Overlay Network Port Policy Isolation via Gateway Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional network communication protocols, such as IP, pose security challenges due to the dual role of network addresses as both identifiers and locations, leading to vulnerabilities like man-in-the-middle attacks and denial of service attacks, especially in modern distributed networking environments where hosts frequently change locations.

Innovation Solution

Implementing an underlay network that communicatively couples source and target gateways using underlay protocols, with overlay networks providing separate gateway identifiers and enabling encrypted payloads exchange, and using virtual device addresses to route network traffic securely across different network segments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If network addresses are used for both host identity and location, then routing and addressing are simplified, but security vulnerabilities increase due to spoofing and man-in-the-middle attacks

Engineering Contradiction:
Improveaddressing complexityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the dual function of network addresses by introducing separate identifier and location components. Network packets are divided into an outer envelope containing location information for routing and an inner payload containing identifier information for host recognition, thereby separating the previously combined functions into distinct segments that can be independently secured.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism (the outer envelope with source network address) that mediates between the actual host identity and the routing process. This intermediary layer allows the network to route packets based on location while the inner identifier reveals the true host identity, preventing direct spoofing of host identity for routing purposes.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If overlay networks are implemented to provide security and flexibility, then network security and adaptability improve, but integration with underlay network protocols increases system complexity

Engineering Contradiction:
Improvenetwork securityVSAvoidprotocol integration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a nested structure where the overlay network protocol is embedded within the underlay network protocol framework. The outer envelope follows underlay protocol standards for routing compatibility, while the inner payload carries overlay network information for security and identification, allowing the overlay to function within the underlay without requiring complete protocol replacement.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent creates a multi-functional packet structure that simultaneously serves routing purposes (through the outer envelope address) and security/identification purposes (through the inner payload identifier). This universal structure allows a single protocol mechanism to fulfill multiple network functions, reducing the need for separate specialized protocols.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If hosts frequently change locations in modern distributed networking, then network flexibility and adaptability improve, but security challenges increase due to ephemeral addresses

Engineering Contradiction:
Improvenetwork flexibilityVSAvoidhost identification reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments host identification from location information, allowing the identifier to remain constant while the location (network address) changes. The inner payload contains the stable host identifier that maintains identity recognition even when the outer envelope's location address changes due to mobility or ephemeral addressing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a dynamic packet structure where the outer envelope's location information can change as hosts move or obtain new addresses, while the inner payload's identifier remains static. This dynamic adaptability allows the system to handle mobile hosts and ephemeral addresses while maintaining reliable identification through the immutable inner identifier.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12095743B2Port level policy isolation in overlay networks
Publication Date: 2024.09.17 TYCO FIRE & SECURITY GMBH
  • US12095743B2 patent drawing
  • US12095743B2 patent drawing
  • US12095743B2 patent drawing

AI summary

Embodiments are directed to managing communication over one or more networks. An underlay network that couples a source gateway and a target gateway using underlay protocols may be provided such that the target gateway includes two or more port groups that may each be associated with a separate target node. An overlay network may be provided on the underlay network based on policy information such that the source gateway and the target gateway may each be assigned separate gateway identifiers (GIDs) that are associated with the overlay network. In response to the source gateway authorizing a source node to employ the overlay network to communicate one or more encrypted payloads to a target node, the one or more encrypted payloads may be provided to the target node based on the overlay network and the policy information.