IP Library › Granted Patent US 12,609,829
Granted Patent B2
US 12,609,829 · App. 17/990,474 · Granted Apr 21, 2026

Method and apparatus for verifying SRv6 packet

Inventors: Dongjie Lu (Shenzhen, CN); Rui Gu (Beijing, CN); Huizhi Wen (Beijing, CN); Yaqun Xiao (Beijing, CN)
Assignee: Huawei Technologies Co., Ltd.
H04L9/3242H04L63/0236H04L63/029H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,609,829
App. No.
17/990,474
Granted
Apr 21, 2026
Kind
B2
Abstract

Embodiments of this application disclose a method for verifying an SRv6 packet. An egress node of an IPsec tunnel may receive an SRv6 packet, where the SRv6 packet is a packet encapsulated in an IPsec transport mode. The SRv6 packet includes an AH and at least one SRH. The SRv6 packet carries first indication information, where the first indication information indicates the egress node to perform AH verification on the SRv6 packet. A verification range of the AH verification includes the at least one SRH.

Claims (34)

1 . A method for verifying a segment routing over Internet Protocol version 6 (SRv6) packet, wherein the method comprises:

receiving, by an egress node of an Internet Protocol security (IPsec) tunnel, an SRv6 packet, wherein the SRv6 packet is a packet encapsulated in an IPsec transport mode, the SRv6 packet comprises an authentication header (AH) and at least one segment routing header (SRH), the SRv6 packet carries first indication information, and the first indication information indicates the egress node to perform AH verification on the SRv6 packet, and wherein the SRv6 packet comprises second indication information, and the second indication information indicates a verification range of the AH verification; and

performing, by the egress node, the AH verification on the SRv6 packet based on the first indication information and the AH, wherein the second indication information indicates that the verification range of the AH verification comprises the at least one SRH.

2 . The method according to claim 1 , wherein the SRH carries the first indication information.

3 . The method according to claim 2 , wherein a reserved field or an extended type length value (TLV) field of the SRH carries the first indication information.

4 . The method according to claim 3 , wherein the reserved field is a flag field.

5 . The method according to claim 1 , wherein a destination address of the SRv6 packet carries the first indication information.

6 . The method according to claim 5 , wherein an arguments field or a function field of the destination address carries the first indication information.

7 . The method according to claim 5 , wherein the egress node stores a correspondence between the destination address and the first indication information.

8 . The method according to claim 1 , wherein the destination address of the SRv6 packet is a second segment identifier (SID), and the second SID is associated with the IPsec tunnel.

9 . The method according to claim 8 , wherein the second SID is an egress IP address of the IPsec tunnel.

10 . The method according to claim 1 , wherein the AH comprises the second indication information.

11 . The method according to claim 10 , wherein a reserved field of the AH carries the second indication information.

12 . The method according to claim 1 , wherein the performing, by the egress node, the AH verification on the SRv6 packet based on the first indication information and the AH comprises:

performing, by the egress node, the AH verification on the SRv6 packet based on the first indication information, the second indication information, and the AH.

13 . The method according to claim 1 , wherein the second indication information indicates that the verification range of the AH verification further comprises a payload of the SRv6 packet.

14 . The method according to claim 1 , wherein the second indication information indicates that the verification range of the AH verification further comprises an IPv6 packet header of the SRv6 packet.

15 . The method according to claim 1 , wherein the egress node of the IPsec tunnel is an ingress node of an SRv6 trusted domain.

16 . The method according to claim 1 , wherein the SRv6 packet comprises a plurality of SRHs, and wherein the second indication information indicates that the range of the AH verification comprises the plurality of SRHs.

17 . The method according to claim 1 , wherein the method further comprises:

forwarding, by the egress node, the SRv6 packet that passes the AH verification; or

discarding, by the egress node, the SRv6 packet that fails the AH verification.

18 . A method for verifying a segment routing over Internet Protocol version 6 (SRv6) packet, wherein the method comprises:

obtaining, by an ingress node of an Internet Protocol security (IPsec) tunnel, an SRv6 packet, wherein the SRv6 packet is a packet encapsulated in an IPsec transport mode, the SRv6 packet comprises an authentication header (AH) and at least one segment routing header (SRH), the SRv6 packet carries first indication information, the first indication information indicates an egress node of the IPsec tunnel to perform AH verification on the SRv6 packet, wherein the SRv6 packet comprises second indication information, and the second indication information indicates a verification range of the AH verification, and wherein the second indication information indicates that the verification range of the AH verification comprises the at least one SRH; and

sending, by the ingress node, the SRv6 packet to the egress node.

19 . A network apparatus, used in an egress node of an Internet Protocol security (IPsec) tunnel, comprising:

a communication interface; and

a processor, connected to the communication interface, wherein based on the communication interface and the processor, the network apparatus is configured to:

receive a segment routing over Internet Protocol version 6 (SRv6) packet, wherein the SRv6 packet is a packet encapsulated in an IPsec transport mode, the SRv6 packet comprises an authentication header (AH) and at least one segment routing header (SRH) the SRv6 packet carries first indication information, and the first indication information indicates the network apparatus to perform AH verification on the SRv6 packet, and wherein the SRv6 packet comprises second indication information, and the second indication information indicates a verification range of the AH verification; and

perform the AH verification on the SRv6 packet based on the first indication information and the AH, wherein the second indication information indicates that the verification range of the AH verification comprises the at least one SRH.

20 . The method according to claim 18 , wherein the second indication information indicates that the verification range of the AH verification further comprises at least one of:

a payload of the SRv6 packet;

an IPv6 packet header of the SRv6 packet; or

a plurality of SRHs comprised in the SRv6 packet.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 10, 2026
From: LU, DONGJIE; GU, RUI; WEN, HUIZHI; XIAO, YAQUN
To: HUAWEI TECHNOLOGIES CO., LTD.
Reel/Frame 073748/0667 →
Priority Claims (2)
CN 202010424481.4 · May 19, 2020 · national
CN 202010476797.8 · May 29, 2020 · national
Continuity (2)
Continuation PCTCN2021079919 · Mar 10, 2021
Related Publication 20230102984A1 · Mar 30, 2023
References Cited (11)
US 10736029B1 · Young · 2020 [cited by examiner]
US 20180316723A1 · Murgia · 2018 [cited by examiner]
US 20190394211A1 · Filsfils · 2019 [cited by examiner]
Filsfils et al., “IPV6 Segment Routing Header (SRH),” RFC 8754, Total 27 pages, Internet Engineering Task Force (Mar. 2020). [cited by applicant]
Krawczyk et al., “HMAC: Keyed-Hashing for Message Authentication,” RFC 2104, Total 11 pages (Feb. 1997). [cited by applicant]
Kent et al., “IP Authentication Header,” RFC 4302, Total 34 pages (Dec. 2005). [cited by applicant]
Deering et al., “Internet Protocol, Version 6 (IPv6) Specification,” RFC 8200, Total 42 pages (Jul. 2017). [cited by applicant]
Li et al., “Security Considerations for SRv6 Networks draft-li-spring-srv6-security-consideration-03,” Total 24 pages (Nov. 4, 2019). [cited by applicant]
Filsfils et al., “SRv6 Network Programming draft-filsfils-spring-srv6-network-programming-07,” Total 83 pages (Feb. 14, 2019). [cited by applicant]
Kent et al., “IP Encapsulating Security Payload (ESP),” RFC 4303, Total 44 pages Dec. 2005). [cited by applicant]
Deering et al., “Internet Protocol, Version 6 (IPv6) Specification,” RFC 2460, Total 39 pages (Dec. 1998). [cited by applicant]