 source addresses to originating entities. By determining the originating entity based on the first received packet's source address and using this entity identifier for resource allocation, the system prevents direct resource allocation to individual addresses, thereby avoiding denial-of-service attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If network device resources are allocated per originating entity, then resource depletion is prevented, but the complexity of determining and managing entities increases

Engineering Contradiction:
Improvenetwork resource managementVSAvoidoriginating entity identification mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by determining the originating entity based on the first received packet's source address before allocating network device resources. This preliminary identification establishes the entity mapping in advance, simplifying subsequent resource allocation and avoiding the need for complex continuous entity determination mechanisms.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If protocol translation is performed between IPv4 and IPv6, then network compatibility is improved, but resource management challenges increase during transition

Engineering Contradiction:
ImproveIPv4-IPv6 protocol compatibilityVSAvoidresource allocation management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal resource allocation mechanism that works across both IPv4 and IPv6 protocols. By identifying originating entities through IPv6 source addresses and allocating resources based on entity rather than address, the system provides consistent resource management during the protocol transition period, supporting both legacy and new protocols without increasing management complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8699515B2Limiting of network device resources responsive to IPv6 originating entity identification
Publication Date: 2014.04.15 CISCO TECHNOLOGY INC
  • US8699515B2 patent drawing
  • US8699515B2 patent drawing
  • US8699515B2 patent drawing

AI summary

Methods, apparatus, computer-storage media, mechanisms, and means associated therewith are used to limit network device resources based on the identification of the Internet Protocol version 6 (IPv6) originating entity (e.g., subscriber of a network carrier). As an IPv6 originating entity will typically be assigned 264 or more valid IPv6 addresses, the originating entity may send packets with a source address of any of these valid IPv6 addresses and still be compliant with Internet standards and/or other specifications (e.g., RFCs). By determining the originating entity and controlling the allocation of network device resources based on the originating entity (in contrast to on a per valid IPv6 address basis), a network service provider can manage its network device resources, such as in a manner to prevent a depletion of resources caused by an originating entity using a plethora valid IPv6 addresses, or a malicious denial-of-service attack.