SRv6 Packet Forwarding With SID-Based Security Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The SRv6 packet forwarding is compromised by unreliable network nodes or links, leading to security issues.

Innovation Solution

Implement security authentication processing on SRv6 packets based on a target argument indicated by a security authentication instruction in the segment identifier (SID) of the packet header, performing encapsulation or decapsulation as needed, and forwarding the processed packet.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If SRv6 packet forwarding is performed without security authentication, then forwarding efficiency is maintained, but security is compromised due to unreliable network nodes or links

Engineering Contradiction:
ImprovesecurityVSAvoidforwarding efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by embedding security authentication instructions and arguments directly into the SID (Segment Identifier) during packet generation. The originating network node performs security authentication processing in advance, embedding the authentication mechanism into the packet header itself. This allows intermediate network nodes to perform authentication verification without adding extra processing steps, thus maintaining forwarding efficiency while improving security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses the SID (Segment Identifier) as an intermediary to carry security authentication information. The SID serves as both a routing identifier and a security credential carrier, embedding authentication instructions and arguments within its structure. This intermediary approach allows security authentication to be integrated into the existing SRv6 forwarding mechanism without requiring separate authentication protocols or additional packet processing steps.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security authentication instructions are embedded in SID, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by making the SID multi-functional. The SID not only performs its traditional routing function but also carries security authentication instructions and arguments. By encoding authentication information within the existing SID structure (using function fields and argument fields), the patent avoids adding separate authentication data structures. This multi-functionality reduces overall system complexity while embedding security mechanisms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes the parameters of the SID structure to accommodate security authentication. Specific function fields and argument fields within the SID are assigned security-related meanings and values. For example, certain function field values indicate authentication operations, while argument fields contain authentication credentials. This parameter transformation allows the existing SID framework to support security authentication without structural modifications.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12413510B2Method and apparatus for packet forwarding, network node and storage medium
Publication Date: 2025.09.09 NEW H3C TECH CO LTD
  • US12413510B2 patent drawing
  • US12413510B2 patent drawing
  • US12413510B2 patent drawing

AI summary

Method and apparatus for packet forwarding, which relate to the network technology field and are applied to a network node. The method comprises: obtaining an SRV6 packet; if a function field in a target SID contains a security authentication instruction, obtaining a target argument based on an operation indicated by the security authentication instruction, and performing security authentication processing on the SRv6 packet based on the target argument; wherein, the target SID is an SID, corresponding to the network node, in a segment list carried by a header of the SRv6 packet, and the target argument is: an argument for the security authentication instruction recorded in the header; and forwarding the processed SRv6 packet to a next-hop device. By applying the solution for packet forwarding according to examples of the present disclosure, the security in forwarding the SRv6 packet along the SRv6 forwarding path can be improved.