IPv6 Packet Filtering Using Flow Label Triplet

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current packet filtering in IPv4-based networks is complex due to the difficulty in obtaining source port and destination port information from IP packet headers, especially when encryption is involved, making it challenging to ensure quality of service and communication security.

Innovation Solution

A method and system for filtering packets in an IPv6-based network where a media gateway controller sets packet filtering information that uniquely identifies media stream characteristics in the packet header, allowing media gateways to filter packets based on source address, destination address, and flow label, simplifying the filtering process by using triplet information available in the IPv6 packet header.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If packet filtering is performed in IPv4-based networks using quintuplet information, then packet filtering capability is achieved, but filtering complexity increases due to difficulty in obtaining source port and destination port information

Engineering Contradiction:
Improvepacket filtering capabilityVSAvoidfiltering process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent transitions from IPv4 quintuplet parameters (source address, source port, destination address, destination port, protocol type) to IPv6 triplet parameters (source address, destination address, flow label). This parameter change eliminates the need to extract port information from encrypted packet bodies, as IPv6 flow labels are directly available in the packet header and uniquely identify media streams.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent extracts and utilizes the flow label field from the IPv6 packet header as a dedicated identifier for media streams. By taking out this specific parameter that is directly available in the header, the system avoids the complex process of extracting port information from encrypted packet bodies while maintaining reliable packet filtering capability.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If source port and destination port information is obtained by resolving IP packet body, then complete packet filtering information is achieved, but processing time increases and encryption makes resolution difficult

Engineering Contradiction:
Improvepacket filtering accuracyVSAvoidpacket processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The IPv6 flow label is预先 (in advance) embedded in the packet header by the sender, serving as a pre-prepared identifier for media stream identification. This preliminary action eliminates the need for time-consuming resolution of port information from packet bodies during filtering operations, as the flow label is directly available in the header for immediate use.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If encryption is applied to IP packet body, then communication security is improved, but packet filtering becomes more complex as port information cannot be easily obtained

Engineering Contradiction:
Improvecommunication securityVSAvoidpacket filtering complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The IPv6 flow label acts as an intermediary parameter that bridges the need for packet filtering and communication security. Instead of requiring decryption of the packet body to obtain port information, the flow label provides a secure, encrypted-friendly identifier that is directly available in the packet header, allowing filtering to proceed without compromising security or requiring complex decryption processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8089962B2Method, system and apparatus for filtering packets
Publication Date: 2012.01.03 HUAWEI TECH CO LTD
  • US8089962B2 patent drawing
  • US8089962B2 patent drawing
  • US8089962B2 patent drawing

AI summary

The present disclosure discloses a method, system, and apparatus for filtering packets. The method includes setting packet filtering information that uniquely identifies the basic characteristics of a media stream in an Internet Protocol version 6 (IPv6)-based packet header. As an apparatus for filtering packets, a media gateway (MG) uses the packet filtering information sent by the media gateway controller (MGC) to filter packets for the media stream when transferring the media stream. The method, system, and apparatus enable packet filtering for the media streams in an IPv6-based PS network. Moreover, the filtering conditions in the packet filtering information in the present disclosure is triplet information that uniquely identifies the basic characteristics of a media stream and can be obtained from the IPv6 packet header, thus reducing the complexity of the packet filtering process.