Unlock instant, AI-driven research and patent intelligence for your innovation.

Method, device and equipment for preventing packet loss after IPsec SA aging and storage medium

A technology of packet loss and peer device, applied in the field of communication, can solve the problems of packet discarding, unable to decrypt normally, and unable to decrypt packets, etc., to avoid packet loss.

Inactive Publication Date: 2021-06-04
武汉思普崚技术有限公司
View PDF5 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

When the message encrypted by Party B using the old SA reaches Party A, Party A's SA has been deleted, and normal decryption cannot be performed, and the message will be discarded;
[0005] 2. Party A updates the SA, and Party B renegotiates the IPsec SA message, which is delayed in the network and does not arrive, so the new SA is not updated. At this time, the data encrypted by Party A using the new SA reaches Party B, and the message cannot be decrypted. Packets are discarded
[0006] Therefore, after the current SA ages, packet loss often occurs

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Method, device and equipment for preventing packet loss after IPsec SA aging and storage medium

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0034] Preferred embodiments of the present invention will be described in detail below in conjunction with the accompanying drawings, wherein the accompanying drawings constitute a part of the application and together with the embodiments of the present invention are used to explain the principle of the present invention and are not intended to limit the scope of the present invention.

[0035] see figure 1 The method for preventing packet loss after IPsec SA aging provided by the embodiment of the present invention includes the following steps:

[0036] S1. Establish an IPsec channel with a peer device, and generate a first IPsec SA.

[0037] Specifically, IPSec (Internet Protocol Security) is an open standard framework structure. By using encrypted security services to ensure confidential and secure communication on the Internet Protocol (IP) network, SA (Security Association) records each Policies and policy parameters for IP security channels. Security association is th...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention relates to a method, device and equipment for preventing packet loss after IPsec SA aging and a storage medium, and the method comprises the steps: S1, building an IPsec channel with opposite terminal equipment, and generating a first IPsec SA; S2, when a key exchange message sent by opposite-end equipment is received or when the first IPsec SA meets an aging requirement, sending the key exchange message to the opposite-end equipment, after the opposite-end equipment negotiates a key again, creating a second IPsec SA, and retaining the first IPsec SA; S3, starting a timer, and encrypting the encrypted message sent to the opposite-end equipment by adopting the first IPsec SA before the time of the timer is up; S4, after the time of the timer is up, judging whether the encrypted message sent by the opposite-end equipment is encrypted by adopting a second IPsec SA or not; and S5, when the time of the timer is up and the encrypted message sent by the opposite terminal equipment is encrypted by adopting the second IPsec SA, deleting the first IPsec SA, otherwise, repeating the steps S3 to S4. According to the invention, the problem of frequent packet loss after SA aging at present is solved.

Description

technical field [0001] The present invention relates to the field of communication technology, in particular to a method, device, equipment and storage medium for preventing packet loss after IPsec SA ages. Background technique [0002] In order to ensure the safety of communication, when performing IPsec communication, an SA is set up. For safety, an update aging mechanism is designed for IPsec SA. There are two ways of traffic aging and time aging. That is, when the traffic reaches a certain limit, the IPsec SA is updated; or when the time reaches Update the IPsec SA when the limit is set. [0003] At present, the common update method is: when party A's traffic or time reaches the limit, it starts to renegotiate IPsec SA, and sends renegotiation IPsec SA message; Party B receives renegotiation IPsec SA message. Both parties update the new SA, and two problems will arise at this time: [0004] 1. Party A updates the SA and deletes the old SA; Party B uses the old SA to co...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Applications(China)
IPC IPC(8): H04L29/06
CPCH04L63/166H04L63/0428
Inventor 李洪宇
Owner 武汉思普崚技术有限公司