Controller authentication-based encrypted tunnel establishment method and device, and electronic device
By introducing an SD-WAN controller into the SD-WAN network for parallel dual-track authentication, the problem of insufficient static authorization detection in the encrypted tunnel establishment process is solved, realizing dynamic real-time authentication and authorization, and improving network security and tunnel connection reliability.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA TOWER CO LTD
- Filing Date
- 2025-11-11
- Publication Date
- 2026-07-24
AI Technical Summary
Existing SD-WAN security mechanisms have shortcomings in authentication and real-time authorization. They lack dynamic identity binding and real-time authorization, are vulnerable to replay attacks, and are difficult to audit traceably. As a result, the encrypted tunnel establishment process relies on static authorization detection, which cannot cover real-time dynamic attacks and is therefore not secure enough.
An SD-WAN controller is introduced as a third-party authentication mechanism. Through a parallel dual-track authentication method, the client device and the server device securely negotiate to generate initial key materials and send a chain establishment permission request to the controller. The controller performs dual verification of registration status and real-time permissions to ensure the legitimacy of tunnel establishment. The server device performs digital signature verification and timestamp check to achieve dynamic real-time authorization.
It enhances the security and reliability of the encrypted tunnel establishment process, dynamically defends against various attacks, ensures the stability and reliability of the tunnel connection, and strengthens the level of network security protection, especially in the ever-changing distributed network environment, providing a robust barrier for data transmission.
Smart Images

Figure CN121508952B_ABST
Abstract
Citation Information
Patent Citations
SPA single packet authentication method and device based on zero-trust network stealth
CN115549929A
Secure communication method between edge server and terminal equipment
CN120434624A