Overlay Network Identity-Based Relay for Secure Routing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional network communication protocols, such as IP, face challenges in securing networks due to the dual role of IP addresses as both identifiers and location markers, leading to vulnerabilities like man-in-the-middle attacks and denial of service attacks, especially in modern distributed networking environments where host identities are ephemeral and non-unique.
Innovation Solution
Implementing an overlay network identity-based relay system that uses separate gateway identifiers (GIDs) instead of network addresses for communication, with a relay engine determining connection routes and translating packets between different network protocols, while managing connection routes and performance metrics to ensure secure and efficient communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If IP addresses are used for both host identification and location routing, then network communication can be established using standard protocols, but network security is compromised due to spoofing and man-in-the-middle attacks
Solution Approach 1:
The patent segments the dual function of IP addresses by introducing separate identifier and location components. The overlay network identifier (ONI) handles host identification while the underlying IP address handles location routing, separating these previously combined functions to eliminate spoofing vulnerabilities.
Solution Approach 2:
The patent introduces an intermediary translation layer that maps overlay network identifiers to underlying IP addresses. This mediator component enables secure identifier-based communication while maintaining compatibility with existing IP-based routing infrastructure, without requiring endpoints to directly handle both identification and location functions.
2Productivity
If network addresses are used to determine host identity, then routing return packets is simplified, but vulnerabilities to spoofing attacks and denial of service attacks increase
Solution Approach 1:
The patent divides the network address function into two separate components: overlay network identifiers for host identity recognition and underlying IP addresses for location-based routing. This segmentation allows packet routing to efficiently use IP addresses while host identity verification uses secure overlay identifiers, preventing spoofing attacks.
Solution Approach 2:
The patent creates an overlay network layer that copies essential identification functionality from the IP layer without relying on IP addresses for identity determination. This copy maintains routing efficiency through the underlying IP infrastructure while adding a secure identification layer that cannot be spoofed.
3Adaptability or versatility
If ephemeral and non-unique network addresses are used for mobile hosts, then host mobility is supported, but host identity determination becomes challenging
Solution Approach 1:
The patent separates host identity (overlay network identifier) from host location (IP address). Mobile hosts can change their IP address to support mobility while maintaining a consistent overlay network identifier that preserves their identity, allowing other hosts to communicate with them regardless of location changes.
Solution Approach 2:
The patent introduces an intermediary mapping system that associates ephemeral IP addresses with persistent overlay network identifiers. This mediator maintains host identity information even when IP addresses change, enabling reliable identity determination for mobile hosts through the stable overlay identifier rather than the transient IP address.
Data Source
AI summary
Embodiments are directed to a relay that receives packets from a source gateway associated with a source gateway identifier (GID) and a target GID associated with a target gateway where each GID is separate from a network address or a hostname of the source gateway or the target gateway. The relay determines a connection route based on an association between the connection route and an ingress identifier obtained from the packets. The relay provides the connection route based on the source GID and the target GID. The relay determines network address information associated with the target gateway based on the connection route. And, the relay forwards the packets provided by the source gateway to the target gateway based on the network address information.


