Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

25 results about "Ip prefix" patented technology

TLDR: an IP address prefix is the fixed part in a contiguous block of IP address, also know as a subnet. Prefixes are useful to refer to the entire subnet for planning, documentation, and routing purposes. Now for the long answer.

Route selection method and related device

This application discloses a route selection method and a related device. A control entity determines first metric information of a first segment routing (SR) path, generates a first border gateway protocol (BGP) update message including the first metric information, and sends the first BGP update message to an ingress node of the first SR path, where the first metric information represents quality of the first SR path, the first metric information is used for route selection on a plurality of paths, each of the plurality of paths has a same IP prefix of a destination node, and the plurality of paths include the first SR path. According to the method, the control entity can send, to the ingress node of the SR path by using the BGP update message, the metric information that represents the quality of the SR path.
Owner:HUAWEI TECH CO LTD

Advertisement of routing information in network management

ActiveUS12445378B2TransmissionNetwork managementIp prefix
A network management apparatus comprises: an acquisition unit (21) configured to acquires IP prefix information managed in each of one or more subnetworks in a first network as routing information; an aggregation unit (22) configured to generate aggregated IP prefix information which is an aggregation of the IP prefix information managed in each of the one or more subnetworks as aggregated routing information; and an advertising unit (23) configured to advertise the route information and the aggregated routing information to a second network different from the first network.
Owner:RAKUTEN MOBILE INC

Multi-tenant unified storage routing table item compression method and system based on identification mapping

The invention relates to a multi-tenant unified storage routing table item compression method and system based on identification mapping. The method comprises the following steps: in a routing table entry insertion stage, dynamically distributing a minimum available reduce ID for each new tenant, and ensuring that an IP prefix space of the new tenant is not overlapped with a tenant using the same reduce ID; in the lookup stage, a message VNI is firstly converted into a reduce ID through a mapping table realized based on an RAM, then the reduce ID and a destination IP are used as a joint key to look up the TCAM, and by constructing a mapping relation from the VNI to the reduce ID, the table item bit width of the TCAM is remarkably reduced on the premise of ensuring the routing correctness. The method is suitable for an IPv4 / IPv6 multi-tenant environment, the hardware area and power consumption can be effectively reduced especially in an FPGA or ASIC high-performance data plane, and meanwhile the line speed forwarding capacity is kept.
Owner:NAT UNIV OF DEFENSE TECH +1

BGP anomalous route identification method and apparatus, device and medium

PCT designated stageWO2026103459A1TransmissionPathPingInternet traffic
Disclosed in the present application are a BGP anomalous route identification method and apparatus, a device and a medium. The method comprises: acquiring from a border router of each AS a plurality of pieces of network traffic data and a plurality of route update messages whose AS paths have a target AS as the origin AS within a current time period; on the basis of route announcement data or route withdrawal data of each route update message, determining an anomalous IP prefix and a normal IP prefix of the target AS; on the basis of a destination IP address of each piece of network traffic data, the anomalous IP prefix and the normal IP prefix, determining indicator data of the anomalous IP prefix and indicator data of the normal IP prefix within the current time period; on the basis of the indicator data of the anomalous IP prefix and the indicator data of the normal IP prefix within the current time period, determining a degree of anomaly impact; and, on the basis of the degree of anomaly impact and a set threshold, determining whether an anomalous route is present in the target AS within the current time period. The method can improve the accuracy of identifying BGP anomalous routes.
Owner:CHINA TELECOM NETWORK SECURITY TECH CO LTD

A method, apparatus, device, and medium for identifying abnormal BGP routes.

This application discloses a method, apparatus, device, and medium for identifying abnormal BGP routes. The method includes: obtaining multiple network traffic data points within the current time period from the border routers of each AS, as well as multiple route update messages with the source AS as the destination AS in the AS path; determining the abnormal IP prefix and normal IP prefix of the target AS based on the route advertisement data or route withdrawal data of each route update message; determining the indicator data of the abnormal IP prefix and the indicator data of the normal IP prefix within the current time period based on the destination IP address, abnormal IP prefix, and normal IP prefix of each network traffic data point; determining the degree of abnormality based on the indicator data of the abnormal IP prefix and the indicator data of the normal IP prefix within the current time period; and determining whether there is an abnormal route in the target AS within the current time period based on the degree of abnormality and a set threshold. This method can improve the accuracy of identifying abnormal BGP routes.
Owner:CHINA TELECOM NETWORK SECURITY TECH CO LTD

Encoding and decoding method and system for route origin authorization (ROA)

Described are an encoding method and system for ROAs. The encoding method includes the following steps: given a set of authorized IP prefixes an AS which are maintained with an IP address trie. By specifying a sequence of hanging levels on the IP address trie, it is divided into a set of non-overlapping sub-trees, each rooted at a hanging level. A node on a hanging level uniquely defines a sub-tree rooted at it, whose prefix can be encoded as the identifier of this sub-tree. All authorized prefixes covered by a sub-tree can be encoded into a bitmap of 2h bits, where h is the height of this sub-tree. Thus, the set of authorized IP prefixes of an AS is encoded into several tuples (identifier, bitmap).
Owner:COMP NETWORK INFORMATION CENT CHINESE ACADEMY OF SCI

BGP Backup Path Selection Excluding Fate Shared Paths

Techniques for performing Border Gateway Protocol (BGP) backup path selection are provided. In one set of embodiments, a BGP speaker can select a best path for an Internet Protocol (IP) prefix and can determine that the best path is in a first fate shared group comprising a group of paths that are vulnerable to a common failure. The BGP speaker can then determine one or more candidate backup paths that are in a second fate shared group different from the first fate shared group (or are not in any fate shared group) and can select at least one of the one or more candidate backup paths as a backup path for the IP prefix.
Owner:ARISTA NETWORKS INC

Route hijacking detection method and equipment for BGP (Border Gateway Protocol) route and medium

The invention provides a routing hijacking detection method and device for BGP routing and a medium, and relates to the technical field of routing hijacking, and the method comprises the steps: building a routing space-time stable database based on BGP routing notification data obtained by a global distributed monitoring node, and the routing space-time stable database comprises an IP prefix mapping table and an ASPATH mapping table; when a BGP routing notification A is received, the A is analyzed to obtain a specific information set corresponding to the A, and the specific information set comprises an IP prefix, an ASN corresponding to the IP prefix and an ASN triple list obtained based on an attribute value of an ASPATH corresponding to the A; according to the method, whether the A has prefix hijacking or path hijacking or not is judged based on the IP prefix mapping table, the ASPATH mapping table and the specific information set corresponding to the A, dependence on the route origin authorization signing and issuing rate or the internet route registry is not needed, detection of the prefix hijacking and the path hijacking is supported at the same time, and the coverage range and the detection accuracy of route hijacking detection are remarkably improved.
Owner:CHINA ACADEMY OF INFORMATION & COMM

Access control lists rules reduction

The present disclosure relates to methods and systems for reducing access control lists (ACLs). The methods and systems combine multiple allowed internet protocol (IP) addresses from the ACLs to a single or small number of IP prefixes. The methods and systems calculate a minimum of the bit changes in transforming the IP addresses from one to another. Using the information for the minimum bit changes in transforming the IP addresses from one to another, the methods and systems build a graph of IP addresses, where the nodes are the IP addresses, and the edges denote that the IP addresses are transformed from one to another using the minimum number of bit changes. The methods and systems recursively merge the nodes to reduce the ACL rules into a compressed ACL rule graph. The methods and systems generate a reduced set of ACL rules using the compressed ACL rule graph.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Method and system for compressing multi-tenant uniform storage routing table entries based on identity mapping

The application relates to a multi-tenant uniform storage routing table item compression method and system based on identification mapping. The method comprises the following steps: in a routing table item insertion stage, a minimum available reduceID is dynamically allocated for each new tenant, and it is ensured that the IP prefix space of the tenant is not overlapped with a tenant using the same reduceID; in a lookup stage, a message VNI is converted into a reduceID through a mapping table based on RAM, and then reduceID+destination IP is used as a joint key to query a TCAM, and the mapping relationship between the VNI and the reduceID is constructed, so that the bit width of the TCAM table item is significantly reduced under the premise of ensuring routing correctness. The application is suitable for an IPv4 / IPv6 multi-tenant environment, and can effectively reduce the hardware area and power consumption in a FPGA or ASIC high-performance data plane, while maintaining the line-speed forwarding capability.
Owner:NAT UNIV OF DEFENSE TECH +1

Communication system, router, program, and communication management method

PendingCN121970300ANetwork connectionsCommunications systemIp prefix
A communication system is provided with a first router and a second router, the first router stores a correspondence table having a table storage unit and storing an IP Prefix of a lower layer network of the first router and an SRv6 SID in which a Locator + Function length is smaller than an IP Prefix length corresponding to the IP Prefix, and the second router has an SID generation unit that generates an SID, and a storage unit that stores the SRv6 SID in which the Locator + Function length of the lower layer network of the first router is smaller than the Locator + Function length of the lower layer network of the first router and the SRv6 SID in which the Locator + Function length is smaller than the IP Prefix length corresponding to the IP Prefix. The SID comprises a partial address of a destination located under the first router and header information; and a packet transmission unit that transmits an SRv6 packet including the SID to the first router, the first router having a packet generation unit that, when the first router receives the SRv6 packet issued by the second router, specifies an IP Prefix corresponding to the SID included in the SRv6 packet by looking up the correspondence table, and transmits the SRv6 packet to the second router. And determining the address of the destination using the partial address of the destination included in the IP Prefix and the SID, and generating a packet to be transmitted to the destination using the determined address and header information.
Owner:SOFTBANK CORPORATION

IP address searching method and device

An IP address searching method is applied to IPv6 and comprises the steps that a searching data structure tree is built based on a multi-bit Trie tree, and each Trie node internally provided with a real node corresponds to one or more IP prefixes in an IP forwarding table; determining a mappable pipeline level range of each node according to an inverse distance of each node in the data structure tree, a pipeline level where a child node is located, a path length from the node to a root node and a position of a pipeline level where a father node is located; wherein the inverse distance is defined as the maximum distance between the node and all subsequent leaf nodes; dynamically mapping each node into an independent storage resource of the corresponding pipeline level according to the mappable pipeline level range and the storage space condition of each pipeline level; and in each pipeline level, parallelly executing IP address searching according to a node mapping result so as to realize pipeline parallel searching. The method can improve the searching efficiency.
Owner:COMP NETWORK INFORMATION CENT CHINESE ACADEMY OF SCI

Group-Based Network Segmentation Using Dynamic Groups

A network is partitioned into multiple domains and managed by a network controller. The network controller stores segmentation policies defined in terms of user groups, wherein members in a user group are identified by IP addresses or IP prefixes. An administrator controls which user groups communicate with each other and in which domains by associating segmentation policies with domains. Classification sources external to the network controller inform the network controller of changes to the membership of the user groups. The network controller uses the group membership information and segmentation policy / domain assignments to generate traffic policies. Each traffic policy is specific to a domain; the traffic policy is generated only from the segmentation policies of the domain, and consists of segmentation policy rules associated with the domain and members in the group's associated with those policy rules.
Owner:ARISTA NETWORKS INC

Routing origin authorization coding and decoding method and system based on dynamic subtree division

The invention provides a routing origin authorization encoding and decoding method and system based on dynamic subtree division, and the specific implementation scheme of the encoding method is as follows: a relying party synchronizes ROA data from an RPKI database and analyzes an authorization information set {lt, Prefix, ASNgt,...}, and divides the authorization information set into subsets based on ASN; respectively constructing an IP prefix binary tree for each subset to maintain authorization information; the relying party sets a PDU format based on a communication protocol between the relying party and the router; taking the minimum pre-estimated coding length as a sub-tree division basis to obtain an optimal sub-tree division scheme of each IP prefix binary tree; coding a sub-tree containing an authorized node in each IP prefix binary tree to obtain N lt; the method comprises the following steps of: selecting a template, namely, a template, Prefix, MaxLength and AuthStategt; n is greater than or equal to 1; and constructing N PDUs, and writing the data information in the N triads. According to the technical scheme provided by the invention, on the premise of ensuring the security and accessibility of the inter-domain routing system, the transmission, verification and storage overhead of ROA data in the RPKI system can be reduced.
Owner:COMP NETWORK INFORMATION CENT CHINESE ACADEMY OF SCI

Multi-source authentication method and system for resource public key infrastructure

The invention provides a multi-source authentication method and system of a resource public key infrastructure, relates to the technical field of computer networks, and realizes binding authentication of an IP prefix and a resource record through a reverse domain name system of domain name system security expansion. And after the resource certificate of the resource holding end is revoked, the relying party RP provides access service to the outside based on the domain name system security extension. According to the method, data and trust sources of resource records obtained by the relying party RP are effectively increased, authentication endorsement of the same resource record by multiple trust sources is realized, so that the revocation authority of the resource public key infrastructure is reduced, potential risks caused by unilateral revocation of the resource public key infrastructure are effectively dealt with, and seamless integration can be realized in an existing network environment.
Owner:COMP NETWORK INFORMATION CENT CHINESE ACADEMY OF SCI

Group-based network segmentation using dynamic groups

ActiveUS12689589B2Ip addressNetwork control
A network is partitioned into multiple domains and managed by a network controller. The network controller stores segmentation policies defined in terms of user groups, wherein members in a user group are identified by IP addresses or IP prefixes. An administrator controls which user groups communicate with each other and in which domains by associating segmentation policies with domains. Classification sources external to the network controller inform the network controller of changes to the membership of the user groups. The network controller uses the group membership information and segmentation policy / domain assignments to generate traffic policies. Each traffic policy is specific to a domain; the traffic policy is generated only from the segmentation policies of the domain, and consists of segmentation policy rules associated with the domain and members in the group's associated with those policy rules.
Owner:ARISTA NETWORKS INC

IP address lookup method and apparatus

An IP address lookup method applied to IPv6, the method comprising: constructing a lookup data structure tree based on a multi-bit Trie tree, wherein each internal Trie node with a real node corresponds to one or more IP prefixes in an IP forwarding table; determining a mappable pipeline stage range of each node according to a reverse distance of each node in the lookup data structure tree, a pipeline stage where a child node is located, a path length from the node to a root node, and a position of a pipeline stage where a parent node is located; wherein the reverse distance is defined as a maximum distance between the node and all successor leaf nodes thereof; dynamically mapping each node to an independent storage resource of a corresponding pipeline stage according to the mappable pipeline stage range and a storage space condition of each pipeline stage; and performing IP address lookup in parallel in each pipeline stage according to the node mapping result to realize pipeline parallel lookup. The method can improve lookup efficiency.
Owner:COMP NETWORK INFORMATION CENT CHINESE ACADEMY OF SCI

Routing interruption detection method and device, equipment and storage medium

The invention provides a routing interruption detection method, device and equipment and a storage medium, and the method comprises the steps: collecting the BGP (border gateway protocol) routing data of a control plane in a network through an observation point, and determining a target AS (autonomous system) with routing change and the routing information of the target AS based on the BGP routing data, the routing information of the target AS comprises a path withdrawing proportion of the target AS, a total number of paths of the target AS, an IP prefix withdrawing proportion of the target AS, a total number of IP prefixes of the target AS, a next hop withdrawing proportion of an observation point and a total number of next hops of the observation point, and finally performing feature extraction on the routing information of the target AS to obtain an AS routing feature vector. And inputting the AS routing feature vector into an interruption detection model for interruption detection to obtain an interruption detection result so as to judge whether the target AS is interrupted or not. According to the embodiment of the invention, routing interruption detection can be realized.
Owner:TSINGHUA UNIVERSITY

Route selection method and related device

This application discloses a route selection method and a related device. A control entity determines first metric information of a first segment routing (SR) path, generates a first border gateway protocol (BGP) update message including the first metric information, and sends the first BGP update message to an ingress node of the first SR path, where the first metric information represents quality of the first SR path, the first metric information is used for route selection on a plurality of paths, each of the plurality of paths has a same IP prefix of a destination node, and the plurality of paths include the first SR path. According to the method, the control entity can send, to the ingress node of the SR path by using the BGP update message, the metric information that represents the quality of the SR path.
Owner:HUAWEI TECH CO LTD

Method for providing IP prefixes using existing PC5 links

PendingCN121241654AConnection managementIp addressIp prefix
A method for providing prefix information to a remote wireless transmit / receive unit (WTRU) is described herein. A method may include transmitting or receiving a protocol data unit (PDU) over a link to a remote WTRU, the protocol data unit (PDU) including a first IP address associated with a PDU session utilizing session service and session continuity mode 3 (SSC3). The method may include receiving a message for modifying the PDU session indicating that reactivation is requested, and transmitting the message for modifying the PDU session. The method may include receiving new IP prefix information, transmitting a message including the new IP prefix information over a link to a remote WTRU, and transmitting or receiving a PDU over a link to the remote WTRU, the PDU including a second IP address generated based on the new IP prefix information.
Owner:INTERDIGITAL PATENT HOLDINGS INC

Inter-domain routing message data feature extraction method and device

The invention discloses an inter-domain routing message data feature extraction method and device, and the method comprises the steps: loading a routing snapshot, updating a dump file, and constructing a global real-time routing table, an autonomous system routing prefix table and a routing prefix autonomous system mapping table; establishing and updating an autonomous system country mapping table based on AS number distribution data and IP prefix country affiliation information, and excluding ASs of which registration places are inconsistent with operation places; processing route update data in a bucket manner according to a fixed time interval, and extracting route change characteristics of a prefix level and an autonomous system level; and aggregating to generate national granularity features, constructing a national routing topological graph, and extracting graph structure features such as node number and diameter. Through a three-level granularity feature extraction and hierarchical convergence strategy, cross-domain noise is effectively isolated, feature stability and interpretability are improved, accurate and hierarchical input features are provided for machine learning detection of BGP abnormal events, and the method is suitable for routing anomaly monitoring and analysis in the network space security field.
Owner:BEIJING UNIV OF POSTS & TELECOMM

A method, apparatus, electronic device, and storage medium for detecting routing interruptions.

This application provides a routing interruption detection method, apparatus, electronic device, and storage medium. The method includes: collecting raw routing table data and routing registration data within a target autonomous system; establishing a prefix tree based on the prefixes of each routing entry in the raw routing table data, and establishing a mapping dictionary based on the mapping relationship between each target autonomous system and the prefix in the routing registration data; aggregating the connectivity status of each target autonomous system based on the mapping dictionary and the connectivity status of the corresponding prefix stored in each prefix node of the prefix tree to establish a prefix matrix; and determining that a routing interruption event has occurred if the prefix statistics under each timestamp meet a preset interruption condition. This application uses the prefix tree data structure as the basic data storage for routing interruption detection and significantly optimizes the lookup efficiency of IP prefixes by utilizing the binary characteristics of IP addresses, thus providing a data foundation for improving the detection efficiency of routing interruptions.
Owner:CHINA TELECOM NETWORK SECURITY TECH CO LTD

Message processing method and device and related equipment

The invention relates to the technical field of network communication, in particular to a message processing method and device and related equipment. The method comprises the following steps: receiving an extended route notification which is sent by Leaf equipment in networking and is used for notifying an IP prefix of a host under the Leaf equipment, the extended route notification further comprising an equipment identifier of the Leaf equipment accessed by the host and a port identifier of a port on the Leaf equipment for accessing the host; maintaining a mapping relationship among an IP prefix of the host, an equipment identifier of Leaf equipment accessed by the host and a port identifier of a port used for accessing the host on the Leaf equipment in a mapping table; receiving a message, and judging whether a target mapping table item matched with the IP address of the message exists in the mapping table or not; and if it is judged that a target mapping table item matched with the IP address of the message exists in the mapping table, forwarding the message according to a target device identifier and a target port identifier included in the target mapping table item.
Owner:NEW H3C TECH CO LTD

Route advertisement method, apparatus, and system

ActiveUS12621239B2Networks interconnectionIp addressVirtual routing and forwarding
A route advertisement method includes advertising, by a first network device, an Internet Protocol (IP) prefix route to a second network device, where the IP Prefix route includes a gateway (GW) IP address and a Multi-Protocol Label Switching (MPLS) label. The GW IP address is an IP address of a first interface of the first network device. The MPLS Label is a label of a first IP-virtual routing and forwarding (IP-VRF) instance of the first network device. The first network device advertises a media access control (MAC) / IP route to the second network device, where the MAC / IP route includes the IP address of the first interface and a MAC address of the first interface.
Owner:HUAWEI TECH CO LTD