基本信息:
- 专利标题: 통합 IP 패킷 지원 보안 장치 및 방법
- 专利标题(英):Method and apparatus for using fpga supporting ipv4 and ipv6
- 专利标题(中):使用FPGA支持IPV4和IPV6的方法和设备
- 申请号:KR1020070052931 申请日:2007-05-30
- 公开(公告)号:KR1020080052215A 公开(公告)日:2008-06-11
- 发明人: 박상길 , 오진태 , 남택용
- 申请人: 한국전자통신연구원
- 申请人地址: 대전광역시 유성구 가정로 *** (가정동)
- 专利权人: 한국전자통신연구원
- 当前专利权人: 한국전자통신연구원
- 当前专利权人地址: 대전광역시 유성구 가정로 *** (가정동)
- 代理人: 리앤목특허법인
- 优先权: KR1020060122659 2006-12-05
- 主分类号: H04L12/22
- IPC分类号: H04L12/22 ; H04L12/781 ; H04L12/56 ; H04L29/06
摘要:
A unified security apparatus for supporting IP packets and a method thereof are provided to enable permission/filtering to be applied to an IPv4 packet and an IPv6 packet by physically using a single chipset when a dual stack scheme and a permission/filtering rule are applied. A unified security apparatus for supporting IP packets includes a packet classifier(210), a key generator(220), a lookup engine(230), and an intrusion response unit(240). The packet classifier classifies an IPv4 packet and an IPv6 packet based on version information in header information of an input IP packet. The key generator generates header information corresponding to the IPv4 packet or the IPv6 packet classified by the packet classifier and generates a discrimination key corresponding to the IPv4 packet or the IPv6 packet based on the generated header information. The lookup engine includes two banks(231,232). Different bits are assigned to the two banks. An IPv4 security policy and an IPv6 security policy are recorded in the lookup engine. In this way, both an IPv4 packet and an IPv6 packet can be searched in the current embodiment by physically using a single lookup engine. The intrusion response unit includes a packet filtering unit(241) and a bandwidth controller(242). The packet filtering unit decides a lookup key, which is a key value corresponding to the security policy established in the first bank or the second bank, and if the lookup key matches the discrimination key generated according to the IPv4 packet or the IPv6 packet by the key generator, the packet filtering unit discards or transmits the packet according to the security policy. The bandwidth controller decides a lookup key, which is a key value corresponding to the security policy established in the first bank or the second bank, and if the lookup key matches the discrimination key, the bandwidth controller controls a bandwidth according to the security policy.
摘要(中):
提供一种用于支持IP分组的统一安全装置及其方法,用于当应用双栈方案和许可/过滤规则时,通过物理地使用单个芯片组来允许/过滤应用于IPv4分组和IPv6分组。 用于支持IP分组的统一安全装置包括分组分类器(210),密钥生成器(220),查找引擎(230)和入侵响应单元(240)。 分组分类器基于输入IP分组的报头信息中的版本信息对IPv4分组和IPv6分组进行分类。 密钥发生器生成对应于IPv4分组的报头信息或由分组分类器分类的IPv6分组,并且基于生成的报头信息生成与IPv4分组或IPv6分组对应的鉴别密钥。 查找引擎包括两个库(231,232)。 不同的位被分配给两个存储体。 查询引擎中记录了IPv4安全策略和IPv6安全策略。 以这种方式,可以在当前实施例中通过物理地使用单个查找引擎来搜索IPv4分组和IPv6分组。 入侵响应单元包括分组过滤单元(241)和带宽控制器(242)。 分组过滤单元确定查找密钥,该查找密钥是与在第一组或第二组中建立的安全策略相对应的密钥值,如果查找密钥与根据IPv4分组或IPv6分组生成的鉴别密钥相匹配, 密钥生成器,包过滤单元根据安全策略丢弃或发送数据包。 带宽控制器决定查询密钥,该查找密钥是与在第一组或第二组中建立的安全策略相对应的密钥值,如果查找密钥与鉴别密钥一致,则带宽控制器根据安全策略控制带宽。
公开/授权文献:
- KR100875931B1 통합 IP 패킷 지원 보안 장치 및 방법 公开/授权日:2008-12-26