IPv6 Packet Signature Verification for Firewall Bypass Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In IPv6 networks, ensuring that packets pass through a specific key node, such as a firewall, for security is challenging due to potential tampering that can bypass these nodes.

Innovation Solution

A packet processing method that includes embedding a signature in the packet header of IPv6 packets, allowing downstream nodes to verify if the packet has passed through a designated key node by comparing the signature with a calculated hash based on the packet content.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IPv6 packets are forwarded through key nodes for security verification, then network security is improved, but packets may be tampered with to bypass these nodes

Engineering Contradiction:
Improvenetwork securityVSAvoidpacket tampering
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by embedding a signature in the packet header before the packet reaches the key node. This signature is generated in advance and included in the packet, allowing the key node to verify the packet's authenticity and ensure it has passed through the designated key node without being tampered with during forwarding.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback by having the key node verify the signature embedded in the packet header. This verification process provides feedback on whether the packet has legitimately passed through the key node, enabling the system to detect and prevent tampered packets that attempt to bypass security measures.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If a signature is embedded in the packet header for verification, then the ability to determine packet routing is improved, but the packet header complexity increases

Engineering Contradiction:
Improvepacket routing verificationVSAvoidpacket header structure
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies universality by using the packet header to serve multiple functions: it not only carries standard IPv6 routing information but also embeds the signature for verification purposes. This multi-functional use of the packet header allows routing verification without requiring entirely separate verification structures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes the parameters of the packet header by adding a signature field with specific format and verification rules. This parameter change enables the header to carry both routing information and verification data, improving measurement precision for routing verification while managing complexity through standardized parameter definitions.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12224978B2Packet processing method and apparatus
Publication Date: 2025.02.11 HUAWEI TECH CO LTD
  • US12224978B2 patent drawing
  • US12224978B2 patent drawing
  • US12224978B2 patent drawing

AI summary

A packet processing method and apparatus are provided. The method includes: on a forwarding path of an IPv6 packet, a key node (for example, a firewall) signs a packet, and a downstream apparatus of the key node verifies the signature, to determine whether the packet passes through the key node in a forwarding process. According to this application, the key node performs checking, to effectively prevent a packet which packet header is modified by attackers from bypassing the key node.