IPv6 Prefix Filtering for Unauthorized Packet Blocking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is no technology available in IPv6 network environments to automatically configure rules for blocking unauthorized IPv6 packets, similar to those in IPv4 networks, which poses a security risk.

Innovation Solution

A communication control device and system that receive prefix information from a router advertisement, store it, and use this information to block or allow communication packets based on matching or non-matching source and destination addresses, ensuring only authorized packets are passed through.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If prefix information is stored and used to block packets, then network security is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The communication control device receives and stores prefix information from router advertisements in advance before blocking packets. This preliminary action of storing authorized prefixes enables the device to automatically identify and block unauthorized packets without complex real-time analysis, resolving the contradiction between security improvement and device complexity.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If automatic rule configuration is implemented, then ease of operation is improved, but device complexity increases

Engineering Contradiction:
Improveease of operationVSAvoiddevice complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The communication control device automatically configures blocking rules by receiving router advertisements and autonomously determining which packets to block based on stored prefix information. This self-service mechanism eliminates the need for manual rule configuration while maintaining simple device architecture, resolving the contradiction between ease of operation and device complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9100433B2Communications control device, communications system, and program
Publication Date: 2015.08.04 PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD
  • US9100433B2 patent drawing
  • US9100433B2 patent drawing
  • US9100433B2 patent drawing

AI summary

A communication control apparatus (1) is connected to a router (6) and a terminal device (4), and upon receiving prefix information transmitted from the router (6) by a router advertisement, stores the prefix information. In a case where prefix information of a transmission source address or a destination address, which is included in the received communication packet, is different from the stored prefix information, the communication control apparatus (1) blocks the communication packet, and in a case where the prefix information of the transmission source address or the destination address, which is included in the received communication packet, is the stored prefix information, the communication control apparatus (1) allows passing of the communication packet. In such a way, an unauthorized communication packet can be blocked appropriately under an IPv6 network environment.