Data Packet Processing Using DSCP Identification for Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network security devices struggle to accurately allow or forbid access behavior due to IP address translation in virtualization technologies, leading to invalid security policies and incorrect decision-making.
Innovation Solution
Write identification information into the DSCP field of data packets, which remains unchanged during transmission, allowing all network devices to accurately determine access behavior based on real identification information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If IP address translation is used in virtualization technologies, then device mobility and resource sharing are improved, but security policy accuracy deteriorates
Solution Approach 1:
The patent introduces DSCP field as an intermediary carrier to transport real IP address information through the network. Instead of relying on the translated IP address in the packet header, the system uses the DSCP field as a mediator to carry the original IP address information, allowing security devices to accurately identify the real source IP address even when IP translation is applied in virtualization environments.
2Device complexity
If existing IP address fields are used for security policies, then device complexity is reduced, but information accuracy is lost due to IP translation
Solution Approach 1:
The patent leverages the existing DSCP field's universality in data packets. The DSCP field, which is already universally present and understood by network devices for quality of service purposes, is repurposed to carry real IP address information. This multi-functional use of the DSCP field avoids the need for new packet formats or additional header fields, maintaining simplicity while solving the information loss problem.
3Adaptability or versatility
If IP address translation is applied, then network virtualization capability is improved, but security decision accuracy deteriorates
Solution Approach 1:
The patent applies preliminary action by marking the real IP address information in the DSCP field at the source or at an intermediate point before the packet reaches the security device. This preliminary marking ensures that the real IP address information is preserved and available for security decisions even after IP translation has occurred, allowing security devices to make accurate decisions without needing to reverse the translation process.
Data Source
AI summary
A data packet processing method includes that when a destination address of a first data packet points to a first object, after writing identification information into a DSCP field of the first data packet, a first device sends the first data packet. After obtaining the first data packet, a second device allows or forbids, based on the identification information in the DSCP field of the first data packet, access behavior corresponding to the first data packet. Because a value of the DSCP field generally does not change in a transmission process of a data packet, the second device can obtain real identification information from the DSCP field, and can accurately make a decision of allowing or forbidding access behavior corresponding to the data packet.


