Secure IP Access Protocol Framework for Host-to-Host Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for IP hosts to initialize IP networking over shared links lack security or suffer from routing efficiency problems, such as inadequate security in DHCP, reliance on gateway routers for encryption, and overloading in PPPoE and link-layer access control mechanisms.

Innovation Solution

The Secure IP Access (SIA) protocol framework, which integrates enhanced DHCP and ARP security options, deploys SIA clients and servers to establish secure data channels using cryptography, mutual authentication, and key exchange, ensuring security without extra packet generation and improving routing efficiency by encrypting communications directly between hosts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If PPPoE with encryption is used to authenticate IP hosts and protect security, then security protection is improved, but routing efficiency deteriorates because all host-to-host communications must go through the gateway router for decryption and re-encryption

Engineering Contradiction:
Improvesecurity protectionVSAvoidrouting efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the encryption function from the gateway router to individual IP hosts. Each host performs its own encryption and decryption operations locally, eliminating the need for centralized decryption/re-encryption at the gateway router. This segmentation resolves the contradiction by maintaining security protection while restoring routing efficiency for host-to-host communications.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements self-service encryption where each IP host autonomously performs encryption of outgoing packets and decryption of incoming packets using its own cryptographic keys. This eliminates the dependency on the gateway router for security operations, allowing direct host-to-host communication without router involvement in encryption/decryption, thus maintaining both security and routing efficiency.

Inventive Principle:
Principle #25Self-service

2Reliability

If link-layer access control and encryption mechanisms (802.1x, 802.11i) are used to protect security, then security protection is improved, but routing efficiency deteriorates when communications occur between IP hosts associated with the same access point

Engineering Contradiction:
Improvesecurity protectionVSAvoidrouting efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent moves security functions from the link layer to the network layer, segmenting the security domain from the access point to individual IP hosts. This allows hosts to establish direct encrypted communication channels at the IP layer without requiring access point involvement, resolving the efficiency problem while maintaining security protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent shifts the security implementation from the link layer dimension to the network layer dimension. By implementing security at the IP protocol level rather than the link layer, the system enables direct host-to-host encrypted communication that bypasses access point constraints, thereby improving routing efficiency while preserving security.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Productivity

If static IP addresses with gratuitous ARP are used for initialization, then routing efficiency is maintained, but security functions are lacking

Engineering Contradiction:
Improverouting efficiencyVSAvoidsecurity functions
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent merges DHCP functionality with security authentication in a unified protocol exchange. The enhanced DHCP protocol simultaneously performs IP address allocation, network configuration delivery, and mutual authentication with key exchange, combining the benefits of efficient IP initialization with strong security functions in a single integrated process.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent performs security authentication and key exchange as preliminary actions during the DHCP initialization phase, before any actual data communication begins. This ensures that security protections are established in advance, allowing subsequent communications to proceed efficiently with already-established security contexts, thus adding security without sacrificing routing efficiency.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8046577B2Secure IP access protocol framework and supporting network architecture
Publication Date: 2011.10.25 AT&T INTELLECTUAL PROPERTY II LP
  • US8046577B2 patent drawing
  • US8046577B2 patent drawing
  • US8046577B2 patent drawing

AI summary

A protocol framework for a Secure IP Access (SIA) method, and supporting components deployed on IP hosts and IP networks. Using this method, an IP host can establish a secure data channel within an IP network over an insecure shared link while requesting IP address and networking configuration parameters from the IP network. A system administrator can implement strong access control against various attacks that an edge IP network may have to face, such as a denial-of-service attack that exhausts assignable IP addresses. This is a lightweight, scalable, and backward-compatible solution that can improve security performance for public and corporate LANs having open access such as wireless access points and Ethernet jacks.