SRv6 Packet Forwarding With SID-Based Security Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The SRv6 packet forwarding is compromised by unreliable network nodes or links, leading to security issues.
Innovation Solution
Implement security authentication processing on SRv6 packets based on a target argument indicated by a security authentication instruction in the segment identifier (SID) of the packet header, performing encapsulation or decapsulation as needed, and forwarding the processed packet.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If SRv6 packet forwarding is performed without security authentication, then forwarding efficiency is maintained, but security is compromised due to unreliable network nodes or links
Solution Approach 1:
The patent applies preliminary action by embedding security authentication instructions and arguments directly into the SID (Segment Identifier) during packet generation. The originating network node performs security authentication processing in advance, embedding the authentication mechanism into the packet header itself. This allows intermediate network nodes to perform authentication verification without adding extra processing steps, thus maintaining forwarding efficiency while improving security.
Solution Approach 2:
The patent uses the SID (Segment Identifier) as an intermediary to carry security authentication information. The SID serves as both a routing identifier and a security credential carrier, embedding authentication instructions and arguments within its structure. This intermediary approach allows security authentication to be integrated into the existing SRv6 forwarding mechanism without requiring separate authentication protocols or additional packet processing steps.
2Reliability
If security authentication instructions are embedded in SID, then security is improved, but device complexity increases
Solution Approach 1:
The patent applies universality by making the SID multi-functional. The SID not only performs its traditional routing function but also carries security authentication instructions and arguments. By encoding authentication information within the existing SID structure (using function fields and argument fields), the patent avoids adding separate authentication data structures. This multi-functionality reduces overall system complexity while embedding security mechanisms.
Solution Approach 2:
The patent changes the parameters of the SID structure to accommodate security authentication. Specific function fields and argument fields within the SID are assigned security-related meanings and values. For example, certain function field values indicate authentication operations, while argument fields contain authentication credentials. This parameter transformation allows the existing SID framework to support security authentication without structural modifications.
Data Source
AI summary
Method and apparatus for packet forwarding, which relate to the network technology field and are applied to a network node. The method comprises: obtaining an SRV6 packet; if a function field in a target SID contains a security authentication instruction, obtaining a target argument based on an operation indicated by the security authentication instruction, and performing security authentication processing on the SRv6 packet based on the target argument; wherein, the target SID is an SID, corresponding to the network node, in a segment list carried by a header of the SRv6 packet, and the target argument is: an argument for the security authentication instruction recorded in the header; and forwarding the processed SRv6 packet to a next-hop device. By applying the solution for packet forwarding according to examples of the present disclosure, the security in forwarding the SRv6 packet along the SRv6 forwarding path can be improved.


