Router Advertisement Suppression in IPv6 Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In IPV6 networks, unauthorized devices can inadvertently or intentionally become designated routers, leading to security issues and network disruptions by advertising false prefixes, which can divert packet traffic and compromise network security.

Innovation Solution

A network device is configured to filter and suppress router advertisements from unauthorized devices, using pre-defined filters to prevent unauthorized devices from becoming default gateways and creating excessive virtual interfaces, thereby enhancing network security and maintainability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If stateless address autoconfiguration is used in IPV6 networks, then network configuration becomes simpler and more automated, but network security is compromised as unauthorized devices can become designated routers

Engineering Contradiction:
Improveaddress autoconfigurationVSAvoidnetwork security
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The patent introduces a network device as an intermediary between unauthorized devices and the IPV6 network. This intermediary filters router advertisement packets, blocking malicious advertisements while permitting legitimate ones. The network device acts as a mediator that maintains the automated address configuration benefit while preventing security compromises by controlling which devices can become designated routers.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If any device can access a physical port and become a designated router, then network adaptability increases, but network stability deteriorates due to unauthorized route advertisements

Engineering Contradiction:
Improvedevice access flexibilityVSAvoidnetwork stability
Core Design Contradiction:
Adaptability or versatilityVSStability of the object's composition

Solution Approach 1:

The patent applies local quality by treating different network ports differently. The network device is configured to permit router advertisement packets from specific authorized ports while filtering advertisements from other ports. This localized differentiation maintains network adaptability for authorized devices while ensuring stability by blocking unauthorized advertisements from specific locations.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If router advertisements are permitted from all ports, then legitimate router functionality is maintained, but unauthorized devices can divert packet traffic and compromise security

Engineering Contradiction:
Improverouter advertisement processingVSAvoidunauthorized route diversion
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary anti-action by proactively filtering router advertisement packets before they can affect the network. The network device is pre-configured with rules to identify and block advertisements from unauthorized devices. This preventive measure counteracts potential harmful actions before they occur, maintaining ease of operation for legitimate routers while preventing unauthorized route diversion.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS7567522B2Suppression of router advertisement
Publication Date: 2009.07.28 HEWLETT PACKARD ENTERPRISE CO
  • US7567522B2 patent drawing
  • US7567522B2 patent drawing
  • US7567522B2 patent drawing

AI summary

In an embodiment, an apparatus for detecting a router advertisement, includes: a network device configured to generate a response when a router advertisement is received in a port in the network device. In another embodiment, a method for detecting a router advertisement, includes: generating a response when a router advertisement is received in a port in the network device.