IPv6 Packet Signature Verification for Firewall Bypass Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In IPv6 networks, ensuring that packets pass through a specific key node, such as a firewall, for security is challenging due to potential tampering that can bypass these nodes.
Innovation Solution
A packet processing method that includes embedding a signature in the packet header of IPv6 packets, allowing downstream nodes to verify if the packet has passed through a designated key node by comparing the signature with a calculated hash based on the packet content.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If IPv6 packets are forwarded through key nodes for security verification, then network security is improved, but packets may be tampered with to bypass these nodes
Solution Approach 1:
The patent applies preliminary action by embedding a signature in the packet header before the packet reaches the key node. This signature is generated in advance and included in the packet, allowing the key node to verify the packet's authenticity and ensure it has passed through the designated key node without being tampered with during forwarding.
Solution Approach 2:
The patent implements feedback by having the key node verify the signature embedded in the packet header. This verification process provides feedback on whether the packet has legitimately passed through the key node, enabling the system to detect and prevent tampered packets that attempt to bypass security measures.
2Measurement precision
If a signature is embedded in the packet header for verification, then the ability to determine packet routing is improved, but the packet header complexity increases
Solution Approach 1:
The patent applies universality by using the packet header to serve multiple functions: it not only carries standard IPv6 routing information but also embeds the signature for verification purposes. This multi-functional use of the packet header allows routing verification without requiring entirely separate verification structures.
Solution Approach 2:
The patent changes the parameters of the packet header by adding a signature field with specific format and verification rules. This parameter change enables the header to carry both routing information and verification data, improving measurement precision for routing verification while managing complexity through standardized parameter definitions.
Data Source
AI summary
A packet processing method and apparatus are provided. The method includes: on a forwarding path of an IPv6 packet, a key node (for example, a firewall) signs a packet, and a downstream apparatus of the key node verifies the signature, to determine whether the packet passes through the key node in a forwarding process. According to this application, the key node performs checking, to effectively prevent a packet which packet header is modified by attackers from bypassing the key node.


