IPV6-based service packet forwarding method and device and computer equipment

By using an IPv6-based service packet forwarding method and leveraging IPv6 tunnel encapsulation and SRv6 technology, the limitations of the traditional PPPoE protocol in crossing three-layer networks are resolved. This enables remote dial-up authentication and refined management of service flows, simplifies network deployment, and improves operational efficiency and service quality assurance.

CN122179138APending Publication Date: 2026-06-09CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER
Filing Date
2026-01-26
Publication Date
2026-06-09

AI Technical Summary

Technical Problem

The traditional PPPoE protocol requires the client and server to be on the same Ethernet network, which limits applications that cross three layers of the network, leads to complex deployment of two-layer tunneling technology and the risk of broadcast storms, and increases network resource consumption.

Method used

A service packet forwarding method based on IPv6 is adopted, which encapsulates PPPoE request packets through IPv6 tunnels and uses SRv6 technology to achieve fine-grained management of service flows. This includes establishing a mapping relationship between service types and segment identifiers on the client side, using network configuration information issued by a centralized management and control system, and using IPv6 tunnel access addresses and segment identifier lists to achieve remote dial-up authentication and fine-grained management of service flows.

Benefits of technology

It enables remote dial-up authentication for clients on IP layer networks, avoiding the complex configuration and broadcast storm risks of large Layer 2 networks, simplifying network deployment and maintenance, improving the efficiency and convenience of separating the network control plane and forwarding plane, and achieving refined management of user services and differentiated quality of service assurance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122179138A_ABST
    Figure CN122179138A_ABST
Patent Text Reader

Abstract

This application relates to a service packet forwarding method, apparatus, and computer device based on IPv6. The method includes: initiating authentication with a management system; upon successful authentication, receiving network configuration information issued by the management system; establishing a mapping relationship between service types and segment identifiers locally based on a segment identifier list; generating a PPPoE request packet containing user authentication information; forming a PPPoEov6 dial-up packet using the local IPv6 tunnel source address and IPv6 tunnel access address, and sending the PPPoEov6 dial-up packet to the remote PPPoE server; and forwarding the PPPoEov6 dial-up packet by the remote PPPoE server according to the destination IPv6 tunnel SID. This method enables the PPPoE protocol to support Layer 3 networking based on IPv6, achieving flexible and efficient remote dial-up authentication.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network communication technology, and in particular to a service message forwarding method, apparatus, computer equipment, computer-readable storage medium, and computer program product based on IPv6. Background Technology

[0002] PPPoE (Point-to-Point Protocol over Ethernet) is a widely used authentication technology in broadband access, but it has the following main limitations:

[0003] Traditional PPPoE requires the client and server to be within the same Ethernet network (Layer 2 network) to achieve broadcast-based discovery and authentication. This limits its application across Layer 3 networks. In actual operator networks, to achieve cross-regional access, it is often necessary to construct large Layer 2 networks using complex Layer 2 tunneling technology, resulting in cumbersome configuration and vulnerability to security risks such as broadcast storms. Furthermore, existing PPPoE interactions rely on a separate control plane channel for additional negotiation, increasing protocol overhead and network resource consumption. With the widespread adoption of IPv6 and SRv6 technologies, networks now possess the capability for programmable forwarding based on Layer 3.

[0004] Therefore, there is an urgent need for a service packet forwarding method, device, computer equipment, computer-readable storage medium, and computer program product based on IPv6, so that the PPPoE protocol can support IPv6-based three-layer networking to achieve flexible and efficient remote dial-up authentication, and utilize technologies such as SRv6 to achieve refined management of service flows. Summary of the Invention

[0005] Based on this, it is necessary to provide a service packet forwarding method, device, computer equipment, computer-readable storage medium, and computer program product that enables the PPPoE protocol to support IPv6-based Layer 3 networking, thereby achieving flexible and efficient remote dial-up authentication, and utilizing technologies such as SRv6 to achieve fine-grained management of service flows.

[0006] Firstly, this application provides a service packet forwarding method based on IPv6, including:

[0007] Initiate authentication to the management and control system, and after successful authentication, receive network configuration information issued by the management and control system. The network configuration information includes at least the IPv6 tunnel access address of the remote PPPoE server and a list of segment identifiers associated with different service types.

[0008] Based on the segment identifier list, a mapping relationship between service types and segment identifiers is established locally;

[0009] Generate a PPPoE request message containing user authentication information;

[0010] Using the local IPv6 tunnel source address and the IPv6 tunnel access address, a PPPoEov6 dial-up message is formed and sent to the remote PPPoE server.

[0011] The remote PPPoE server forwards the PPPoEov6 dial-up packets according to the destination IPv6 tunnel SID.

[0012] In one embodiment, before performing IPv6 tunnel encapsulation on the PPPoE request message using the local IPv6 tunnel source address and the IPv6 tunnel access address, the method further includes:

[0013] Obtain the IPv6 tunnel address prefix from the IPv6 access gateway of the local connection;

[0014] Receive tunnel address suffix configuration information issued by the control system;

[0015] The local IPv6 tunnel source address is generated by combining the IPv6 tunnel address prefix with the suffix portion indicated in the tunnel address suffix configuration information.

[0016] In one embodiment, the step of initiating authentication with the management and control system and receiving network configuration information issued by the management and control system after successful authentication includes:

[0017] Initiate a management authentication request to the control system;

[0018] After management authentication is passed, the system receives secondary dialing enable parameters issued by the control system.

[0019] The generation of the PPPoE request message containing user authentication information is triggered based on the user's input account information and password information, provided that the secondary dialing enable parameter is valid.

[0020] In one embodiment, the forwarding of the PPPoEov6 dial-up message by the remote PPPoE server based on the destination IPv6 tunnel SID includes:

[0021] The remote PPPoE server forwards the PPPoEov6 dial-up packets according to the destination IPv6 tunnel SID and a forwarding policy for different target segment identifiers; wherein the forwarding policy includes:

[0022] The remote PPPoE server is instructed to forward the decapsulated service data based on the routing table, based on a specific L3VPN tunnel, or through a specified Layer 3 network interface.

[0023] In one embodiment, the step of using the target segment identifier as the IPv6 tunnel destination address to encapsulate the service data and generate a PPPoEov6 service packet includes:

[0024] Construct an IPv6 tunnel header, setting the local IPv6 tunnel source address as the source address field of the IPv6 tunnel header, and setting the target segment identifier as the destination address field of the IPv6 tunnel header;

[0025] Based on the established PPPoE session, add a PPPoE session header to the service data;

[0026] The service data with the PPPoE session header added is encapsulated as the payload after the IPv6 tunnel header to form the PPPoEov6 service packet.

[0027] In one embodiment, after the remote PPPoE server forwards the PPPoEov6 dial-up message according to the destination IPv6 tunnel SID, the method further includes:

[0028] If a session termination condition is detected, a PPPoE session termination request message is generated.

[0029] The PPPoE session termination request message is encapsulated with IPv6 tunnel to form a PPPoEov6 termination message and sent.

[0030] Upon receiving a session termination confirmation from the remote PPPoE server, the service IP address and related PPPoE session resources are released.

[0031] Secondly, this application also provides an IPv6-based service packet forwarding device, comprising:

[0032] The initiation module is used to initiate authentication to the management and control system, and after successful authentication, receive network configuration information issued by the management and control system. The network configuration information includes at least the IPv6 tunnel access address of the remote PPPoE server and a list of segment identifiers associated with different service types.

[0033] The processing module is used to establish a mapping relationship between service types and segment identifiers locally based on the segment identifier list;

[0034] The processing module is also used to generate PPPoE request messages containing user authentication information;

[0035] The processing module is also used to form a PPPoEov6 dialing message using the local IPv6 tunnel source address and the IPv6 tunnel access address, and send the PPPoEov6 dialing message to the remote PPPoE server.

[0036] The forwarding module is used to forward the PPPoEov6 dialing packets through the remote PPPoE server according to the destination IPv6 tunnel SID.

[0037] Thirdly, this application also provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to perform the following steps:

[0038] Initiate authentication to the management and control system, and after successful authentication, receive network configuration information issued by the management and control system. The network configuration information includes at least the IPv6 tunnel access address of the remote PPPoE server and a list of segment identifiers associated with different service types.

[0039] Based on the segment identifier list, a mapping relationship between service types and segment identifiers is established locally;

[0040] Generate a PPPoE request message containing user authentication information;

[0041] Using the local IPv6 tunnel source address and the IPv6 tunnel access address, a PPPoEov6 dial-up message is formed and sent to the remote PPPoE server.

[0042] The remote PPPoE server forwards the PPPoEov6 dial-up packets according to the destination IPv6 tunnel SID.

[0043] Fourthly, this application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, performs the following steps:

[0044] Initiate authentication to the management and control system, and after successful authentication, receive network configuration information issued by the management and control system. The network configuration information includes at least the IPv6 tunnel access address of the remote PPPoE server and a list of segment identifiers associated with different service types.

[0045] Based on the segment identifier list, a mapping relationship between service types and segment identifiers is established locally;

[0046] Generate a PPPoE request message containing user authentication information;

[0047] Using the local IPv6 tunnel source address and the IPv6 tunnel access address, a PPPoEov6 dial-up message is formed and sent to the remote PPPoE server.

[0048] The remote PPPoE server forwards the PPPoEov6 dial-up packets according to the destination IPv6 tunnel SID.

[0049] Fifthly, this application also provides a computer program product, including a computer program that, when executed by a processor, performs the following steps:

[0050] Initiate authentication to the management and control system, and after successful authentication, receive network configuration information issued by the management and control system. The network configuration information includes at least the IPv6 tunnel access address of the remote PPPoE server and a list of segment identifiers associated with different service types.

[0051] Based on the segment identifier list, a mapping relationship between service types and segment identifiers is established locally;

[0052] Generate a PPPoE request message containing user authentication information;

[0053] Using the local IPv6 tunnel source address and the IPv6 tunnel access address, a PPPoEov6 dial-up message is formed and sent to the remote PPPoE server.

[0054] The remote PPPoE server forwards the PPPoEov6 dial-up packets according to the destination IPv6 tunnel SID.

[0055] The aforementioned IPv6-based service packet forwarding method, apparatus, computer equipment, computer-readable storage medium, and computer program products, by constructing a PPPoEov6 architecture based on IPv6 tunnels and introducing a centralized management and control system, can overcome the dependence of traditional PPPoE protocols on Layer 2 networking. This enables clients to remotely dial and authenticate at the IP layer network, thus avoiding the complex configurations and Layer 2 broadcast storm risks associated with deploying large Layer 2 networks, significantly simplifying network deployment and maintenance complexity. Simultaneously, by centrally distributing tunnel configurations, segment identifiers, and service policies to both clients and servers through the management and control system, effective separation of the network control plane and forwarding plane can be achieved, improving the efficiency and convenience of centralized management and unified policy distribution for large-scale PPPoE devices. Furthermore, by mapping and binding SRv6 segment identifiers to different service types or quality of service requirements, clients can select the corresponding segment identifier for encapsulation based on the service type during data transmission, thereby guiding the network to execute differentiated forwarding and processing strategies for user service traffic. Ultimately, this achieves refined management of user services and differentiated quality of service assurance. Attached Figure Description

[0056] To more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the drawings used in the description of the embodiments of this application or related technologies will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0057] Figure 1 This is a flowchart illustrating a service packet forwarding method based on IPv6 in one embodiment;

[0058] Figure 2 This is a flowchart illustrating a service packet forwarding method based on IPv6 in another embodiment;

[0059] Figure 3 This is a network architecture diagram of the most detailed embodiment of this application;

[0060] Figure 4 This is a protocol layer interaction diagram of the PPPoEov6 client, server, and IPv6 access gateway in the most detailed embodiment of this application.

[0061] Figure 5 This is a flowchart illustrating the most detailed embodiment of the PPPoE remote dialing implementation based on an IPv6 tunnel in this application.

[0062] Figure 6 This is a structural block diagram of a service packet forwarding device based on IPv6 in one embodiment;

[0063] Figure 7 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation

[0064] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0065] It should be noted that the terms "first," "second," etc., used in this application can be used to describe various elements, but these elements are not limited by these terms. These terms are only used to distinguish the first element from the second element. The terms "comprising" and "having," and any variations thereof, used in this application, are intended to cover non-exclusive inclusion. The term "multiple" used in this application refers to two or more. The term "and / or" used in this application refers to one of the embodiments, or any combination of multiple embodiments.

[0066] In one exemplary embodiment, such as Figure 1 As shown, a service packet forwarding method based on IPv6 is provided. This method is applied to a PPPoE client for illustration, including the following steps S102 to S110. Wherein:

[0067] Step S102: Initiate authentication with the management and control system, and after successful authentication, receive network configuration information issued by the management and control system. The network configuration information includes at least the IPv6 tunnel access address of the remote PPPoE server and a list of segment identifiers associated with different service types.

[0068] Specifically, when a client first goes online or needs to update its configuration, it proactively initiates an authentication request to the management interface address known to the management system. This request should at least include device information that uniquely identifies the client, such as a device serial number, pre-shared key, or digital certificate. Once the management system verifies the validity of this information, it determines that the management authentication is successful. This authentication process is independent of subsequent PPPoE service authentication based on user account and password, aiming to ensure that only trusted and managed devices can obtain network configurations from the management system, thereby achieving centralized management of secure access and control at the device level.

[0069] After successful authentication, the management and control system generates and sends the necessary network configuration information for remote PPPoE dialing and subsequent service transmission, based on the network planning strategy and the client's service subscription attributes. This network configuration information is a collection of key parameters. Among them, the IPv6 tunnel access address of the remote PPPoE server is the logical interface address of the PPPoE server used by the client on the WAN side to locate and establish the IPv6 tunnel connection. During the subsequent dialing phase, the client will use this address as the destination address for IPv6 tunnel encapsulation, ensuring that its PPPoE OV6 dialing packets can traverse the three layers of the IP network and be accurately routed to the designated remote server—this is the foundation for remote dialing. The list of segment identifiers associated with different service types refers to SRv6 (Segment Routing over IPv6) segment identifiers. Based on the operator's service policies, the management and control system predefines a series of SIDs. Each SID is not only an IPv6 address but also encodes specific network processing instructions (such as forwarding to a specific service anchor point, applying specific quality of service policies, etc.).

[0070] Step S104: Based on the segment identifier list, establish a mapping relationship between service types and segment identifiers locally.

[0071] Specifically, after parsing and verifying the received list of segment identifiers, the client performs the action of establishing a mapping relationship. In software implementation, this is manifested as creating and maintaining a data structure, such as a "business type-segment identifier mapping table," in the client device's local storage area (e.g., a policy table in memory). Each row (or entry) of this table stores a pair of related information obtained from the list of segment identifiers, thereby binding the abstract business type with a specific, routable segment identifier.

[0072] Once the local mapping relationship is established, when a client generates or forwards user service data, it needs to determine the service type based on the characteristics of the data packet (such as the application type identified by Deep Packet Inspection (DPI) or the Differential Service Code Point (DSCP) value in the IP header of the data packet). Once the service type is determined, the client queries this local mapping table to quickly and accurately obtain the corresponding destination segment identifier used to encapsulate the outer IPv6 tunnel header.

[0073] Step S106: Generate a PPPoE request message containing user authentication information.

[0074] Specifically, this is based on user-initiated actions (such as clicking the broadband connection) or the device's automatic reconnection mechanism. Its core input information is user authentication information, which includes: Username: A string assigned by the operator to uniquely identify the user. Password: The credential used to verify identity corresponding to the username. Optional authentication protocol indication: Specifies the PPP authentication protocol to be used, such as PAP (Password Authentication Protocol), CHAP (Challenge-Handshake Authentication Protocol), or the more secure EAP (Extensible Authentication Protocol), etc.

[0075] Step S108: Using the local IPv6 tunnel source address and IPv6 tunnel access address, a PPPoEov6 dial-up message is formed and sent to the remote PPPoE server to establish a PPPoE session.

[0076] Specifically, after generating a standard PPPoE request message (containing an Ethernet header, a PPPoE header, and PPP authentication information), the client uses it as the payload data. Subsequently, the client's protocol stack adds a new IPv6 header. The source address field of this header is set to the client's local IPv6 tunnel source address, and the destination address field is set to the IPv6 tunnel access address of the remote PPPoE server issued by the management system. The resulting message is the PPPoEov6 dial-up message. This message converts the original Layer 2 PPPoE frame, which is based on Ethernet MAC address addressing, into a Layer 3 data packet based on IPv6 address addressing, enabling it to be transmitted remotely through the routing network.

[0077] The client sends the aforementioned PPPoE OV6 dial-up message, which is routed to the remote PPPoE server via the IP network. The server decapsulates the outer IPv6 header to obtain the original PPPoE request message and executes the standard PPPoE session negotiation and user authentication process accordingly. The client and server ultimately establish a PPPoE session by exchanging PPPoE messages carried within the IPv6 tunnel (including discovery messages such as PADI / PADO / PADR / PADS, and subsequent LCP, authentication, and NCP messages).

[0078] After a PPPoE session is successfully established, during the NCP negotiation phase (e.g., via IPCP), the remote PPPoE server or its associated DHCP server will assign an inner IP address (IPv4 or IPv6) to the client for service communication, i.e., the service IP address. Once the client obtains this address, it means it has successfully accessed the service network and is qualified to transmit user data over the established PPPoE session.

[0079] Specifically, when a client application layer generates or receives business data that needs to be forwarded, the client (usually at its data plane or policy enforcement point) needs to classify the business data. This is achieved by parsing specific attributes of the data packets. Based on the classification strategy, the client maps the data packets to a defined business type, such as high-definition video, voice calls, ordinary internet access, low-latency gaming, or IoT data.

[0080] Based on the service type determined in the previous step, the client queries its locally maintained service type-segment identifier mapping table. Through the query, the client obtains the target segment identifier (Target SID) uniquely corresponding to that service type. This segment identifier is a specific IPv6 address that encodes the network's instructions for handling this type of service traffic, such as: directing traffic to a specified service anchor (e.g., a video optimization server), applying a specific Quality of Service (QoS) policy, or entering a Service Function Chain (SFC).

[0081] After obtaining the target segment identifier, the client performs an encapsulation operation to generate the final PPPoEov6 service message, including:

[0082] Outer IPv6 tunnel encapsulation: Construct a new IPv6 header with the source address being the client's local IPv6 tunnel source address and the destination address being set to the target segment identifier obtained in the previous step. The destination address carries forwarding instructions.

[0083] Inner PPPoE and Session Encapsulation: The original business data is used as the payload, and based on the established PPPoE session, the corresponding PPPoE session header is added. This header contains information such as the session ID, which identifies which specific user session the data belongs to.

[0084] The inner data with the PPPoE header added is used as the payload and encapsulated after the IPv6 header to form a complete PPPoEov6 service message.

[0085] Step S110: The remote PPPoE server forwards the PPPoEov6 dial-up packets according to the destination IPv6 tunnel SID.

[0086] The forwarding of PPPoEov6 dial-up packets by the remote PPPoE server based on the destination IPv6 tunnel SID includes: forwarding PPPoEov6 dial-up packets by the remote PPPoE server based on the destination IPv6 tunnel SID and a forwarding strategy for different target segment identifiers; wherein the forwarding strategy includes: guiding the remote PPPoE server to forward the decapsulated service data based on the routing table, L3VPN tunnel and / or through a specified Layer 3 network interface.

[0087] Specifically, after receiving a PPPoEov6 service packet, the PPPoEov6 server decapsulates the IPv6 tunnel header and PPPoE header, and records the binding information (inner service IP, service type, PPPoE session information, and client tunnel source SID). Then, based on the destination IPv6 tunnel SID, it performs a forwarding decision on the PPPoEov6 service packet. The specific forwarding decision includes:

[0088] (1)END.DPPPoET46 SID: Remove the IPv6 tunnel header, PPPoE header, and PPP header, and forward the decrypted service IPv4 / IPv6 packets according to the routing table;

[0089] (2) End.DX3PPPoE SID: Remove the IPv6 tunnel header, PPPoE header, and PPP header, and forward the unblocked service IPv4 / IPv6 packets to the L3 VPN tunnel according to the binding relationship between the PPPoE session information and the VPN.

[0090] (3) End.DPPPoE.X SID: Strip the IPv6 tunnel header, PPPoE header, and PPP header, and forward the unsealed service IPv4 / IPv6 packets to a specific next hop according to the binding relationship between the destination SID and the Layer 3 interface;

[0091] The binding relationship between PPPoE session information and VPN, including the corresponding VPN tunnel source and destination addresses, as well as the binding relationship between the destination SID and the Layer 3 interface, is issued to the PPPoE server by the management and control system. This method enables business packets to be forwarded to the corresponding VPN tunnel or business channel.

[0092] Subsequently, the client sends the encapsulated PPPoEov6 service packet through its network interface. This packet is routed within the IP network based on its destination address (i.e., the target segment identifier). Upon receiving the packet, SRv6 nodes in the network (such as transport routers or servers) parse the segment identifier and execute the encoded operations, thereby achieving differentiated processing of the service flow. In the above IPv6-based service packet forwarding method, by constructing a PPPoEov6 architecture based on IPv6 tunnels and introducing a centralized management and control system, the dependence of the traditional PPPoE protocol on Layer 2 networking can be overcome. This enables remote dial-up authentication and access for clients in the IP layer network, thus avoiding the complex configuration and Layer 2 broadcast storm risks associated with deploying large Layer 2 networks by operators, significantly simplifying network deployment and maintenance complexity. Simultaneously, by uniformly and centrally distributing tunnel configurations, segment identifiers, and service policies to clients and servers through the management and control system, effective separation of the network control plane and forwarding plane can be achieved, improving the efficiency and convenience of centralized management and unified policy distribution for large-scale PPPoE devices. Furthermore, by mapping and binding SRv6 segment identifiers with different service types or quality of service requirements, clients can select the corresponding segment identifier for encapsulation based on the service type during the data transmission phase. This guides the network to implement differentiated forwarding and processing strategies for user service traffic, ultimately achieving refined management of user services and differentiated quality of service assurance.

[0093] In one embodiment, such as Figure 2 As shown, before performing IPv6 tunnel encapsulation on the PPPoE request packet using the local IPv6 tunnel source address and IPv6 tunnel access address, the following steps are also included:

[0094] Step S202: Obtain the IPv6 tunnel address prefix from the IPv6 access gateway of the local connection;

[0095] Step S204: Receive tunnel address suffix configuration information issued by the control system;

[0096] Step S206: Combine the IPv6 tunnel address prefix with the suffix portion indicated in the tunnel address suffix configuration information to generate a local IPv6 tunnel source address.

[0097] Specifically, the client interacts with its directly connected IPv6 access gateway to obtain an IPv6 address prefix. This is typically achieved through standard IPv6 address allocation protocols, such as Stateless Address Autoconfiguration (SLAAC) or Dynamic Host Configuration Protocol version 6 (DHCPv6). This prefix is ​​assigned by the network infrastructure and determines the client's approximate location or routing range within the carrier's IPv6 network.

[0098] The client receives tunnel address suffix configuration information from the management system. This information is a parameter generated by the management system based on network management policies or customer subscription attributes, and it explicitly specifies the suffix portion used to constitute the complete tunnel source address. The suffix can be a fixed interface identifier (such as one generated based on a device ID) or a sequence number dynamically assigned by the management system, used to uniquely distinguish different clients or client sessions under the same prefix.

[0099] The client combines the address prefix obtained from the access gateway with the address suffix issued by the management system according to the IPv6 address format to form a complete 128-bit local IPv6 tunnel source address. Its general format is: [Gateway-assigned prefix]: [Management system-specified suffix].

[0100] For example, the IPv6 access gateway assigns the prefix 2001:db8:1000:: / 60 to the client via DHCPv6-PD (prefix delegation). Simultaneously, the management system sends the suffix configuration information :0:1 to the client. The client then combines these two to generate its local IPv6 tunnel source address: 2001:db8:1000::0:1.

[0101] In this embodiment, by providing and combining the address prefix and suffix respectively from the network infrastructure and the centralized management and control system, flexible, accurate, and centralized management of tunnel addresses is achieved. This ensures that the client tunnel address conforms to the global network routing plan (guaranteed by the prefix) while also reflecting the management and control policies and the client's identity (reflected by the suffix).

[0102] In one embodiment, authentication is initiated with the management and control system, and upon successful authentication, network configuration information is received from the management and control system, including:

[0103] Initiate a management authentication request to the control system;

[0104] After management authentication is passed, receive the secondary dialing enable parameters issued by the control system;

[0105] The generation of a PPPoE request message containing user authentication information is triggered based on the user's input account and password information, provided that the secondary dialing enable parameters are valid.

[0106] Specifically, after the client device starts up, it proactively initiates a management authentication request to the pre-configured or discovered management interface of the control system. This aims to verify the legitimacy of the client device itself, such as whether it is a terminal authorized by the operator to access the network. Authentication credentials are typically based on device hardware information, such as the device serial number, a pre-installed digital certificate, or a pre-shared key. This process ensures that only legitimate, managed, and tamper-proof devices can establish a trust relationship with the control system and receive network configurations.

[0107] After management authentication is passed, the control system determines that the device is qualified to be managed. At this point, the control system decides whether to allow the device to initiate PPPoE dialing for user services based on the device's subscription status or operator policy. This decision is communicated to the client by sending a secondary dialing enable parameter. This parameter is a control identifier, and its state (such as enabled / True or disabled / False) directly determines whether the client is authorized to perform subsequent user dialing operations.

[0108] The user-layer service authentication action of generating a PPPoE request message containing user authentication information is configured to require a prerequisite: the client's local secondary dialing enable parameter must be in a valid state (e.g., its value is enabled). Only when this condition is met will the client software (such as a dialer) respond to the user's connection operation, prompting the user to enter or read the saved personal account information (e.g., user@example.com) and password information, and using this to generate a standard PPPoE authentication request message. If this parameter is invalid or disabled, even if the device has passed management authentication, the client will refuse to initiate the user dialing process, thereby implementing access control at the service layer.

[0109] In this embodiment, device-level management authentication ensures that the network infrastructure only opens configuration channels to trusted devices, preventing unauthorized terminal access. Secondly, through secondary dialing enable parameters, operators can centrally control the service access permissions of specific devices or user groups on the management and control system side (e.g., shutting down services for users who have arrears, whose policies have changed, or who are under testing), achieving decoupling of the control plane and service plane and flexible policy distribution, thus improving the automation and security of network operation.

[0110] In one embodiment, determining the business type based on the attributes of the business data includes:

[0111] Based on the quintuple information or differential service code point field, business data is classified and judged so as to map the business data to the corresponding business type;

[0112] The five-tuple information includes the source IP address, destination IP address, transport layer protocol type, source port number, and destination port number of the business data.

[0113] Specifically, source IP address and destination IP address identify the initiator and target of the communication. A specific range of server addresses (such as a video CDN address range) can be directly associated with a type of service.

[0114] Transport layer protocol types: such as TCP, UDP, or ICMP. Different protocols often correspond to different types of services (e.g., TCP is often used for web browsing, and UDP is often used for streaming media).

[0115] Source and destination port numbers: These identify the specific application process on the host. Well-known port numbers (such as 80 for HTTP, 443 for HTTPS, and 5060 for SIP) are direct clues for identifying the application type.

[0116] Differential Service Code Point (DSCP) field: This field is located in the IP header (ToS field in IPv4 or TrafficClass field in IPv6) and is used to mark the priority or service class of a data packet. Upstream network devices or the client itself can pre-set DSCP values ​​for data packets according to policies (e.g., EF for low-latency voice, AF41 for video), and the client can directly read this value as a classification basis.

[0117] The client maintains a set of classification policy rules predefined or issued by the management system. This rule set contains a series of condition-action rules, where the condition part is defined based on the aforementioned 5-tuple or DSCP.

[0118] Judgment process: When a business data packet arrives at the classification point, the client extracts its quintuple and DSCP value, and matches them sequentially with the conditions in the rule set.

[0119] Mapping Output: Upon matching a rule, the corresponding action is executed, mapping the data packet to the corresponding service type. For example, one rule can be defined as: if the destination IP address belongs to the video server network segment and the protocol is UDP, then it is mapped to the service type VIDEO_STREAM. Another rule can be defined as: if the DSCP field value is EF(46), then it is mapped to the service type LOW_LATENCY_VOICE.

[0120] For example, suppose a data packet has the following attributes: Destination IP=203.0.113.10 (video server), Protocol=UDP, Destination Port=5000. The client matches the data according to the rule set and classifies it as a video service. Subsequently, the client queries its local mapping table and finds that the video service corresponds to SID2001:db8::100, so it uses this SID as the destination address for IPv6 tunneling.

[0121] In this embodiment, the network layer information carried by the data packets themselves is utilized, avoiding the performance overhead and privacy concerns that may arise from complex deep packet inspection (DPI), while ensuring real-time classification. By combining the five-tuple / DSCP with the policies issued by the management and control system, centralized definition and dynamic adjustment of traffic classification standards for network control are achieved, providing a reliable prerequisite for ultimately realizing refined business management based on SID.

[0122] In one embodiment, the target segment identifier is used as the IPv6 tunnel destination address to encapsulate the service data and generate a PPPoEov6 service packet, including:

[0123] Construct the IPv6 tunnel header, set the local IPv6 tunnel source address as the source address field of the IPv6 tunnel header, and set the destination segment identifier as the destination address field of the IPv6 tunnel header;

[0124] Based on the established PPPoE session, add PPPoE session headers to the business data;

[0125] The service data with the PPPoE session header added is encapsulated as the payload after the IPv6 tunnel header to form a PPPoEov6 service packet.

[0126] Specifically, the client first creates a new IPv6 tunnel header, which will serve as the outermost layer of the packet for routing and forwarding within the Layer 3 IP network. The IPv6 header includes two key fields:

[0127] The source address field is set to the client's local IPv6 tunnel source address, which is the client's logical identifier in the operator's IPv6 network and is used to identify the origin of the traffic.

[0128] The destination address field is set to the destination segment identifier, which is not a regular terminal IPv6 address, but an SRv6 segment identifier (SID). Internally, it encodes specific operational instructions that the network needs to perform on this packet. Placing it in the IPv6 destination address field means that the packet will follow the SRv6 forwarding mechanism: routers in the network (that support SRv6), after reading this destination address, will parse and execute the embedded instructions, rather than simply routing it to the final destination. This allows the network to perform differentiated forwarding based on the service type (mapped to the SID), such as directing to specific service nodes or applying quality of service policies.

[0129] The client sends the raw service data as the payload. Then, based on the PPPoE session successfully established during the previous dialing phase, a PPPoE session header is added to this service data. This header contains crucial information such as the session ID.

[0130] Finally, the service data with the PPPoE session header added (i.e., data in PPP frame format) is placed as a single data block after the previously constructed IPv6 tunnel header as its payload. The resulting complete data structure is the PPPoEov6 service message. Its hierarchical structure from the inside out is as follows: [Original Service Data] -> [PPPoE Session Header] -> [IPv6 Header (including SRv6 SID)].

[0131] In this embodiment, a layered encapsulation mechanism couples user service data (payload), user session management (PPPoE header), and service-based network programmable forwarding policies (SRv6 SID as IPv6 destination address) into a single packet. This enables the network to identify user sessions for billing and management during hop-by-hop forwarding, and to perform fine-grained service path guidance and quality of service assurance based on the SID. Ultimately, this achieves intelligent, differentiated, and programmable transport of traditional PPPoE service flows on the IP layer network.

[0132] In one embodiment, after the remote PPPoE server forwards the PPPoEov6 dial-up message according to the destination IPv6 tunnel SID, the method further includes:

[0133] If a session termination condition is detected, a PPPoE session termination request message is generated.

[0134] The PPPoE session termination request message is encapsulated with IPv6 tunnel to form a PPPoEov6 termination message and then sent.

[0135] After receiving a session termination confirmation message from the remote PPPoE server, release the business IP address and related PPPoE session resources.

[0136] Specifically, the client continuously monitors the session status. When a session termination condition is detected, a termination process is triggered. Session termination conditions typically include: User-initiated disconnection: The user manually clicks to disconnect via the client interface. Management command trigger: A forced offline or re-authentication command is received from the management system. Local anomaly or timeout: An anomaly is detected in the local network interface, the system is hibernating / shutting down, or the session's continuous idle time exceeds a preset threshold. Authentication or billing failure: The backend detects that the user account is in arrears, authentication has expired, or billing policy has changed.

[0137] Once the conditions are met, the client protocol stack constructs a PPPoE session termination request message according to the PPPoE protocol standard (RFC 2516). This message is an Active Termination (PADT) message at the PPPoE layer, with its PPPoE header's Code field set to 0xa7 and containing the currently active session ID to indicate the specific session to be terminated. To ensure this termination request reaches the remote server through the Layer 3 network, the client uses the same encapsulation logic as when sending service data packets: it uses the standard PPPoE termination request message as the payload; its local IPv6 tunnel source address as the source address of the outer IPv6 header; and the remote PPPoE server's IPv6 tunnel access address (or a specific management SID agreed upon with the server) as the destination address of the outer IPv6 header. IPv6 tunnel encapsulation is then performed to form a PPPoEov6 termination message, which is then sent over the IP network.

[0138] After sending a termination request, the client waits for confirmation from the server. Upon receiving the termination message, the server processes the request and sends back a PPPoE session termination confirmation message (usually encapsulated within an IPv6 tunnel). After receiving the session termination confirmation from the remote PPPoE server, the client performs critical resource cleanup tasks:

[0139] Release service IP addresses: Remove the IPv4 or IPv6 service addresses previously negotiated via PPPoE from the local interface, or mark them as reusable. Release related PPPoE session resources: Clear all locally maintained data structures related to this session, including but not limited to session ID, PPP link status, NCP negotiation information, and various timers and buffers established to ensure the session. If no confirmation is received from the server within a certain period of time, the client can attempt to resend the termination request or perform forced local cleanup.

[0140] In this embodiment, a session termination mechanism provides complete, reliable, and standards-compliant session lifecycle management. This enables the graceful and controllable teardown of remote PPPoE sessions based on IPv6 tunnels, timely reclaiming network addresses and system resources to prevent resource leaks. Simultaneously, standard signaling interaction ensures consistency between client and server states, creating a clean environment for establishing new sessions and guaranteeing the long-term stability and efficiency of the entire system.

[0141] This application provides a detailed embodiment of PPPoE remote dialing and service management based on an IPv6 tunnel. The network architecture involved in this embodiment mainly includes four core components: a PPPoE OV6 client, an IPv6 access gateway, a PPPoE OV6 server, and a centralized management and control system, such as... Figure 3As shown in the diagram. The PPPoEov6 client is an upgraded version of the traditional PPPoE client, capable of encapsulating PPPoE packets through IPv6 tunnels. The IPv6 access gateway, acting as the next-hop device for the client in the network access, is responsible for providing the IPv6 tunnel underlay path and allocating IPv6 tunnel address prefixes to the client. The PPPoEov6 server is an enhanced PPPoE server that supports not only traditional user authentication and address allocation but also SRv6 (Segment Routing over IPv6) policy processing. The management and control system, as the control plane hub, is responsible for unified configuration distribution and policy management for both the client and server.

[0142] The complete process can be divided into four main stages: prefix address acquisition stage, suffix address acquisition and configuration distribution stage, secondary dialing and service authentication stage, and data transmission and session management stage.

[0143] In the first phase, the prefix address acquisition phase, after the PPPoEov6 client starts up, it first obtains an IPv6 address prefix from the IPv6 access gateway directly connected to it, either through static configuration or dynamic request (e.g., using the DHCPv6 protocol). This prefix is ​​used to identify the approximate routing location of the client within the carrier's IPv6 network. The access gateway responds to this request and assigns it a globally unique IPv6 prefix.

[0144] The second phase is the suffix address acquisition and configuration distribution phase. After obtaining the prefix, the client proactively initiates a device-level management authentication request to the management system using its management address. This request carries the client's device identification information (such as device serial number or certificate). After the management system verifies that the device is a legitimate managed device, authentication is successful. Subsequently, the management system generates and distributes a series of network configuration parameters to the client based on the client's subscription attributes and operator policies. These parameters are collectively referred to as the first configuration information. This information includes at least: an IPv6 address suffix portion used to assemble the complete tunnel source address, the IPv6 tunnel access address of the remote PPPoEov6 server, a secondary dialing enable parameter, and a first segment identifier list. The first segment identifier list defines the SRv6 segment identifiers (SIDs) associated with different service types (e.g., low-latency applications, high-bandwidth applications, VPN applications). After receiving this information, the client combines the IPv6 address prefix previously obtained from the access gateway with the suffix portion issued by the management system to generate a complete local IPv6 tunnel source address (e.g., a prefix of 2001:db8:1000:: / 60 and a suffix of :0:1, resulting in 2001:db8:1000::0:1). Simultaneously, the client parses the first segment of the identifier list and establishes and maintains a service type-SID mapping table locally. While issuing configurations to the client, the management system also issues corresponding policy configurations to the PPPoEov6 server, including the AAA authentication server address and a list defining the mapping relationship between service types and corresponding processing SIDs.

[0145] The third stage is the secondary dialing and service authentication stage. The client checks the secondary dialing enable parameters issued by the management system. If they are valid, it responds to the user's operation, prompting the user to enter their username and password. Subsequently, the client initiates a standard PPPoE dialing process: First, it generates a PPPoE request message containing user authentication information (username and password, encapsulated according to protocols such as PAP or CHAP). Next, the client uses its local IPv6 tunnel source address and the remote server tunnel access address issued by the management system to encapsulate the PPPoE request message with IPv6, forming a PPPoEov6 dialing message, such as... Figure 4As shown in the protocol hierarchy, the original PPPoE frame (including the Ethernet header) is completely encapsulated within a new IPv6 header. The client sends this PPPoEov6 dial-up message, which is routed to the PPPoEov6 server via the IPv6 access gateway and backbone network. The server decapsulates the outer IPv6 header, extracts the inner PPPoE request message, and completes user authentication based on the AAA server address issued by the management system. After successful authentication, the server and client establish a session by exchanging standard PPPoE messages (such as LCP, IPCP / NCP negotiation messages) carried within the IPv6 tunnel, and the server assigns the client an inner IP address (IPv4 or IPv6) for business communication, i.e., the business IP address. At this point, the PPPoE session is successfully established, and the data transmission phase begins.

[0146] The fourth stage is the data transmission and session management stage. When a client needs to send business data, it first determines the service type (e.g., identified as a low-latency application) based on the data packet's attributes (such as 5-tuple information or DSCP field values). Then, the client queries its local service type-SID mapping table to obtain the target SID corresponding to that service type. Figure 3 In the uplink direction, for low-latency applications, the client uses SID A as part of the source tunnel address (or identifier) ​​and SID 1 as the destination tunnel address. During encapsulation, the client constructs a new IPv6 tunnel header, setting its source address field to its own local IPv6 tunnel source address and its destination address field to the target SID obtained earlier. Then, based on the established PPPoE session, a PPPoE session header is added to the original service data, and this data with the added PPPoE header is encapsulated after the aforementioned IPv6 header as the payload, forming a PPPoEov6 service packet and sending it. SRv6 nodes in the network (including the server) perform a preset forwarding action (such as forwarding via a low-latency path) based on the SID in the destination address field of the packet. After receiving the packet, the server decapsulates the IPv6 and PPPoE headers to obtain the service data. Simultaneously, the server records the binding relationship between the inner source IP address, service type, PPPoE session information, and the SID used by the client in the service data. For downlink service data (such as... Figure 3 (As shown in the downlink direction), the server queries the binding relationship based on the destination IP address and service type of the data, obtains the corresponding client SID and PPPoE session information, and uses the corresponding SID as the destination address to encapsulate the IPv6 tunnel header before sending the data back to the client. In this way, traffic of different service types is directed to different logical paths or processing anchors on the network, achieving differentiated services.

[0147] When the session needs to be terminated (e.g.) Figure 5 As shown in the diagram, the client or server generates a standard PPPoE session termination request (PPPoE) message, encapsulates it with IPv6 tunneling, and sends it to the other party. After the other party returns an acknowledgment, both parties release the service IP address, PPPoE session ID, and related network resources, completing the graceful teardown of the session.

[0148] In summary, this embodiment extends traditional Layer 2 PPPoE dialing to a Layer 3 IP network by constructing a PPPoE over IPv6 (PPPoEov6) architecture, enabling remote authentication access for clients. By introducing a management and control system for centralized policy distribution and leveraging the network programmability of SRv6, user service traffic can receive differentiated path selection and network services based on its type. This simplifies network deployment, avoids Layer 2 broadcast storms, and achieves refined management and operational-grade service capabilities for user services.

[0149] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.

[0150] Based on the same inventive concept, this application also provides an IPv6-based service packet forwarding device for implementing the IPv6-based service packet forwarding method described above. The solution provided by this device is similar to the implementation described in the above method. Therefore, the specific limitations in one or more IPv6-based service packet forwarding device embodiments provided below can be found in the limitations of the IPv6-based service packet forwarding method described above, and will not be repeated here.

[0151] In one exemplary embodiment, such as Figure 6 As shown, an IPv6-based service packet forwarding device is provided, comprising:

[0152] The initiating module 604 is used to initiate authentication to the management and control system, and after successful authentication, it receives network configuration information issued by the management and control system. The network configuration information includes at least the IPv6 tunnel access address of the remote PPPoE server and a list of segment identifiers associated with different service types.

[0153] Processing module 606 is used to establish a mapping relationship between service types and segment identifiers locally based on the segment identifier list;

[0154] Processing module 606 is also used to generate a PPPoE request message containing user authentication information;

[0155] The processing module 606 is also used to form a PPPoEov6 dialing message using the local IPv6 tunnel source address and the IPv6 tunnel access address, and send the PPPoEov6 dialing message to the remote PPPoE server.

[0156] The forwarding module 608 is used to forward PPPoEov6 dial-up packets through a remote PPPoE server based on the destination IPv6 tunnel SID.

[0157] In an exemplary embodiment, the acquisition module 602 is used to acquire the IPv6 tunnel address prefix from the locally connected IPv6 access gateway; receive tunnel address suffix configuration information issued by the management and control system; and the processing module 604 is further used to combine the IPv6 tunnel address prefix with the suffix part indicated in the tunnel address suffix configuration information to generate a local IPv6 tunnel source address.

[0158] In an exemplary embodiment, the initiating module 604 is further configured to initiate a management authentication request to the management and control system; the obtaining module 602 is further configured to receive secondary dialing enable parameters issued by the management and control system after the management authentication is passed; wherein, the generation of a PPPoE request message containing user identity authentication information is triggered based on the user's input account information and password information when the secondary dialing enable parameters are valid.

[0159] In an exemplary embodiment, the forwarding module 608 is further configured to forward PPPoEov6 dial-up packets according to the destination IPv6 tunnel SID and forwarding policies for different target segment identifiers via a remote PPPoE server; wherein the forwarding policy includes: guiding the remote PPPoE server to forward the decapsulated service data based on the routing table, based on a specific L3VPN tunnel, or through a specified Layer 3 network interface.

[0160] In an exemplary embodiment, the processing module 606 is further configured to classify and distinguish the service data based on the five-tuple information or the differential service code point field, so as to map the service data to the corresponding service type; wherein, the five-tuple information includes the source IP address, destination IP address, transport layer protocol type, source port number and destination port number of the service data.

[0161] In an exemplary embodiment, the processing module 606 is further configured to construct an IPv6 tunnel header, set the local IPv6 tunnel source address as the source address field of the IPv6 tunnel header, and set the destination segment identifier as the destination address field of the IPv6 tunnel header; add a PPPoE session header to the service data based on the established PPPoE session; and encapsulate the service data with the added PPPoE session header as the payload after the IPv6 tunnel header to form a PPPoEov6 service packet.

[0162] In an exemplary embodiment, the processing module 606 is further configured to generate a PPPoE session termination request message when a session termination condition is detected; encapsulate the PPPoE session termination request message with an IPv6 tunnel to form a PPPoEov6 termination message and send it; and release the service IP address and related PPPoE session resources after receiving session termination confirmation information from a remote PPPoE server.

[0163] The modules in the IPv6-based service packet forwarding device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the memory of a computer device as software, so that the processor can call and execute the corresponding operations of each module.

[0164] In one exemplary embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 7As shown, this computer device includes a processor, memory, input / output interfaces (I / O), and a communication interface. The processor, memory, and I / O interfaces are connected via a system bus, and the communication interface is also connected to the system bus via the I / O interfaces. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and a database. The internal memory provides the environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The database stores service data to be transmitted. The I / O interfaces are used for exchanging information between the processor and external devices. The communication interface is used for communicating with external terminals via a network connection. When executed by the processor, the computer program implements an IPv6-based service packet forwarding method.

[0165] Those skilled in the art will understand that Figure 7 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0166] In one exemplary embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of the method described above.

[0167] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the steps of the above-described method.

[0168] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps of the method described above.

[0169] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of the relevant data must comply with relevant regulations.

[0170] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, artificial intelligence (AI) processors, etc., and are not limited to these.

[0171] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.

[0172] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.

Claims

1. A service packet forwarding method based on IPv6, applied to a PPPoE client, characterized in that, The method includes: Initiate authentication to the management and control system, and after successful authentication, receive network configuration information issued by the management and control system. The network configuration information includes at least the IPv6 tunnel access address of the remote PPPoE server and a list of segment identifiers associated with different service types. Based on the segment identifier list, a mapping relationship between service types and segment identifiers is established locally; Generate a PPPoE request message containing user authentication information; Using the local IPv6 tunnel source address and the IPv6 tunnel access address, a PPPoEov6 dial-up message is formed and sent to the remote PPPoE server. The remote PPPoE server forwards the PPPoEov6 dial-up packets according to the destination IPv6 tunnel SID.

2. The method according to claim 1, characterized in that, Before using the local IPv6 tunnel source address and the IPv6 tunnel access address, the method further includes: Obtain the IPv6 tunnel address prefix from the IPv6 access gateway of the local connection; Receive tunnel address suffix configuration information issued by the control system; The local IPv6 tunnel source address is generated by combining the IPv6 tunnel address prefix with the suffix portion indicated in the tunnel address suffix configuration information.

3. The method according to claim 1, characterized in that, The process of initiating authentication with the management and control system and receiving network configuration information from the management and control system after successful authentication includes: Initiate a management authentication request to the control system; After management authentication is passed, the system receives secondary dialing enable parameters issued by the control system. The generation of the PPPoE request message containing user authentication information is triggered based on the user's input account information and password information, provided that the secondary dialing enable parameter is valid.

4. The method according to claim 1, characterized in that, The forwarding of the PPPoEov6 dial-up packets by the remote PPPoE server based on the destination IPv6 tunnel SID includes: The remote PPPoE server forwards the PPPoEov6 dial-up packets according to the destination IPv6 tunnel SID and a forwarding policy for different target segment identifiers; wherein the forwarding policy includes: The remote PPPoE server is instructed to forward the decapsulated service data based on the routing table, based on a specific L3VPN tunnel, or through a specified Layer 3 network interface.

5. The method according to claim 1, characterized in that, The step of using the target segment identifier as the IPv6 tunnel destination address to encapsulate the service data and generate a PPPoEov6 service packet includes: Construct an IPv6 tunnel header, setting the local IPv6 tunnel source address as the source address field of the IPv6 tunnel header, and setting the target segment identifier as the destination address field of the IPv6 tunnel header; Based on the established PPPoE session, add a PPPoE session header to the service data; The service data with the PPPoE session header added is encapsulated as the payload after the IPv6 tunnel header to form the PPPoEov6 service packet.

6. The method according to claim 1, characterized in that, After the remote PPPoE server forwards the PPPoEov6 dial-up message according to the destination IPv6 tunnel SID, the process further includes: If a session termination condition is detected, a PPPoE session termination request message is generated. The PPPoE session termination request message is encapsulated with IPv6 tunnel to form a PPPoEov6 termination message and sent. Upon receiving a session termination confirmation from the remote PPPoE server, the service IP address and related PPPoE session resources are released.

7. A service packet forwarding device based on IPv6, characterized in that, The device includes: The initiation module is used to initiate authentication to the management and control system, and after successful authentication, receive network configuration information issued by the management and control system. The network configuration information includes at least the IPv6 tunnel access address of the remote PPPoE server and a list of segment identifiers associated with different service types. The processing module is used to establish a mapping relationship between service types and segment identifiers locally based on the segment identifier list; The processing module is also used to generate PPPoE request messages containing user authentication information; The processing module is also used to form a PPPoEov6 dialing message using the local IPv6 tunnel source address and the IPv6 tunnel access address, and send the PPPoEov6 dialing message to the remote PPPoE server. The forwarding module is used to forward the PPPoEov6 dialing packets through the remote PPPoE server according to the destination IPv6 tunnel SID.

8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 6.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.

10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.