Methods and devices for protecting a stream of packets
A method for protecting a stream of packets in a network composed of packet router nodes and stream transmitter and receiver nodes. The receiver node is connected to a router node handling routing of a packet to the receiver node according to an expected value of a protection parameter included in at least one field of a packet of the stream. The method is implemented by a device associated with the receiver node and includes: transmitting to the router node connected to the receiver node a message containing the expected value of the protection parameter. A method is also provided for filtering a stream of packets, which is implemented by the router node connected to the receiver node and includes: receiving from a device associated with the receiver node a message containing the expected value of the protection parameter, and filtering packets not containing the expected value of the parameter.
1 . A protection method comprising:
protecting at least one packet in a network composed of router nodes routing packets including a first router node, transmitter nodes transmitting packets, and receiver nodes receiving packets including a first receiver node connected to the first router node, the protecting being implemented by a device associated with the first receiver node and comprising:
transmitting a message comprising an expected value of a protection parameter destined for the first router node, the first router node processing routing of said at least one packet destined for the first receiver node based on said expected value of said protection parameter being contained in at least one field of said at least one packet; and
after expiration of a defined period since transmitting the message, transmitting a new message with a new value of the protection parameter.
2 . The protection method as claimed in claim 1 , wherein the transmitting the message comprising the expected value of the protection parameter is triggered by obtaining information indicative of congestion between the one of the transmitter nodes and the first receiver node.
3 . A filtering method comprising:
filtering at least one packet in a network composed of router nodes routing packets including a first router node, transmitter nodes transmitting packets including a first transmitter node, and receiver nodes receiving packets including a first receiver node connected to the first router node, the filtering being implemented by the first router node and comprising:
receiving a message comprising an expected value of a protection parameter from a device associated with the first receiver node;
receiving said at least one packet from the first transmitter node, said at least one packet being destined for said first receiver node and comprising said protection parameter;
filtering said at least one packet when a value of said protection parameter does not correspond to said expected value;
after expiration of a defined period since receiving said message, receiving a new message from said device associated with the first receiver node comprising a new expected value of the protection parameter; and
filtering at least one new packet received from the first transmitter node and destined for said first receiver node when said new value of said protection parameter does not correspond to said new expected value.
4 . The filtering method as claimed in claim 3 , wherein the filtering of the at least one packet and the filtering of the at least one new packet comprises blocking, or destroying, or lowering priority of the packets not comprising the expected value of the protection parameter.
5 . The filtering method as claimed in claim 3 , furthermore comprising transmitting the message comprising the expected value of the protection parameter to a router node neighboring the first router node connected to the first receiver node.
6 . The filtering method as claimed in claim 3 , wherein the protection parameter is contained in a destination Internet Protocol version 6 (IPv6) address of the at least one packet.
7 . The filtering method as claimed in claim 3 , wherein the flow is an Internet Protocol security (IPsec) tunnel or an Internet Protocol (IP) tunnel.
8 . The filtering method as claimed in claim 3 , wherein the at least one field comprising the protection parameter is one or more of the fields selected from a list consisting of:
“Security Parameters Index” (SPI) of Internet Protocol security (IPsec),
“Protocol” of Internet Protocol version 4 (IPv4),
“Next Header” of Internet Protocol version 6 (IPv6),
“Flow Label” of IPv6,
Source Internet Protocol (IP) address, or destination IP address, or source port, or destination port, of IPv4 or IPv6,
“Key” of Generic Routing Encapsulation (GRE),
Segment List, or Segment List [n], or Tag, or hash-based message authentication code (HMAC) tag-length-value (TLV) of Segment Routing IPv6 (SRv6).
9 . The filtering method as claimed in claim 3 , wherein the message comprising the expected value of the protection parameter is a message in accordance with a protocol selected from the group consisting of:
Border Gateway Protocol (BGP) Flow Spec,
Network Configuration Protocol (NETCONF),
Representational State Transfer Configuration (RESTCONF),
Command line interface (CLI),
Simple Network Management Protocol (SNMP),
Application Program Interface (API) Representational State Transfer Configuration (REST), and
API.
10 . A device for protecting at least one packet in a network composed of router nodes routing packets including a first router node, transmitter nodes transmitting packets, and receiver nodes receiving packets including a first receiver node connected to the first router node, the device being associated with the first receiver node and comprising:
a receiver;
a transmitter;
at least one processor; and
at least one memory coupled to the at least one processor with instructions stored thereon which when executed by the at least one processor implement a method comprising:
transmitting a message comprising an expected value of a protection parameter destined for the first router node, the first router node processing routing of said at least one packet destined for the first receiver node based on said expected value of said protection parameter being contained in at least one field of said at least one packet; and
after expiration of a defined period since transmitting the message, transmitting a new message with a new value of the protection parameter.
11 . A device for filtering at least one packet in a network composed of router nodes routing packets including a first router node, transmitter nodes transmitting packets including a first transmitter node, and receiver nodes receiving packets including a first receiver node connected to the first router node, the device being implemented in the first router node and comprising:
a receiver;
a transmitter;
at least one processor; and
at least one memory coupled to the at least one processor with instructions stored thereon which when executed by the at least one processor implement a method comprising:
receiving a message comprising an expected value of a protection parameter from a device associated with the first receiver node;
receiving said at least one packet from the first transmitter node, said at least one packet being destined for said first receiver node and comprising said protection parameter;
filtering said at least one packet when a value of said protection parameter does not correspond to said expected value;
after expiration of a defined period since receiving said message, receiving a new message from said device associated with the first receiver node comprising a new expected value of the protection parameter; and
filtering at least one new packet received from the first transmitter node and destined for said first receiver node when said new value of said protection parameter does not correspond to said new expected value.
12 . At least one non-transitory computer readable information medium comprising instructions stored thereon which when executed by at least one processor of a protection device associated with a first receiver node implement a protection method comprising:
protecting at least one packet in a network composed of router nodes routing packets including a first router node connected to the first receiver node, transmitter nodes transmitting packets, and receiver nodes receiving packets including the first receiver node, the protecting comprising:
transmitting a message comprising multiple expected values of a protection parameter destined for the first router node, each expected value corresponding to a different period of use, the first router node processing routing of said at least one packet destined for the first receiver node based on one said expected values of said protection parameter being contained in at least one field of said at least one packet; and
after expiration of a defined period since transmitting the message, transmitting a new message with a new value of the protection parameter.
13 . The protection method as claimed in claim 1 , wherein the protection parameter is contained in a destination Internet Protocol version 6 (IPv6) address of the at least one packet.
14 . The protection method as claimed in claim 1 , wherein the flow is an Internet Protocol security (IPsec) tunnel or an Internet Protocol (IP) tunnel.
15 . The protection method as claimed in claim 1 , wherein the at least one field comprising the protection parameter is one or more of the fields selected from a list consisting of:
“Security Parameters Index” (SPI) of Internet Protocol security (IPsec),
“Protocol” of Internet Protocol version 4 (IPv4),
“Next Header” of Internet Protocol version 6 (IPv6),
“Flow Label” of IPv6,
source Internet Protocol (IP) address, or destination IP address, or source port, or destination port, of IPv4 or IPv6,
“Key” of Generic Routing Encapsulation (GRE),
Segment List, or Segment List [n], or Tag, or hash-based message authentication code (HMAC) tag-length-value (TLV) of Segment Routing IPv6 (SRv6).
16 . The protection method as claimed in claim 1 , wherein the message comprising the expected value of the protection parameter is a message in accordance with a protocol selected from the group consisting of:
Border Gateway Protocol (BGP) Flow Spec,
Network Configuration Protocol (NETCONF),
Representational State Transfer Configuration (RESTCONF),
Command line interface (CLI),
Simple Network Management Protocol (SNMP),
Application Program Interface (API) Representational State Transfer Configuration (REST), and
API.