首页> 外国专利> METHOD AND APPARATUS FOR USING FPGA SUPPORTING IPV4 AND IPV6

METHOD AND APPARATUS FOR USING FPGA SUPPORTING IPV4 AND IPV6

机译:使用FPGA支持ipv4和ipv6的方法和装置

摘要

A unified security apparatus for supporting IP packets and a method thereof are provided to enable permission/filtering to be applied to an IPv4 packet and an IPv6 packet by physically using a single chipset when a dual stack scheme and a permission/filtering rule are applied. A unified security apparatus for supporting IP packets includes a packet classifier(210), a key generator(220), a lookup engine(230), and an intrusion response unit(240). The packet classifier classifies an IPv4 packet and an IPv6 packet based on version information in header information of an input IP packet. The key generator generates header information corresponding to the IPv4 packet or the IPv6 packet classified by the packet classifier and generates a discrimination key corresponding to the IPv4 packet or the IPv6 packet based on the generated header information. The lookup engine includes two banks(231,232). Different bits are assigned to the two banks. An IPv4 security policy and an IPv6 security policy are recorded in the lookup engine. In this way, both an IPv4 packet and an IPv6 packet can be searched in the current embodiment by physically using a single lookup engine. The intrusion response unit includes a packet filtering unit(241) and a bandwidth controller(242). The packet filtering unit decides a lookup key, which is a key value corresponding to the security policy established in the first bank or the second bank, and if the lookup key matches the discrimination key generated according to the IPv4 packet or the IPv6 packet by the key generator, the packet filtering unit discards or transmits the packet according to the security policy. The bandwidth controller decides a lookup key, which is a key value corresponding to the security policy established in the first bank or the second bank, and if the lookup key matches the discrimination key, the bandwidth controller controls a bandwidth according to the security policy.
机译:提供了一种用于支持IP分组的统一安全设备及其方法,以使得当应用双栈方案和许可/过滤规则时,能够通过物理上使用单个芯片组将许可/过滤应用于IPv4分组和IPv6分组。支持IP分组的统一安全设备包括分组分类器(210),密钥生成器(220),查找引擎(230)和入侵响应单元(240)。分组分类器基于输入IP分组的报头信息中的版本信息对IPv4分组和IPv6分组进行分类。密钥生成器生成与由分组分类器分类的IPv4分组或IPv6分组相对应的报头信息,并基于所生成的报头信息来生成与IPv4分组或IPv6分组相对应的鉴别密钥。查找引擎包括两个存储库(231,232)。将不同的位分配给两个存储体。 IPv4安全策略和IPv6安全策略记录在查找引擎中。以这种方式,在当前实施例中,可以通过物理上使用单个查找引擎来搜索IPv4分组和IPv6分组。入侵响应单元包括分组过滤单元(241)和带宽控制器(242)。分组过滤单元确定查找密钥,该查找密钥是与在第一存储体或第二存储体中建立的安全策略相对应的密钥值,以及查找密钥是否与由IPv4分组或IPv6分组生成的鉴别密钥相匹配。密钥生成器,分组过滤单元根据安全策略丢弃或发送分组。带宽控制器确定查找密钥,该查找密钥是与在第一存储体或第二存储体中建立的安全策略相对应的密钥值,并且如果查找密钥与区分密钥匹配,则带宽控制器根据安全策略来控制带宽。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号