Stateless NAT66 Encryption for Dual IPv6 Address Obfuscation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for protecting IP addresses in networks require complex encryption/decryption algorithms that are performance-intensive in the data path, and existing solutions do not effectively obfuscate both source and destination IP addresses concurrently, leading to potential visibility and identifiability of network endpoints.

Innovation Solution

A dynamic and stateless NAT66 encryption/decryption method using a 4-bit cipher and encryption/decryption flavor to obfuscate both source and destination IPv6 addresses concurrently, ensuring 100% reversibility and zero collisions, protecting both addresses simultaneously.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If complex encryption/decryption algorithms are used to protect IP addresses, then privacy protection is improved, but processing performance deteriorates

Engineering Contradiction:
Improveprivacy protectionVSAvoidprocessing performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent changes the parameters of the encryption algorithm by using a simplified 4-bit cipher instead of complex encryption methods. This parameter change maintains privacy protection functionality while significantly reducing computational complexity and improving processing performance in the data path.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent employs a lightweight, disposable encryption approach using simple 4-bit ciphers that can be rapidly applied and discarded. This eliminates the need for heavy, long-lived cryptographic keys and algorithms, thereby improving processing speed while maintaining adequate privacy protection for IP addresses.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

2Device complexity

If only source IP address is obfuscated, then implementation complexity is reduced, but destination IP address visibility increases

Engineering Contradiction:
Improveimplementation complexityVSAvoidprivacy protection
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent merges the obfuscation of source and destination IP addresses into a unified encryption process. By applying the same 4-bit cipher to both addresses simultaneously, the system achieves dual protection without significantly increasing implementation complexity, as the encryption logic remains identical for both operations.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal encryption function that handles both source and destination IP addresses using the same 4-bit cipher mechanism. This multi-functional approach ensures comprehensive privacy protection while avoiding the need for separate complex encryption systems for each address type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12413567B2Method to achieve dynamic NAT66 encryption and decryption
Publication Date: 2025.09.09 CISCO TECHNOLOGY INC
  • US12413567B2 patent drawing
  • US12413567B2 patent drawing
  • US12413567B2 patent drawing

AI summary

The disclosed technology addresses the need in the art for systems and methods of dynamic but stateless NAT encryption and decryption. The disclosed technology provides a robust encryption/decryption algorithm for concurrently obfuscating source and destination IPv6 addresses for SNAP deployments with 100% reversal and zero collisions, thereby providing protection to both the source and destination IPv6 simultaneously.