Communication method and apparatus
By encapsulating security information in messages and using network equipment to verify credibility, the service interruption and delay problems caused by message attacks in existing technologies are solved, and business continuity and real-time protection are achieved.
Patent Information
- Application Number
- CN202111083005.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-09-15
- Publication Date
- 2025-10-14
- Estimated Expiration
- 2041-09-15
AI Technical Summary
Existing network security solutions cannot simultaneously guarantee business continuity and real-time performance when preventing message attacks. Black hole solutions lead to business interruptions, and traffic cleaning solutions cause business delays.
By encapsulating security information in the message, using the first network device to determine the trusted message, and the second network device to verify the credibility of the message based on the encapsulated security information, without the need for deep analysis, it can achieve resistance to message attacks while ensuring business continuity and real-time performance.
It ensures the continuity and real-time performance of services in the event of message attacks, reduces the consumption of processing resources of network equipment, and improves resource utilization and operational efficiency.
Smart Images

Figure CN115834090B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communications, and in particular to a communication method and device. Background Art
[0002] In the field of network security, some network security solutions can be deployed, such as black hole solutions and traffic cleaning solutions, to prevent abnormal business messages, such as attack messages, malicious messages, untrusted messages, or messages with low security levels from attacking corresponding devices, thereby avoiding data leakage, equipment paralysis, etc.
[0003] Among them, for the black hole solution, the device attacked by the message (hereinafter referred to as the attacked device) can send all the received traffic to the black hole, that is, a device dedicated to receiving traffic, to ensure that the attacked device is no longer affected. However, the traffic sent to the black hole also includes normal business messages, which will cause business interruption and business continuity cannot be guaranteed. For the traffic cleaning solution, the attacked device can send all the received traffic to the high-defense cleaning center. The high-defense cleaning center can identify normal business messages and abnormal business messages by performing deep analysis of the messages, and then return the normal business messages to the attacked device to ensure business continuity. However, the high-defense cleaning center takes a long time to perform deep analysis of the messages, resulting in a significant lag in the business and the real-time nature of the business cannot be guaranteed. Summary of the Invention
[0004] The embodiments of the present application provide a communication method and apparatus to achieve resistance to message attacks while ensuring service continuity and real-time performance.
[0005] This application adopts the following technical solutions:
[0006] In a first aspect, a communication method is provided. The method includes: a first network device receiving a first message from a terminal and sending a second message to a second network device. The second message is obtained by encapsulating security information within the first message, and the security information is used to indicate that the second message is a trusted message determined by the first network device.
[0007] According to the method described in the first aspect, by encapsulating security information in the first message, the obtained second message is a trusted message determined by the first network device. In this way, the second network device can determine whether the second message is an attack message based on the security information encapsulated in the second message, without the need for deep analysis of the second message. While achieving resistance to message attacks, it can also ensure business continuity and real-time performance.
[0008] In a possible design, the security information can include first verification information, and the first verification information is used to indicate that the second packet is a trusted packet determined by the first network device. Optionally, the first verification information is password protection information. In this way, the security information can be prevented from being forged or tampered, thereby improving the trustworthiness of the security information.
[0009] Optionally, the security information can further include second verification information, and the second verification information can include one or more of the following: an identifier of a verification algorithm, anti-replay information, an identifier of the first network device, key ciphertext, an identifier of the second network device, an internal reachable address of a third device, or first indication information. The third device is a downstream device of the second network device, and the first indication information is used to indicate a type of the security information. The second verification information carries the one or more of the above information, and is mainly used for verification and forwarding by the second network device, that is, the second network device can use the information to verify the security information and use the information to forward the third packet. In this case, the second network device does not need to dynamically maintain the information locally by carrying the information with the packet, thereby saving processing resources of the second network device and improving resource utilization and operation efficiency of the second network device.
[0010] Optionally, the second verification information can further include second indication information, and the second indication information is used to indicate whether the security information includes one or more of the following: an identifier of a verification algorithm, anti-replay information, an identifier of the first network device, or key ciphertext.
[0011] Optionally, the second verification information can further include second indication information, and the second indication information is used to indicate a position and / or length of one or more of the following in the second packet: the first verification information, an identifier of a verification algorithm, anti-replay information, an identifier of the first network device, or key ciphertext.
[0012] In this way, the second network device can accurately extract the one or more of the above information from the second packet according to the second indication information, so as to ensure the accuracy and reliability of subsequent verification and avoid verification failure due to the second network device failing to accurately extract the one or more of the above information. Since the second indication information can indicate the position and / or length of the one or more of the above information in the second packet, the one or more of the above information can be more flexibly encapsulated in the second packet, so that the structure of the second packet is more flexible, the service compatibility is better, and more service scenarios can be applied.
[0013] Optionally, the first verification information may be at the head or tail of the second message, and the second verification information may be at the head or tail of the second message. It is understandable that the second network device parses the second message from the head to the tail of the second message. On this basis, an optional method is to encapsulate the first verification information at the tail of the second message and the second verification information at the head of the second message, so that the second network device can synchronize the processing of the second verification information and the parsing of the second message. For example, when the second network device is ready for verification based on the second verification information, it also synchronizes the parsing of the second message to the tail and extracts the first verification information, so as to verify the second message in the first place, avoid excessive waiting time, and improve the verification efficiency of the second network device.
[0014] Optionally, the second message is an Internet Protocol version 4 (IPv4) message or an Internet Protocol version 6 (IPv6) message. If the second message is an IPv4 message, the second verification information is located between the IPv4 header and the payload of the IPv4 message, or if the second message is an IPv6 message, the second verification information is located in an extension header of the IPv6 protocol header of the IPv6 message, so as to achieve compatibility with current IPv4 messages or IPv6 messages, with smaller protocol changes and greater convenience for practical application.
[0015] Optionally, before the first network device sends the second message to the second network device, the method described in the first aspect may further include: the first network device receives first configuration information from the network controller. The first configuration information may include one or more of the following: the public address of the third device, the first verification information, the verification algorithm, the identifier of the verification algorithm, anti-replay information, the first key, the anti-replay information, the identifier of the first network device, the key ciphertext, the identifier of the second network device, the internal reachable address of the third device, the first indication information, or the second indication information. The verification algorithm, the anti-replay information, and the first key are used to determine the first verification information. The network controller configures the first configuration information to the first network device so that the first network device can encapsulate security information in the first message according to the first configuration information to obtain the second message. In this way, the second network device can determine whether the second message is an attack message based on the security information encapsulated in the second message, without the need to perform in-depth analysis of the second message. While achieving resistance to message attacks, it can also ensure business continuity and real-time performance.
[0016] Optionally, the destination address of the first message and the second message is the public address of the third device. The public address of the third device refers to an address that points to the third device but is unreachable. That is, a message carrying the public address of the third device cannot be sent directly to the third device, but can be sent to a network device that is reachable to the third device, such as the first network device or the second network device. After these network devices determine that the message is not an attack message, they update the destination address of the message with the internal reachable address of the third device and then forward it to the third device, thereby preventing the third device from being directly attacked by the message.
[0017] In one possible design scheme, the first network device is any one of the following: a router, a gateway, or a switch, and the second network device is a router. That is, the method described in the first aspect can be applied to the routing forwarding scenario to achieve cross-regional, cross-area, or cross-network layer resistance to message attacks in the forwarding scenario.
[0018] In a second aspect, a communication method is provided. The method includes: a second network device receiving a second message from a first network device, and the second network device verifying the second message. The second message is encapsulated with security information, the security information being used to indicate that the second message is a trusted message determined by the first network device.
[0019] In one possible design, the security information may include first verification information, where the first verification information is used to indicate that the second message is a trusted message confirmed by the first network device. Optionally, the first verification information is password-protected information.
[0020] Optionally, the security information may also include second verification information, which may include one or more of the following: an identifier of the verification algorithm, anti-replay information, an identifier of the first network device, a key ciphertext, an identifier of the second network device, an internally reachable address of the third device, or first indication information, where the first indication information is used to indicate the type of security information.
[0021] Optionally, the second verification information may further include second indication information, where the second indication information is used to indicate whether the security information includes one or more of the following: an identifier of a verification algorithm, anti-replay information, an identifier of the first network device, or a key ciphertext.
[0022] Optionally, the second verification information may also include second indication information, which is used to indicate the position and / or length of one or more of the following in the second message: first verification information, an identifier of the verification algorithm, anti-replay information, an identifier of the first network device, or a key ciphertext.
[0023] Optionally, the first verification information is at the head or tail of the second message, and the second verification information is at the head or tail of the second message.
[0024] Optionally, the second packet is an Internet Protocol version 4 (IPv4) packet or an Internet Protocol version 6 (IPv6) packet. When the second packet is an IPv4 packet, the second verification information is located between an IPv4 header and a payload of the IPv4 packet, or when the second packet is an IPv6 packet, the second verification information is located in an extension header of an IPv6 protocol header of the IPv6 packet.
[0025] Optionally, the second network device verifying the second packet can include: the second network device determining third verification information according to the second verification information, so as to verify the second packet according to the first verification information and the third verification information.
[0026] Further, the second network device verifying the second packet according to the first verification information and the third verification information can include: if the first verification information is the same as the third verification information, the second network device updating a destination address of the second packet to an internal reachable address of the third device to obtain a third packet, and sending the third packet to the third device. Or, if the first verification information is different from the third verification information, the second network device discarding the second packet. In this way, by comparing whether the first verification information is the same as the third verification information, it can be accurately identified whether the first verification information is tampered with or whether the first verification information is fake information, so as to improve the security and reliability of the verification.
[0027] Further, the second network device determining the third verification information according to the second verification information can include: the second network device determining a second key according to the key ciphertext or the identifier of the first network device, so as to determine the third verification information according to the verification algorithm, the anti-replay information and the second key. It can be seen that the second key is not directly carried in the security information, but is determined by the second network device according to the key ciphertext or the identifier of the first network device, that is, the second key is a sufficiently secure key which is difficult to be forged or tampered with. Therefore, on the basis of ensuring that the second key is sufficiently secure, an attack packet can usually only tamper with or forge other information, such as the verification algorithm, the anti-replay information, etc. However, since the verification process is to determine the third verification information according to the verification algorithm, the anti-replay information and the second key, once the verification algorithm, the anti-replay information, etc. are forged or tampered with, the third verification information will be different from the first verification information, so as to fail the verification, thereby reliably and securely verifying whether the second packet is a fake or tampered attack packet.
[0028] Optionally, the second network device determining the third verification information based on the second verification information may include: the second network device determining whether the security information includes the identifier of the first network device; if the second network device determines that the security information includes the identifier of the first network device, determining the third verification information based on the second verification information. Alternatively, the second network device verifying the second message may include: the second network device determining that the security information does not include the identifier of the first network device, the second network device discarding the second message, or the second network device sending the second message to a high-defense scrubbing center.
[0029] The second message carries the identifier of the first network device, indicating that it originates from a trusted device, such as the first network device. Based on this principle, if the second message does not include the identifier of the first network device, it indicates that the second message is untrusted. The second network device can then bypass verification and send the second message to the high-security scrubbing center. This, on the one hand, conserves processing resources on the second network device and improves its operational efficiency. On the other hand, the fact that the second message is untrusted does not necessarily mean it is an attack message; it could also be a regular data message from the internet. Therefore, sending the second message to the high-security scrubbing center ensures that even if the second message is a regular data message, it can still access the third device, thus ensuring service reliability and stability. However, if the second message still fails verification despite carrying the identifier of the first network device, it could indicate that the second message is a tampered or forged attack message. The second network device can discard the second message and not send it to the high-security scrubbing center, thus conserving its processing resources.
[0030] In one possible design, before the second network device verifies the second message, the method described in the second aspect may further include: the second network device receives second configuration information from the network controller, the second configuration information including one or more of the following: an internally reachable address of a third device, an identifier of the second network device, an identifier of the first network device, or a third key, the third key being used to decrypt the key ciphertext to obtain the second key. It can be seen that by configuring the second configuration information to the second network device, the network controller enables the second network device to verify the second message based on the second configuration information to determine whether the second message is an attack message, without the need for deep parsing of the second message. While achieving resistance to message attacks, it can also ensure business continuity and real-time performance.
[0031] In one possible design, the first network device is any one of the following: a router, a gateway, or a switch, and the second network device is a router.
[0032] In addition, other technical effects of the method described in the second aspect can refer to the technical effects of the method described in the first aspect, and will not be repeated here.
[0033] In a third aspect, a communication device is provided. The communication device can be used in the first network device of the first aspect. The communication device can be a router, a gateway, or a switch, or a device in a router, a gateway, or a switch (for example, a chip, or a chip system, or a circuit), or a device that can be used in conjunction with a router, a gateway, or a switch. In one possible implementation, the communication device may include: a module or unit corresponding to executing the method / operation / step / action described in the first aspect, and the module or unit may be a hardware circuit, or software, or a combination of a hardware circuit and software.
[0034] In one possible implementation, the communication device described in the third aspect includes: a transceiver module and a processing module. The transceiver module is configured to receive a first message from a terminal. The processing module is configured to obtain a second message. The transceiver module is configured to send the second message to a second network device. The second message is obtained by encapsulating security information within the first message, the security information being used to indicate that the second message is a trusted message determined by the communication device.
[0035] In one possible design, the security information may include first verification information, the first verification information being used to indicate that the second message is a trusted message determined by the communication device described in aspect 3. Optionally, the first verification information is password-protected information.
[0036] Optionally, the security information may also include second verification information, which may include one or more of the following: an identifier of the verification algorithm, anti-replay information, an identifier of the communication device described in the third aspect, a key ciphertext, an identifier of the second network device, an internally reachable address of the third device, or a first indication information, where the third device is a downstream device of the second network device, and the first indication information is used to indicate the type of security information.
[0037] Optionally, the second verification information may further include second indication information, and the second indication information is used to indicate whether the security information includes one or more of the following: an identifier of the verification algorithm, anti-replay information, an identifier of the communication device described in the third aspect, or a key ciphertext.
[0038] Optionally, the second verification information may also include second indication information, and the second indication information is used to indicate the position and / or length of one or more of the following in the second message: the first verification information, the identification of the verification algorithm, anti-replay information, the identification of the communication device described in the third aspect, or the key ciphertext.
[0039] Optionally, the first verification information is in a header or a tail of the second packet, and the second verification information is in a header or a tail of the second packet.
[0040] Optionally, the second packet is an Internet Protocol version 4 (IPv4) packet or an Internet Protocol version 6 (IPv6) packet. When the second packet is an IPv4 packet, the second verification information is between an IPv4 header and a payload of the IPv4 packet, or when the second packet is an IPv6 packet, the second verification information is in an extension header of an IPv6 protocol header of the IPv6 packet.
[0041] Optionally, the transceiver is further configured to receive first configuration information from the network controller before sending the second packet to the second network device. The first configuration information can include one or more of a public address of the third device, the first verification information, a verification algorithm, an identifier of the verification algorithm, anti-replay information, a first key, the anti-replay information, an identifier of the apparatus of the third aspect, a key cipher, an identifier of the second network device, an internal reachable address of the third device, first indication information, or second indication information, the verification algorithm, the anti-replay information, and the first key being used to determine the first verification information.
[0042] Optionally, the destination address of the first packet and the second packet is the public address of the third device.
[0043] In a possible design, the apparatus of the third aspect is any one of a router, a gateway, or a switch, and the second network device is a router.
[0044] Optionally, the transceiver can include a sending module and a receiving module. The sending module is configured to implement the sending function of the apparatus of the third aspect, and the receiving module is configured to implement the receiving function of the apparatus of the third aspect.
[0045] Optionally, the apparatus of the third aspect can further include a storage module storing a program or an instruction. When the processing module executes the program or the instruction, the apparatus can perform the method of the first aspect.
[0046] In addition, the technical effects of the apparatus of the third aspect can refer to those of the method of the first aspect, which are not described herein again.
[0047] In a fourth aspect, a communication apparatus is provided. The communication apparatus can be used in the second network device of the second aspect. The communication apparatus can be a router, or a device (e.g., a chip, or a chip system, or a circuit) in the router, or a device capable of being used in the router. In a possible implementation, the communication apparatus can include a module or unit corresponding to the method / operation / step / action described in the second aspect. The module or unit can be a hardware circuit, or software, or a combination of hardware circuit and software.
[0048] In a possible implementation, the communication apparatus of the fourth aspect includes a transceiver module and a processing module. The transceiver module is configured to receive the second packet from the first network device. The processing module is configured to verify the second packet. The second packet encapsulates security information. The security information is used to indicate that the second packet is a trusted packet determined by the first network device.
[0049] In a possible design, the security information can include first verification information. The first verification information is used to indicate that the second packet is a trusted packet determined by the first network device. Optionally, the first verification information is password protection information.
[0050] Optionally, the security information can further include second verification information. The second verification information can include one or more of the following: an identifier of a verification algorithm, anti-replay information, an identifier of the first network device, a key ciphertext, an identifier of the communication apparatus, an internal reachable address of a third device, or first indication information used to indicate a type of the security information.
[0051] Optionally, the second verification information can further include second indication information. The second indication information is used to indicate whether the security information includes one or more of the following: the identifier of the verification algorithm, the anti-replay information, the identifier of the first network device, or the key ciphertext.
[0052] Optionally, the second verification information can further include second indication information. The second indication information is used to indicate a position and / or length of one or more of the following in the second packet: the first verification information, the identifier of the verification algorithm, the anti-replay information, the identifier of the first network device, or the key ciphertext.
[0053] Optionally, the first verification information is in a header or a tail of the second packet, and the second verification information is in the header or the tail of the second packet.
[0054] Optionally, the second message is an Internet Protocol version 4 (IPv4) message, or an Internet Protocol version 6 (IPv6) message. If the second message is an IPv4 message, the second verification information is located between the IPv4 header and the payload of the IPv4 message, or if the second message is an IPv6 message, the second verification information is located in an extension header of the IPv6 protocol header of the IPv6 message.
[0055] Optionally, the processing module is further configured to determine third verification information based on the second verification information, thereby verifying the second message based on the first verification information and the third verification information.
[0056] Furthermore, if the first verification information and the third verification information are the same, the processing module is further configured to update the destination address of the second message to the internally reachable address of the third device, obtain a third message, and control the transceiver module to send the third message to the third device. Alternatively, if the first verification information and the third verification information are different, the processing module is further configured to discard the second message.
[0057] Furthermore, the processing module is further configured to determine the second key according to the key ciphertext or the identifier of the first network device, thereby determining the third verification information according to the verification algorithm, the anti-replay information and the second key.
[0058] Optionally, the processing module is further configured to determine, before determining the third verification information based on the second verification information, that the security information includes the identifier of the first network device. Alternatively, the processing module is further configured to determine that the security information does not include the identifier of the first network device, and the processing module discards the second message or controls the transceiver module to send the second message to the high-defense scrubbing center.
[0059] In one possible design, the transceiver module is further configured to receive second configuration information from the network controller before the processing module verifies the second message. The second configuration information includes one or more of the following: an internally reachable address of a third device, an identifier of the communication device described in the fourth aspect, an identifier of the first network device, or a third key, where the third key is used to decrypt the key ciphertext to obtain the second key.
[0060] In one possible design scheme, the first network device is any one of the following: a router, a gateway, or a switch, and the communication device described in the fourth aspect is a router.
[0061] Optionally, the transceiver module may also include a sending module and a receiving module, wherein the sending module is used to implement the sending function of the device described in the fourth aspect, and the receiving module is used to implement the receiving function of the device described in the fourth aspect.
[0062] Optionally, the apparatus described in the fourth aspect may further include a storage module, wherein the storage module stores a program or instruction. When the processing module executes the program or instruction, the apparatus may execute the method described in the second aspect.
[0063] In addition, the technical effects of the device described in the fourth aspect can refer to the technical effects of the method described in the second aspect, and will not be repeated here.
[0064] In a fifth aspect, a communication device is provided. The device includes a processor. The processor is configured to execute the method described in the first aspect or the second aspect.
[0065] In one possible design solution, the apparatus described in the fifth aspect may further include a transceiver. The transceiver may be a transceiver circuit or an interface circuit. The transceiver may be used for the apparatus to communicate with other apparatuses.
[0066] In one possible design, the apparatus described in the fifth aspect may further include a memory. The memory may be integrated with the processor or provided separately. The memory may be used to store the computer program (or a set of instructions) and / or data involved in the method described in the first aspect or the second aspect.
[0067] In the present application, the apparatus described in the fifth aspect may be the network device described in the first aspect or the second aspect, or a chip (system) or other parts or components that may be set in the network device, or an apparatus including the network device.
[0068] In addition, the technical effects of the device described in the fifth aspect can refer to the technical effects of the method described in the first aspect or the second aspect, and will not be repeated here.
[0069] In a sixth aspect, a communication device is provided. The device includes a processor coupled to a memory. The memory is configured to store computer instructions, and when the processor executes the instructions, the device executes the method described in the first or second aspect.
[0070] In one possible design solution, the apparatus described in the sixth aspect may further include a transceiver. The transceiver may be a transceiver circuit or an interface circuit. The transceiver may be used for the apparatus to communicate with other apparatuses.
[0071] In the present application, the apparatus described in the sixth aspect may be the network device described in the first aspect or the second aspect, or a chip (system) or other parts or components that may be set in the network device, or an apparatus including the network device.
[0072] In addition, the technical effects of the device described in the sixth aspect can refer to the technical effects of the method described in the first aspect or the second aspect, and will not be repeated here.
[0073] In a seventh aspect, a communication device is provided, which includes a logic circuit and an input / output interface.
[0074] In one possible implementation, the communication device described in the seventh aspect is applicable to the network device described in the first aspect, such as the first network device, or a chip (system) or other parts or components that can be set in the network device, or a device including the network device.
[0075] The input / output interface is configured to receive a first message from a terminal. The logic circuit is configured to obtain a second message. The input / output interface is further configured to send the second message to a second network device. The second message is obtained by encapsulating security information within the first message, and the security information indicates that the second message is a trusted message determined by the communication device.
[0076] Optionally, the apparatus described in the seventh aspect may further include a transceiver. The transceiver may be a transceiver circuit or an interface circuit. The transceiver may be used for the apparatus to communicate with other apparatuses.
[0077] Optionally, the apparatus described in the seventh aspect may further include a memory. The memory may be integrated with the processor or provided separately. The memory may be used to store the computer program and / or data involved in the method described in the first aspect.
[0078] In another possible implementation, the communication device described in the seventh aspect is applicable to the network device described in the second aspect, such as the second network device, or a chip (system) or other parts or components that can be set in the network device, or a device including the network device.
[0079] The input / output interface is configured to receive a second message from the first network device. The logic circuit is configured to verify the second message. The second message is encapsulated with security information, the security information being configured to indicate that the second message is a trusted message determined by the first network device.
[0080] Optionally, the apparatus described in the seventh aspect may further include a transceiver. The transceiver may be a transceiver circuit or an interface circuit. The transceiver may be used for the apparatus to communicate with other apparatuses.
[0081] Optionally, the apparatus described in the seventh aspect may further include a memory. The memory may be integrated with the processor or provided separately. The memory may be used to store the computer program and / or data involved in the method described in the second aspect.
[0082] In addition, the technical effects of the device described in the seventh aspect can refer to the technical effects of the method described in the first aspect or the second aspect, and will not be repeated here.
[0083] In an eighth aspect, a communication device is provided. The device includes a processor and a transceiver. The transceiver is used to exchange information between the communication device and other devices, and the processor executes program instructions to perform the method described in the first or second aspect.
[0084] In one possible design, the apparatus described in aspect 8 may further include a memory. The memory may be integrated with the processor or provided separately. The memory may be used to store the computer program and / or data involved in the method described in aspect 1 or aspect 2.
[0085] In the present application, the apparatus described in the eighth aspect may be the network device described in the first aspect or the second aspect, or a chip (system) or other parts or components that may be set in the network device, or an apparatus including the network device.
[0086] In addition, the technical effects of the device described in the eighth aspect can refer to the technical effects of the method described in the first aspect or the second aspect, and will not be repeated here.
[0087] In a ninth aspect, a communication system is provided, which includes the network device in the method described in the first aspect, such as the first network device and the positioning management network element, and the network device in the method described in the second aspect, such as the second network device.
[0088] In a tenth aspect, a computer-readable storage medium is provided, comprising: a computer program; when the computer program runs on a computer, the method described in the first aspect or the second aspect is executed.
[0089] In an eleventh aspect, a computer program product is provided, comprising a computer program, wherein when the computer program or instructions are run on a computer, the method described in the first aspect or the second aspect is executed. BRIEF DESCRIPTION OF THE DRAWINGS
[0090] Figure 1 This is a schematic diagram of a flood attack scenario;
[0091] Figure 2 Schematic diagram of the black hole solution and traffic cleaning solution;
[0092] Figure 3 A schematic diagram of the architecture of a communication system provided in an embodiment of the present application;
[0093] Figure 4 Schematic diagram of the communication method provided in this embodiment Figure 1 ;
[0094] Figure 5 Schematic diagram of the structure of the IPv4 message in the communication method provided in the embodiment of the present application Figure 1;
[0095] Figure 6 Schematic diagram of the structure of the IPv4 message in the communication method provided in the embodiment of the present application Figure 2 ;
[0096] Figure 7 A schematic diagram of the structure of an IPv6 message in the communication method provided in an embodiment of the present application;
[0097] Figure 8 Schematic diagram of the structure of the IPv4 message in the communication method provided in the embodiment of the present application Figure 3 ;
[0098] Figure 9 Schematic diagram of the structure of the IPv4 message in the communication method provided in the embodiment of the present application Figure 4 ;
[0099] Figure 10 A schematic diagram of an application scenario of the communication method provided in an embodiment of the present application;
[0100] Figure 11 Schematic diagram of the structure of the communication device provided in the embodiment of the present application Figure 1 ;
[0101] Figure 12 Schematic diagram of the structure of the communication device provided in the embodiment of the present application Figure 2 ;
[0102] Figure 13 Schematic diagram of the structure of the communication device provided in the embodiment of the present application Figure 3 . DETAILED DESCRIPTION
[0103] The following introduces the technical terms involved in the embodiments of this application.
[0104] 1. Packet attack:
[0105] A packet attack occurs when an attacker disguises attack packets and then attacks a targeted device, potentially leaking data or even causing device failure, resulting in significant economic losses. A typical packet attack is a distributed denial of service (DDoS) attack, such as a flooding DDoS attack (hereinafter referred to as a flooding attack). The attacker utilizes a large number of botnet hosts to centrally send attack traffic to the targeted device. This overwhelming resource advantage depletes the device's bandwidth, computing, or storage resources, causing device failure and service interruption.
[0106] There are two main types of flood attacks: Figure 1See (a) and (b) in the Figure 1 In (a), a flood attack (denoted as flood attack 1) is an attack in which the attacker sends a large number of attack packets to the attacked device. These attack packets carry false or unreachable Internet Protocol (IP) addresses, causing the attacked device to maintain a large number of semi-connections or respond to a large number of unreachable packets, causing the attacked device to exhaust its resources. Figure 1 In another flooding attack (b) (denoted as Flood Attack 2), the attacker uses a large number of zombie hosts to send a large number of packets to the attacked device, directly exhausting the attacked device's resources. Therefore, three solutions have been proposed for flooding attacks: black hole, traffic scrubbing, and interactive challenge verification. They are described below.
[0107] 2. Black Hole
[0108] See also Figure 2 The black hole solution means that when the attack traffic of a flood attack reaches the attacked device, the attacked device can request its Internet service provider (ISP) to direct all traffic sent to the attacked device to a black hole, that is, a device dedicated to receiving traffic, to ensure that the attacked device is no longer affected. For example, other devices connected to the attacked device or sharing the link are not affected.
[0109] 3. Traffic cleaning:
[0110] See also Figure 2 The traffic cleaning solution means that when the attack traffic of a flood attack reaches the attacked device, the attacked device can request its ISP to send all traffic destined for the attacked device to a high-defense cleaning center. The high-defense cleaning center can be a device specifically designed to identify flood attacks. By deeply analyzing the messages, the high-defense cleaning center can identify the attack characteristics of flood attacks and thus distinguish between legitimate traffic, that is, traffic including normal business messages, and illegal traffic, that is, traffic including abnormal business messages, or attack messages. In this way, the high-defense cleaning center can return the legitimate traffic to the attacked device to ensure business continuity.
[0111] It should be noted that both blackhole and traffic scrubbing solutions are applicable to flood attacks 1 and 2 described above. However, with the blackhole solution, the traffic directed by the ISP to the blackhole often also includes normal business traffic, such as a large number of normal business packets. Since the blackhole only passively receives traffic and does not return this normal business traffic to the attacked device, it causes service interruption and compromises business continuity. With the traffic scrubbing solution, the high-defense scrubbing center takes a long time to deeply analyze the packets, resulting in significant service delays and compromises real-time service delivery.
[0112] 4. Interactive Challenge Verification:
[0113] Interactive challenge verification is a solution to flood attack 1. It determines whether the originally received message is an attack message of flood attack 1 by judging whether the response message from the client is received.
[0114] Specifically, the client can send message 1 to the server. Message 1 can be a synchronous idle character (SYN) message, or any other possible form of message, without limitation. The server determines the SYN cookie. For example, the server can encrypt and calculate the SYN cookie based on the source IP address, destination IP address, source port, destination port, and SYN sequence number of message 1, so that the SYN cookie cannot be forged. Afterwards, the server can send message 2 to the client. Message 2 can be an acknowledgment (ACK) message for message 1, carrying the SYN cookie. In this way, the client can determine SYN cookie+1. For example, the client can extract the SYN cookie from message 2 to further determine SYN cookie+1. Finally, the client can send message 3 to the server. Message 3 can be an ACK message for message 2, carrying SYN cookie+1. The server can verify Message 3 and, based on the SYN cookie+1 in Message 3, determine that Message 3 is a normal service message. It can then continue processing the service to ensure real-time and continuous service. However, if the server determines that Message 3 does not carry the SYN cookie+1, or if it times out without receiving Message 3, then Message 1 is an attack message from a spoofed IP address. The server can terminate the half-connection with the client to avoid the overhead of maintaining the half-connection and conserve server resources.
[0115] As can be seen, in the interactive challenge authentication scheme, the server encapsulates the SYN cookie in each received message by responding to it, thereby identifying flood attack 1 through the SYN cookie. Because the server needs to respond to every received message, this response method will still cause the server's resources to be quickly exhausted when facing flood attack 2, making it unable to resist flood attacks.
[0116] Therefore, neither black hole, traffic cleaning, nor interactive challenge verification can achieve the goal of resisting message attacks while ensuring business continuity and real-time performance.
[0117] In response to the above technical problems, the embodiments of the present application propose the following technical solutions. The technical solutions of the embodiments of the present application can be applied to various data networks, such as data center networks, enterprise or campus networks, edge computing networks, cloud networks, etc.
[0118] This application will present various aspects, embodiments, or features in the context of systems that may include multiple devices, components, modules, etc. It should be understood and appreciated that each system may include additional devices, components, modules, etc., and / or may not include all of the devices, components, modules, etc. discussed in conjunction with the figures. Furthermore, combinations of these aspects may also be used.
[0119] Additionally, in the embodiments of this application, words such as "exemplarily" and "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described in this application as an "exemplary" should not be construed as being preferred or advantageous over other embodiments or designs. Rather, the use of the word "exemplary" is intended to present concepts in a concrete manner.
[0120] The network architecture and business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. Ordinary technicians in this field will know that with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.
[0121] To facilitate understanding of the embodiments of the present application, first Figure 3 The communication system shown in FIG is used as an example to describe in detail the communication system applicable to the embodiment of the present application. Figure 3 A schematic diagram of the architecture of a communication system applicable to the communication method provided in an embodiment of the present application.
[0122] like Figure 3 As shown, the communication system includes: a terminal and a network device.
[0123] The terminal is a terminal that accesses the communication system and has transceiver functions, or a chip or chip system that can be set in the terminal. The terminal can also be called user equipment (UE), access terminal, subscriber unit, user station, mobile station (MS), mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent or user device. The terminal in the embodiments of the present application can be a mobile phone, a cellular phone, a smart phone, a tablet computer, a wireless data card, a personal digital assistant (PDA), a wireless modem, a handset, a laptop computer, a machine type communication (MTC) terminal, a computer with wireless transceiver function, a virtual reality (VR) terminal, an augmented reality (AR) terminal, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical care, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, a vehicle-mounted terminal, an RSU with terminal function, etc. The terminal of the present application can also be a vehicle-mounted module, a vehicle-mounted module, a vehicle-mounted component, a vehicle-mounted chip or a vehicle-mounted unit built into a vehicle as one or more components or units. It should be noted that a terminal may be provided with a corresponding client, so the client mentioned below may be understood as the terminal where the client is located, and the two may be interchangeable.
[0124] The above-mentioned network devices can be multiple, such as a first network device and a second network device, which are located on the network side of the above-mentioned communication system and are devices with transceiver functions or chips or chip systems that can be set in the devices. The network device may include: a forwarding device, such as a router, such as an access router (AR), a switch, such as an access switch, an aggregation switch, a core switch, or a gateway, and other physical devices supporting routing or switching functions; it may also be a virtual device supporting route publishing and message forwarding, etc. It may be a controller in a communication network, or it may also be a node or server in the communication network, such as a data server, a network server, a cloud server, etc., or a server cluster composed of these servers, such as a gNB in a new radio (NR) system, or one or a group of antenna panels (including multiple antenna panels) of a base station in a 5G system, or it may also be a network node constituting a gNB, a transmission and reception point (TRP) or a transmission point (TP), or a transmission measurement function (TMF), such as a baseband unit (BBU), a central unit (CU), a distributed unit (DU), a road side unit (RSU) with base station functions, or a wired access gateway, etc. In addition, in systems using different wireless access technologies, the names of network devices may be different, such as NB (NodeB) in wideband code division multiple access (WCDMA), eNB or eNodeB (evolutionaryNodeB) in long term evolution (LTE). Network devices can also be wireless controllers in cloud radio access network (CRAN) scenarios. In addition, network devices can also include access points (APs) in wireless fidelity (WiFi) systems, wireless relay nodes, wireless backhaul nodes, various forms of macro base stations, micro base stations (also known as small stations), relay stations, access points, wearable devices, vehicle-mounted devices, and so on.
[0125] Specifically, taking the first network device as an example, the first network device can be customer premises equipment (CPE), and an example of its device form can be any of the following: a router, a switch, or a gateway, etc., which supports routing or switching functions. Or it can also be a server, such as a data server, a network server, a cloud server, or a server cluster composed of these servers. This application does not impose any restrictions on this. There can be multiple first network devices, and multiple first network devices are interconnected to form a ring network, such as a star ring network, a single ring network or a multi-ring network, a non-ring network, or any other possible form of network topology. This application does not impose any restrictions on this.
[0126] Taking the second network device as an example, the second network device can be a CPE, a cloud entry device, or a cloud exit device. Similar to the first network device, an example of its device form factor can be any of the following: a forwarding device supporting routing or switching functions, such as a router, switch, or gateway; or a server, such as a data server, a network server, a cloud server, or a server cluster composed of these servers. There can also be multiple second network devices, which can be interconnected to form a ring network, a non-ring network, or any other possible network topology.
[0127] Optionally, the communication system may further include a third device, which may be a network device different from the first network device and the second network device in the communication system, or may be a terminal different from the terminal. On the one hand, with respect to the physical form of the first network device, it may specifically be a server, such as a data server, a network server, a cloud server, etc., or a server cluster composed of these servers, and this application does not impose any restrictions on this. With respect to the functional form of the first network device, the third device may provide security services, such as a firewall; in addition, the third device may provide cloud services, that is, the third device may be a cloud device, but this is not limited, and the third device may also provide conventional services, i.e., non-cloud services.
[0128] Among them, the terminal, the first network device, the second network device and the third device can be applied to the routing forwarding scenario, and execute the communication method provided in the embodiment of the present application to achieve cross-regional, cross-area, or cross-network layer anti-message attack in the forwarding scenario. Figure 4-Figure 9 The communication method provided in the embodiments of the present application is described in detail.
[0129] For example, Figure 4 Schematic diagram of the communication method provided in this embodiment Figure 1 This communication method can be applied to Figure 3The communication system shown in FIG. 1 includes communication between a terminal and a network device, such as a first network device and a second network device. Figure 4 As shown, the communication method includes:
[0130] S401: A terminal sends a first message to a first network device. Correspondingly, the first network device receives the first message from the terminal.
[0131] The first message may be an Internet Protocol version 4 (IPv4) message or an Internet Protocol version 6 (IPv6) message. Alternatively, the first message may be a next-generation Internet Protocol message, for example, the next-generation Internet Protocol message may be called an Internet Protocol version 6 (IPv6+) message, an Internet Protocol version 9 (IPv9) message, a new Internet Protocol version (New IP) message, or any other possible naming form, which is not limited in this application.
[0132] The destination device corresponding to the first message can be a third device, that is, the first message needs to be sent to the third device, and can pass through the first network device and the second network device, that is, the third device is the downstream device of the first network device and the second network device. In this way, the destination address of the first network device can be the address of the third device, such as the public address of the third device. The public address of the third device means: the address points to the third device, but the third device is not reachable. For example, it can be the high-defense IP address prefix of the third device. In other words, the message carrying the public address of the third device cannot be sent directly to the third device, but can be sent to a network device that can reach the third device, such as the first network device or the second network device. After these network devices determine that the message is not an attack message, they update the destination address of the message to the internal reachable address of the third device, and then forward it to the third device to avoid the third device being directly attacked by the message. Among them, the internal reachable address can be a true destination IP address (true inner destination IP address, TrueInnerDstIP) and is only available to a third device, that is, only the third device can recognize the internal reachable address and route or consume messages according to the internal reachable address. For specific implementation, please refer to the following S403 and the relevant introduction in the second possible application scenario, which will not be repeated here.
[0133] For the terminal, the terminal can obtain the public address of the third device from a domain name server (DNS), or the public address of the third device can be pre-configured locally, without limitation. Taking obtaining from the DNS as an example, the DNS is pre-configured with a correspondence between the domain name of the third device and the public address of the third device, for example, the correspondence is configured for the DNS by a network control entity (NCE). The terminal can access the DNS according to the domain name of the third device, thereby obtaining the public address of the third device, and encapsulate the public address of the third device into the message to be sent to obtain the first message.
[0134] S402: The first network device sends a second message to the second network device. Correspondingly, the second network device receives the second message from the first network device.
[0135] The second message is obtained by encapsulating security information within the first message. The security information is used to indicate that the second message is a trusted message confirmed by the first network device, or in other words, the security information is used to indicate that the second message is a trusted message confirmed, guaranteed, verified, authenticated, or certified by the first network device. If the first message is an IPv4 message, an IPv6 message, or a next-generation Internet Protocol message, the obtained second message is also an IPv4 message, an IPv6 message, or a next-generation Internet Protocol message.
[0136] The security information may include first verification information, which may be an authentication code (authcode) or password-protected information, used to indicate that the second message is a trusted message determined by the first network device. In this way, the security information can be prevented from being forged or tampered with, thereby improving the credibility of the security information. The first verification information may be determined by the first network device based on a verification algorithm, anti-replay information, and a first key. The verification algorithm may, for example, be a hash-based message authentication code (HMAC) algorithm, a cipher-based message authentication code (CMAC) algorithm, a message authentication code based on universal hashing (UMAC) algorithm, a Galois message authentication code (GMAC) algorithm, etc. The anti-replay information may, for example, be a non-repeating sequence number (SEQ), a random number, a timestamp, etc. The first key may be a private key of the first network device, such as a secret symmetric key, an asymmetric decryption key, or a quantum key, etc.
[0137] In one possible implementation, the first network device is pre-configured with a public address list. For messages sent to the corresponding public address in the public address list, the first network device needs to add security information to the message to prove that the message is a trusted message determined by the first network device, rather than an attack message, thereby ensuring that the trusted message can be received by the device corresponding to the public address. On this basis, after receiving the first message, the first network device determines that the public address of the third device in the first message belongs to the public address in the public address list, thereby determining the first verification information based on the verification algorithm, SEQ and the first key information, and encapsulating the first verification information in the first message to obtain the second message. Optionally, the first verification information is encapsulated in the head or tail of the first message to obtain the second message. For example, Figure 5 As shown, the second message is an IPv4 message, and the first verification information can be located at the end of the IPv4 message. Figure 6As shown, the second message is an IPv6 message, and the first verification information can be located at the end of the IPv6 message, for example, encapsulated in an integrity check value (ICV) at the end of the IPv6 message. It should be noted that the length of the first verification information and the position of the first verification information in the second message can be agreed upon in advance by the first network device and the second network device, or predefined by the protocol, so that the second network device can subsequently extract the first verification information from the second message.
[0138] Optionally, the security information may also include second verification information, which may include one or more of the following: an identifier of the first network device or a key ciphertext. The identifier of the first network device may be an authenticated identifier (AID), and the second message carries the identifier of the first network device, indicating that the second message is from a trusted device, such as a trusted message from the first network device. There may be multiple first network devices, each of which may have its own corresponding identifier. These identifiers may be the same or different to distinguish between the first network devices, such as first network device 1 {AID1}, first network device 2 {AID2}, first network device 3 {AID3}, and so on. Furthermore, the key ciphertext may be a cryptographic key descriptor (KeyInfo), which may be encrypted using a second key, or an identifier of the second key, indicating the second key. The second key may be the same key as the first key, or a different key. For example, the first key and the second key may have a derivative relationship, and the second key may be calculated based on the first key to verify the security information on the second network device. As can be seen, as a method for implementing verification, the first network device does not directly send the second key to the second network device. Instead, it sends a key ciphertext indicating the second key or encrypted with the second key. This can improve communication security, prevent the second key from being stolen during communication, and ensure the reliability of verification. The specific implementation of the second network device verifying the security information can be referred to the relevant description of S403 below and will not be repeated here.
[0139] Optionally, the second verification information may further include second indication information, and the second indication information is used to indicate whether the security information includes one or more of the following: the identification of the first network device or the key ciphertext. For example, the second indication information includes multiple bits (recorded as bit string 1), and the value of each bit in the bit string 1 can be used to indicate whether the security information includes the above-mentioned corresponding information, such as the identification of the first network device or the key ciphertext. Assume that the second indication information includes 2 bits, the value of the first bit is used to indicate whether the security information includes the identification of the first network device, and the value of the second bit is used to indicate whether the security information includes the key ciphertext. Alternatively, the value combination of the bit string 1 can be used to indicate whether the security information includes one or more of the following: the identification of the first network device, or the key ciphertext. Continuing with the above assumption, the second indication information includes 2 bits. A value of 11 for the 2 bits indicates that the security information includes the identifier and key ciphertext of the first network device. A value of 00 for the 2 bits indicates that the security information does not include the identifier and key ciphertext of the first network device. A value of 10 for the 2 bits indicates that the security information only includes the identifier of the first network device. A value of 01 for the 2 bits indicates that the security information only includes the key ciphertext. Alternatively, the second indication information is further used to indicate the position and / or length of one or more of the following in the second message: the identifier of the first network device, or the key ciphertext. For example, the second indication information also includes more bits (denoted as bit string 2) to indicate the position and length of the identifier of the first network device in the second message, such as the starting position, ending position, length, etc. of the identifier of the first network device in the second message, and / or to indicate the position and / or length of the key ciphertext in the second message, such as the starting position, ending position, length, etc. of the key ciphertext in the second message. Continuing with the above assumption, the second indication information also includes 6 bits after the above 2 bits. Among these 6 bits, the value combination of 3 bits is used to indicate the position and / or length of the identifier of the first network device in the second message, and the value combination of the other 3 bits is used to indicate the position and / or length of the key ciphertext in the second message.
[0140] It should be noted that in the above implementation, the second indication information indicates whether the security information includes the identifier of the first network device and / or the key ciphertext through the bit string 1, and indicates the position and / or length of the identifier of the first network device and / or the key ciphertext in the second message through the bit string 2. In other implementations, for each piece of information in the identifier of the first network device and the key ciphertext, the second indication information can also use the same bit to indicate whether the security information includes the piece of information, and the position and / or length of the piece of information in the second message. For example, if the bits are in a specific value combination, it indicates that the security information does not include the piece of information; if the bits are in another value combination, it indicates the position and / or length of the piece of information in the second message, that is, implicitly indicates that the security information includes the piece of information. Continuing the above assumption, the second indication information includes 8 bits, and the specific value combination of the first 4 bits, such as all 0 or all 1, is used to indicate that the security information does not include the identifier of the first network device, and the other value combination of the first 4 bits, such as 1010, is used to indicate the position and / or length of the identifier of the first network device in the second message. Similarly, the specific value combination of the last 4 bits, such as all 0 or all 1, is used to indicate that the security information does not include the key ciphertext, and the other value combination of the last 4 bits, such as 0011, is used to indicate the position and / or length of the key ciphertext in the second message. In yet other implementations, the second indication information can also be used to indicate the position and / or length of the above-mentioned first verification information in the second message, for example, the start position, end position, length, and the like of the first verification information in the second message. The specific implementation is similar to the above-mentioned identifier of the first network device and / or key ciphertext, and can be understood with reference, and will not be described again. In another possible implementation, the length of the identifier of the first network device and / or the key ciphertext, and the position thereof in the second message can be previously agreed upon by the first network device and the second network device, or predefined by a protocol, so that the second network device can subsequently extract the identifier of the first network device and / or the key ciphertext from the second message. In addition, if the second indication information only indicates the position of the above-mentioned information, the length of the information can be previously agreed upon by the first network device and the second network device, or predefined by a protocol, for example, a fixed length; similarly, if the second indication information only indicates the length of the above-mentioned information, the position of the information can be previously agreed upon by the first network device and the second network device, or predefined by a protocol.
[0141] It can be understood that by carrying the second indication information in the second verification information, the second network device can accurately extract the above-mentioned one or more information from the second message based on the second indication information, such as the above-mentioned first verification information, the identification of the first network device, the key ciphertext, etc., to ensure the accuracy and reliability of subsequent verification, and avoid verification failure caused by the second network device's failure to accurately extract the above-mentioned one or more information. Because the second indication information can indicate the position and / or length of the above-mentioned one or more information in the second message, the above-mentioned one or more information can be more flexibly encapsulated in the second message, making the structure of the second message more flexible, the business compatibility better, and applicable to more business scenarios.
[0142] Similar to the first verification information being at the head or tail of the second message, the second verification information can also be at the head or tail of the second message. That is, the first network device can encapsulate the first verification information and the second verification information at the head or tail of the first message, respectively, to obtain the second message. Among them, since the second network device usually parses the second message in the order from the head to the tail of the second message. On this basis, an optional method is to encapsulate the first verification information at the tail of the second message and the second verification information at the head of the second message, so that the second network device can synchronize the processing of the second verification information and the parsing of the second message. For example, when the second network device is ready for verification according to the second verification information, it also synchronizes the parsing to the tail of the second message and extracts the first verification information to verify the second message at the first time, avoid excessive waiting time, and improve the verification efficiency of the second network device.
[0143] Method 11, such as Figure 5 and Figure 6As shown, the second verification information is located between the IPv4 header and the payload of the IPv4 message, for example, between the User Datagram Protocol (UDP) header after the IPv4 header and the inner IP header before the payload. Specifically, the second verification information can be encapsulated in the SecTag header of the Media Access Control (MAC) security policy (SEC) between the UDP header and the payload. The SecTag header may include: an Ethernet type cell, a Tag Control Information (TCI) cell, a Security Association Number (AN) cell, a Short Length (SL) cell, a Packet Number (PN) cell, and a Secure Channel Indicator (SCI) cell. The Ethernet type cell is 2 bytes long. The TCI cell is 6 bits long, and the AN cell is 2 bits long, so the sum of the lengths of the TCI cell and the AN cell is 1 byte. The SL cell is 1 byte long. The PN cell is 4 bytes long. The SCI cell is 8 bytes long. The second verification information can be encapsulated in one or more of the aforementioned cells, such as the SCI cell, or any other possible cell, to achieve cell multiplexing and reduce communication overhead. Of course, encapsulating the second verification information in the SecTag header is merely an example and not a limitation. For example, the second verification information can be encapsulated as a separate cell between the SecTag header and the inner IP header, and this application does not impose any limitations on this.
[0144] Method 12, such as Figure 7 As shown, the second verification information can be located in an extension header of the IPv6 protocol header of the IPv6 packet. Specifically, the second verification information can be encapsulated in some cells of the extension header, such as the destination options, or any other possible cells, and identified by a type-length-value (TLV) to achieve cell multiplexing and save communication overhead. Of course, the second verification information can also be encapsulated in the extension header as an independent cell, and this application does not impose any restrictions on this.
[0145] Combining the above-mentioned methods 11 and 12, it can be seen that by encapsulating the second verification information between the IPv4 header and the payload of the IPv4 message, or in the extension header of the IPv6 protocol header of the IPv6 message, compatibility with the current IPv4 message or IPv6 message can be achieved, the protocol changes are smaller, and it is more convenient for practical application.
[0146] In this embodiment of the present application, the destination address of the second message is still the public address of the third device. Thus, the first network device can send the second message to the second network device based on the egress port corresponding to the public address of the third device. Accordingly, the second network device can receive the second message through the ingress port connected to the first network device, thereby continuing to execute S403 below.
[0147] S403: The second network device parses the second message.
[0148] The second network device parsing the second message refers to decapsulating the second message and extracting the security information from the second message.
[0149] Specifically, in one embodiment, the security information includes first verification information. The second network device can locally pre-configure the corresponding verification algorithm, anti-replay information, and second key, or configure third verification information determined by the verification algorithm, anti-replay information, and second key, either through pre-configuration or protocol pre-defined methods. In this way, after extracting the first verification information from the second message based on a pre-agreed position and length, or a position and length pre-defined by the protocol, the second network device can further determine whether the first verification information is identical to the third verification information. By comparing the first and third verification information for identity, it is possible to accurately identify whether the first verification information has been tampered with or whether the first verification information is forged, thereby improving the security and reliability of the verification. For example, if the first and third verification information are identical, it indicates that the second message is legitimate and verification of the second message has passed. The second network device can then update the destination address of the second message to the internally reachable address of the third device. For example, the second network device can traverse the routing table entries and update the internally reachable address of the third device recorded in the routing table entries to the destination address of the second message, thereby obtaining the third message and sending the third message to the third device. If the first verification information is different from the third verification information, it means that the second message may be an illegal message, and the verification of the second message fails. The second network device can discard the second message, or the second network device can still send the second message to the high-defense cleaning center.
[0150] In another embodiment, the security information includes first verification information and second verification information. The second network device may extract the first verification information, the key ciphertext, and / or the identifier of the first network device from the second message based on a pre-agreed position and length, or a position and length predefined by the protocol. Alternatively, if the second verification information includes second indication information, the second network device may further extract the first verification information, the key ciphertext, and / or the identifier of the first network device from the second message based on the second indication information. In this manner, the second network device may determine the second key based on the key ciphertext or the identifier of the first network device, as described in detail below.
[0151] In Method 21, when the key ciphertext is encrypted using the second key, the second network device may be pre-configured with a corresponding third key. The third key can be used to decrypt the key ciphertext. For example, the third key and a corresponding decryption algorithm can be used to decrypt the key ciphertext to obtain the second key. The third key can be a private key of the second network device, such as a secret symmetric key, an asymmetric decryption key, or a quantum key. When the key ciphertext is an identifier of the second key, the second network device is pre-configured with a corresponding relationship between the identifier of the second key and the second key, and the second key can be determined based on this relationship.
[0152] In method 22, the second network device dynamically maintains a list of identifiers for the first network device. This list records the correspondence between each identifier of the first network device and the key corresponding to the identifier. This correspondence can be dynamically updated based on the configuration issued by the NCE. For example, AID1{key1}, AID2{key2}, AID3{key3}, AID4{key4}, and so on. The second network device can traverse the list of identifiers based on the identifier of the first network device carried in the second verification information to determine the key corresponding to the identifier of the first network device, such as the second key.
[0153] In this way, after the second network device determines the second key, it can determine the third verification information based on the verification algorithm, anti-replay information and the second key, and determine whether the first verification information and the third verification information are the same. If the first verification information and the third verification information are the same, the second network device can update the destination address of the second message to the internal reachable address of the third device, obtain the third message, and send the third message to the third device. If the first verification information and the third verification information are not the same, the second network device can discard the second message, or the second network device can still send the second message to the high-defense cleaning center. Of course, if the second network device determines that the received message does not carry the first verification information, the second network device can also directly discard the message, or send the message to the high-defense cleaning center.
[0154] As can be seen, since the second key is not directly carried in the security information, but needs to be determined by the second network device based on the key ciphertext or the identifier of the first network device, or directly configured locally on the second network device, the second key is a sufficiently secure key that is difficult to forge or tamper with. Therefore, on the premise of ensuring the sufficient security of the second key, the attack message can usually only tamper with or forge other information, such as the verification algorithm and anti-replay information. This means that if the verification algorithm, anti-replay information, etc. are forged or tampered with, the first verification information will be different from the third verification information, resulting in verification failure, thereby reliably and securely verifying whether the second message is a forged or tampered attack message.
[0155] In summary, according to Figure 4 The method shown encapsulates security information in the first message so that the obtained second message is a trusted message determined by the first network device. In this way, the second network device does not need to perform in-depth analysis of the second message. Based on the security information encapsulated in the second message, it can determine whether the second message is an attack message. While achieving resistance to message attacks, such as anti-flood attack 1 and anti-flood attack 2, it can also ensure business continuity and real-time performance. In addition, Figure 4 The application of the method shown in the figure to resisting message attacks is only an example, and the method can also be applied to more scenarios, such as restricting access according to security levels, restricting access according to service quality priorities, etc.
[0156] Optionally, in combination with the above embodiment, in one possible application scenario, the second network device may determine the third verification information based on the second verification information by: the second network device determines whether the security information includes the identifier of the first network device; if the second network device determines that the security information includes the identifier of the first network device, the second network device determines the third verification information based on the second verification information. Conversely, if the second network device determines that the security information does not include the identifier of the first network device, the second network device may discard the second message without performing the above verification process.
[0157] As can be seen, the second message carries the identifier of the first network device, indicating that it comes from a trusted device, such as the first network device. If the second message does not include the identifier of the first network device, it indicates that the second message is untrusted. The second network device can then bypass verification and send the second message to the high-security scrubbing center. This saves processing resources on the second network device and improves its operational efficiency. Furthermore, the fact that the second message is untrusted does not necessarily mean it is an attack message; it could also be a regular data message from the internet. Therefore, sending the second message to the high-security scrubbing center ensures that even if the second message is a regular data message, it can still access the third device, ensuring service reliability and stability. However, if the second message still fails verification despite carrying the identifier of the first network device, it could indicate that it is a tampered or forged attack message. The second network device can discard the second message and not send it to the high-security scrubbing center, thus conserving processing resources.
[0158] It should be noted that the second network device discarding the second message based on determining that the second message carries the identifier of the first network device and fails verification is only an example and not a limitation. At this time, the second network device can still send the second message to the high-defense cleaning center.
[0159] Optionally, in combination with the above embodiments, in a possible application scenario, the above-mentioned second verification information may also include one or more of the following: first indication information, identification of the second network device, identification of the verification algorithm, anti-replay information, or the internal reachable address of the third device.
[0160] The above-mentioned first indication information can be used to indicate the type of security information, such as indicating that the security information is information for resisting flood attack 1 and / or resisting flood attack 2, such as Anti-DDoS information, or can also be used to indicate the type of the second message, such as indicating that the second message is a true and non-forged message or a non-attack message. In addition, since the security information in the embodiment of the present application is not only used for resisting flood attack 1 and / or resisting flood attack 2, it can also be used to limit access according to security level, limit access according to service quality priority, etc., the first indication information can also be used to indicate one or more of the following: the security level of the terminal, the credibility of the message sender, such as the credibility of the terminal or the first network device, the health of the second message, or the priority of service quality, etc., and the present application does not impose any restrictions on this.
[0161] The identifier of the second network device indicates that the second message needs to be processed by the corresponding second network device, which can be a match identifier (Match ID) of a security function executor of the second network device, or any other possible identifier. As an example, there can be multiple second network devices, each of which has a corresponding identifier, which can be the same or different, to distinguish the second network devices. For example, assuming that the multiple second network devices include a second network device 1, a second network device 2, and a second network device 3, the identifiers of the multiple second network devices can be second network device 1{Match ID1}, second network device 2{Match ID2}, and second network device 3{Match ID3}. For a second network device, after receiving the second message, the second network device can determine whether the identifier of the second network device is the same as the identifier of the second network device carried in the second message. If the identifier of the second network device is the same as the identifier of the second network device carried in the second message, the second network device processes the second message, i.e., performs the verification process of S403, which is described above and will not be repeated. If the identifier of the second network device is different from the identifier of the second network device carried in the second message, the second network device can forward the second message to other second network devices until it is forwarded to a second network device with the same identifier. For example, continuing the above assumption, the second message carries Match ID3, and the second network device 1 receives the second message and determines that the Match ID3 carried in the second message is different from the identifier of the second network device 1 itself. According to the routing table, the second network device 1 forwards the second message to the second network device 2. The second network device 2 receives the second message and also determines that the Match ID3 carried in the second message is different from the identifier of the second network device 2 itself, and thus forwards the second message to the second network device 3 according to the routing table. In this way, the second network device 3 can determine that the Match ID3 carried in the second message is the same as the identifier of the second network device 3 itself, and thus verifies the second message. As can be seen, the identifier of the second network device can realize that the second message is sent to a specified second network device for verification, i.e., the first network device determines in advance that different traffic is verified by different second network devices, avoiding sending a large amount of traffic to the same second network device for verification, to realize load balancing of multiple second network devices. Of course, load balancing through the identifier of the second network device is only an example and is not limited. For example, load balancing can also be realized by configuring a specified link between the first network device and the second network device.
[0162] The identifier of the verification algorithm is used to indicate that the second packet needs to be verified by using the corresponding verification algorithm, which can be a cipher suite identifier (CipherSuitID) of the verification algorithm. The second network device is locally configured with multiple verification algorithms, and is further configured with a correspondence between each verification algorithm and the identifier of the verification algorithm. In this way, the second network device can determine the verification algorithm required for generating the second key from the multiple verification algorithms according to the identifier of the verification algorithm in the security information and the correspondence, so as to avoid the failure of verification of the security information due to the generation of an incorrect key by using an incorrect verification algorithm, thereby improving the reliability of verification.
[0163] The anti-replay information can be used by the second network device to generate the third key, and can also be used to prevent replay attacks, for example, the second network device can determine whether the second packet is a replay packet or a new packet by using the anti-replay information. The internal reachable address of the third device can be used by the second network device to generate the third packet, and specific implementation can be referred to the related description in S403 above, which will not be repeated here.
[0164] On the basis that the second verification information includes one or more of the following information: the first indication information, the identifier of the second network device, the identifier of the verification algorithm, the anti-replay information, or the internal reachable address of the third device, if the second packet is an IPv4 packet, the information included in the second verification information can be carried in the same information element, different information elements, or as an independent information element in the IPv4 packet. For example, as shown in Figure 8 and Figure 9 The internal reachable address of the third device is carried as an independent information element between the SecTag header and the inner IP header, or can also be carried at any other possible position. The anti-replay information can be carried in the PN information element in the SecTag header, or can also be carried in any other possible information element. The information in the second verification information, except for the internal reachable address of the third device and the anti-replay information, can be carried in the SCI information element in the SecTag header, or can also be carried in any other possible information element. Alternatively, if the second packet is an IPv6 packet, the information included in the second verification information can be carried in the same information element, different information elements, or as an independent information element in the IPv6 packet, and specific implementation can be referred to the related description of the IPv6 packet above, which will not be repeated here.
[0165] On this basis, the second indication information can also be used to indicate whether the security information includes one or more of the following information of the second verification information: the first indication information, the identifier of the second network device, the identifier of the verification algorithm, the anti-replay information, or the internal reachable address of the third device; and the second indication information can also be used to indicate the position and / or length of the information in the second packet. For details, refer to the related description in 402 above, which will not be described here. Of course, if the second indication information does not indicate whether the security information includes the information, whether the security information includes the information can be previously agreed by the first network device and the second network device, or predefined by a protocol. Similarly, if the second indication information does not indicate the position and / or length of the information in the second packet, the position and length of the information in the second packet can be previously agreed by the first network device and the second network device, or predefined by a protocol.
[0166] It can be seen that the second verification information carries one or more of the above information, such as the anti-replay information or the internal reachable address of the third device, which is mainly used for verification and forwarding of the second network device, i.e., the second network device can use the information to verify the security information and use the information to forward the third packet. In this case, by carrying the information with the packet, the second network device does not need to dynamically maintain the information locally, thereby saving the processing resources of the second network device and improving the resource utilization and operation efficiency of the second network device.
[0167] In addition, the second verification information including one or more of the above information is only an example and does not serve as a limitation. The second verification information can also include any other possible information, such as one or more of the following information: the identifier of the first domain, and the identifier of the terminal, and the first domain can be a network area managed by the first network device or any other possible network device.
[0168] Optionally, in combination with the above embodiment, in a possible application scenario, the first network device may further receive first configuration information from the network controller. The first configuration information may be carried in one or more of the following messages: a hypertext transfer protocol secure (HTTPS) message, a network configuration protocol (NETCONF) message, a representational state transfer configuration protocol (RESTCONF) message, or a restful message. The first configuration information may include one or more of the following: a public address of a third device, first verification information, a verification algorithm, an identifier of the verification algorithm, a first key, anti-replay information, an identifier of the first network device, a key ciphertext, an identifier of the second network device, an internally reachable address of the third device, first indication information, or second indication information.
[0169] In one possible design, when the first verification information is included in the first configuration information, that is, the network controller can directly configure the first verification information to the first network device, and the first network device does not need to determine the first verification information by itself. In this case, the first configuration information may not include relevant information used by the first network device to determine the first verification information, such as the first key, anti-replay information, verification algorithm, identification of the verification algorithm and other information, so as to save resources and reduce communication overhead. Of course, when the first configuration information includes the first verification information, the fact that the first configuration information does not include these relevant information is only an example, and the first configuration information may also include these relevant information, and this application does not impose any restrictions on this. In another possible design, when the first configuration information does not include the first verification information, the first configuration information may include these relevant information so that the first network device can determine the first verification information by itself based on these relevant information. In another possible design, when one or more of the following information: first indication information, an identifier of the second network device, an identifier of the verification algorithm, anti-replay information, or an internally reachable address of the third device needs to be carried with the packet, such as being carried in the second verification information of the second message, the first configuration information may include this information; however, when this information does not need to be carried with the packet, the first configuration information may include or not include this information, and this application does not impose any restrictions on this. In another possible design, when the first network device is pre-configured with a verification algorithm locally, the first configuration information may not include the verification algorithm, but include the identifier of the verification algorithm, to indicate to the first network device through the identifier of the verification algorithm to use the verification algorithm corresponding to the identifier of the verification algorithm; or, in this case, the first configuration information may still include the verification algorithm, and this application does not impose any restrictions on this. In addition, when the first network device is not pre-configured with a verification algorithm locally, the first configuration information may include the verification algorithm, but not include the identifier of the verification algorithm, to directly indicate to the first network device through the verification algorithm that the verification algorithm needs to be used; or, in this case, the first configuration information may still include the identifier of the verification algorithm, and this application does not impose any restrictions on this.
[0170] As can be seen, by configuring the first configuration information for the first network device, the network controller enables the first network device to encapsulate security information within the first message based on the first configuration information, thereby obtaining a second message. This allows the second network device to determine whether the second message is an attack message based on the security information encapsulated within the second message, without the need for in-depth analysis of the second message. This protects against message attacks while also ensuring service continuity and real-time performance.
[0171] Optionally, in combination with the above embodiment, in a possible application scenario, the second network device may further receive second configuration information from the network controller. The second configuration information may be carried in one or more of the following messages: an HTTPS message, a NETCONF message, a RESTCONF message, or a RESTful message, and the second configuration information includes one or more of the following: an internally reachable address of a third device, an identifier of the second network device, an identifier of the first network device, or a third key, where the third key is used to decrypt the key ciphertext to obtain the second key.
[0172] In one possible design, on the basis that the internal reachable address of the third device and / or the identifier of the second network device are carried with the packet, for example, carried in the above-mentioned second verification information of the second message, the second configuration information may not include the internal reachable address of the third device and / or the identifier of the second network device, so as to save communication overhead, reduce the amount of information maintenance of the second network device, and improve the operating efficiency of the second network device. Alternatively, on the basis that the internal reachable address of the third device and / or the identifier of the second network device are carried with the packet, the second configuration information may still include the internal reachable address of the third device and / or the identifier of the second network device, and this application does not impose any restrictions on this. In another possible design, if the second network device needs to obtain the second key using the above-mentioned method 21, the second configuration information includes the third key and may not include the identifier of the first network device, so as to save communication overhead and improve communication efficiency. Alternatively, on the basis that the second network device needs to obtain the second key using the above-mentioned method 21, the second configuration information may still include the identifier of the first network device, and this application does not impose any restrictions on this. If the second network device needs to obtain the second key using the above-described method 22, the second configuration information includes the identifier of the first network device and may not include the third key, thereby reducing communication overhead and improving communication efficiency. Alternatively, if the second network device needs to obtain the second key using the above-described method 22, the second configuration information may still include the third key. This application does not impose any restrictions on this.
[0173] It can be seen that the network controller configures the second configuration information to the second network device, so that the second network device can verify the second message according to the second configuration information to determine whether the second message is an attack message. There is no need to perform in-depth analysis of the second message. While achieving resistance to message attacks, it can also ensure business continuity and real-time performance.
[0174] Combination of the above Figure 4 The overall process of the communication method provided by the embodiment of the present application is introduced below. Figure 10 Detailed description Figure 4 The communication method shown in FIG. Figure 10The application scenarios shown include: NCE, DNS, high-defense scrubbing center, clients (such as Client 1 and Client 2), CPE (such as CPE1 and CEP2), cloud entry devices (such as Cloud Entry Device 1, Cloud Entry Device 2, Cloud Entry Device 3, and Cloud Entry Device 4), and cloud services (such as Cloud Service 1, Cloud Service 2, and Cloud Service 3). The terminals can be clients, the first network device can be a CPE, the second network device can be a cloud entry device, and the third device can be a cloud service. For ease of understanding, the following description uses Client 1, CEP 1, Cloud Entry Device 1, and Cloud Service 1 as examples.
[0175] The NCE may send the corresponding relationship between the public address of cloud service 1 and the domain name of cloud service 1 to the DNS. The NCE may send corresponding first configuration information to CPE 1. The first configuration information may include one or more of the public address of cloud service 1, the internally reachable address of cloud service 1, first verification information, a verification algorithm, an identifier of the verification algorithm, anti-replay information, a first key, a key ciphertext, an identifier of CPE 1, an identifier of cloud entry device 1, first indication information, and second indication information. The NCE may send corresponding second configuration information to cloud entry device 1. The second configuration information may include the internally reachable address of cloud service 1, an identifier of cloud entry device 1, an identifier of CPE 1, and a third key.
[0176] Client 1 can access the DNS based on the domain name of Cloud Service 1 to obtain the public address of Cloud Service 1. Client 1 can encapsulate the public address of Cloud Service 1 into the destination address of the message to be sent, obtaining Message A. Client 1 can traverse the local routing table and send Message A to CPE 1.
[0177] CPE1 determines that the destination address of message A is the same as the locally configured address, that is, both are the public addresses of cloud service 1. CPE1 encapsulates security information in message A to obtain message B. The security information may include the first verification information and the second verification information. The second verification information may include the identifier of the verification algorithm, anti-replay information, key ciphertext, first indication information, second indication information, the identifier of CPE1, the identifier of cloud entry device 1, and the internally reachable address of cloud service 1. CPE1 may traverse the local routing table and send message B to cloud entry device 1.
[0178] Cloud access device 1 extracts the security information from message B and determines that the cloud access device identifier in the security information is the same as the locally configured identifier, that is, both are the identifier of cloud access device 1. If cloud access device 1 determines that the cloud access device identifier in the security information is different from the locally configured identifier, for example, if the security information includes the identifier of cloud access device 2, cloud access device 1 forwards message B to cloud access device 2. Still using cloud access device 1 as an example, cloud access device 1 further determines that the identifier in the security information is the same as the locally configured identifier, that is, both are the identifier of CPE 1. Cloud access device 1 then uses the locally configured third key to decrypt the key ciphertext in the security information to obtain the second key. Cloud access device 1 encrypts the anti-replay information in the security information and the second key using the verification algorithm corresponding to the verification algorithm identifier in the security information to obtain third verification information. Finally, cloud access device 1 determines that the third verification information is the same as the first verification information in the security information. It then strips the security information from message B, updates the destination address in message B to the internally reachable address of cloud service 1 in the security information, obtains message C, and sends message C to cloud service 1.
[0179] It should be noted that for data packets that directly access cloud service 1 from the Internet, the data packets usually do not have encapsulated security information and do not carry identifiers. At this time, cloud entry device 1 cannot determine whether the data packet is a normal packet or an attack packet, so it can forward the data packet to the high-defense cleaning center. If the high-defense cleaning center determines through deep analysis that the data packet is an attack packet, the data packet is discarded. If the high-defense cleaning center determines through deep analysis that the data packet is a normal packet, the data packet is forwarded to cloud entry device 1 so that cloud entry device 1 updates the destination address in the data packet to the internal reachable address of cloud service 1, and then sends the data packet to cloud service 1, ensuring that if the data packet is a normal packet, the data packet can eventually still be sent to cloud service 1. However, if some attack messages forge or tamper with the security information in the above messages, such as forging or tampering with the above key ciphertext, anti-replay information, etc., the cloud entry device 1 can determine through verification that the identifier in the security information is different from the locally configured identifier, or that the third verification information is different from the first verification information in the security information, and then determine that the message is an attack message, and thus discard the message.
[0180] Combination of the above Figures 4-10 The communication method provided by the embodiment of the present application is described in detail. Figure 11-13 A communication device for executing the communication method provided in an embodiment of the present application is described in detail.
[0181] For example, Figure 11 This is a schematic diagram of the structure of the communication device provided in the embodiment of the present application. Figure 1The communication device 1100 may include: a module or unit corresponding to executing the above method / operation / step / action, and the module or unit may be a hardware circuit, or software, or a combination of hardware circuit and software. Figure 11 As shown, the communication device 1100 includes: a transceiver module 1101 and a processing module 1102. For ease of description, Figure 11 Only the main components of the communication device are shown.
[0182] In some embodiments, the communication device 1100 may be suitable for Figure 3 In the communication system shown in FIG, execution Figure 4 The function of the first network device in the method shown in .
[0183] The transceiver module 1101 is configured to receive a first message from a terminal. The processing module 1102 is configured to obtain a second message. The transceiver module 1101 is configured to send the second message to a second network device. The second message is obtained by encapsulating security information within the first message. The security information indicates that the second message is a trusted message determined by the communication device.
[0184] In one possible design scheme, the security information may include first verification information, where the first verification information is used to indicate that the second message is a trusted message determined by the communication device 1100.
[0185] Optionally, the security information may also include second verification information, which may include one or more of the following: an identifier of the verification algorithm, anti-replay information, an identifier of the communication device 1100, a key ciphertext, an identifier of the second network device, an internally reachable address of the third device, or a first indication information, where the third device is a downstream device of the second network device, and the first indication information is used to indicate the type of security information.
[0186] Optionally, the second verification information may further include second indication information, where the second indication information is used to indicate whether the security information includes one or more of the following: an identifier of the verification algorithm, anti-replay information, an identifier of the communication device 1100 , or a key ciphertext.
[0187] Optionally, the second verification information may also include second indication information, which is used to indicate the position and / or length of one or more of the following in the second message: first verification information, identification of the verification algorithm, anti-replay information, identification of the communication device 1100, or key ciphertext.
[0188] Optionally, the first verification information may be at the head or tail of the second message, and the second verification information may be at the head or tail of the second message.
[0189] Optionally, the second message is an Internet Protocol version 4 (IPv4) message or an Internet Protocol version 6 (IPv6) message. If the second message is an IPv4 message, the second verification information is located between the IPv4 header and the payload of the IPv4 message, or if the second message is an IPv6 message, the second verification information is located in an extension header of the IPv6 protocol header of the IPv6 message.
[0190] Optionally, the transceiver module 1101 is further configured to receive first configuration information from the network controller before sending the second message to the second network device. The first configuration information may include one or more of the following: a public address of the third device, first verification information, a verification algorithm, an identifier of the verification algorithm, anti-replay information, a first key, anti-replay information, an identifier of the communication device 1100, a key ciphertext, an identifier of the second network device, an internally reachable address of the third device, first indication information, or second indication information. The verification algorithm, anti-replay information, and first key are used to determine the first verification information.
[0191] Optionally, the destination addresses of the first message and the second message are public addresses of the third device.
[0192] In one possible design, the communication device 1100 is any one of the following: a router, a gateway, or a switch, and the second network device is a router.
[0193] Optionally, the transceiver module 1101 may also include a sending module and a receiving module ( Figure 11 (not shown in the figure). The sending module is used to implement the sending function of the communication device 1100, and the receiving module is used to implement the receiving function of the communication device 1100.
[0194] Optionally, the communication device 1100 may further include a storage module ( Figure 11 (not shown in FIG), the storage module stores a program or instruction. When the processing module executes the program or instruction, the communication device 1100 can execute Figure 4 Functionality of the first network device in the illustrated method.
[0195] It should be understood that the processing module involved in the communication device 1100 can be implemented by a processor or processor-related circuit components, which can be a processor or a processing unit; the transceiver module can be implemented by a transceiver or transceiver-related circuit components, which can be a transceiver or a transceiver unit.
[0196] It should be noted that the communication device 1100 can be used for the above-mentioned first network device. The communication device 1100 can be a router, a gateway or a switch, or a device in a router, a gateway or a switch (for example, a chip, or a chip system, or a circuit), or a device that can be used in combination with a router, a gateway or a switch.
[0197] In addition, the technical effects of the communication device 1100 can be referred to Figure 4 The corresponding technical effects of the method shown will not be repeated here.
[0198] In some other embodiments, the communication device 1100 may be suitable for Figure 3 In the communication system shown in FIG, execution Figure 4 The function of the second network device in the method shown in .
[0199] The transceiver module 1101 is configured to receive a second message from the first network device. The processing module 1102 is configured to verify the second message. The second message is encapsulated with security information, which indicates that the second message is a trusted message confirmed by the first network device.
[0200] In one possible design, the security information may include first verification information, where the first verification information is used to indicate that the second message is a trusted message determined by the first network device.
[0201] Optionally, the security information may also include second verification information, which may include one or more of the following: an identifier of the verification algorithm, anti-replay information, an identifier of the first network device, a key ciphertext, an identifier of the communication device 1100, an internal reachable address of a third device, or first indication information, the first indication information being used to indicate the type of security information.
[0202] Optionally, the second verification information may further include second indication information, where the second indication information is used to indicate whether the security information includes one or more of the following: an identifier of a verification algorithm, anti-replay information, an identifier of the first network device, or a key ciphertext.
[0203] Optionally, the second verification information may also include second indication information, which is used to indicate the position and / or length of one or more of the following in the second message: first verification information, an identifier of the verification algorithm, anti-replay information, an identifier of the first network device, or a key ciphertext.
[0204] Optionally, the first verification information is at the head or tail of the second message, and the second verification information is at the head or tail of the second message.
[0205] Optionally, the second message is an Internet Protocol version 4 (IPv4) message, or an Internet Protocol version 6 (IPv6) message. If the second message is an IPv4 message, the second verification information is located between the IPv4 header and the payload of the IPv4 message, or if the second message is an IPv6 message, the second verification information is located in an extension header of the IPv6 protocol header of the IPv6 message.
[0206] Optionally, the processing module 1102 is further configured to determine third verification information according to the second verification information, thereby verifying the second message according to the first verification information and the third verification information.
[0207] Furthermore, if the first verification information and the third verification information are the same, the processing module 1102 is further configured to update the destination address of the second message to the internally reachable address of the third device, obtain a third message, and control the transceiver module 1101 to send the third message to the third device. Alternatively, if the first verification information and the third verification information are different, the processing module 1102 is further configured to discard the second message.
[0208] Furthermore, the processing module 1102 is further configured to determine the second key according to the key ciphertext or the identifier of the first network device, thereby determining the third verification information according to the verification algorithm, the anti-replay information and the second key.
[0209] Optionally, processing module 1102 is further configured to determine, before determining the third verification information based on the second verification information, that the security information includes the identifier of the first network device. Alternatively, processing module 1102 is further configured to determine that the security information does not include the identifier of the first network device, and to cause processing module 1102 to discard the second message or control transceiver module 1101 to send the second message to the high-defense scrubbing center.
[0210] In one possible design, transceiver module 1101 is further configured to receive second configuration information from the network controller before processing module 1102 verifies the second message. The second configuration information includes one or more of the following: an internally reachable address of a third device, an identifier of communication apparatus 1100, an identifier of the first network device, or a third key, where the third key is used to decrypt the key ciphertext to obtain the second key.
[0211] In one possible design, the first network device is any one of the following: a router, a gateway, or a switch, and the communication device 1100 is a router.
[0212] Optionally, the transceiver module 1101 may also include a sending module and a receiving module ( Figure 11 (not shown in the figure). The sending module is used to implement the sending function of the communication device 1100, and the receiving module is used to implement the receiving function of the communication device 1100.
[0213] Optionally, the communication device 1100 may further include a storage module ( Figure 11 (not shown in FIG), the storage module stores a program or instruction. When the processing module executes the program or instruction, the communication device 1100 can execute Figure 4 Functionality of the second network device in the illustrated method.
[0214] It should be understood that the processing module involved in the communication device 1100 can be implemented by a processor or processor-related circuit components, which can be a processor or a processing unit; the transceiver module can be implemented by a transceiver or transceiver-related circuit components, which can be a transceiver or a transceiver unit.
[0215] It should be noted that the communication device 1100 can be used for the above-mentioned second network device. The communication device 1100 can be a router, or a device in a router (for example, a chip, or a chip system, or a circuit), or a device that can be used in conjunction with a router.
[0216] In addition, the technical effects of the communication device 1100 can be referred to Figure 4 The corresponding technical effects of the method shown will not be repeated here.
[0217] For example, Figure 12 Schematic diagram of the structure of the communication device provided in the embodiment of the present application Figure 3 The communication device may be a terminal device or a network device, or may be a chip (system) or other component or assembly that can be provided in the terminal device or the network device. Figure 12 As shown, the communication device 1200 may include a processor 1201. Optionally, the communication device 1200 may further include a memory 1202 and / or a transceiver 1203. The processor 1201 is coupled to the memory 1202 and the transceiver 1203, for example, via a communication bus.
[0218] The following combination Figure 12 The components of the communication device 1200 are described in detail.
[0219] The processor 1201 is the control center of the communication device 1200 and can be a single processor, a collective term for multiple processing elements, or a logic circuit. For example, the processor 1201 can be one or more central processing units (CPUs), an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application, such as one or more microprocessors (digital signal processors, DSPs) or one or more field programmable gate arrays (FPGAs).
[0220] Optionally, the processor 1201 may execute various functions of the communication device 1200 by running or executing a software program stored in the memory 1202 and calling data stored in the memory 1202 .
[0221] In a specific implementation, as an embodiment, the processor 1201 may include one or more CPUs, such as Figure 12 CPU0 and CPU1 are shown in FIG.
[0222] In a specific implementation, as an embodiment, the communication device 1200 may also include multiple processors, such as Figure 2 1 and 1204. Each of these processors can be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). A processor herein can refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).
[0223] The memory 1202 is used to store the software program for executing the solution of the present application and is controlled by the processor 1201 so that the above Figure 4 The method shown is executed.
[0224] Alternatively, the memory 1202 may be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compact disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 1202 may be integrated with the processor 1201 or exist independently and be connected to the processor 1201 through the interface circuit of the communication device 1200, or the input and output interface ( Figure 12 (not shown) is coupled to the processor 1201, which is not specifically limited in this embodiment of the present application.
[0225] The transceiver 1203 is configured to communicate with other communication devices. For example, the communication device 1200 is a terminal, and the transceiver 1203 can be configured to communicate with a network device or another terminal. For another example, the communication device 1200 is a network device, and the transceiver 1203 can be configured to communicate with a terminal or another network device.
[0226] Optionally, the transceiver 1203 can include a receiver and a transmitter (not shown in the figure separately). Figure 12 The receiver is configured to implement the receiving function, and the transmitter is configured to implement the transmitting function.
[0227] Optionally, the transceiver 1203 can be integrated with the processor 1201, or exist independently and be coupled with the processor 1201 through an interface circuit (not shown in the figure) of the communication device 1200. The embodiments of the present application do not make a limitation in this aspect. Figure 12
[0228] In a possible implementation, the communication device 1200 can further include an input / output interface and a logic circuit (not shown in the figure). Figure 12
[0229] On one hand, the communication device 1200 can be applied to a network device, for example, a first network device, in the method embodiments described above, or can be a chip (system) or other components or assemblies arranged in the network device, or a device containing the network device. The input / output interface is configured to receive a first packet from a terminal. The logic circuit is configured to obtain a second packet. The input / output interface is further configured to send the second packet to a second network device. The second packet is a packet obtained by encapsulating security information in the first packet, and the security information is used to indicate that the second packet is a trusted packet determined by the communication device.
[0230] On the other hand, the communication device 1200 can be applied to a network device, for example, a second network device, in the method embodiments described above, or can be a chip (system) or other components or assemblies arranged in the network device, or a device containing the network device. The input / output interface is configured to receive a second packet from a first network device. The logic circuit is configured to verify the second packet. The second packet encapsulates security information, and the security information is used to indicate that the second packet is a trusted packet determined by the first network device.
[0231] It should be noted that the structure of the communication device 1200 shown in the figure does not constitute a limitation on the communication device, and an actual communication device can include more or fewer components than those shown in the figure, or combine certain components, or have a different component arrangement. Figure 12
[0232] In addition, the technical effects of the communication device 1200 can refer to the technical effects of the above-mentioned method embodiment, and will not be repeated here.
[0233] See also Figure 13 , Figure 13 Schematic diagram of the structure of the communication device 1300 provided in this application Figure 4 , the communication device 1300 can be configured as Figure 3 The communication device 1300 includes a main control board 1310 and an interface board 1330 .
[0234] Main control board 1310 , also known as the main processing unit (MPU) or route processor card, is responsible for controlling and managing various components in communication device 1300 , including routing calculation, device management, device maintenance, and protocol processing. Main control board 1310 includes a central processing unit (CPU) 1313 and memory 1313 .
[0235] Interface board 1330 is also known as a line processing unit (LPU), line card, or service board. It provides various service interfaces and implements data packet forwarding. Service interfaces include, but are not limited to, Ethernet interfaces and POS (packet over SONET / SDH) interfaces. Ethernet interfaces, for example, are interfaces for flexible Ethernet clients (FlexE Clients). Interface board 1330 includes a central processing unit (CPU) 1331, a network processor (NPU) 1332, a forwarding table memory 1334, and a physical interface card (PIC) 1333.
[0236] The central processing unit 1331 on the interface board 1330 is used to control and manage the interface board 1330 and communicate with the central processing unit 1313 on the main control board 1310 .
[0237] The network processor 1332 is used to implement message forwarding processing. The network processor 1332 can be in the form of a forwarding chip. Specifically, the network processor 1332 is used to forward received messages, such as forwarding the first message or the second message, based on the forwarding table stored in the forwarding table entry memory 1334, such as the forwarding table corresponding to the first message or the second message. If the destination address of the message is the address of the communication device 1300, the message is sent to the CPU (such as the central processing unit 1313) for processing; if the destination address of the message is not the address of the communication device 1300, the next hop and output interface corresponding to the destination address are found in the forwarding table according to the destination address, and the message is forwarded to the output interface corresponding to the destination address, thereby forwarding the message to the corresponding next hop, such as sending the second message to the second device, or sending the third message to the third device. The processing of the uplink message includes: processing of the message input interface, forwarding table search; processing of the downlink message: forwarding table search, etc.
[0238] Physical interface card 1333 implements physical layer interconnection. Raw traffic enters interface board 1330 through this card, and processed packets are sent from this physical interface card 1333. Physical interface card 1333, also known as a daughter card, can be installed on interface board 1330. It converts optical and electrical signals into packets, performs a validity check on these packets, and then forwards them to network processor 1332 for processing. In some embodiments, a central processing unit (CPU) can also perform the functions of network processor 1332, such as implementing software forwarding based on a general-purpose CPU. Therefore, physical interface card 1333 does not require network processor 1332.
[0239] Optionally, the communication device 1300 includes multiple interface boards. For example, the communication device 1300 further includes an interface board 1340 . The interface board 1340 includes a central processing unit 1341 , a network processor 1342 , a forwarding table entry memory 1344 , and a physical interface card 1343 .
[0240] Optionally, communication device 1300 further includes a switching fabric board 1320. Switching fabric board 1320 may also be referred to as a switch fabric unit (SFU). If communication device 1300 includes multiple interface boards 1330, switching fabric board 1320 is used to exchange data between the interface boards. For example, interface board 1330 and interface board 1340 can communicate via switching fabric board 1320.
[0241] The master board 1310 and the interface board 1330 are coupled. For example, the master board 1310, the interface board 1330 and the interface board 1340, and the switching network board 1320 are connected through a system bus to a system backboard to realize intercommunication. In a possible implementation, an inter-process communication (IPC) channel is established between the master board 1310 and the interface board 1330, and the master board 1310 and the interface board 130 communicate through the IPC channel.
[0242] In logic, the communication apparatus 1300 includes a control plane and a forwarding plane, the control plane includes the master board 1310 and the central processor 1331, and the forwarding plane includes various components performing forwarding, such as the forwarding table item memory 1334, the physical interface card 1333 and the network processor 1332. The control plane performs functions such as router, generating a forwarding table, processing signaling and protocol packets, configuring and maintaining a state of the device, and the like, and the control plane issues the generated forwarding table to the forwarding plane, in which the network processor 1332 performs table lookup and forwarding based on the forwarding table issued by the control plane, on the physical interface card 1333. The forwarding table issued by the control plane can be stored in the forwarding table item memory 1334. In some embodiments, the control plane and the forwarding plane can be completely separated and not on the same device.
[0243] If the communication apparatus 1300 is configured as the first network device, the physical interface card 1333 receives a first packet from a terminal, sends the first packet to the network processor 1332, the network processor 1332 encapsulates security information in the first packet to obtain a second packet, and sends the second packet to the second network device through the physical interface card 1333.
[0244] If the communication apparatus 1300 is configured as the second network device, the physical interface card 1333 receives a second packet from the first network device, sends the second packet to the network processor 1332, the network processor 1332 verifies the second packet, can strip the security information carried in the second packet, encapsulates an internal reachable address of the third device in the second packet to obtain a third packet, and sends the third packet to the second device through the physical interface card 1333.
[0245] The operations of the interface board 1340 in the embodiment are consistent with the operations of the interface board 1330, and are not described herein again for brevity. The communication apparatus 1300 in the embodiment can correspond to the first network device in each of the method embodiments, and the master board 1310, the interface board 1330 and / or 1340 in the communication apparatus 1300 can implement the functions and / or various steps implemented by the first network device or the second network device in each of the method embodiments, which are not described herein again for brevity.
[0246] It's worth noting that there may be one or more main control boards (SPUs), which can include both active and standby SPUs. There may be one or more interface boards. The higher the network device's data processing capabilities, the more interface boards it provides. Interface boards can also have one or more physical interface cards. There may be no SPUs, one or more SPUs, and multiple SPUs can be used to achieve load balancing and redundant backup. In a centralized forwarding architecture, network devices may not require SPUs; the interface boards handle the entire system's service data processing. In a distributed forwarding architecture, network devices may have at least one SPU, which enables data exchange between multiple interface boards, providing high-capacity data exchange and processing capabilities. Therefore, network devices with distributed architectures have greater data access and processing capabilities than those with centralized architectures. Alternatively, a network device can consist of a single card, without a switching fabric board (SFB), integrating the functions of the interface board and the main control board. In this case, the central processing unit (CPU) on the interface board and the CPU on the main control board can be combined into a single CPU on this card, performing the combined functions of the two. This type of device has lower data exchange and processing capabilities (for example, low-end network devices such as switches or routers). The specific architecture used depends on the specific network deployment scenario and is not specified here.
[0247] In some possible embodiments, the above-mentioned first network device or second network device can be implemented as a virtualized device. Taking the first network device as an example, for example, the virtualized device can be a virtual machine (VM) running a program for sending message functions, and the virtual machine is deployed on a hardware device (for example, a physical server). A virtual machine refers to a complete computer system with complete hardware system functions simulated by software and running in a completely isolated environment. The virtual machine can be configured as a first network device. For example, the first network device can be implemented based on a general physical server in combination with network function virtualization (NFV) technology. The first network device is a virtual host, a virtual router or a virtual switch. Those skilled in the art can virtualize a first network device with the above-mentioned functions on a general physical server in combination with NFV technology by reading this application. I will not go into details here.
[0248] For example, the virtualized device can be a container, and the container is an entity for providing an isolated virtualized environment. For example, the container can be a docker container. The container can be configured as a first network device. For example, the first network device can be created through a corresponding image. For example, a container instance can be created for the proxy-container through an image of a container (proxy-container) that provides proxy services, such as a container instance proxy-container1, and the container instance proxy-container1 is provided as the first network device. When implemented using container technology, the first network device can run using the kernel of a physical machine, and multiple first network devices can share the operating system of the physical machine. Different first network devices can be isolated through container technology. The containerized first network device can run in a virtualized environment, for example, in a virtual machine, and the containerized first network device can also run directly in a physical machine.
[0249] For example, a virtualized device can be a Pod, which is a basic unit for deploying, managing, and orchestrating containerized applications using a container orchestration engine (Kubernetes, K8s). A Pod can include one or more containers. Each container in the same Pod is typically deployed on the same host, so each container in the same Pod can communicate through the host and can share the storage resources and network resources of the host. The Pod can be configured as a first network device. For example, specifically, a container as a service (CaaS) can be instructed to create a Pod and provide the Pod as a routing management device.
[0250] Of course, the first network device may also be other virtualized devices, which are not listed here one by one.
[0251] In some possible embodiments, the first network device may be implemented by a general-purpose processor. For example, the general-purpose processor may be in the form of a chip. Specifically, the general-purpose processor implementing the first network device includes a processing circuit and an input interface and an output interface that are internally connected and communicated with the processing circuit. The processing circuit is configured to execute the message generation step in each of the above-mentioned method embodiments via the input interface, the processing circuit is configured to execute the receiving step in each of the above-mentioned method embodiments via the input interface, and the processing circuit is configured to execute the sending step in each of the above-mentioned method embodiments via the output interface. Optionally, the general-purpose processor may further include a storage medium, and the processing circuit is configured to execute the storage step in each of the above-mentioned method embodiments via the storage medium. The storage medium may store instructions executed by the processing circuit, and the processing circuit is configured to execute the instructions stored on the storage medium to perform each of the above-mentioned method embodiments.
[0252] The embodiment of the present application provides a communication system. The communication system includes the above-mentioned one or more terminals and one or more network devices. The present application also provides a communication system, which may include the above-mentioned first network device and second network device. The communication system can be used to implement the operations performed by the first network device and the second network device in any possible implementation of the above-mentioned method embodiment and the method embodiment. For example, the communication system may have the following Figure 3 The structure shown.
[0253] An embodiment of the present application also provides a computer-readable storage medium, which stores a computer program or instructions, and the computer program or instructions are executed by a computer (e.g., a processor) to implement part or all of the steps of any method performed by any device in the embodiment of the present application.
[0254] An embodiment of the present application provides a computer program product. When the computer program product is run on a computer, the computer is enabled to execute the method in the above method embodiment.
[0255] The various product forms of the above-mentioned devices respectively have any functions of the first network device in the above-mentioned method embodiment, which will not be described in detail here.
[0256] Those skilled in the art will appreciate that the various method steps and units described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the steps and components of each embodiment have been generally described in terms of function in the above description. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art may use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0257] Those skilled in the art will clearly understand that, for the sake of convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0258] In the several embodiments provided in this application, the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the unit is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, or can be electrical, mechanical or other forms of connection.
[0259] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the embodiments of the present application.
[0260] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0261] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially, or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a ROM, a RAM, a magnetic disk, or an optical disk.
[0262] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and such modifications or substitutions should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.
[0263] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware or any combination thereof. When implemented using software, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer program instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions in accordance with the embodiments of the present application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer program instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center via wired or wireless means. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more available media integrated therein. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a digital video disc (DVD), or a semiconductor medium (e.g., a solid-state drive), etc.
[0264] Those skilled in the art will understand that all or part of the steps to implement the above embodiments may be accomplished by hardware, or may be accomplished by a program to instruct the relevant hardware, and the program may be stored in a computer-readable storage medium, and the above-mentioned storage medium may be a read-only memory, a disk or an optical disk, etc.
[0265] The above description is only an optional embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the principles of the present application should be included in the scope of protection of the present application.
Claims
1. A communication method, characterized in that: The method comprises: The first network device receives a first message from the terminal; The first network device sends a second message to the second network device, where the second message is obtained by encapsulating security information in the first message, where the security information includes first verification information and second verification information, where the first verification information is used to indicate that the second message is a trusted message determined by the first network device, and the second verification information includes an internal reachable address of a third device, where the third device is a downstream device of the second network device.
2. The method according to claim 1, characterized in that The second verification information also includes one or more of the following: an identifier of a verification algorithm, anti-replay information, an identifier of the first network device, a key ciphertext, an identifier of the second network device, or first indication information, where the first indication information is used to indicate the type of the security information.
3. The method according to claim 2, characterized in that The second verification information also includes second indication information, and the second indication information is used to indicate whether the security information includes one or more of the following: the identifier of the verification algorithm, the anti-replay information, the identifier of the first network device, or the key ciphertext.
4. The method according to claim 2 or 3, characterized in that The second verification information also includes second indication information, which is used to indicate the position and / or length of one or more of the following in the second message: the first verification information, the identifier of the verification algorithm, the anti-replay information, the identifier of the first network device, or the key ciphertext.
5. The method according to any one of claims 1 to 3, characterized in that The first verification information is at the head or tail of the second message, and the second verification information is at the head or tail of the second message.
6. The method according to any one of claims 1 to 3, characterized in that Before the first network device sends the second message to the second network device, the method further includes: The first network device receives first configuration information from the network controller, and the first configuration information includes one or more of the following: the public address of the third device, the first verification information, the verification algorithm, the identifier of the verification algorithm, anti-replay information, the first key, the identifier of the first network device, the key ciphertext, the identifier of the second network device, the internal reachable address of the third device, first indication information, or second indication information; wherein the verification algorithm, the anti-replay information and the first key are used to determine the first verification information.
7. A communication method, characterized in that: The method comprises: The second network device receives a second message from the first network device, where the second message is encapsulated with security information, the security information including first verification information and second verification information, the first verification information being used to indicate that the second message is a trusted message determined by the first network device, and the second verification information including an internally reachable address of a third device, where the third device is a downstream device of the second network device; The second network device verifies the second message.
8. The method according to claim 7, characterized in that The second verification information includes one or more of the following: an identifier of a verification algorithm, anti-replay information, an identifier of the first network device, a key ciphertext, an identifier of the second network device, or first indication information, where the first indication information is used to indicate the type of the security information.
9. The method according to claim 8, characterized in that The second verification information also includes second indication information, and the second indication information is used to indicate whether the security information includes one or more of the following: the identifier of the verification algorithm, the anti-replay information, the identifier of the first network device, or the key ciphertext.
10. The method according to claim 8 or 9, characterized in that The second verification information also includes second indication information, which is used to indicate the position and / or length of one or more of the following in the second message: the first verification information, the identifier of the verification algorithm, the anti-replay information, the identifier of the first network device, or the key ciphertext.
11. The method according to any one of claims 7 to 9, characterized in that The first verification information is at the head or tail of the second message, and the second verification information is at the head or tail of the second message.
12. The method according to claim 8 or 9, characterized in that The second network device verifying the second message includes: The second network device determines third verification information according to the second verification information; The second network device verifies the second message according to the first verification information and the third verification information.
13. The method according to claim 12, characterized in that The second network device verifies the second message according to the first verification information and the third verification information, including: If the first verification information is the same as the third verification information, the second network device updates the destination address of the second message to the internal reachable address of the third device, obtains a third message, and sends the third message to the third device; or If the first verification information is different from the third verification information, the second network device discards the second message.
14. The method according to claim 12, characterized in that The second network device determines third verification information according to the second verification information, including: The second network device determines whether the security information includes the identifier of the first network device; If the second network device determines that the security information includes the identification of the first network device, the second network device determines the third verification information according to the second verification information.
15. The method according to claim 12, characterized in that The second network device determines third verification information according to the second verification information, including: The second network device determines a second key according to the key ciphertext or the identifier of the first network device; The second network device determines third verification information according to the verification algorithm, the anti-replay information and the second key.
16. The method according to any one of claims 7 to 9, characterized in that Before the second network device verifies the second message, the method further includes: The second network device receives second configuration information from the network controller, and the second configuration information includes one or more of the following: the internal reachable address of the third device, the identifier of the second network device, the identifier of the first network device, or a third key, and the third key is used to decrypt the key ciphertext to obtain the second key.
17. A communication device, characterized in that: The device includes: a transceiver module and a processing module, wherein: The transceiver module is configured to receive a first message from a terminal; the processing module being configured to obtain a second message, where the second message is obtained by encapsulating security information within the first message, the security information including first verification information and second verification information, the first verification information being used to indicate that the second message is a trusted message determined by the first network device, and the second verification information including an internally reachable address of a third device, where the third device is a downstream device of the second network device; The transceiver module is used to send a second message to the second network device.
18. The device according to claim 17, characterized in that The security information also includes second verification information, which includes one or more of the following: an identifier of the verification algorithm, anti-replay information, an identifier of the communication device, a key ciphertext, an identifier of the second network device, or first indication information, and the first indication information is used to indicate the type of the security information.
19. The device according to claim 18, characterized in that The second verification information further includes second indication information, and the second indication information is used to indicate whether the security information includes one or more of the following: an identifier of the verification algorithm, the anti-replay information, an identifier of the communication device, or the key ciphertext.
20. The device according to claim 18 or 19, characterized in that The second verification information also includes second indication information, which is used to indicate the position of one or more of the following in the second message: the first verification information, the identifier of the verification algorithm, the anti-replay information, the identifier of the communication device, or the key ciphertext.
21. The device according to any one of claims 17 to 19, characterized in that The first verification information is at the head or tail of the second message, and the second verification information is at the head or tail of the second message.
22. The device according to any one of claims 17 to 19, characterized in that The transceiver module is also used to receive first configuration information from the network controller before the transceiver module sends the second message to the second network device, and the first configuration information includes one or more of the following: the public address of the third device, the first verification information, the verification algorithm, the identification of the verification algorithm, anti-replay information, the first key, the identification of the communication device, the key ciphertext, the identification of the second network device, the internal reachable address of the third device, the first indication information, or the second indication information; wherein the verification algorithm, the anti-replay information and the first key are used to determine the first verification information.
23. A communication device, characterized in that: The device includes: a transceiver module and a processing module, wherein: The transceiver module is configured to receive a second message from the first network device, the second message being encapsulated with security information, the security information including first verification information and second verification information, the first verification information being used to indicate that the second message is a trusted message determined by the first network device, and the second verification information including an internally reachable address of a third device, the third device being a downstream device of the second network device; The processing module is used to verify the second message.
24. The device according to claim 23, characterized in that The security information also includes second verification information, which includes one or more of the following: an identifier of the verification algorithm, anti-replay information, an identifier of the first network device, a key ciphertext, an identifier of the communication device, or first indication information, and the first indication information is used to indicate the type of the security information.
25. The device according to claim 24, characterized in that The second verification information also includes second indication information, and the second indication information is used to indicate whether the security information includes one or more of the following: the identifier of the verification algorithm, the anti-replay information, the identifier of the first network device, or the key ciphertext.
26. The device according to claim 24 or 25, characterized in that The second verification information also includes second indication information, and the second indication information is used to indicate the position and / or length of one or more of the following in the second message: the first verification information, the identifier of the verification algorithm, the anti-replay information, the identifier of the first network device, or the key ciphertext.
27. The device according to any one of claims 23 to 25, characterized in that The first verification information is at the head or tail of the second message, and the second verification information is at the head or tail of the second message.
28. The device according to claim 24 or 25, characterized in that The processing module is further configured to determine third verification information based on the second verification information, and verify the second message based on the first verification information and the third verification information.
29. The device according to claim 28, wherein If the first verification information is the same as the third verification information, the processing module is also used to update the destination address of the second message to the internal reachable address of the third device, obtain the third message, and control the transceiver module to send the third message to the third device; or, if the first verification information is different from the third verification information, the processing module discards the second message.
30. The device according to claim 28, wherein The processing module is further configured to determine whether the security information includes the identifier of the first network device; if the processing module determines that the security information includes the identifier of the first network device, the third verification information is determined based on the second verification information.
31. The device according to claim 28, characterized in that The processing module is further configured to determine a second key based on the key ciphertext or the identifier of the first network device, and determine third verification information based on the verification algorithm, the anti-replay information and the second key.
32. The device according to any one of claims 23 to 25, characterized in that The transceiver module is also used to receive second configuration information from the network controller before the processing module verifies the second message. The second configuration information includes one or more of the following: the internal reachable address of the third device, the identification of the communication device, the identification of the first network device, or a third key. The third key is used to decrypt the key ciphertext to obtain the second key.
33. A communication device, characterized in that: include: a processor coupled to a memory; The memory is used to store instructions, and the processor is used to execute the instructions, so that the communication device performs the method according to any one of claims 1 to 6, or performs the method according to any one of claims 7 to 16.
34. A communication system, characterized in that include: The first network device in the method according to any one of claims 1 to 6, and the second network device in the method according to any one of claims 7 to 16.
35. A computer-readable storage medium, characterized in that include: Computer program; when the computer program is run on a computer, the method according to any one of claims 1 to 16 is executed.
36. A computer program product, characterized in that The computer program product comprises a computer program, which enables the method according to any one of claims 1 to 16 to be performed when the computer program is run on a computer.
Citation Information
Patent Citations
Cloud security resource pool, smart home gateway and Internet of Things security protection system
CN112235313A
Cited By
Communication method and apparatus
WO2023040653A1