Controller authentication-based encrypted tunnel establishment method and device, and electronic device

By introducing an SD-WAN controller into the SD-WAN network for parallel dual-track authentication, the problem of insufficient static authorization detection in the encrypted tunnel establishment process is solved, realizing dynamic real-time authentication and authorization, and improving network security and tunnel connection reliability.

CN121508952BActive Publication Date: 2026-07-24CHINA TOWER CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA TOWER CO LTD
Filing Date
2025-11-11
Publication Date
2026-07-24

AI Technical Summary

Technical Problem

Existing SD-WAN security mechanisms have shortcomings in authentication and real-time authorization. They lack dynamic identity binding and real-time authorization, are vulnerable to replay attacks, and are difficult to audit traceably. As a result, the encrypted tunnel establishment process relies on static authorization detection, which cannot cover real-time dynamic attacks and is therefore not secure enough.

Method used

An SD-WAN controller is introduced as a third-party authentication mechanism. Through a parallel dual-track authentication method, the client device and the server device securely negotiate to generate initial key materials and send a chain establishment permission request to the controller. The controller performs dual verification of registration status and real-time permissions to ensure the legitimacy of tunnel establishment. The server device performs digital signature verification and timestamp check to achieve dynamic real-time authorization.

Benefits of technology

It enhances the security and reliability of the encrypted tunnel establishment process, dynamically defends against various attacks, ensures the stability and reliability of the tunnel connection, and strengthens the level of network security protection, especially in the ever-changing distributed network environment, providing a robust barrier for data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121508952B_ABST
    Figure CN121508952B_ABST
Patent Text Reader

Abstract

The application discloses a kind of based on controller authentication's encryption tunnel establishment method and device, electronic equipment, it is related to network security technical field or other related fields, the method includes: after encryption tunnel establishment flow is started, by client device to server device sends security negotiation request, and by server device returns security negotiation response;After receiving security negotiation response, by client device to server device sends identity authentication request, simultaneously to controller sends chain building permission request;By controller, chain building permission response is generated based on chain building permission request, and is synchronized to server device;By server device, chain building permission response and identity authentication request are verified, in the case where verification succeeds, the communication encryption tunnel between server device and client device is established based on identity authentication request.The application solves the technical problem that encryption tunnel establishment flow in the related art relies on static authorization detection, cannot cover real-time dynamic attack, leading to insufficient security.
Need to check novelty before this filing date? Find Prior Art

Citation Information

Patent Citations

  • SPA single packet authentication method and device based on zero-trust network stealth

    CN115549929A

  • Secure communication method between edge server and terminal equipment

    CN120434624A