Packet Forwarding Device Authentication for QoS Integrity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

QoS technologies like DiffServ and RSVP rely on stored values in packet headers for priority control, making them vulnerable to counterfeiting, which can lead to network faults and attacks by maliciously altered packets.

Innovation Solution

A packet forwarding device with an evaluation unit to authenticate communication quality control information in packet headers, using a secret shared key to verify the authenticity of the information, and a forwarding unit to control packet forwarding based on proper authentication, thereby preventing the influence of counterfeit packets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If QoS technology uses stored values in packet headers for priority control, then communication quality control is achieved, but the system becomes vulnerable to counterfeit packets

Engineering Contradiction:
Improvecommunication quality controlVSAvoidcounterfeit packet vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by pre-storing authentication information (such as MAC addresses or digital signatures) in the packet header before the packet enters the network. This allows receiving devices to verify the authenticity of the packet in advance, preventing counterfeit packets from being processed while maintaining legitimate QoS functionality.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces authentication information as an intermediary element between the packet header and the QoS control mechanism. This intermediary layer verifies the legitimacy of the packet before QoS processing occurs, thereby protecting against counterfeit packets while preserving the original QoS control capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication information is added to packet headers, then counterfeit packets are prevented, but packet processing complexity increases

Engineering Contradiction:
Improvepacket authenticationVSAvoidpacket processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by implementing authentication only at specific critical points in the packet processing pipeline, such as at the receiving end or at gateway devices, rather than requiring authentication at every node. This selective approach reduces overall system complexity while maintaining security effectiveness.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent uses copying by storing authentication information in a lookup table or database at receiving devices, allowing fast verification without complex real-time authentication calculations. This pre-computed copy of authentication data enables efficient verification while reducing processing complexity.

Inventive Principle:
Principle #26Copying

3Reliability

If authentication verification is performed for every packet, then network security is improved, but processing time increases

Engineering Contradiction:
Improvenetwork securityVSAvoidpacket processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-computing and storing authentication results in lookup tables, allowing receiving devices to perform fast verification through simple table lookups rather than complex real-time calculations. This significantly reduces packet processing time while maintaining strong security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the parameter of authentication verification from complex real-time computation to fast table lookup by pre-computing authentication results. This parameter change transforms the verification process into a low-time-cost operation while preserving network security.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9397994B2Packet forwarding device, packet forwarding system, and packet forwarding method
Publication Date: 2016.07.19 YOKOGAWA ELECTRIC CORP
  • US9397994B2 patent drawing
  • US9397994B2 patent drawing
  • US9397994B2 patent drawing

AI summary

A packet forwarding device includes: an evaluation unit configured to judge whether or not authentication information is stored in a header, the authentication information being for authenticating communication quality control information stored in the header of a packet transmitted via a network, and evaluate whether or not the authentication information is proper, the evaluation being made when the authentication information is stored in the header; and a forwarding unit that configured to control a communication quality using the communication quality control information, and forward the packet toward a transmission destination, the control being made when the authentication information is evaluated by the evaluation unit to be proper.