IPv6 Prefix Filtering for Unauthorized Packet Blocking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is no technology available in IPv6 network environments to automatically configure rules for blocking unauthorized IPv6 packets, similar to those in IPv4 networks, which poses a security risk.
Innovation Solution
A communication control device and system that receive prefix information from a router advertisement, store it, and use this information to block or allow communication packets based on matching or non-matching source and destination addresses, ensuring only authorized packets are passed through.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If prefix information is stored and used to block packets, then network security is improved, but device complexity increases
Solution Approach 1:
The communication control device receives and stores prefix information from router advertisements in advance before blocking packets. This preliminary action of storing authorized prefixes enables the device to automatically identify and block unauthorized packets without complex real-time analysis, resolving the contradiction between security improvement and device complexity.
2Ease of operation
If automatic rule configuration is implemented, then ease of operation is improved, but device complexity increases
Solution Approach 1:
The communication control device automatically configures blocking rules by receiving router advertisements and autonomously determining which packets to block based on stored prefix information. This self-service mechanism eliminates the need for manual rule configuration while maintaining simple device architecture, resolving the contradiction between ease of operation and device complexity.
Data Source
AI summary
A communication control apparatus (1) is connected to a router (6) and a terminal device (4), and upon receiving prefix information transmitted from the router (6) by a router advertisement, stores the prefix information. In a case where prefix information of a transmission source address or a destination address, which is included in the received communication packet, is different from the stored prefix information, the communication control apparatus (1) blocks the communication packet, and in a case where the prefix information of the transmission source address or the destination address, which is included in the received communication packet, is the stored prefix information, the communication control apparatus (1) allows passing of the communication packet. In such a way, an unauthorized communication packet can be blocked appropriately under an IPv6 network environment.


