Stateless IP Routing via Embedded Affiliation Metadata

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network communication solutions over public and wide-area networks face challenges in providing secure, scalable, and efficient communication for globally distributed enterprises, as they often require complex stateful operations and dedicated software, which can lead to increased costs and reduced flexibility.

Innovation Solution

A communication system utilizing multiple Point-of-Presence (POP) interfaces in a Wide-Area Network (WAN) with processors that assign client and service IP addresses embedding affiliation information, enabling stateless routing and security policy enforcement based on embedded metadata, without the need for complex switching decisions or dedicated software.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Virtual Private Networks (VPNs) or application-level protocols such as HTTPS are employed for secure communication, then security is improved, but device complexity and cost increase due to requiring dedicated software and complex stateful operations

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity of dedicated software and stateful operations
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security and routing functionality from complex dedicated software into the IP address structure itself. By embedding affiliation information (such as enterprise ID, department ID, or service ID) directly into the IP address fields, the system eliminates the need for separate VPN clients, certificates, and stateful authentication mechanisms, achieving secure communication through standard IP networking

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent changes the parameters of the IP address structure to include additional affiliation information. By utilizing available bits in the IP address (such as bits in the network portion or through IPv6 extensions) to encode affiliation data, the system transforms the IP address from a simple location identifier into a multi-functional parameter that carries both routing and security policy information

Inventive Principle:
Principle #35Parameter changes

2Reliability

If complex stateful operations and dedicated software are used for secure communication, then security policy enforcement is improved, but productivity decreases due to increased costs and reduced flexibility

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidcommunication efficiency and flexibility
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements self-service by embedding all necessary security and routing information directly in the IP address. Network routers can automatically enforce security policies and perform routing decisions based solely on the IP address fields, without requiring external authentication servers, stateful session management, or dedicated software agents, thereby improving communication efficiency

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The IP address structure is designed to serve multiple functions simultaneously: it provides traditional routing information, embeds security policy identifiers, indicates affiliation relationships, and enables both routing and security enforcement in a single data structure, eliminating the need for separate protocols or software layers

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If affiliation information is embedded in IP addresses for stateless routing, then routing efficiency is improved, but measurement precision may be affected due to information embedding in limited address space

Engineering Contradiction:
Improverouting efficiencyVSAvoidaddress space utilization
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent utilizes the dimensional space of the IP address structure (particularly in IPv6 with its 128-bit address space) to embed affiliation information. By organizing the address into hierarchical fields (such as network portion, subnetwork portion, and host portion) where different levels represent different dimensions of affiliation (enterprise, department, service), the system efficiently packs multiple layers of information without excessive overhead

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The IP address is segmented into distinct fields, each carrying specific types of information. For example, certain bits may represent enterprise affiliation, other bits may represent department or service affiliation, and remaining bits provide traditional routing information. This segmentation allows routers to efficiently extract and process only the relevant affiliation fields needed for security policy enforcement

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11979319B2IP address and routing schemes for overlay network
Publication Date: 2024.05.07 GOLDMAN SACHS BANK USA
  • US11979319B2 patent drawing
  • US11979319B2 patent drawing
  • US11979319B2 patent drawing

AI summary

A communication system includes multiple Point-of-Presence (POP) interfaces distributed in a Wide-Area Network (WAN), and one or more processors coupled to the POP interfaces. The processors are configured to assign to an initiator in the communication system a client Internet Protocol (IP) address, including embedding in the client IP address an affiliation of the initiator with a group of initiators, to assign to a responder in the communication system a service IP address, including embedding in the service IP address an affiliation of the service with a group of responders, and to route traffic between the initiator and the responder, over the WAN via one or more of the POP interfaces, in a stateless manner, based on the affiliation of the initiator and the affiliation of the service, as embedded in the client and service IP addresses.