Network Services Header Context Authentication in Transitive IP Domains

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication networks face challenges in preserving and securely conveying context information across multiple transitive IP domains, as current methods often result in context loss, misinterpretation, or lack of authentication and authorization, especially when IP flows are encrypted.

Innovation Solution

The implementation of a Network Services Header (NSH) that carries context fields, allowing context to be preserved and securely revealed across transitive IP domains, with encryption and authentication mechanisms using security groups and an Authentication and Authorization server to ensure integrity and accessibility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IP flows are encrypted to secure communications, then security is improved, but context information cannot be accessed by transitive IP domains for enhanced services

Engineering Contradiction:
ImprovesecurityVSAvoidcontext information accessibility
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The packet structure is segmented into encrypted payload and unencrypted Network Services Header. The NSH contains context information that is accessible to transitive IP domains while the payload remains encrypted, allowing services to be provided without compromising security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The Network Services Header acts as an intermediary between the encrypted payload and the transitive IP domains. It carries context information that enables domains to provide enhanced services without needing to decrypt the payload, thus maintaining security while enabling service functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If context is conveyed across multiple transitive IP domains, then service enhancement is enabled, but context loss or misinterpretation occurs

Engineering Contradiction:
Improveservice enhancement capabilityVSAvoidcontext integrity
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The Network Services Header is designed as a universal structure that can carry context information across multiple different transitive IP domains. It provides a standardized format that ensures consistent interpretation and preservation of context information throughout the network path.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Context information is embedded in the Network Services Header at the ingress to the first transitive IP domain before traversal begins. This preliminary action ensures that all subsequent domains can access and interpret the context correctly without risk of loss or misinterpretation during transmission.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If overlay VPN technology is used to secure traffic, then security is improved, but device complexity and configuration overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security and context conveyance functions are merged into a single packet structure. The Network Services Header provides both security metadata and context information in one unified format, eliminating the need for separate overlay VPN configurations and reducing device complexity.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10104050B2Authenticated group context in transitive IP network domains
Publication Date: 2018.10.16 CISCO TECHNOLOGY INC
  • US10104050B2 patent drawing
  • US10104050B2 patent drawing
  • US10104050B2 patent drawing

AI summary

A method is provided in one example embodiment and includes receiving at a node of a transitive IP network a data packet including a Network Services Header (“NSH”); accessing by the transitive IP network node context contained in the NSH, wherein the context may be used by the transitive IP network node to perform an enhanced network service in connection with the received data packet; performing by the transitive IP network node the enhanced network service in connection with the received data packet using the accessed context; and, subsequent to the performing, forwarding the received packet to a next node.