A message encryption and decryption method of IP packets

By generating an initialization vector for encryption/decryption in the IP packet header and using a stream encryption algorithm to encrypt and decrypt IP packet data, the complexity and network performance issues caused by IPSEC packet splitting are resolved, achieving efficient encryption and decryption processing.

CN116260579BActive Publication Date: 2026-06-26BEIJING JN TASS TECH

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIJING JN TASS TECH
Filing Date
2023-03-08
Publication Date
2026-06-26

AI Technical Summary

Technical Problem

The existing IPsec packet encryption and decryption process is complex, leading to increased network traffic, reduced network utilization, and increased network latency, especially when the IP packet length exceeds the MTU limit, requiring packet splitting and merging.

Method used

A stream encryption algorithm is adopted, which uses the field content of the IP packet header to generate an initial encryption/decryption vector. Only the IP packet data/payload is encrypted/decrypted, keeping the IP packet header unchanged. The key stream data segment generated by the stream encryption algorithm is then used for encryption and decryption.

Benefits of technology

It simplifies the encryption and decryption process, avoids packet splitting and repackaging, improves encryption and decryption speed, reduces processing latency, and maintains the normal operation of the network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116260579B_ABST
    Figure CN116260579B_ABST
Patent Text Reader

Abstract

The application provides a message encryption and decryption method of an IP packet, which comprises the following steps: obtaining a plaintext IP packet, and extracting an IP packet header and plaintext data / payload from the plaintext IP packet; obtaining an encryption initial vector, position information of the plaintext IP packet in an upper layer packet and length information of the plaintext data / payload according to field content in the IP packet header; obtaining a key stream data segment corresponding to the position information according to the encryption initial vector, the position information, the length information and a pre-agreed key, wherein the length of the key stream data segment is equal to the length of the plaintext data / payload of the plaintext IP packet; performing data encryption operation on the plaintext data / payload according to the key stream data segment to generate ciphertext data / payload; and combining and packaging the IP packet header and the ciphertext data / payload to generate a ciphertext IP packet. The application avoids disassembling, assembling, re-packaging and the like of the original text data packet, improves the encryption and decryption speed, and reduces the processing delay.
Need to check novelty before this filing date? Find Prior Art

Citation Information

Patent Citations

  • Content data, transmitter apparatus, receiver apparatus and decrypting method

    CN101479985A

  • Encryption method and device, decryption method and device, electronic equipment and storage medium

    CN110995411A

Cited By

  • Method for verifying integrity of ethernet data packet

    CN116781394B