Overlay Network Port Policy Isolation via Gateway Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional network communication protocols, such as IP, pose security challenges due to the dual role of network addresses as both identifiers and locations, leading to vulnerabilities like man-in-the-middle attacks and denial of service attacks, especially in modern distributed networking environments where hosts frequently change locations.
Innovation Solution
Implementing an underlay network that communicatively couples source and target gateways using underlay protocols, with overlay networks providing separate gateway identifiers and enabling encrypted payloads exchange, and using virtual device addresses to route network traffic securely across different network segments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If network addresses are used for both host identity and location, then routing and addressing are simplified, but security vulnerabilities increase due to spoofing and man-in-the-middle attacks
Solution Approach 1:
The patent segments the dual function of network addresses by introducing separate identifier and location components. Network packets are divided into an outer envelope containing location information for routing and an inner payload containing identifier information for host recognition, thereby separating the previously combined functions into distinct segments that can be independently secured.
Solution Approach 2:
The patent introduces an intermediary mechanism (the outer envelope with source network address) that mediates between the actual host identity and the routing process. This intermediary layer allows the network to route packets based on location while the inner identifier reveals the true host identity, preventing direct spoofing of host identity for routing purposes.
2Reliability
If overlay networks are implemented to provide security and flexibility, then network security and adaptability improve, but integration with underlay network protocols increases system complexity
Solution Approach 1:
The patent implements a nested structure where the overlay network protocol is embedded within the underlay network protocol framework. The outer envelope follows underlay protocol standards for routing compatibility, while the inner payload carries overlay network information for security and identification, allowing the overlay to function within the underlay without requiring complete protocol replacement.
Solution Approach 2:
The patent creates a multi-functional packet structure that simultaneously serves routing purposes (through the outer envelope address) and security/identification purposes (through the inner payload identifier). This universal structure allows a single protocol mechanism to fulfill multiple network functions, reducing the need for separate specialized protocols.
3Adaptability or versatility
If hosts frequently change locations in modern distributed networking, then network flexibility and adaptability improve, but security challenges increase due to ephemeral addresses
Solution Approach 1:
The patent segments host identification from location information, allowing the identifier to remain constant while the location (network address) changes. The inner payload contains the stable host identifier that maintains identity recognition even when the outer envelope's location address changes due to mobility or ephemeral addressing.
Solution Approach 2:
The patent creates a dynamic packet structure where the outer envelope's location information can change as hosts move or obtain new addresses, while the inner payload's identifier remains static. This dynamic adaptability allows the system to handle mobile hosts and ephemeral addresses while maintaining reliable identification through the immutable inner identifier.
Data Source
AI summary
Embodiments are directed to managing communication over one or more networks. An underlay network that couples a source gateway and a target gateway using underlay protocols may be provided such that the target gateway includes two or more port groups that may each be associated with a separate target node. An overlay network may be provided on the underlay network based on policy information such that the source gateway and the target gateway may each be assigned separate gateway identifiers (GIDs) that are associated with the overlay network. In response to the source gateway authorizing a source node to employ the overlay network to communicate one or more encrypted payloads to a target node, the one or more encrypted payloads may be provided to the target node based on the overlay network and the policy information.


