Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

35 results about "IPv6" patented technology

Internet Protocol version 6 (IPv6) is the most recent version of the Internet Protocol (IP), the communications protocol that provides an identification and location system for computers on networks and routes traffic across the Internet. IPv6 was developed by the Internet Engineering Task Force (IETF) to deal with the long-anticipated problem of IPv4 address exhaustion. IPv6 is intended to replace IPv4. In December 1998, IPv6 became a Draft Standard for the IETF, who subsequently ratified it as an Internet Standard on 14 July 2017.

Data transmission control method and apparatus, network element, and medium

ActiveCN116436847BPathPingEngineering
The application discloses a data transmission control method and device, a network element and a medium. The method comprises the following steps: when a data packet is received, a two-layer member link adjacency segment identifier corresponding to a segment routing based on an IPv6 forwarding plane of the data packet is acquired; a first forwarding path corresponding to the data packet is determined according to the two-layer member link adjacency segment identifier; when the first forwarding path has a fault, a processing mode corresponding to the two-layer member link adjacency segment identifier is determined, and the data packet is processed according to the processing mode. The application improves the flexibility of data packet transmission and processing.
Owner:CHINA MOBILE COMM GRP CO LTD

Optimization method for multicast SSM path in IPv6 environment

This invention discloses a method for optimizing multicast paths in a specified source multicast SSM environment under IPv6, relating to the field of IPv6 multicast transmission technology. The method includes acquiring real-time network node status information and establishing a network performance model, quantifying the transmission cost and potential bottlenecks of each link in the path, and calculating the comprehensive transmission overhead estimate of the initial multicast forwarding path. A path evolution engine searches for a set of alternative forwarding paths in the network topology, calculates the comprehensive transmission overhead estimate of each alternative path, filters out a set of candidate optimized paths with lower overhead than the initial path, selects the path with the lowest overhead as the optimized multicast forwarding path, and forwards the multicast data to the receiver along this path. This invention can achieve accurate quantification of link-level transmission performance, adapt to real-time network status, determine the optimal path through two-level filtering, avoid link bottlenecks, reduce multicast transmission overhead, and improve the adaptability and transmission efficiency of IPv6 SSM multicast transmission.
Owner:HANGZHOU XIDE INTELLIGENT TECH CO LTD

Message processing method, device and communication system

The present disclosure provides a message processing method and device and a communication system, relating to the field of communication. The method comprises: a first gateway receiving a first virtual extensible local area network (VxLAN) message from a first VxLAN in a first domain, the first VxLAN message comprising a first identifier of a second VxLAN in a second domain and a first load; the first gateway performing processing on the first VxLAN message to obtain a segment routing (SRv6) message, the SRv6 message comprising a second identifier of the second VxLAN, the first load and a path from the first gateway to a second gateway; and the first gateway sending the SRv6 message to an IPv6 network, so that the second gateway sends a second VxLAN message comprising the first identifier and the first load to the second VxLAN according to the second identifier, wherein the SRv6 message is forwarded along the path in the IPv6 network.
Owner:CHINA TELECOM CORP LTD

An intelligent substation path controllable network system and method based on IPv6 and white box exchange

PendingCN122120232ATransmissionPathPingSmart substation
The application relates to the technical field of smart grid communication, and discloses a smart substation path controllable network system and method based on IPv6 and white box switching. A centralized controller is used to gather link state information of each white box switch to construct a global topology view. Based on the view and a service demand vector, network service flow is optimized and evaluated to generate a path planning table. Then, the path planning table is translated and coded by a rule conversion module, and is sent to a programmable data plane of the switch through a southbound interface and is solidified into a hardware forwarding table. According to the path planning table, an access side switch matches a received original service packet, generates an IPv6 encapsulated packet with a path strategy expansion header, and finally performs destination address overwrite and hop-by-hop controllable forwarding along the path indicated by the expansion header to obtain a target service packet. In this way, the closed architecture of traditional underlying equipment is broken, and accurate control and high-reliability deterministic flexible transmission of the end-to-end path of massive service in a substation are realized.
Owner:STATE GRID HENAN INFORMATION & TELECOMM CO

Bier packet forwarding method, device, and system

ActiveUS12671655B2Data packTelecommunications
A first network device receives a BIER packet sent by a second network device, where the BIER packet includes an IPv6 header, a BIER header, and a multicast packet, a destination address of the IPv6 header or a first field of the BIER header carries a service identifier, and the service identifier identifies a virtual private network VPN instance. The first network device determines a VRF table based on the service identifier and a first correspondence, where the first correspondence includes a correspondence between the service identifier and the VRF table. The first network device sends the multicast packet to a first CE device in the VRF table based on the VRF table.
Owner:HUAWEI TECH CO LTD

A distributed energy storage device plug and play communication interface device and method

PendingCN122457569ASimplify the access processFlexible networkingFree accessCommunication interface
The application discloses a kind of plug and play communication interface device and method of distributed energy storage equipment, it is related to power storage access technical field.The device includes information model construction module, fusion communication networking module, access management module and energy storage adaptation terminal;Unified light self-description information model is established based on IEC61850 standard, IPv6 multi-protocol fusion communication network is built, and transparent communication channel is provided for edge-end equipment.Access management module is deployed in intelligent fusion terminal, and pre-set device model library is generated based on information model and built-in, to realize equipment automatic identification and matching;Energy storage adaptation terminal has double communication mode, and can automatically protocol polling, networking and registration.The application can realize energy storage equipment power-on self-discovery, automatic networking, configuration-free access, improve access efficiency and communication reliability, and is suitable for distributed energy storage flexible deployment and efficient regulation and control scene.
Owner:STATE GRID HUNAN ELECTRIC POWER CO LTD ELECTRIC POWER SCI RES INST +2

A method and system for dynamic micro-isolation of an SDN financial terminal under IPv6 dual stack

PendingCN122457376AEngineeringImaging data
The application discloses a kind of SDN financial terminal dynamic micro-isolation method and system under IPv6 double stack, belong to network security technical field.Method includes: deployment system architecture and complete initialization configuration;Multi-dimensional access authentication is executed and terminal comprehensive trust image is initialized;Real-time collaborative monitoring is carried out to terminal accessed, and image score is updated according to abnormal identification result;Integrate authentication, monitoring and image data to generate terminal state view, and generate different double stack dynamic micro-isolation strategy based on view;Double stack traffic isolation forwarding is executed and real-time feedback is carried out;According to abnormal level, trigger hierarchical response mechanism;Whole-process log is retained and image evolution track is traced back, and audit data is back to model iteration.The application takes terminal comprehensive trust image as core and runs through whole process, realizes the accurate consistency control of double stack traffic, multi-dimensional authentication and real-time monitoring linkage, abnormal terminal hierarchical rapid response and whole-process compliance audit, effectively improves the security protection capability of financial terminal.
Owner:SHANDONG CITY COMMERCIAL BANK COOP ALLIANCE CO LTD

A tenant security access control method, device and electronic equipment

This application provides a tenant secure access control method, apparatus, and electronic device, relating to the field of communication technology. In this application, a traffic packet sent by a tenant is received. The traffic packet includes a source address and a destination address, and the source address includes a service subscription identifier field. The source address is parsed to extract a first field value corresponding to the service subscription identifier field, and the target security services subscribed to by the tenant are determined based on the first field value. Each target security service is invoked to perform security detection on the traffic data packet corresponding to the traffic packet, and corresponding detection results are obtained. The detection results include detection passed and detection failed. A protection policy corresponding to the detection result is invoked to process the traffic packet. This approach can meet the high-performance transmission service requirements of tenant isolation across multiple regions in an IPv6 network environment.
Owner:NSFOCUS INFORMATION TECHNOLOGY CO LTD +2

IPV6-based service packet forwarding method and device and computer equipment

This application relates to a service packet forwarding method, apparatus, and computer device based on IPv6. The method includes: initiating authentication with a management system; upon successful authentication, receiving network configuration information issued by the management system; establishing a mapping relationship between service types and segment identifiers locally based on a segment identifier list; generating a PPPoE request packet containing user authentication information; forming a PPPoEov6 dial-up packet using the local IPv6 tunnel source address and IPv6 tunnel access address, and sending the PPPoEov6 dial-up packet to the remote PPPoE server; and forwarding the PPPoEov6 dial-up packet by the remote PPPoE server according to the destination IPv6 tunnel SID. This method enables the PPPoE protocol to support Layer 3 networking based on IPv6, achieving flexible and efficient remote dial-up authentication.
Owner:CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1

Secure packet sending method with partially encrypted segment routing header in IPV6 network

A packet sending method, a network device, and a program product are disclosed, and pertain to the field of segment routing technologies. The method includes: A network device sends a packet which includes a segment routing header SRH and a payload, the SRH includes an encrypted field and an unencrypted field, the encrypted field includes at least an encrypted SID list, and the SID list indicates a transmission path of the packet. A SID list in an SRH of an SRv6 packet transmitted over a POP network is encrypted, thereby protecting SID information from being leaked. In addition, an intermediate node on a packet transmission path only needs to decrypt an encrypted field in the SRH to determine a next hop from the SID list, and does not need to decrypt the payload. This improves forwarding efficiency of the network device and protects secure transmission of the payload.
Owner:HUAWEI TECH CO LTD

A Three-Stage Cascaded IPv6 DDoS Attack Detection and Protection Method Based on Deep Learning

PendingCN122339851AData setClosed loop feedback
This invention relates to the field of network security technology and proposes a three-stage cascaded IPv6 DDoS attack detection and protection method based on deep learning. The method involves: acquiring a multi-source fusion dataset; performing filtering and protection processing based on dynamic rules; inputting the packet-level dataset from the multi-source fusion dataset into a lightweight packet-level pre-detection model for real-time classification and inference to obtain preliminary classification results; making scheduling decisions based on the preliminary classification results; inputting the flow-level dataset from the multi-source fusion dataset into a flow-level deep detection model for deep detection processing to obtain final prediction results; and performing closed-loop feedback based on the final prediction results. This invention avoids the influence of easily confused categories and decision-making limitations, improving detection accuracy and efficiency.
Owner:NANCHANG UNIV

A method, system, and device for migrating low-Earth orbit satellite network services based on mobile virtual service groups.

PendingCN122316435AData packGreedy algorithm
This invention discloses a method, system, and device for migrating low-Earth orbit satellite network services based on Mobile Virtual Service Groups (MVSGs), belonging to the field of satellite communication technology. The method includes: an orchestration management entity acquiring user trajectories and satellite ephemeris data; constructing a user-centric Mobile Virtual Service Group (MVSG); calculating a satellite service schedule with the minimum number of handovers using a greedy algorithm; generating flow table entries and control commands, and sending them to an SDN controller; the SDN controller receiving the schedule, issuing commands to the target physical satellite to start VNF ​​containers and allocate fixed virtual IP addresses, maintaining a dynamic mapping between virtual IPs and physical addresses, and issuing data plane forwarding rules and handover rules; the access satellite encapsulating user data packets with IPv6 tunnels and routing them to the target satellite; during handover, the source satellite migrates its VNF state to the target satellite. This invention significantly reduces the number of service handovers, ensures service continuity, and reduces signaling overhead through MVSG, pre-calculated scheduling, virtual IP decoupling, and state migration.
Owner:WUHAN UNIV

Method, device, and system for implementing service path detection

A method, a device, and a system for implementing service path detection are provided. The method is applied to an SRv6 network, and includes: A first network device generates a first packet based on IPv6 and sends the first packet to a second network device, where the first packet includes a first indication and identification information of a service, and the first indication indicates that the first packet is a detection packet; and after receiving the first packet, the second network device detects, based on the first indication and the identification information of the service, a path for carrying the service.
Owner:HUAWEI TECH CO LTD

ICMPv6-DDoS attack detection method and system based on feature optimization

PendingCN122372309AFeature setAttack
The application provides an ICMPv6- DDoS attack detection method and system based on feature optimization, belongs to the technical field of cyberspace security, and solves the core problems of insufficient feature representation ability, missing security target constraint and high feature space redundancy of the existing detection method. The application first performs traffic aggregation and basic feature data extraction on ICMPv6 traffic, constructs an extended feature set, removes redundant features to obtain a low-redundancy candidate feature set, then completes two-stage feature selection through information gain rate filtering and an improved binary particle swarm optimization algorithm with recall rate constraint, outputs an optimal feature subset, and finally constructs a detection model based on the optimal feature subset to complete attack detection. The application significantly improves the attack detection rate, balances the detection accuracy and model lightweight, and can be widely applied to various IPv6 network security monitoring scenes.
Owner:GUANGZHOU UNIVERSITY

Flow label based traffic scheduling method, device and equipment

The application discloses a flow label-based traffic scheduling method, device and equipment. The method comprises the following steps: a source computing node divides the service flow in a single RDMA queue pair into multiple independent sub-flows based on a preset semantic boundary; the source computing node generates an IPv6 flow label for each sub-flow, and fills the IPv6 flow label into the corresponding field of an IPv6 header when encapsulating a data packet; and the source computing node and / or a network node schedules the data packets of different sub-flows to different network paths for transmission based on the IPv6 flow label in a path selection process. The application can greatly improve the traffic entropy of the network by performing semantic subdivision on the service flow in the queue pair, dividing the service flow into multiple independent sub-flows, and allocating different IPv6 flow labels to each sub-flow, so that the elephant flow can be transmitted through multiple paths, and the out-of-order problem caused by the multi-path transmission can be avoided by using the intermittent characteristics of the traffic.
Owner:XINGRONG METADATA TECH (SUZHOU) CO LTD

Apparatus and methods for packetized content routing and delivery

Apparatus and methods for managing content delivery in a packetized network. In one embodiment, the network provide content to a plurality of clients via a plurality of nodes and origin points, and resources are discreetly represented (e.g., with IP addresses, such as those afforded under the IPv6 protocol) to allows for direct advertisement of resources. Exemplary solutions described herein further advantageously leverage extant architectures and protocols (such as BGP), and make use of a common control plane, which can be utilized for example by different content delivery network (CDN) operators and different delivery components to advertise resources. Internally within a given CDN, increased granularity of resource addressing and advertisement may provide benefits including: (i) resource affinity; (ii) resource-level balancing; (iii) dynamic resource scoping; and (iv) “zero-touch” provisioning and resource relocation.
Owner:CHARTER COMM OPERATING LLC

Packet forwarding methods, devices, network equipment, and storage media

The present invention provides a packet forwarding method, apparatus, network equipment, and storage medium, and relates to the field of network communication technology. A packet forwarding method applicable to a first network device includes receiving a traffic packet transmitted from a user-side device, buffering the traffic packet in a scheduling queue corresponding to the deterministic flow to which the traffic packet belongs, and, when the scheduling cycle of the scheduling queue is reached, transmitting a composite packet to a second network device, which includes an IPv6 header, a segment routing header (SRH), and a plurality of traffic packets in the scheduling queue. This can improve bandwidth utilization.
Owner:NEW H3C TECH CO LTD

SRv6 processing method and device supporting variable-length compressed sid mix

ActiveCN116938790BTransmissionData packSpatial computing
This invention discloses an SRv6 processing method and apparatus supporting mixed encoding of variable-length compressed SIDs. The method includes: S100, the source node receives a compressed SRH and the IPv6 destination address encoded by a controller or manually; S101, intermediate nodes parse the IPv6 destination address and SRH in the received header to obtain FSID and FFlag information; S102, based on the parsing result, determine the space of the next-hop node, calculate the start bit of the next-hop node, and update the values ​​in each field of FFlag; S103, based on the parsing and calculation results, update the IPv6 destination address and SRH; the operation on the SRH includes updating the SL and LastEntry fields, stripping the entire SRH, or pushing it out of the stack; S104, forwarding the updated data packet containing the compressed data. This invention pioneers a new technical approach in the field of SRv6 compression, using flag bits containing multiple fields; and for the first time, extends SRv6 compression processing from pre-transmission to in-transmission, thus achieving higher flexibility, higher compression efficiency, and higher transmission efficiency.
Owner:XIAMEN UNIV

A method and device for detecting network elements in IPv6 network space

ActiveCN116405362Bquick treatfast traverseTransmissionEngineeringNetwork topology
The application discloses a network element detection method of IPv6 network space, comprising the following steps: obtaining a list of network elements to be detected, the list of network elements to be detected recording a plurality of first network elements to be detected; performing detection on each first network element to obtain a second network element directly connected with the first network element; judging whether the second network element is an anonymous network element, if yes, using a preset probe program to find an IPv6 global unicast address of the anonymous network element based on a seed node in a preset seed set to determine network element information of the anonymous network element; repeatedly performing detection until the detection of each first network element in the list of network elements to be detected is completed; and forming a network topology of the IPv6 network space based on the network element information of each second network element. The method disclosed by the application can quickly traverse all network element devices in a sparse IPv6 network space, and quickly form a network element use condition under the IPv6 network space according to the formed table.
Owner:ACADEMY OF BROADCASTING SCI STATE ADMINISTATION OF PRESS PUBLICATION RADIO FILM & TELEVISION

Method for efficient routing of multicast traffic

A method of routing Internet Protocol Version 6, IPV6, multicast traffic in a utility metering system. The method includes creating a tunnel between each of a plurality of devices of a utility metering system on a first network and at least one device of the utility metering system on a second network to allow bidirectional communication therebetween, wherein each of the plurality of devices on the first network facilitates communication with at least one multicast group; generating and assigning a unique network prefix to each of the plurality of devices on the first network; prepending a multicast prefix to each unique network prefix to generate a unique device multicast prefix for each of the plurality of devices on the first network, the unique device multicast prefix including only the unique network prefix and the multicast prefix and not including a group ID identifying the at least one multicast group; populating a multicast routing table using the unique device multicast prefix of each of the plurality of devices on the first network to allow communication routing between each of the plurality of devices on the first network and the at least one device on the second network to be established; and using the multicast routing table to route multicast traffic from the at least one device on the second network to the relevant devices of the plurality of devices on the first network.
Owner:LANDIS GYR TECH INC

ROOT SYSTEM AND MULTIFACTOR AUTHENTICATION METHOD BASED ON IPV6

The present application relates to an IPv6-based multi-factor authentication root system, comprising: a first capture module, used for obtaining a plurality of pieces of identity information of a user, a plurality of pieces of enterprise information, and an enterprise code; a second capture module, used for obtaining an IPv6 digital address of the user; a third capture module, used for obtaining a plurality of digital certificates provided by a plurality of digital authentication centers and a plurality of corresponding keys; an information authentication module, used for carrying out digital authentication on the plurality of pieces of identity information of the user and the plurality of pieces of enterprise information and generating a plurality of pieces of authenticated identity information and a plurality of pieces of authenticated enterprise information; an electronic personal seal / corporate seal generation module, used for generating an electronic personal seal of the user and an electronic corporate seal; and a root certificate issuance module, used for carrying out multi-key authentication on the plurality of pieces of authenticated identity information and the plurality of pieces of authenticated enterprise information on the basis of the plurality of digital certificates and the plurality of corresponding keys, and issuing a plurality of root certificates.
Owner:ХУ ЦЯНЬЦЯНЬ

Message encapsulation and de-encapsulation method and device, storage medium, and electronic device

Provided is a message encapsulation and de-encapsulation method and device, a storage medium, and an electronic device. The message encapsulation method includes: encapsulating a bit indexed explicit replication (BIER) header in an IPv6 extended header of an IPv6 message in combination with a generic fragmentation header (GFH), a generic encapsulating security payload (GESP), or a generic authentication header (GAH). The problem in the related art of how to combine a GFH mechanism with a BIER header encapsulated in an IPv6 extended header can be solved; when the BIER header is encapsulated in the IPv6 extended header, the BIER header can be combined with the GFH / GESP / GAH, thereby simply and efficiently realizing fragmentation, encapsulating security and authentication functions of a BIER multicast message.
Owner:ZTE CORP

An IPv6 encrypted traffic advanced persistent threat attack identification method and system

PendingCN122457381AFeature vectorAttack
The application relates to the technical field of network security, in particular to an IPv6 encrypted traffic advanced persistent threat attack identification method and system; the method comprises the following steps: extracting a cipher suite arrangement sequence, an extended field type set and a cipher library version identifier; performing sequence comparison and tolerance determination with a preset legal client variant fingerprint library to determine a suite arrangement coincidence level; screening out to-be-identified messages with a coincidence level lower than a preset legal threshold to generate a to-be-identified object set; and performing clustering analysis based on the arrangement feature vectors of the to-be-identified object set to identify a homologous concealed imitated traffic subset. In this way, the technical problem that the identification precision of a handshake fingerprint template and the overall identification accuracy are difficult to be considered in the prior art when dealing with the realistic scene of diversified client fingerprints in a signal creation environment is solved, and the accuracy and reliability of encrypted threat identification are improved.
Owner:LISHUI POWER SUPPLY COMPANY OF STATE GRID ZHEJIANG ELECTRIC POWER