IPv6 Access Device Port Identifier for Dedicated Prefix Allocation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
IPv6 stateless configuration in access networks poses security and scalability issues due to the inability to allocate dedicated address prefixes for each DSL line, particularly in layer 2 access devices with limited VLAN identifiers and unsupported VLAN stacking.
Innovation Solution
Incorporating a relay-agent port identifier option in RS and RA messages allows the IPv6 edge router to allocate a specific address prefix for each DSL user, enabling stateless address configuration by encapsulating DSL line ID information, which supports bridge mode operation and shared VLANs without requiring VLAN stacking support.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If standard IPv6 stateless configuration is applied in access network, then configuration flexibility and plug&play capability are improved, but security and scalability deteriorate due to inability to allocate dedicated prefixes per DSL line
Solution Approach 1:
The patent segments the address configuration by allocating a dedicated IPv6 address prefix to each DSL line (port) at the access device. This is achieved by modifying the Router Advertisement message to include port identifier information, allowing the access device to maintain and enforce port-specific prefix assignments, thereby preventing IP address spoofing while maintaining configuration flexibility.
Solution Approach 2:
The access device acts as an intermediary between the edge router and user equipment. It intercepts Router Solicitation and Router Advertisement messages, extracts or assigns port identifier information, and forwards modified messages to/from the edge router. This intermediary function enables the access device to enforce port-specific prefix allocation without requiring changes to the edge router or user equipment.
2Ease of operation
If standard IPv6 stateless configuration is applied in access network, then configuration simplicity is improved, but scalability deteriorates due to RA message relay to all DSL line users
Solution Approach 1:
The patent segments the Router Advertisement message distribution by associating each RA message with a specific port identifier. The access device uses this port identifier to determine which DSL line (port) the RA message should be relayed to, thereby avoiding unnecessary message flooding to all ports and improving scalability.
Solution Approach 2:
The patent introduces port identifier information as a new parameter in the Router Advertisement message. This parameter enables the access device to make intelligent routing decisions based on the target port, transforming the broadcast-like RA message distribution into a targeted, scalable message relay mechanism.
3Reliability
If VLAN-based cross-connected mode is used to allocate dedicated prefix per DSL line, then security and scalability are improved, but device complexity increases due to VLAN configuration requirements
Solution Approach 1:
The patent changes the parameter used for port identification from VLAN ID to a simpler port identifier that can be derived from the access device's internal port numbering. This eliminates the need for complex VLAN configuration and mapping while achieving the same security and scalability benefits of dedicated prefix allocation per DSL line.
Solution Approach 2:
Instead of using VLAN configuration to achieve port-specific prefix allocation (complex approach), the patent inverts the approach by using simple port identifiers directly in the IPv6 Neighbor Discovery messages. This simplifies the configuration while maintaining the ability to allocate dedicated prefixes per port.
4Reliability
If VLAN identifier limit is reached in cross-connected mode, then security and scalability are maintained, but adaptability deteriorates due to inability to support additional DSL lines
Solution Approach 1:
The patent segments the port identification mechanism from the VLAN identifier space. By using port-specific identifiers that are independent of VLAN configuration, the system can support additional DSL lines beyond the VLAN identifier limit while maintaining dedicated prefix allocation and security.
Solution Approach 2:
The port identifier mechanism is designed to be universal and independent of VLAN configuration. It can identify and differentiate any number of DSL lines without being constrained by VLAN identifier limitations, thereby providing multi-functionality that supports both security requirements and scalability to additional users.
Data Source
AI summary
The present invention relates to an IPv6-based access device, edge router and method for stainless address configuration for IPv6 user equipment in an Ethernet access network, wherein, the access device adds the relay agent ID indicating the access device itself and the relevant port identifier indicating the user equipment to a router solicitation message sent by the user equipment in the form of a newly defined option, and forwards the message to the relevant edge router; and the edge router configures a dedicated address prefix for the user equipment according to the relay agent ID and port identifier, combines the address prefix, the relay ID and the port identifier into a router response message, and sends the response message to the relevant access equipment indicated by the relay ID; the access device sends a router advertisement message only including the address prefix via the line port indicated by the port identifier to user equipment. By allocating the dedicated address prefix to every data subscriber line for IPv6 service, IPv6 stainless address configuration is achieved to solve the security and scalability problems in the prior art.


