一种报文处理方法及装置

By dividing virtual logical instances and configuring segment identifiers in network security devices, the problem of unrecognizable inner packets in SRv6 service chain networking is solved, achieving both security protection and storage space saving.

CN117728978BActive Publication Date: 2026-07-17NEW H3C SECURITY TECH CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
NEW H3C SECURITY TECH CO LTD
Filing Date
2023-11-09
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

In SRv6 service chain networking, network security devices cannot identify and intercept attack traffic or viruses in inner packets, resulting in insufficient security protection.

Method used

By dividing the network security device into multiple virtual logical instances, each instance is configured with a segment identifier. The target virtual logical instance is called based on the outer destination IP address to extract the inner packet from the SRv6 packet, and the corresponding security policy is used for detection and processing.

Benefits of technology

It enables secure identification and protection of inner packets of SRv6 messages, ensuring network security and saving storage space.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117728978B_ABST
    Figure CN117728978B_ABST
Patent Text Reader

Abstract

本申请提供了一种报文处理方法及装置,应用于网络安全设备中,所述网络安全设备包括多个虚拟逻辑实例,且所述网络安全设备配置有与所述多个虚拟逻辑实例分别对应的段标识;则网络安全设备接收SRv6报文;若所述SRv6报文中的外层目的IP地址为目标虚拟逻辑实例对应的段标识,则调用所述目标虚拟逻辑实例,以由所述目标虚拟逻辑实例从所述SRv6报文中提取出内层报文,并利用所述目标虚拟逻辑实例对应的安全策略对所述内层报文进行安全检测处理。由此,实现了对SRv6报文的内层报文地安全识别,达到了安全防护的目的。
Need to check novelty before this filing date? Find Prior Art