IP Library Granted Patent US 12,224,978
Granted Patent B2
US 12,224,978 · App. 18/315,365 · Granted Feb 11, 2025

Packet processing method and apparatus

Inventors: Yanping Xu (Beijing, CN); Liang Xia (Shenzhen, CN); Xiaohui Tong (Beijing, CN)
Assignee: Huawei Technologies Co., Ltd.
H04L61/5007H04L63/1416H04L2101/659H04L2463/146
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,224,978
App. No.
18/315,365
Granted
Feb 11, 2025
Kind
B2
Abstract

A packet processing method and apparatus are provided. The method includes: on a forwarding path of an IPv6 packet, a key node (for example, a firewall) signs a packet, and a downstream apparatus of the key node verifies the signature, to determine whether the packet passes through the key node in a forwarding process. According to this application, the key node performs checking, to effectively prevent a packet which packet header is modified by attackers from bypassing the key node.

Claims (33)

1. A packet processing method, performed by a first communication apparatus, and the method comprising:

obtaining a first internet protocol version 6 (IPv6) packet, wherein a packet header of the first IPV6 packet comprises a first signature, and the first signature is for verifying whether the first IPv6 packet passes through a second communication apparatus in a forwarding process;

forwarding the first IPV6 packet;

wherein the first signature which is determined by fixed-length data in payloads of the first IPv6 packet uniquely identifies the first IPV6 packet, and is different from signatures of other IPv6 packets; and

wherein the first signature is obtained by performing hash calculation based on first content in the first IPV6 packet, and the first content comprises the fixed-length data in the payload and anti-replay attack check information.

2. The method according to claim 1 , wherein the first IPV 6 packet is a segment routing internet protocol version 6 (SRv6) packet.

3. The method according to claim 2 , wherein the first signature is comprised in a segment routing header (SRH).

4. The method according to claim 3 , wherein the SRH comprises an extended type length value (TLV) field, and the extended TLV field comprises the first signature.

5. The method according to claim 1 , wherein the packet header further comprises the anti-replay attack check information.

6. The method according to claim 1 , wherein the packet header further comprises first indication information, and the first indication information indicates at least one type of the anti-replay attack check information comprised in the first content.

7. The method according to claim 5 , wherein the anti-replay attack check information comprises one or more of the following:

a packet sequence number, a timestamp, and a random number.

8. The method according to claim 1 , wherein the packet header further comprises second indication information, and the second indication information indicates a type of the second communication apparatus.

9. The method according to claim 1 , wherein the first communication apparatus and the second communication apparatus are a same apparatus, and the obtaining the first IPv6 packet comprises:

generating the first signature based on a first private key of the second communication apparatus.

10. The method according to claim 1 , wherein the first communication apparatus is a downstream apparatus of the second communication apparatus on a forwarding path of the first IPV6 packet, and before the forwarding the first IPV6 packet, the method further comprises:

verifying the first signature based on a first public key of the second communication apparatus.

11. The method according to claim 10 , further comprising: receiving the first public key sent by a control management entity.

12. A packet processing method, performed by a first communication apparatus, and the method comprising:

receiving a first internet protocol version 6 (IPv6) packet, wherein the first IPv6 packet comprises a first signature, and the first signature is for verifying whether a forwarding path of the first IPV6 packet passes through a second communication apparatus;

verifying the first signature, and processing the first IPV6 packet based on a verification result;

wherein the first signature which is determined by fixed-length data in payloads of the first IPv6 packet uniquely identifies the first IPv6 packet and is different from signatures of other IPv6 packets; and

wherein the first signature is obtained by performing hash calculation based on first content in the first IPV6 packet, and the first content comprises the fixed-length data in the payload and anti-replay attack check information.

13. The method according to claim 12 , further comprising:

discarding the first IPV6 packet in response to a failure of the verification.

14. The method according to claim 12 , wherein the first IPV 6 packet is a segment routing internet protocol version 6 (SRv6) packet.

15. The method according to claim 14 , wherein the first signature is comprised in a segment routing header (SRH).

16. The method according to claim 15 , wherein the SRH comprises an extended type length value (TLV) field, and the extended TLV field comprises the first signature.

17. The method according to claim 12 , wherein the packet header further comprises the anti-replay attack check information.

18. The method according to claim 12 , wherein the packet header further comprises first indication information, and the first indication information indicates at least one type of the anti-replay attack check information comprised in the first content.

19. The method according to claim 17 , wherein the anti-replay attack check information comprises one or more of the following:

a packet sequence number, a timestamp, and a random number.

20. The method according to claim 12 , wherein the packet header further comprises second indication information, and the second indication information indicates a type of the second communication apparatus.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 13, 2023
From: XU, YANPING; XIA, LIANG; TONG, XIAOHUI
To: HUAWEI TECHNOLOGIES CO., LTD.
Reel/Frame 063937/0170 →
Priority Claims (1)
CN 202011256559.2 · Nov 11, 2020 · national
Continuity (2)
Continuation PCTCN2021109153 · Jul 29, 2021
Related Publication 20230283588A1 · Sep 7, 2023
References Cited (20)
US 8228896B2 · Smith · 2012 [cited by examiner]
US 10498529B1 · Hashmi · 2019 [cited by examiner]
US 20060041568A1 · Mahalal · 2006 [cited by examiner]
US 20160315819A1 · Dara et al. · 2016 [cited by applicant]
US 20180054417A1 · Schibuk · 2018 [cited by examiner]
US 20180294973A1 · Miller · 2018 [cited by examiner]
US 20190182051A1 · Benson · 2019 [cited by applicant]
US 20200322266A1 · Clad et al. · 2020 [cited by applicant]
US 20200322380A1 · Sheth et al. · 2020 [cited by applicant]
CN 101640631A · 2010 [cited by applicant]
CN 102196423A · 2011 [cited by applicant]
CN 109981458A · 2019 [cited by applicant]
CN 111585890B · 2021 [cited by applicant]
Filsfils et al. RFC 8402: Segment Routing Architecture. Internet Engineering Task Force. 32 Pages. (Year: 2018). [cited by examiner]
Psenak et al. IS-IS Extension to Support Segment Routing over IPv6 Dataplane. draft-ietf-Isr-isis-srv6-extensions-08.txt. Apr. 23, 2020. 50 Pages. (Year: 2020). [cited by examiner]
C. Filsfils, Ed et al., “IPv6 Segment Routing Header (SRH), draft-ietf-6man-segment-routing-header-26,” Network Working Group, Internet-Draft, Total 32 pages (Oct. 22, 2019). [cited by applicant]
H. Krawczyk et al., “HMAC: Keyed-Hashing for Message Authentication,” Network Working Group, Request for Comments: 2104, Total 11 pages (Feb. 1997). [cited by applicant]
C. Li et al., “Security Considerations for SRv6 Networks, draft-li-spring-srv6-security-consideration-03,” Spring, Internet-Draft, Total 13 pages (Nov. 4, 2019). [cited by applicant]
C. Filsfils, Ed et al., “IPv6 Segment Routing Header (SRH), draft-ietf-6man-segment-routing-header-23,” Network Working Group, Internet-Draft, Total 63 pages (Sep. 15, 2019). [cited by applicant]
C. Filsfils, Ed et al., “IPv6 Segment Routing Header (SRH),” Internet Engineering Task Force (IETF), Request for Comments: 8754, Total 27 pages (Mar. 2020). [cited by applicant]