Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

218 results about "IPv6" patented technology

Internet Protocol version 6 (IPv6) is the most recent version of the Internet Protocol (IP), the communications protocol that provides an identification and location system for computers on networks and routes traffic across the Internet. IPv6 was developed by the Internet Engineering Task Force (IETF) to deal with the long-anticipated problem of IPv4 address exhaustion. IPv6 is intended to replace IPv4. In December 1998, IPv6 became a Draft Standard for the IETF, who subsequently ratified it as an Internet Standard on 14 July 2017.

Computer-implemented methods and systems for improved communications across a blockchain network

The invention resides in a computer-implemented communication method. The method comprises a mechanism for distributing blockchain and / or cryptocurrency-related communications such as alerts, notifications and updates across an electronic network to one or more recipients as efficiently and swiftly as possible. Embodiments may use IPv6 multicast to perform such improved communications. A communication can comprise a code, flag or filter which enables the communication to be targeted at particular recipient(s) and allow multicast group members that have no interest or authorised access to the contents of the communication to ignore it. Thus, improvements are provided in respect of processing resources and time. In some examples, the disclosure can be advantageous for the implementation of a blockchain-related alert key or system which can aid in network responses to emergencies or threats, thus improving the security of the blockchain network.
Owner:NCHAIN LICENSING AG

IPv6 network mode adaptive configuration method and system based on RA message

The invention relates to the technical field of IPv6 self-configuration, in particular to an IPv6 network mode self-adaptive configuration method and system based on an RA message. In the method, a finite-state machine establishes a state transition path according to the combination relation of M and O flag bits in an RA message cache set and prefix field content, converts a network mode recognition process into a quantifiable state judgment sequence, and sends the state judgment sequence to the RA message cache set; configuration ambiguity caused by flag bit fluctuation in traditional static judgment is eliminated, pattern recognition under network environment changes has continuity and self-consistency, the classification regression tree constructs a branch judgment path with the duration, the advertisement interval and the prefix consistency of an RA source as characteristic variables, an optimal node is selected through a hierarchical splitting algorithm, and the judgment accuracy is improved. The dynamic mapping of stateful and stateless configuration paths is realized, the misjudgment rate of configuration branches is reduced, and the address allocation delay is optimized, so that the IPv6 self-configuration has a structured decision-making capability and a parameter mapping self-optimization characteristic, and the connection reliability, the address generation speed and the configuration accuracy are improved.
Owner:SHENZHEN TONGKANG CHUANGZHI TECH CO LTD

System and method to detect and countermeasure RPL attacks in IoT network

A system and a method to detect an attack on an IoT network is disclosed. The IoT network includes interconnection of multiple IoT devices. The method includes receiving, by a network connection device, multiple ICMPv6 network packets from IoT devices and outputting multiple output packets; and matching, by a routing device, a network traffic pattern to attack signatures structured as a taxonomy according to which part of a packet is misused. The taxonomy includes a branch to a data plane attack and a control plane attack, respectively. When an IPv6 RPL packet is detected, the method includes checking for generating, modifying, and replaying attacks by an attacker. When a non-RPL packet is detected, the method includes checking for dropping and leaking packet attacks by the attacker. When the attack is detected, the method includes invoking a solution to the attack. The solution includes mitigation of the attack by the attacker.
Owner:KING FAHD UNIVERSITY OF PETROLEUM AND MINERALS

IPv6 stateless address dynamic planning method and system based on elastic prefix

The invention discloses an IPv6 stateless address dynamic planning method and system based on an elastic prefix, particularly relates to the field of network communication, is used for solving the problems of prefix rigidity and service semantic deficiency in IPv6 stateless address configuration of a railway network, and is implemented by extracting basic prefix information and compressing a service level identifier to generate an elastic sub-prefix bit string. The prefix is ensured to be flexibly embedded into multi-level semantics; fusing the MAC address of the host to construct a temporary interface ID, and enabling the address to have deep association between equipment and service; splicing candidate addresses and broadcasting verification information to collect conflict feedback to realize real-time conflict detection; based on feedback calculation correlation strength and a variation rate index, driving a bit flipping optimization prefix and an interface ID through a support vector machine decision, and forming an iterative adjustment closed loop; and finally, repeatedly verifying and confirming a final address and feeding back the final address to the semantic pool, or rolling back and expanding the prefix so as to solve stubborn conflicts, thereby overcoming the prefix rigidity and semantic deficiency of the traditional mechanism.
Owner:SHENYANG QIANGXIN COMM TECH CO LTD

Data forwarding method and device, network equipment and SRv6 data forwarding system

The embodiment of the invention provides a data forwarding method and device, network equipment and an SRv6 data forwarding system, and relates to the technical field of IPv6 forwarding. The method comprises the following steps: a network device receives a shared key generated and issued by a controller based on network topology information of the SRv6 data forwarding system, encrypts a preset header field of an original message based on the shared key when the shared key is used as a source node of data forwarding, and forwards the encrypted message; when serving as an intermediate node for data forwarding, verifying and re-encrypting a preset header field of the received message based on the shared key, and forwarding; and when the received message is used as a destination node for data forwarding, the preset header field of the received message is verified and decrypted based on the shared key to obtain the original message, so that an attacker is prevented from obtaining path information through a plaintext, and network topology exposure is avoided.
Owner:MAIPU COMM TECH CO LTD

Internet of vehicles security authentication and data encryption transmission system integrated with IPv6 technology

The invention discloses an Internet of Vehicles security certification and data encryption transmission system integrated with an IPv6 (Internet Protocol Version 6) technology. According to the invention, the key strategy can be automatically optimized according to the dynamic environment in the actual operation of the Internet of Vehicles, and the dynamic balance between the security protection and the communication efficiency is realized. The system can intelligently judge the cracking risk faced by a current key by combining real-time data such as a vehicle driving state and network environment characteristics, so as to flexibly adjust the key length and the updating frequency: when the network environment is safe and the vehicle is in a low-risk area, the key service cycle is properly prolonged, and the basic key length is maintained to reduce the communication overhead; when a potential threat is detected or a vehicle enters a complex road section, the secret key security level is automatically improved, and the rotation period is shortened to enhance the protection capability. The system burden cannot be increased due to excessive encryption, potential safety hazards cannot be left due to insufficient protection, and key management better meets the actual requirements of high-speed movement of vehicles and rapid change of scenes in the Internet of Vehicles.
Owner:XIANGTAN TECHNICIAN COLLEGE

Power data network wide area synchronous transmission system based on APN6 intelligent slicing

The invention discloses a power data network wide area synchronous transmission system based on APN6 intelligent slicing, and relates to the technical field of power system communication, the service type of current transmission data is obtained through an identification embedding module, and a structured APN6 identifier is embedded in a Hop-by-Hop option header of an IPv6 extension header; the slice creation module judges whether retransmission is carried out or not according to CRC verification, dynamically creates multi-level slices according to time delay levels, and calculates an optical fiber refraction compensation value according to topological path coding; when the phase compensation module monitors that a line fault or a node is overloaded, different strategies are executed for slices of different levels, and transmission phases of slices around a fault area are adjusted through the signal modulation module; and when the slice capacity expansion module detects that the new energy cluster oscillates, bandwidth directional capacity expansion is executed according to the slice resource elastic scheduling framework. According to the method and the device, the data identification accuracy and the slice resource adaptability are improved.
Owner:CHINA SOUTHERN POWER GRID COMPANY

Methods, devices, and systems for BIER message forwarding

This application provides a method, device, and system for forwarding BIER packets. The method includes: a first network device receiving a BIER packet sent by a second network device. The BIER packet includes an IPv6 header, a BIER header, and a multicast packet. The destination address in the IPv6 header or a first field in the BIER header carries a service identifier, which is used to identify a Virtual Private Network (VPN) instance. The first network device determines a Virtual Private Network (VRF) table based on the service identifier and a first correspondence, whereby the first correspondence includes the correspondence between the service identifier and the VRF table. The first network device then sends a multicast packet to a first User Edge (CE) device listed in the VRF table. The technical solution provided by this application is relatively simple to implement when the egress edge device identifies a VPN instance.
Owner:HUAWEI TECH CO LTD

Dynamic distributed scanning method and system based on IPv6 geographic tag

The invention discloses a dynamic distributed scanning method and system based on an IPv6 geographic tag, and relates to the technical field of the Internet, and the method comprises the steps: carrying out the region division of an IPv6 seed address through combining with geographic information, obtaining the IPv6 seed addresses of a plurality of geographic regions, constructing an address space tree of each geographic region, determining the change dimension of the address space tree, and carrying out the calculation of the change dimension of the address space tree; generating candidate sub-modes based on the change dimension, and selecting a sub-mode from the candidate sub-modes; generating an address according to the sub-mode, and further obtaining a target address; performing comprehensive evaluation on each sub-mode region based on the seed address density and the network development condition to obtain an initial score, and scanning a target address in each sub-mode region according to the initial score; in the scanning process, the initial score is updated by adopting a score updating mechanism, and scanning is continued based on the updated score. Geographic positions and mechanisms based on IPv6 seed addresses are fused, so that the number of real active addresses is hit to the maximum extent under a limited scanning budget, and the detection efficiency is improved.
Owner:QILU UNIVERSITY OF TECHNOLOGY (SHANDONG ACADEMY OF SCIENCES)

IPv6 power line carrier dual-mode communication method and system

The invention provides an IPv6 power line carrier dual-mode communication method and system, belongs to the field of power line carrier communication, and solves the problems that a power line carrier is extremely sensitive to noise, an HRF is easily interfered by the same frequency, but a real-time intelligent prediction or cooperative avoidance mechanism is lacked. The method comprises the following steps: recording a short-term fluctuation trend of a communication error rate of a high-frequency power line carrier communication channel in past N periods at a link layer of the high-frequency power line carrier communication channel through a channel disturbance memory function; recognizing the degradation state of the current high-frequency power line carrier communication channel in combination with a disturbance spectrum recognition model; and when it is determined that the high-frequency power line carrier communication channel is in the degradation state, executing a preset spectrum parameter rollback strategy, and in the spectrum parameter rollback process, establishing a heterogeneous relay path through a high-frequency wireless communication channel to transmit to-be-confirmed key data.
Owner:ZHONGKE GUOYUAN (LIAONING) ELECTRONIC TECH CO LTD

IPv6 lightweight network equipment surveying and mapping method based on behavior fingerprints and hop count verification

The invention relates to an IPv6 lightweight network equipment surveying and mapping method based on behavior fingerprints and hop count verification. Comprising the following steps: collecting metadata of original traffic in an IPv6 network; selecting a multi-dimensional feature vector from the metadata, processing the multi-dimensional feature vector, and generating a unique and stable fingerprint identifier for each device; sending a detection packet to the target device, calculating a forward path hop count, estimating a return path hop count of a response packet to obtain a reverse path hop count, and detecting the path by comparing the forward path hop count with the reverse path hop count; taking the fingerprint identifier as a topological node, taking a bidirectional path hop count detection value as a topological edge weight between devices, constructing an initial topological skeleton through a minimum spanning tree algorithm, and performing clustering optimization in combination with auxiliary data to obtain a network topological structure; and automatically deducing a hierarchical relationship according to the fingerprint identifier, the node hop count, the connection closeness and the behavior consistency, and generating an interactive logic topological graph for displaying abnormal nodes and associated paths.
Owner:NAT COMPUTER NETWORK & INFORMATION SECURITY MANAGEMENT CENT JIANGXI BRANCH

Packet processing method, device, system, and storage medium

This application provides a packet processing method, a device, a system, and a storage medium. A first network device receives an original packet, generates an IPv6 packet based on the original packet and endpoint group (EPG) information, where the IPv6 packet comprises an IPv6 extension header and the original packet, and the IPv6 extension header comprises the EPG information, and sends the IPv6 packet. A second network device receives the IPv6 packet;obtains the EPG information from the IPv6 extension header, and processes the IPv6 packet according to a group based policy corresponding to the EPG information.
Owner:HUAWEI TECH CO LTD

A multi-level management, multi-functional IPv6 traffic monitoring platform

This invention relates to a multi-level managed IPv6 traffic multi-functional monitoring platform, comprising a data acquisition layer, a regional monitoring layer, a core analysis layer, a control and orchestration layer, and a feedback optimization layer. The data acquisition layer, located at the network edge, is responsible for collecting real-time traffic data and performing preliminary traffic classification and anomaly detection. The regional monitoring layer is distributed across various regions, aggregating edge data to construct a regional traffic feature database, while simultaneously handling local traffic anomalies and executing response strategies. The core analysis layer contains a centralized platform core computing unit that optimizes the global AI model through federated learning and introduces a dual-stream neural network to fuse global and personalized features, providing cross-regional collaborative monitoring and global optimization. The control and orchestration layer provides dynamic resource allocation and policy adjustment, coordinating the operation of global and regional nodes. The feedback optimization layer combines digital twins and reinforcement learning to continuously optimize traffic scheduling and protection strategies.
Owner:NAT COMPUTER NETWORK & INFORMATION SECURITY MANAGEMENT CENT JIANGXI BRANCH

User service charging method, network element and related equipment

The invention provides a user service charging method, a network element and related equipment, and relates to the technical field of communication. The method comprises: receiving user traffic data sent by a user plane network element, the user traffic data being obtained by the user plane network element counting a first service message, the first service message comprising a first IPv6-based segment routing SRv6 segment list; when the charging triggering condition is met, a charging data request is sent to a charging network element through a charging triggering network element, the charging triggering network element is arranged in a session management network element, and the charging data request comprises user flow data. Through the technical means, the problem that the differentiated service based on the SRv6 path cannot be charged in the related technology is solved.
Owner:CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1

Public Cloud-Based Virtual Instance Configuration Method and Cloud Management Platform

This application discloses a public cloud-based virtual instance configuration method and a cloud management platform, to simplify an operation of a tenant, quickly respond to a virtual instance creation requirement and an address management requirement of the tenant, and reduce time costs for the tenant, thereby improving user experience. The method in this application includes: After receiving configuration information that is of a to-be-created virtual instance and that is input by a first tenant, based on the configuration information, the cloud management platform may select a first site from a plurality of sites, select a first physical server from a plurality of physical servers at the first site, create a first virtual instance on the first physical server, and allocate an IPv6-format first network address to the first virtual instance.
Owner:HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD

Security protection method and device for IPv6 network attack, electronic equipment and medium

The invention provides a security protection method for IPv6 network attacks, and relates to the technical field of Internet security. The method comprises the steps that a backbone network topology structure is built, the backbone network topology structure comprises an access layer router and a core layer router, and the access layer router and the core layer router are communicated in advance; a BGP4 + routing protocol is deployed based on the backbone network topology structure, and the BGP4 + routing protocol is used for enabling routers in the whole network in the backbone network topology structure to achieve BGP4 + routing reachability; an address control routing strategy is configured based on the backbone network topology structure, and the address control routing strategy is configured to be capable of notifying a forbidden target address to the whole network through a BGP4 + routing protocol; and in response to matching of the attack traffic with the target address in the access layer router, blocking the attack traffic to complete security protection. The invention further provides a security protection device for the IPv6 network attack, electronic equipment and a medium.
Owner:CERNET CORP

IPv6 traffic analysis method and device, electronic equipment and storage medium

The invention discloses an IPv6 traffic analysis method and device, electronic equipment and a storage medium, and relates to the technical field of communication, and the method comprises the steps: obtaining IPv6 traffic monitoring data of a to-be-verified network; analyzing the IPv6 flow monitoring data, and determining an initial influence factor; the initial influence factor represents a factor influencing the IPv6 flow ratio; verifying the initial influence factor based on the simulation network to obtain a verification result, and obtaining a target influence factor based on the verification result; the verification result represents the influence proportion of the target influence factor on the IPv6 flow ratio. Therefore, the influence proportion of each complex factor on the IPv6 traffic proportion can be verified, and accurate analysis of the IPv6 traffic proportion is realized.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD

Distributed cloud node scheduling management method and device, medium and equipment

The application provides a distributed cloud node scheduling management method and device, medium and equipment. The method comprises the following steps: creating a distributed cloud computing task according to actual requirements in an application scenario; splitting the distributed cloud computing task into a plurality of cloud computing subtasks; creating corresponding computing power on a cloud node of a cloud branch of a distributed cloud for each cloud computing subtask, and allocating corresponding IPv6 resources to the computing power; determining the interconnection mode between each cloud computing subtask, creating a corresponding virtual interconnection channel according to the interconnection mode; each computing power executes the corresponding cloud computing subtask, and data interaction is realized based on the IPv6 resources and the virtual interconnection channel in the computing process; and after each cloud computing subtask is executed, the calculation results are summarized and result feedback is performed. The distributed cloud computing power provided based on the IPv6 protocol can meet the needs of cloud development.
Owner:SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD

An interface fault early warning method based on state sequence statistical characteristics and a server

The application discloses an interface fault early warning method based on state sequence statistical characteristics and a server, and relates to the field of operation and maintenance.The method comprises the following steps: collecting the physical layer, IPv4 layer and IPv6 layer states of each interface of a network device, and aligning the states in time sequence to form a multilayer state sequence. Intermittent jitter interfaces with frequent state changes and high availability are identified. Each state change is analyzed one by one, and it is judged whether each layer changes synchronously according to a preset time window, and marked as multilayer linkage or single layer independent change. The linkage change frequency and linkage synchronization rate are calculated according to a statistical unit, and two types of time sequence are generated. When the linkage synchronization rate in the observation window continuously exceeds the threshold value, the linkage change frequency sequence is linearly fitted to obtain a deterioration rate. If the deterioration rate is positive and exceeds the threshold value, the remaining available time window is calculated according to the rate, the current frequency and the unavailable frequency threshold value, and time prediction and fault early warning are output. By implementing the application, the ability to judge the continuous deterioration of the interface health condition can be improved.
Owner:SHENYANG QIANGXIN COMM TECH CO LTD

Data transmission control method and apparatus, network element, and medium

ActiveCN116436847BPathPingEngineering
The application discloses a data transmission control method and device, a network element and a medium. The method comprises the following steps: when a data packet is received, a two-layer member link adjacency segment identifier corresponding to a segment routing based on an IPv6 forwarding plane of the data packet is acquired; a first forwarding path corresponding to the data packet is determined according to the two-layer member link adjacency segment identifier; when the first forwarding path has a fault, a processing mode corresponding to the two-layer member link adjacency segment identifier is determined, and the data packet is processed according to the processing mode. The application improves the flexibility of data packet transmission and processing.
Owner:CHINA MOBILE COMM GRP CO LTD

Lightweight DTLS protocol optimization and dual-mode link secure transmission method

The invention is suitable for the technical field of power internet of things security communication, and relates to a lightweight DTLS protocol optimization and dual-mode link secure transmission method, which is simple in process and convenient to operate, and realizes protocol lightweight by simplifying a DTLS handshake process and adapting to a lightweight encryption algorithm; through a link-key dynamic binding mechanism, a DTLS session key is associated with a PLC / RF link state, so that re-handshake during link switching is avoided; and the data transmission security is ensured by combining forward error correction and integrity verification. According to the invention, the handshake message is reduced by 40%, the computing power occupation is reduced by 35%, the link switching delay is less than or equal to 50ms, the IPv6 protocol and the DL / T645 power protocol are supported, the safety communication requirements of terminals such as low-voltage transformer area electricity meters and photovoltaic inverters are met, the method is compatible with an electric red operating system, and the reliability and the safety of dual-mode link transmission are improved.
Owner:CHINA SOUTHERN POWER GRID COMPANY

Optimization method for multicast SSM path in IPv6 environment

This invention discloses a method for optimizing multicast paths in a specified source multicast SSM environment under IPv6, relating to the field of IPv6 multicast transmission technology. The method includes acquiring real-time network node status information and establishing a network performance model, quantifying the transmission cost and potential bottlenecks of each link in the path, and calculating the comprehensive transmission overhead estimate of the initial multicast forwarding path. A path evolution engine searches for a set of alternative forwarding paths in the network topology, calculates the comprehensive transmission overhead estimate of each alternative path, filters out a set of candidate optimized paths with lower overhead than the initial path, selects the path with the lowest overhead as the optimized multicast forwarding path, and forwards the multicast data to the receiver along this path. This invention can achieve accurate quantification of link-level transmission performance, adapt to real-time network status, determine the optimal path through two-level filtering, avoid link bottlenecks, reduce multicast transmission overhead, and improve the adaptability and transmission efficiency of IPv6 SSM multicast transmission.
Owner:HANGZHOU XIDE INTELLIGENT TECH CO LTD

A domain name resolution method, device and equipment

The application discloses a domain name resolution method and device, electronic equipment and a storage medium, comprising: a mirror server synchronously acquiring and storing mirror data of an IPv6 root server; a plurality of edge leaf nodes are used as exit hot standby gateways, so that the edge leaf nodes receive access requests of clients to the IPv6 root server; receiving the access request returned by the edge leaf node, and resolving the access request according to the mirror data, and returning the obtained resolution result to the edge leaf node, so that the edge leaf node returns the resolution result to the client. In this way, the deployment of the IPv6 root server mirror on the edge of the new metropolitan area cloud network can be realized, the mirror server can directly serve the edge users, which is equivalent to the function of directly accessing the global IPv6 root server, is simpler and more effective than the traditional non-real-time and step-by-step resolution recursion, and significantly improves the efficiency and response speed of the IPv6 domain name resolution.
Owner:CHINA TELECOM CORP LTD

Method and device for evaluating website function accessibility in IPv6 single-stack environment

The invention discloses a website function accessibility evaluation method and device in an IPv6 single-stack environment, and belongs to the technical field of network function detection. The invention aims to solve the problem that in the prior art, website resource dependence and function accessibility cannot be comprehensively detected in an IPv6 single-stack environment. The method comprises the following steps: dynamically creating an isolated IPv6 single-stack network environment, starting a headless browser to capture all resource requests of a webpage, constructing a resource dependency graph, carrying out IPv6 reachability test on each resource, calculating a weighted accessibility score and generating a visual report. According to the method, the IPv6 single-stack user access behavior can be accurately simulated, the target website and all dependent resources of the target website can be comprehensively evaluated, a quantitative accessibility score and a visual dependency relationship visualization graph are provided, and accurate and operable diagnosis information is provided for website developers and operation and maintenance personnel.
Owner:INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES

Data transmission path determination method and device, computer equipment, storage medium and computer program product

The invention relates to a data transmission path determination method and device, computer equipment, a storage medium and a computer program product. Relates to the technical field of computer networks. The method comprises the following steps: receiving an IPv6 data packet sent by a first terminal; ethernet frames sent to the second terminal by the first terminal are packaged in the IPv6 data packet; extracting an identification tuple of the IPv6 data packet from the IPv6 data packet; the identification tuple is a parameter set used for identifying the IPv6 data packet; generating a hash value according to the identification tuple, and determining a corresponding routing table according to the prefix of the network address of the second terminal; selecting a target path from a plurality of equal-cost paths contained in a routing table according to the hash value; and forwarding the IPv6 data packet to the second terminal through the target path. By adopting the method, the efficiency of data transmission in an Ethernet virtual private network environment by an equal-cost multi-path routing technology can be improved.
Owner:CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1

A concurrency control and traffic scheduling system for card data interaction

This invention discloses a concurrency control and traffic scheduling system for card data interaction, relating to the fields of Internet of Things communications and distributed data processing technology. By adding a semantic addressing intent field (PIF) to the IPv6 extension header, the system enables switches to complete parsing and direct traffic to SmartNICs within 16ns. The SmartNIC generates a time-slot micro-ledger with a 500µs cycle and pre-allocates transaction locks using the Edge-Lock Weaving algorithm. Backend nodes complete strongly consistent transaction submissions using a single round of RDMA using a fast two-phase commit protocol. Dynamic congestion management is achieved through a dual-layer token bucket combined with flight windows. This solution achieves nanosecond read and write speeds, sub-millisecond submissions, and highly available decentralized scalability, significantly improving latency, throughput, and fault tolerance.
Owner:SHENZHEN KUYU INTERACTIVE TECH CO LTD

Differentiated network services using map-t translation technology

Methods and systems for providing differentiated network services using Mapping of Address and Port using translation (MAP-T) technology are described. A method includes provisioning a service specific IPv6 network prefix and a service specific basic mapping rule to an access device, the service specific IPv6 network prefix associated with a differentiated network service level, provisioning a service specific mapping rule to a border relay, identifying by the access device service packets associated with the differentiated network service level, translating by the access device the identified service packets to the service specific IPv6 network prefix using the service specific basic mapping rule to generate service specific packets, forwarding the service specific packets to the border relay via a service provider network, translating return packets to service specific return packets using the service specific mapping rule, and forwarding the service specific return packets to the access device.
Owner:CHARTER COMM OPERATING LLC

Method for encrypting and decrypting ipv6 message based on quantum key application mechanism

The application provides an IPv6 message encryption and decryption method based on a quantum key application mechanism, which is realized by a sending end and a receiving end in cooperation, and the sending end and the receiving end exchange roles when transmitting back to realize the encryption transmission of messages in the opposite direction by the same processing procedure; the messages are directly encrypted by using quantum keys, and the message encapsulation uses the extensible characteristics of the IPv6 protocol, and a new extension message header is added in the header of the IPv6 message to record the parameters used for message encryption. The combination of the quantum key encryption and the message of the IPv6 is the innovation point in the application, the quantum key is directly used for encryption when the message is encrypted and decrypted, other key negotiation methods are not needed, and other network protocol negotiation keys are not needed, so that the scheme is safer and simpler. The application encapsulates the encrypted message by using the extensible characteristics of the IPv6 protocol, so that the encrypted message is still a standard IPv6 message, and the messages of the whole scheme follow the IPv6 protocol without additional protocol overhead.
Owner:CAS QUANTUM NETWORK CO LTD

Service chain processing method and device, equipment, storage medium and program product

The invention provides a service chain processing method and device, equipment, a storage medium and a program product, and relates to the technical field of communication, the method is applied to first equipment, the first equipment is gateway entrance equipment of a service chain, and the method comprises the following steps: receiving a service flow and analyzing an SID in the service flow; under the condition that the SID is analyzed to obtain a first function, an IPv6 message in the service flow is analyzed to obtain an application and network capability identifier; wherein the application and network capability identifier is used for indicating a service function (SF); and obtaining an outbound interface or an IP address to a next hop node corresponding to the SF indicated by the application and network capability identifier. Therefore, the service flow can be forwarded based on the outbound interface or the IP address, so that the SID is only used as the identifier of the network path, the coupling degree of the SID and the service is reduced, the number of the SID is reduced, and the routing complexity is reduced.
Owner:CHINA MOBILE COMM LTD RES INST +1