Unlock instant, AI-driven research and patent intelligence for your innovation.

Device and method for preventing IPv6 (Internet Protocol version 6) from being deceptively attached

An ipv6 address, deceptive technology, applied in the direction of security communication devices, digital transmission systems, electrical components, etc., to achieve the effect of ensuring security

Inactive Publication Date: 2010-11-17
ZTE CORP
View PDF0 Cites 4 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

The above-mentioned existing source address protection method can only be used in an IPv6 network based on DHCP for address allocation
However, there is no effective solution for other IPv6 networks based on Stateless Auto-configuration (stateless automatic configuration) or static configuration.

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Device and method for preventing IPv6 (Internet Protocol version 6) from being deceptively attached
  • Device and method for preventing IPv6 (Internet Protocol version 6) from being deceptively attached
  • Device and method for preventing IPv6 (Internet Protocol version 6) from being deceptively attached

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0024] Functional Overview

[0025] Considering that the existing source address protection method based on DHCP Snooping IP Source Guard can only be used in an IPv6 network based on DHCP for address allocation, the embodiment of the present invention provides a universally applicable method for preventing IPv6 addresses from being spoofed Program. The method establishes corresponding binding table items by detecting NS data packets, and formulates forwarding and control strategies of data flow, thereby perfecting the security protection function of the IPv6 network.

[0026] It should be noted that, in the case of no conflict, the embodiments in the present application and the features in the embodiments can be combined with each other. The present invention will be described in detail below with reference to the accompanying drawings and examples.

[0027] Device embodiment

[0028] According to an embodiment of the present invention, a device for preventing IPv6 addresse...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention discloses a device and a method for preventing an IPv6 (Internet Protocol version 6) from being deceptively attached. The method comprises the steps of: detecting NS (Neighbor Solicitation) data packet; judging whether a source address of the data packet is an unspecified address or not; if the source address of the data packet is the unspecified address, detecting the IPv6 address in a Target Address field and judging whether a corresponding binding table entry exists or not; if the source address of the data packet is not the unspecified address, collecting other related information corresponding to the IPv6 address to establish a binding table entry; and establishing a transfer and control policy of data traffic according to the data of the binding table entry, and applying the policy to the transfer and the control of the data traffic. The invention solves the problem that the address is deceptively attached in an IPv6 network carrying out the address allocation based on various address allocation mechanisms.

Description

technical field [0001] The invention relates to the field of network communication security, in particular, a device and method for preventing addresses from being spoofed in an IPv6 (Internet Protocol version 6) network. Background technique [0002] The rapid development of the Internet and the rapid expansion of its scale have caused the existing IPv4 (Internet Protocol version 4) to face many problems in terms of scalability, such as a serious shortage of address space, which is gradually facing exhaustion, etc., which need to be solved urgently. Therefore, some short-term solutions to delay address consumption are being implemented, and some long-term solutions such as IPv6 technology are gradually being developed. [0003] With the gradual deployment and commercialization of IPv6 networks, in some fields and application scenarios, such as broadband access networks, data backbone networks, and telecommunications service bearer networks, IPv6 also exposes many security i...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Applications(China)
IPC IPC(8): H04L29/06H04L9/26H04L12/56
CPCH04L69/16H04L69/167H04L63/0236H04L69/22H04L63/1441H04L61/5007H04L2101/659
Inventor 秦超袁立权
Owner ZTE CORP