Ethernet Ring Edge Device Packet Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Ethernet rings face security vulnerabilities due to potential packet forging by hackers through third-party networks, as existing security measures are inadequate in verifying the authenticity of packets transmitted within the ring.

Innovation Solution

A packet processing method and system where edge devices verify the validity of incoming packets based on identifier and authentication information, using encryption and authentication algorithms to ensure only valid packets are processed, thereby enhancing security by preventing forged packets from attacking the Ethernet ring.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If edge devices allow packets from third-party networks to enter the Ethernet ring, then network connectivity and adaptability are improved, but security deteriorates due to potential packet forging attacks

Engineering Contradiction:
Improvenetwork connectivityVSAvoidpacket forging attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by pre-configuring authentication information and identifier information in edge devices before packets arrive. When a packet enters from a third-party network, the edge device immediately verifies the packet's identifier information against the pre-stored authentication information. This advance preparation enables rapid security verification without affecting network connectivity, allowing legitimate packets to pass through while blocking forged packets from hackers.

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If authentication verification is implemented for all incoming packets, then security is improved, but device complexity and processing overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidverification complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent applies local quality by implementing authentication verification only at edge devices where packets enter from third-party networks, rather than requiring all devices in the Ethernet ring to perform complex verification. The edge devices are specifically configured with authentication information and identifier information, creating a localized security checkpoint. This approach maintains high security while minimizing overall system complexity, as internal ring devices can process packets without full authentication capabilities.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If authentication information is stored in edge devices, then security verification accuracy is improved, but information storage requirements and device configuration complexity increase

Engineering Contradiction:
Improveverification accuracyVSAvoidinformation storage
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent applies the taking out principle by extracting only the essential authentication elements (identifier information and authentication information) needed for verification, rather than storing complete packet data or extensive configuration details. The edge devices store compact authentication information that enables accurate verification of incoming packets. This selective extraction maintains high verification accuracy while minimizing storage requirements and simplifying device configuration compared to storing comprehensive packet metadata or full authentication protocols.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP4044547B1Message processing method, apparatus, and system
Publication Date: 2024.10.30 HUAWEI TECH CO LTD
  • EP4044547B1 patent drawingFigure 1~2
  • EP4044547B1 patent drawingFigure 3
  • EP4044547B1 patent drawingFigure 4

AI summary

This application discloses a packet processing method, apparatus, and system, and belongs to the communications field. The method includes: A first device receives a first packet sent by a second device, where the first packet includes identifier information and first authentication information of an Ethernet ring, the first device is an edge device of the Ethernet ring, and the second device is a device outside the Ethernet ring. The first device verifies validity of the first packet based on the identifier information and the first authentication information. The first device processes the first packet when verifying that the first packet is valid. This application can improve security of the Ethernet ring.