Looking for breakthrough ideas for innovation challenges? Try Patsnap Eureka!

Method for assuring two-layer Ethernet exchanger data safety in city area transmission equipment

A technology of transmission equipment and switches, applied in the field of network communication, can solve the problems of reduced packet forwarding efficiency, no routing in the routing table, hidden dangers of information security, etc. The effect of the filter function

Inactive Publication Date: 2009-06-03
苏师大半导体材料与设备研究院(邳州)有限公司
View PDF4 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0008] (1) The destination MAC address in the message is a unicast address, and there is no corresponding route in the routing table;
[0009] (2) The destination MAC address in the message is a multicast address, and there is no corresponding route in the routing table;
[0016] c. When MAC addresses share different VLANs (virtual local area network) and user / VB (virtual network bridge) / Stack VLAN (nested virtual local area network) / QinQ (multi-layer 802.1Q label encapsulation message format), due to the There are too many links, resulting in a decrease in search efficiency, and thus a decrease in message forwarding efficiency
[0017] Moreover, the broadcast mechanism of the Layer 2 Ethernet switch also has potential hidden dangers: when the switch cannot find the corresponding port in the routing table entry, it broadcasts the data packet to all ports, and the attacker can receive the packet on a certain port. Packets broadcast from other ports, which will also cause information security risks

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Method for assuring two-layer Ethernet exchanger data safety in city area transmission equipment
  • Method for assuring two-layer Ethernet exchanger data safety in city area transmission equipment
  • Method for assuring two-layer Ethernet exchanger data safety in city area transmission equipment

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0049]The core of the present invention is to set up in advance according to the configuration information of the switch the message filtering table that represents the corresponding relationship between the switch input port and its VLAN (virtual local area network) and user ID / VBID / Stack VLAN / QinQ. Port filtering is performed on incoming packets, and packets that do not belong to the incoming port of the switch are discarded, so as to prevent port attacks and ensure port data security; Tuples or triples to look up routes to improve lookup efficiency.

[0050] In order to enable those skilled in the art to better understand the solution of the present invention, the present invention will be further described in detail below in conjunction with the accompanying drawings and embodiments.

[0051] refer to image 3 , image 3 The implementation process of the method of the present invention is shown, including the following steps:

[0052] Step 301: Establish a message filte...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

This invention discloses a method for guaranteeing data safety of two layer Ether net exchange in MAN transmission devices including: setting up a message filter list to filter the messages received by the exchange, setting up a route list to forward the filtered messages based on the route list, which can prevent the attack of network end to increase the data safety in the MAN transmission device.

Description

technical field [0001] The invention relates to the technical field of network communication, in particular to a method for ensuring the data security of a Layer 2 Ethernet switch in metro transmission equipment. Background technique [0002] With the development of metropolitan area network technology, the traditional Ethernet transparent transmission technology can no longer meet the needs of metropolitan area transmission network applications. Therefore, there have been a variety of Layer 2 Ethernet switches based on metropolitan area transmission. The Layer 2 switch is a data link Layer device, which can identify the MAC (Media Access Control) address information in the data packet, forward according to the MAC address, and record these MAC addresses and corresponding ports in the routing table, which indicates the MAC address and switch port corresponding relationship. When the switch receives a data packet from a certain port, it first reads the source MAC address in ...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Patents(China)
IPC IPC(8): H04L12/56H04L45/02
Inventor 金志国李大为刘明伟
Owner 苏师大半导体材料与设备研究院(邳州)有限公司
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Patsnap Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Patsnap Eureka Blog
Learn More
PatSnap group products