US2021014249A1PendingUtilityA1

Packet Transmission Method and Apparatus

Assignee: HUAWEI TECH CO LTDPriority: Nov 4, 2014Filed: Jul 29, 2020Published: Jan 14, 2021
Est. expiryNov 4, 2034(~8.3 yrs left)· nominal 20-yr term from priority
H04L 63/1466H04L 63/0236H04L 63/145H04L 63/164H04L 45/74H04L 63/1416
46
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A packet transmission method and an apparatus pertain to the field of network technologies. The method includes obtaining, by a terminal device, a source IP (Internet Protocol) address in a to-be-transmitted packet and N IP addresses of the terminal device, where N is an integer, and when the source IP address in the to-be-transmitted packet is different from any one of the N IP addresses of the terminal device, determining that the source IP address in the to-be-transmitted packet is forged, and prohibiting transmitting the to-be-transmitted packet. The application can solve the problem that a virus such as Trojan in the terminal device may be prevented from forging a source IP address of another device to randomly transfer an attack packet in the network to improve network security.

Claims

exact text as granted — not AI-modified
1 . A method implemented by a terminal device, wherein the method comprises:
 obtaining a source Internet Protocol (IP) address in a to-be-transmitted packet and N IP addresses of the terminal device, wherein N is a positive integer; and   comparing the source IP address with each of the N IP addresses before transmitting the to-be-transmitted packet; and   prohibiting transmitting the to-be-transmitted packet in response to the source IP address being different from all of the N IP addresses.   
     
     
         2 . The method of  claim 1 , wherein comparing the source IP address with each of the N IP addresses comprises:
 performing an exclusive OR operation on the source IP address and each of the N IP addresses to obtain N exclusive OR operation results;   performing an OR operation on each of the N exclusive OR operation results to obtain N OR operation results; and   performing an AND operation on the N OR operation results to obtain an AND operation result.   
     
     
         3 . The method of  claim 2 , further comprising setting a filtering flag bit indicating that filtering should be performed on the source IP address of the to-be-transmitted packet. 
     
     
         4 . The method of  claim 2 , wherein comparing the source IP address in the to-be-transmitted packet with each of the N IP addresses of the terminal device is performed within one clock cycle. 
     
     
         5 . The method of  claim 1 , wherein prohibiting transmitting the to-be-transmitted packet comprises transmitting a transmission prohibition instruction to a physical coding sublayer (PCS) at a physical layer (PHY), and wherein the transmission prohibition instruction instructs the PCS to prohibit transmitting the to-be-transmitted packet. 
     
     
         6 . The method of  claim 1 , wherein prohibiting transmitting the to-be-transmitted packet comprises prohibiting adding the to-be-transmitted packet to a packet queue used to store a packet to be transmitted by the terminal device. 
     
     
         7 . The method of  claim 1 , further comprising transmitting to a monitoring device, an alarm packet carrying at least one of an IP address or a media access control (MAC) address of the terminal device, wherein the alarm packet instructs the monitoring device to monitor the terminal device. 
     
     
         8 . The method of  claim 1 , wherein before obtaining the source IP address and the N IP addresses, the method further comprises setting the terminal device to a filtering state used to instruct the terminal device to perform filtering on the source IP address in the to-be-transmitted packet. 
     
     
         9 . A terminal device comprising:
 a network interface; and   a processor coupled to the network interface and configured to:
 obtain a source Internet Protocol (IP) address in a to-be-transmitted packet and N IP addresses of the terminal device, wherein N is a positive integer; 
 compare the source IP address with each of the N IP addresses before transmitting the to-be-transmitted packet; 
 determine that the source IP address is forged in response to the source IP address being different from all of the N IP addresses; and 
 prohibit transmitting the to-be-transmitted packet via the network interface when the source IP address is forged. 
   
     
     
         10 . The terminal device of  claim 9 , wherein the processor is further configured to:
 perform an exclusive OR operation on the source IP address and each of the N IP addresses to obtain N exclusive OR operation results;   perform an OR operation on each of the N exclusive OR operation results to obtain N OR operation results; and   perform an AND operation on the N OR operation results to obtain an AND operation result.   
     
     
         11 . The terminal device of  claim 10 , wherein the processor is further configured to prohibit adding the to-be-transmitted packet to a packet queue used to store a packet to be transmitted by the terminal device. 
     
     
         12 . The terminal device of  claim 10 , wherein the network interface is configured to transmit, to a monitoring device, an alarm packet carrying at least one of an IP address or a media access control (MAC) address of the terminal device, wherein the alarm packet instructs the monitoring device to monitor the terminal device. 
     
     
         13 . The terminal device of  claim 10 , wherein the processor is further configured to set the terminal device to a filtering state used to instruct the terminal device to perform filtering on the source IP address in the to-be-transmitted packet. 
     
     
         14 . A packet transmission apparatus comprising:
 a network interface; and   a processor coupled to the network interface and configured to:
 obtain a source Internet Protocol (IP) address in a to-be-transmitted packet and N IP addresses of a terminal device, wherein N is a positive integer; 
 compare the source IP address with each of the N IP addresses before transmitting the to-be-transmitted packet; 
 determine that the source IP address is forged when the source IP address is different from all of the N IP addresses; and 
 prohibit transmitting the to-be-transmitted packet via the network interface when the source IP address is forged. 
   
     
     
         15 . The apparatus of  claim 14 , wherein the processor is further configured to:
 perform an exclusive OR operation on the source IP address and each of the N IP addresses to obtain N exclusive OR operation results;   perform an OR operation on each of the N exclusive OR operation results to obtain N OR operation results; and   perform an AND operation on the N OR operation results to obtain an AND operation result.   
     
     
         16 . The apparatus of  claim 15 , wherein the processor is further configured to set the packet transmission apparatus to a filtering state used to instruct the packet transmission apparatus to perform filtering on the source IP address in the to-be-transmitted packet. 
     
     
         17 . The apparatus of  claim 15 , wherein the processor is further configured to prompt, according to the AND operation result, an event of prohibiting transmitting the to-be-transmitted packet. 
     
     
         18 . The apparatus of  claim 15 , wherein the source IP address is compared with each of the N IP addresses within one clock cycle. 
     
     
         19 . The apparatus of  claim 14 , wherein the processor is further configured to generate an alarm packet carrying at least one of an IP address or a media access control (MAC) address of the terminal device, and wherein the alarm packet is used to instruct a monitoring device to:
 identify the terminal device according to the at least one of the IP address or the MAC address; and   monitor the terminal device.   
     
     
         20 . The apparatus of  claim 14 , wherein the processor is further configured to:
 generate an interrupt signal; and   prompt, according to the interrupt signal, an event that the source IP address in the to-be-transmitted packet is forged.

Join the waitlist — get patent alerts

Track US2021014249A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.