Data Packet Processing Using DSCP Identification for Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network security devices struggle to accurately allow or forbid access behavior due to IP address translation in virtualization technologies, leading to invalid security policies and incorrect decision-making.

Innovation Solution

Write identification information into the DSCP field of data packets, which remains unchanged during transmission, allowing all network devices to accurately determine access behavior based on real identification information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If IP address translation is used in virtualization technologies, then device mobility and resource sharing are improved, but security policy accuracy deteriorates

Engineering Contradiction:
Improvedevice mobilityVSAvoidsecurity policy accuracy
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The patent introduces DSCP field as an intermediary carrier to transport real IP address information through the network. Instead of relying on the translated IP address in the packet header, the system uses the DSCP field as a mediator to carry the original IP address information, allowing security devices to accurately identify the real source IP address even when IP translation is applied in virtualization environments.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If existing IP address fields are used for security policies, then device complexity is reduced, but information accuracy is lost due to IP translation

Engineering Contradiction:
Improvedevice complexityVSAvoidreal IP address information
Core Design Contradiction:
Device complexityVSLoss of information

Solution Approach 1:

The patent leverages the existing DSCP field's universality in data packets. The DSCP field, which is already universally present and understood by network devices for quality of service purposes, is repurposed to carry real IP address information. This multi-functional use of the DSCP field avoids the need for new packet formats or additional header fields, maintaining simplicity while solving the information loss problem.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If IP address translation is applied, then network virtualization capability is improved, but security decision accuracy deteriorates

Engineering Contradiction:
Improvenetwork virtualizationVSAvoidsecurity decision accuracy
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by marking the real IP address information in the DSCP field at the source or at an intermediate point before the packet reaches the security device. This preliminary marking ensures that the real IP address information is preserved and available for security decisions even after IP translation has occurred, allowing security devices to make accurate decisions without needing to reverse the translation process.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250254125A1Data Packet Processing Method and Related Apparatus
Publication Date: 2025.08.07 HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
  • US20250254125A1 patent drawing
  • US20250254125A1 patent drawing
  • US20250254125A1 patent drawing

AI summary

A data packet processing method includes that when a destination address of a first data packet points to a first object, after writing identification information into a DSCP field of the first data packet, a first device sends the first data packet. After obtaining the first data packet, a second device allows or forbids, based on the identification information in the DSCP field of the first data packet, access behavior corresponding to the first data packet. Because a value of the DSCP field generally does not change in a transmission process of a data packet, the second device can obtain real identification information from the DSCP field, and can accurately make a decision of allowing or forbidding access behavior corresponding to the data packet.