中华电信研究所课件.ppt
- 【下载声明】
1. 本站全部试题类文档,若标题没写含答案,则无答案;标题注明含答案的文档,主观题也可能无答案。请谨慎下单,一旦售出,不予退换。
2. 本站全部PPT文档均不含视频和音频,PPT中出现的音频或视频标识(或文字)仅表示流程,实际无音频或视频文件。请谨慎下单,一旦售出,不予退换。
3. 本页资料《中华电信研究所课件.ppt》由用户(晟晟文业)主动上传,其收益全归该用户。163文库仅提供信息存储空间,仅对该用户上传内容的表现方式做保护处理,对上传内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知163文库(点击联系客服),我们立即给予删除!
4. 请根据预览情况,自愿下载本文。本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
5. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007及以上版本和PDF阅读器,压缩文件请下载最新的WinRAR软件解压。
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- 中华电信 研究所 课件
- 资源描述:
-
1、IPv6 技術之發展與現況技術之發展與現況中華電信研究所中華電信研究所交換技術研究室交換技術研究室嚴劍琴嚴劍琴中華民國八十九年四月二十一日中華民國八十九年四月二十一日中華電信研究所Chunghwa Telecom Labs.交換技術研究室Switching Technology Lab.Contentsp下一代網際網路之需求下一代網際網路之需求p IPv6 通訊協定簡介通訊協定簡介p Worldwide Testbed-6Bonep我國我國 IPv6 發展現況發展現況p總結總結中華電信研究所Chunghwa Telecom Labs.交換技術研究室Switching Technology La
2、b.下一代網際網路之需求下一代網際網路之需求中華電信研究所Chunghwa Telecom Labs.交換技術研究室Switching Technology Lab.Internet 之演進之演進p Best Effortm公眾公眾m僅有數據服務僅有數據服務m可擴充可擴充p Commerce Internetm安全安全m私有私有m普遍性普遍性p Multimedia InternetmQoSmMulticastm信號協定信號協定 m多重服務多重服務Best EffortInternetCommerceInternetMultimediaInternet中華電信研究所Chunghwa Telec
3、om Labs.交換技術研究室Switching Technology Lab.新一代網際網路技術及需求新一代網際網路技術及需求(1/3)p高頻寬高頻寬m骨幹網路:Gigabit 10/100 Gigabit Terabitm擷取網路:100 kbit megabit 10/100 megabitpQuality of Servicem資源預留m性能保證的程度m端點對端點 QoSmHigh Availability中華電信研究所Chunghwa Telecom Labs.交換技術研究室Switching Technology Lab.新一代網際網路技術及需求新一代網際網路技術及需求(2/3)p
4、保密性保密性m網際網路商務p擴充性(擴充性(Scalability)m10 millions 使用者 100 millions使用者m過去15年,網際網路的流量(traffic)每年成長2至5倍,同時也沒跡象顯示有減緩趨勢m頻寬、網路節點數、流量數皆需有良好之擴充性中華電信研究所Chunghwa Telecom Labs.交換技術研究室Switching Technology Lab.新一代網際網路技術及需求新一代網際網路技術及需求(3/3)p多重服務(多重服務(Multi-service)mVoice over IPmVideo on demandmMulticast oriented Se
5、rvicesp管理性管理性m有效的資源共享m有效的鍵路使用率m私有企業網路之管理m測試m記帳中華電信研究所Chunghwa Telecom Labs.交換技術研究室Switching Technology Lab.IPv6 通訊協定簡介通訊協定簡介中華電信研究所Chunghwa Telecom Labs.交換技術研究室Switching Technology Lab.The Role of an Internet ProtocolLANLANEnd system (X)End system (Y)Router (1)Router (2)LAN,WAN,orpoint-to-point link
6、Physical PhysicalIPLLCMACIPPhysicalLLCMACPhysicalPhysicalLLCMACIPTCPPhysicalLLCMACIPTCPProtocol architecture including IP中華電信研究所Chunghwa Telecom Labs.交換技術研究室Switching Technology Lab.Introductionp Driving motivation:Limitation imposed by the 32-bit address in IPv4mNAT(Network Access Translator)is a s
7、hort-term solution but not the bestp To provide a platform for new Internet Functionality Improvement rather than derivative of IPv4mAddressing Capacity,Routing Capacity,Support for QoS,Auto-configuration,Security inter-operability and so onp Related IETF working GroupsmIPng(ipngwg)working group und
8、er Internet AreamIPng Transition(ngtrans)working group under Operations and Management Area中華電信研究所Chunghwa Telecom Labs.交換技術研究室Switching Technology Lab.IPv6 vs.IPv4 Packet Data Unitminimum20 octetsmaximum65535 octetsIPv4 PDUFixed40 octetsmaximum65535 octetsIPv6 PDU0 or moreIPv4 HeaderData FieldTrans
9、port-level PDUIPv6 HeaderExtensionHeaderExtensionHeader中華電信研究所Chunghwa Telecom Labs.交換技術研究室Switching Technology Lab.Destination AddressSource AddressVer IHLService TypeIdentificationFlagsOffsetTTLProtocolHeader ChecksumSource AddressDestination AddressOptions+PaddingTotal LengthVerFlow LabelPayload
10、LengthNext HeaderHop LimitTraffic ClassIPv4 vs.IPv6 Header32 bits中華電信研究所Chunghwa Telecom Labs.交換技術研究室Switching Technology Lab.IPv6 Extension Headers(1/2)p Hop-by-hop options headerp Routing headerp Fragment headerp Authentication headerp Encapsulating security payload headerp Destination options hea
11、derIPv6 PDU general formTransport-level PDUIPv6 HeaderExtensionHeaderExtensionHeader40 octets0 or more中華電信研究所Chunghwa Telecom Labs.交換技術研究室Switching Technology Lab.IPv6 Extension Headers(2/2)p IPv6 specification recommended order:mIPv6 headermHop-by-hop options headermDestination options headermRouti
12、ng headermFragment headermAuthentication headermEncapsulation security payload headermDestination options headerIPv6 headerHop-by-hop options headerRouting headerFragment headerAuthentication header Encapsulation security payload header Destination options headerTCP headerApplication dataIPv6 packet
13、 with all extension headersOctets:40VariableVariableVariableVariableVariableVariable820(optional variable part)=Next header field中華電信研究所Chunghwa Telecom Labs.交換技術研究室Switching Technology Lab.Packet Format of IPv6 vs.IPv4p Header size becomes fixedmOption fields are replaced by extension headersO hop-
14、by-hop,routing header,fragment header,authentication header,encapsulating security payload,destination options headerp Decreased number of field,increased total size mSix fields are suppressedOIP header length,type of service,identification,flags,fragment offset,header checksummThree fields are rena
15、medOTotal length:payload lengthO Protocol type:next headerOTime to live:hop limitmTwo fields are addedOtraffic class,flow label 中華電信研究所Chunghwa Telecom Labs.交換技術研究室Switching Technology Lab.Addressing Featuresp Address Capacitym32-bit address 128-bit addressmGive brand-new start for address aggregati
16、on(CIDR,Classless Inter-Domain Routing)p Addressing CapabilitymUnicast,Anycast and Multicastp Anycast addressmMore efficient routing(intermediate nodes)mMore efficient access to mirrored servers(destination nodes)p Single interface with multiple addressmsupport renumbering in a nondisruptive manner中
17、華電信研究所Chunghwa Telecom Labs.交換技術研究室Switching Technology Lab.Routing Capabilityp Size of packet header is fixedp Revised option mechanismmMost bypassed by routersmHint in header(Routing option)p The number of fields in packet header is reducedm12 fixed+options 8 fixedmSuppressed:header length,type of
18、 service,identification,flag,fragment offset,header checksummModified:length,protocol type,time to livemAdded:priority,flow labelo Packet fragmentation is not allowed by routersmPath MTU(Max.Transfer Units)discovery protocolmAt least 1280 octets中華電信研究所Chunghwa Telecom Labs.交換技術研究室Switching Technolog
19、y Lab.More Flexible for QoS Mechanismp New“Flow”conceptmDefined by source address+flow labelmRouting only on flow DA,priority,hop-by-hop,routing option must be the same on a given flowp When used with RSVPmDA+SA(+DP+SP)SA+flow labelmSolve layer violation with routersmStill work with encryptionp Can
20、be used with other Reservation ProceduresmDefine QoS of a flow in hop-by-hop options中華電信研究所Chunghwa Telecom Labs.交換技術研究室Switching Technology Lab.Other Improvementsp More flexible AutoconfigurationmStateless autoconfiguration(New)mStateful autoconfiguration(V6 version of DHCP,Dynamic Host Configurati
21、on Protocol)p Improved Support for Security,Mobility and ARP,etc.mProvide inter-operabilitymmore efficient process中華電信研究所Chunghwa Telecom Labs.交換技術研究室Switching Technology Lab.IPv6 SecuritypIP-level security encompasses two functional areas:authentication and privacypSecurity associationsmAn associat
22、ion is a one-way relationship between a sender and a receivermA security association is uniquely identified by an internet destination address and a security parameter index(SPI)中華電信研究所Chunghwa Telecom Labs.交換技術研究室Switching Technology Lab.AuthenticationNext headerLength081631Authentication headerRes
23、ervedSecurity parameters index Authentication data(variable number of 32-bit words)pThe authentication header provides support for data integrity and authentication of IP packetspRFC 1828 specifies the use of MD5 for authentication中華電信研究所Chunghwa Telecom Labs.交換技術研究室Switching Technology Lab.Encapsul
24、ating Security PayloadIP headerOther IP headersSecure IPv4 datagram or IPv6 packetTransport-level segmentESP headerUnencryptedEncryptedSingle,partially-encrypted IP packet(a)Transport modeIP headerOther IP headersIP header plus transport-level segmentESP headerUnencryptedEncryptedCompletely-encrypte
25、d inner IP packet(b)Tunnel modePartially-encrypted outer IP packet中華電信研究所Chunghwa Telecom Labs.交換技術研究室Switching Technology Lab.Authentication Plus PrivacyCombining privacy and authentication(a)Encryption before authentication(transport or tunnel mode)IP-HTransport-level segmentEncryptedInner IP pack
展开阅读全文