IPv6 Address Embedding for Zone Identification and Secure Session Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network communication systems face challenges in efficiently identifying zones and managing configuration settings within IPv6 addresses, particularly in scenarios involving secure sessions, traffic management, and geographic routing, due to limitations in existing protocols like SSL/TLS and DNS systems.

Innovation Solution

Embedding information or unique identifiers within specific portions of IPv6 addresses allows for zone identification, configuration setting management, and geographic location determination, enabling quicker secure session establishment, improved traffic handling, and optimized routing without relying on host headers or Server Name Indication (SNI) extensions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If information is embedded in IPv6 addresses for zone identification and configuration management, then network security and routing efficiency are improved, but device complexity and difficulty of detecting and measuring increase

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The IPv6 address is divided into multiple segments, where specific portions are allocated for embedding zone identification information and configuration settings. This segmentation allows the address to carry multiple layers of information (global routing prefix, subnet ID, interface ID, and embedded configuration data) without interfering with each other, thereby improving network security and routing efficiency while maintaining address structure integrity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The IPv6 address structure is designed to serve multiple functions simultaneously: traditional routing and addressing, zone identification, configuration setting management, and geographic location determination. By making the address multi-functional, the patent eliminates the need for separate protocols or headers for these purposes, thus improving reliability without proportionally increasing device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Speed

If information is embedded in IPv6 addresses for zone identification, then secure session establishment speed is improved, but difficulty of detecting and measuring increases

Engineering Contradiction:
Improvesecure session establishment speedVSAvoiddifficulty of detecting and measuring
Core Design Contradiction:
SpeedVSDifficulty of detecting and measuring

Solution Approach 1:

Zone identification information and configuration settings are pre-embedded in the IPv6 address before communication occurs. This preliminary encoding allows receiving devices to immediately identify the zone and apply appropriate security policies without requiring additional handshake steps or header inspections, thereby accelerating secure session establishment while the structured embedding methodology keeps detection complexity manageable.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If configuration settings are embedded in IPv6 addresses for traffic management, then traffic handling efficiency is improved, but device complexity increases

Engineering Contradiction:
Improvetraffic handling efficiencyVSAvoiddevice complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The IPv6 address itself carries the configuration settings needed for traffic management, allowing network devices to automatically retrieve and apply routing priorities, geographic location information, and traffic handling parameters directly from the address without requiring external configuration databases or additional signaling. This self-service approach improves traffic handling efficiency while minimizing the need for complex external management systems.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10298601B2Embedding information or information identifier in an IPv6 address
Publication Date: 2019.05.21 CLOUDFLARE INC
  • US10298601B2 patent drawing
  • US10298601B2 patent drawing
  • US10298601B2 patent drawing

AI summary

A network address includes a predefined portion that identifies a hostname, where the predefined portion is less than all of the network address. A request is received for a secure session at the network address. The hostname is identified from the predefined portion of the network address and a secure session negotiation is made including returning a digital certificate for the identified hostname.