IPv6 Access Node Packet Forwarding via Network Prefix Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Implementing network security measures like IP address anti-spoofing in IPv6 access networks is challenging due to increased storage and operational requirements, and the inability to obtain and verify IPv6 address lists used by user terminals.
Innovation Solution
The access node device in an IPv6 access network saves valid network prefixes and checks the network prefix portion of IPv6 addresses, allowing for efficient forwarding of packets by snooping network prefix allocation messages, reducing the need for large storage and enhancing operational performance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If IP address anti-spoofing is implemented in IPv6 access network, then network security is improved, but storage capacity and operational performance requirements increase significantly
Solution Approach 1:
The invention segments the IPv6 address verification process by checking only the network prefix portion (e.g., first 64 bits) rather than the complete IPv6 address. This segmentation reduces the verification data from 128 bits to 64 bits or less, significantly decreasing storage requirements while maintaining security effectiveness.
Solution Approach 2:
The invention extracts only the essential network prefix information from the complete IPv6 address for verification purposes. By taking out and verifying only the network prefix portion rather than the full address, the system achieves security verification with reduced storage and operational overhead.
2Measurement precision
If complete IPv6 address lists are stored for anti-spoofing verification, then verification accuracy is improved, but device complexity and construction cost increase
Solution Approach 1:
The invention extracts only the network prefix portion from complete IPv6 addresses for storage and verification. This extraction approach maintains verification accuracy by checking the essential routing information while eliminating the need to store and process the full IPv6 address space, thereby reducing device complexity.
Solution Approach 2:
The invention changes the verification parameter from complete IPv6 addresses (128 bits) to network prefixes (64 bits or less). This parameter change reduces the data volume requiring storage and processing while maintaining the ability to accurately verify whether packets originate from authorized networks.
3Quantity of substance
If network prefix checking is implemented instead of full IPv6 address verification, then storage requirements are reduced, but verification precision may be compromised
Solution Approach 1:
The invention segments the IPv6 address into network prefix and host identifier portions, verifying only the network prefix. This segmentation approach reduces storage requirements while maintaining verification precision for network-level security, as the network prefix uniquely identifies the originating network.
Solution Approach 2:
The invention applies partial verification by checking only the necessary network prefix portion rather than the complete IPv6 address. This partial action is sufficient for anti-spoofing purposes since the network prefix uniquely identifies the source network, avoiding the need to verify the entire address while maintaining adequate security precision.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
In view of the technical problems that exist during implementing IP address anti-spoofing in an access node device in an IPv6 access network, the present invention proposes a packet forwarding method and apparatus in an IPv6 Access Node, for forwarding a packet from a Residential Gateway. In the method, the access node device first receives a packet from the Residential Gateway, then obtains a network prefix in a source UPv6 address of the packet, judges whether the network prefix in the source IPv6 address of the packet is a valid network prefix of a CPN corresponding to the Residential Gateway, and if yes, forwards the packet finally. Particularly, in the present invention the access node device can automatically obtain valid network prefix using technical means such as snooping a network prefix allocation reply message. Therefore, the present invention greatly increases operation efficiency and security of the IPv6 access network and simplifies network management of the IPv6 access network.