IPv6 Packet Filtering Using Flow Label Triplet
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current packet filtering in IPv4-based networks is complex due to the difficulty in obtaining source port and destination port information from IP packet headers, especially when encryption is involved, making it challenging to ensure quality of service and communication security.
Innovation Solution
A method and system for filtering packets in an IPv6-based network where a media gateway controller sets packet filtering information that uniquely identifies media stream characteristics in the packet header, allowing media gateways to filter packets based on source address, destination address, and flow label, simplifying the filtering process by using triplet information available in the IPv6 packet header.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If packet filtering is performed in IPv4-based networks using quintuplet information, then packet filtering capability is achieved, but filtering complexity increases due to difficulty in obtaining source port and destination port information
Solution Approach 1:
The patent transitions from IPv4 quintuplet parameters (source address, source port, destination address, destination port, protocol type) to IPv6 triplet parameters (source address, destination address, flow label). This parameter change eliminates the need to extract port information from encrypted packet bodies, as IPv6 flow labels are directly available in the packet header and uniquely identify media streams.
Solution Approach 2:
The patent extracts and utilizes the flow label field from the IPv6 packet header as a dedicated identifier for media streams. By taking out this specific parameter that is directly available in the header, the system avoids the complex process of extracting port information from encrypted packet bodies while maintaining reliable packet filtering capability.
2Reliability
If source port and destination port information is obtained by resolving IP packet body, then complete packet filtering information is achieved, but processing time increases and encryption makes resolution difficult
Solution Approach 1:
The IPv6 flow label is预先 (in advance) embedded in the packet header by the sender, serving as a pre-prepared identifier for media stream identification. This preliminary action eliminates the need for time-consuming resolution of port information from packet bodies during filtering operations, as the flow label is directly available in the header for immediate use.
3Reliability
If encryption is applied to IP packet body, then communication security is improved, but packet filtering becomes more complex as port information cannot be easily obtained
Solution Approach 1:
The IPv6 flow label acts as an intermediary parameter that bridges the need for packet filtering and communication security. Instead of requiring decryption of the packet body to obtain port information, the flow label provides a secure, encrypted-friendly identifier that is directly available in the packet header, allowing filtering to proceed without compromising security or requiring complex decryption processes.
Data Source
AI summary
The present disclosure discloses a method, system, and apparatus for filtering packets. The method includes setting packet filtering information that uniquely identifies the basic characteristics of a media stream in an Internet Protocol version 6 (IPv6)-based packet header. As an apparatus for filtering packets, a media gateway (MG) uses the packet filtering information sent by the media gateway controller (MGC) to filter packets for the media stream when transferring the media stream. The method, system, and apparatus enable packet filtering for the media streams in an IPv6-based PS network. Moreover, the filtering conditions in the packet filtering information in the present disclosure is triplet information that uniquely identifies the basic characteristics of a media stream and can be obtained from the IPv6 packet header, thus reducing the complexity of the packet filtering process.


