A secure communication method, device and system

By adopting different encryption strategies for different messages within the same traffic during message transmission between network devices, the problem that encryption policies in the prior art are easily cracked is solved, and the effect of improving communication security is achieved.

CN112714097BActive Publication Date: 2025-06-06HUAWEI TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN201911083768.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-10-25
Filing Date
2019-11-07
Publication Date
2025-06-06
Estimated Expiration
2039-11-07

AI Technical Summary

Technical Problem

In the transmission of packets between network devices, it is difficult to effectively improve the security of encryption policies in the transmission of packets between network devices, resulting in attackers being able to crack the encryption policies and reduce the security of subsequent packet transmissions.

Method used

By using different encryption policies for encryption for different packets within the same traffic, the mapping relationship between traffic and encryption policy groups is used to increase the difficulty of attackers' cracking and improve communication security.

Benefits of technology

It realizes the adoption of different encryption strategies between different packets in the same traffic, enhances communication security and improves the difficulty of cracking attackers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN112714097B_ABST
    Figure CN112714097B_ABST
Patent Text Reader

Abstract

The embodiments of the present application provide a secure communication method, device and system, which relate to the field of security technology and are used to encrypt different messages within the same flow using different encryption strategies, thereby increasing the difficulty of cracking by attackers and improving the security of communications. The method includes: a first network device receives a first message and a second message. The first message and the second message belong to a first flow, and all messages included in the first flow match a first flow distinction rule. The first network device encrypts the first message based on the first encryption strategy to obtain a third message, and encrypts the second message based on the second encryption strategy to obtain a fourth message, according to a mapping relationship between the first flow and the first encryption policy group. The first encryption policy group includes a second encryption strategy and a first encryption strategy, and the first encryption strategy and the second encryption strategy are different encryption strategies. The first network device sends a third message and a fourth message to the second network device.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application claims priority to a Chinese patent application filed with the State Intellectual Property Office on October 25, 2019, with application number 201911024404.3 and application name “A method and device for secure connection”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The embodiments of the present application relate to the field of security technology, and in particular, to a secure communication method, device, and system. Background Art

[0003] When transmitting messages between network devices, in order to ensure the security of message transmission, the sending network device can use encryption technology (for example, Internet Protocol Security (IPSec)) to encrypt the messages to be sent. Before encrypting the messages to be sent, the network devices must negotiate parameters such as encryption algorithms and key exchange methods to determine the encryption strategy.

[0004] After the encryption strategy is determined, the network device can usually use the encryption strategy determined above to encrypt the message. Since the attacker can accelerate the cracking of the encryption strategy by actively constructing messages to encrypt, observing the encrypted messages, and analyzing the rules. And once the attacker understands the cracking rules, even if the session key that encrypts the encryption strategy is updated, the attacker can quickly crack it. Once the encryption strategy is cracked by the attacker, the security of other messages transmitted by the subsequent sender network device and the receiver network device through the encryption strategy will be reduced. Therefore, how to further improve the security of message transmission is a technical problem that needs to be solved urgently. Summary of the invention

[0005] The embodiments of the present application provide a secure communication method, device and system for encrypting different messages in the same flow using different encryption strategies, thereby increasing the difficulty for attackers to crack the messages and improving communication security.

[0006] In order to achieve the above objectives, this application adopts the following technical solutions:

[0007] In a first aspect, an embodiment of the present application provides a secure communication method, the method comprising: a first network device receives a first message and a second message belonging to a first flow. All messages included in the first flow match the first flow differentiation rule. The first network device encrypts the first message based on the first encryption policy according to the mapping relationship between the first flow and the first encryption policy group to obtain a third message. The first network device encrypts the second message based on the second encryption policy to obtain a fourth message. Among them, the first encryption policy group includes the second encryption policy and the first encryption policy, and the first encryption policy and the second encryption policy are different encryption policies. The first network device sends the third message and the fourth message to the second network device.

[0008] Since there is a mapping relationship between the first flow and the first encryption policy group, the first network device can encrypt different messages in the first flow using different encryption policies in the first encryption policy group, for example, encrypting the first message in the first flow based on the first encryption policy, and encrypting the second message in the first flow using the second encryption policy. In this way, different messages in the same flow can be encrypted using different encryption policies, which increases the difficulty of cracking by attackers and improves communication security.

[0009] In the present application, the first encryption policy specifies a first session key and a first encryption algorithm for encrypting the first message, and the second encryption policy specifies a second session key and a second encryption algorithm for encrypting the second message. The first encryption policy and the second encryption policy are different, which may be that the first encryption algorithm and the second encryption algorithm are different, or the first session key and the second session key are different. When the first session key and the second session key are different, the first encryption algorithm and the second encryption algorithm may be the same or different. When the first encryption algorithm and the second encryption algorithm are different, the first session key and the second session key may be the same or different.

[0010] In the present application, the first network device encrypts the message based on the encryption policy and sends the encrypted message, which can also be understood as the first network device sending the message through an encrypted connection. The encrypted connection is a connection that uses the encryption policy to encrypt the message. For example: the first network device encrypts the first message based on the first encryption policy to obtain the third message, and sends the third message to the second network device, which can also be understood as: the first network device sends the first message through the first encrypted connection, and the first encrypted connection is a connection that encrypts the first message using the first encryption policy. Similarly, the first network device encrypts the second message based on the second encryption policy to obtain the fourth message, and sends the fourth message to the second network device, which can be understood as: the first network device sends the second message through the second encrypted connection, and the second encrypted connection is a connection that encrypts the second message using the second encryption policy.

[0011] The mapping relationship between traffic and encryption policy groups can also be understood as the mapping relationship between the traffic differentiation rules matched by the traffic and the encryption policy group, or can be understood as the mapping relationship between the traffic and multiple encrypted connections. The above various statements technically express the same meaning in essence. For example: the mapping relationship between the first traffic and the first encryption policy group can be understood as the mapping relationship between the first traffic differentiation rule and the first encryption policy group, or can be understood as the mapping relationship between the first traffic (or the first traffic differentiation rule) and the first encryption connection group, wherein the first encryption connection group includes multiple different encryption connections. The multiple different encryption connections encrypt messages based on different encryption strategies.

[0012] The first network device encrypts the first message based on the first encryption policy to obtain the third message. Specifically, the first session key is generated based on the key exchange method corresponding to the first encryption policy, and the first message is encrypted based on the first session key and the encryption algorithm corresponding to the first encryption policy to obtain the third message. A person skilled in the art can understand the above technical meaning. Similarly, the first network device encrypts the second message based on the second encryption policy to obtain the fourth message. Specifically, the second session key is generated based on the key exchange method corresponding to the second encryption policy, and the second message is encrypted based on the second session key and the encryption algorithm corresponding to the second encryption policy to obtain the fourth message. As described in the embodiments of the present application, the encryption exchange methods and / or encryption algorithms corresponding to the first encryption policy and the second encryption policy may be the same or different, and will not be repeated here.

[0013] Optionally, the third message carries a first encryption policy identifier, and the first encryption policy identifier indicates that the third message is a message encrypted based on the first encryption policy.

[0014] Optionally, the fourth message carries a second encryption policy identifier, and the second encryption policy identifier indicates that the fourth message is a message encrypted based on a second several seconds policy.

[0015] Optionally, each encryption policy in the first encryption policy group specifies an encryption algorithm and a key exchange method required for encrypting a message.

[0016] In one possible design, the method provided in the embodiment of the present application also includes: the first network device determines the encryption policy corresponding to each message in the received first traffic in one of the following ways: Method 1: The first network device selects an encryption policy from the first encryption policy group in sequence according to the order of each encryption policy in the first encryption policy group, and encrypts each message in the received first traffic. Method 2: The first network device randomly selects an encryption policy from the first encryption policy group, and encrypts each message in the received first traffic. Method 3: The first network device encrypts N messages in the first traffic based on the first encryption policy, and encrypts P messages in the first traffic based on the second encryption policy, the N messages include the first message, the P messages include the second message, and N and P are positive integers. This makes the way in which the first network device determines the encryption policy used for each message more flexible.

[0017] The first network device encrypts the first message based on a first encryption policy to obtain a third message according to a mapping relationship between the first traffic and the first encryption policy group, and encrypts the second message based on a second encryption policy to obtain a fourth message, including:

[0018] The first network device determines a first encryption priority corresponding to the first message, and determines to use the first encryption policy to encrypt the first message to obtain the third message according to the association between the first encryption priority and the first encryption policy;

[0019] The first network device determines a second encryption priority corresponding to the second message, and determines to use the second encryption policy to encrypt the second message to obtain the fourth message based on an association between the second encryption priority and the second encryption policy.

[0020] By setting different encryption priorities, different priority encryption strategies can be used based on the requirements of different messages for secure communication levels. Therefore, for messages with high security requirements, a high-priority encryption strategy is used to encrypt, which can meet the needs of secure communication. For messages with low security requirements, a low-priority encryption strategy is used to encrypt, which can reduce the overhead of encrypting and decrypting messages and improve processor efficiency.

[0021] In one possible design, the encryption priority of the first encryption policy is higher than the encryption priority of the second encryption policy.

[0022] In one possible design, the first message includes a first encryption priority identifier, which is used to indicate the first encryption priority; the second message includes a second encryption priority identifier, which is used to indicate the second encryption priority. In one possible design, a first network device sends a third message and a fourth message to a second network device, including: the first network device sends the third message to the second network device via a first path, and sends the fourth message to the second network device via a second path; wherein the first path is associated with a first encryption policy, and the second path is associated with a second encryption policy. The first path is associated with the first encryption policy, which can also be understood as the first path being a path that uses a first encryption connection. The second path is associated with the second encryption policy, which can be understood as the second path being a path that uses a second encryption connection.

[0023] In a possible design, the method provided by the embodiment of the present application also includes: the first network device obtains multiple second public keys of the second network device; the first network device obtains the policy information associated with each second public key in the multiple second public keys; the policy information includes: key exchange method information and encryption algorithm information; the first network device creates a first encryption policy group based on the multiple second public keys and the policy information associated with each second public key in the multiple second public keys. The key exchange method information is used to indicate the key exchange method, and the encryption algorithm information is used to indicate the encryption algorithm. The key exchange method information and the encryption algorithm information can, for example, use a bit mapping method in the corresponding field of the message to indicate the corresponding key exchange method and encryption algorithm, or use a binary value method in the corresponding field of the message to indicate the corresponding key exchange method and encryption algorithm, or can also be a corresponding character string, identification ID and other information. This application does not impose specific restrictions on this.

[0024] In a possible design, the first network device obtains multiple second public keys of the second network device, including: the first network device obtains the multiple second public keys through a third network device. The third network device may be, for example, a controller, a network management device, or a reflection router.

[0025] In one possible design, the first network device obtains policy information associated with each second public key among multiple second public keys, including: the first network device obtains the policy information associated with each second public key locally, or; the first network device receives the policy information associated with each second public key through a third network device.

[0026] In one possible design, the first network device obtains multiple second public keys of the second network device, and the first network device obtains policy information associated with each of the multiple second public keys, including: the first network device obtains at least one first public key group, and policy information associated with each of the at least one first public key group, and at least one first public key group includes multiple second public keys.

[0027] In one possible design, the first network device creates a first encryption policy group based on multiple second public keys and policy information associated with each second public key, including: the first network device determines n1 public-private key pairs associated with the first policy information; wherein the first policy information includes: a first key exchange method and a first encryption algorithm; the first network device determines n2 public keys associated with the first policy information from the multiple second public keys; the first network device generates a first encryption policy group based on its own n1 public-private key pairs, the n2 public keys of the second network devices and the first policy information, the first encryption policy group including n1×n2 encryption policies, where n1 and n2 are positive integers greater than 1.

[0028] In one possible design, the first network device creates a first encryption policy group based on multiple second public keys and policy information associated with each second public key, including: the policy information associated with the Yth first public-private key pair in the first public-private key pair list is the same as the policy information associated with the Yth second public key in the multiple second public keys; the first network device generates an encryption policy based on the Yth first public-private key pair and the Yth second public key, where Y is an integer greater than or equal to 1.

[0029] In a possible design, the method in the embodiment of the present application further includes: the first network device receives the second traffic, the second traffic includes the fifth message and the sixth message, and all messages included in the second traffic match the second traffic differentiation rule. The first network device encrypts the fifth message and the sixth message based on the corresponding encryption policy in the first encryption policy group according to the mapping relationship between the second traffic and the first encryption policy group; the first network device sends the encrypted fifth message and the encrypted sixth message to the second network device.

[0030] In a second aspect, an embodiment of the present application provides a secure communication method, the method comprising: a second network device receives a third message and a fourth message from a first network device. The second network device decrypts the third message based on a first encryption strategy corresponding to the third message to obtain the first message. The second network device decrypts the fourth message based on a second encryption strategy corresponding to the fourth message to obtain the second message.

[0031] Optionally, the third message carries a first encryption policy identifier, and the first encryption policy identifier indicates that the third message is a message encrypted based on the first encryption policy.

[0032] Optionally, the fourth message carries a second encryption policy identifier, and the second encryption policy identifier indicates that the fourth message is a message encrypted based on a second several seconds policy.

[0033] In one possible design, the second network device determines, based on the first encrypted message carried by the third message, to adopt an encryption policy corresponding to the first encryption policy to decrypt the third message.

[0034] In one possible design, the second network device determines, based on the second encrypted message carried in the fourth message, to adopt an encryption policy corresponding to the first encryption policy to decrypt the third message.

[0035] In one possible design, the method provided in an embodiment of the present application also includes: the second network device sends multiple second public keys of the second network device to the first network device.

[0036] In one possible design, the method provided by an embodiment of the present application also includes: the second network device sends multiple second public keys of the second network device to the first network device, and sends policy information associated with each second public key in the multiple second public keys to the first network device; the policy information includes: a key exchange method and an encryption algorithm.

[0037] In one possible design, the method provided by an embodiment of the present application also includes: the second network device sends at least one first public key group to the first network device, and policy information associated with each first public key group in the at least one first public key group, and the at least one first public key group includes the multiple second public keys.

[0038] In a third aspect, an embodiment of the present application provides a secure communication device, which can be a first network device or a chip used in a first network device. The secure communication device includes a transceiver unit and a processing unit. When the first network device executes the method described in the first aspect and any optional design of the first aspect, the transceiver unit is used to perform transceiver operations, and the processing unit is used to perform operations other than transceiver operations. For example, when the first network device executes the method described in the first aspect, the transceiver unit is used to receive a first message and a second message belonging to a first flow. All messages included in the first flow match the first flow distinction rule. The processing unit is used to encrypt the second message based on the second encryption strategy to obtain a fourth message. Among them, the first encryption strategy group includes a second encryption strategy and a first encryption strategy, and the first encryption strategy and the second encryption strategy are different encryption strategies. The transceiver unit is also used to send a third message and a fourth message to the second network device.

[0039] In a fourth aspect, an embodiment of the present application provides a secure communication device, which can be a second network device or a chip used in a second network device. The secure communication device includes a transceiver unit and a processing unit. When the second network device executes the method described in the second aspect and any optional design of the second aspect, the transceiver unit is used to perform transceiver operations, and the processing unit is used to perform operations other than transceiver operations. For example, when the second network device executes the method described in the second aspect, the transceiver unit is used to receive a third message and a fourth message from the first network device. The processing unit is used to decrypt the third message based on the encryption policy corresponding to the third message to obtain the first message. The processing unit is also used to decrypt the fourth message based on the encryption policy corresponding to the fourth message to obtain the second message.

[0040] In a fifth aspect, the present application provides a first network device, comprising a memory and a processor connected to the memory. The memory stores instructions, and the processor reads the instructions so that the first network device executes the method described in the first aspect and any optional design of the first aspect.

[0041] In a sixth aspect, the present application provides a second network device, comprising a memory and a processor connected to the memory. The memory stores instructions, and the processor reads the instructions so that the second network device executes the method described in the second aspect and any optional design of the second aspect.

[0042] In a seventh aspect, the present application provides a first network device, comprising a communication interface and a processor connected to the communication interface, wherein the first network device is used to execute the method described in the first aspect and any optional design of the first aspect through the communication interface and the processor. The communication interface is used to execute the operations of sending and receiving, and the processor is used to execute operations other than sending and receiving. For example, when the first network device executes the method described in the first aspect, the communication interface is used to receive a first message and a second message belonging to a first flow. All messages included in the first flow match the first flow differentiation rule. The processor is used to encrypt the second message based on the second encryption policy to obtain a fourth message. The first encryption policy group includes a second encryption policy and a first encryption policy, and the first encryption policy and the second encryption policy are different encryption policies. The processor is also used to send a third message and a fourth message to the second network device.

[0043] In an eighth aspect, the present application provides a second network device, comprising a communication interface and a processor connected to the communication interface, wherein the second network device is used to execute the method described in the above two aspects and any one of the optional designs of the second aspect through the communication interface and the processor. The communication interface is used to perform the operations of sending and receiving, and the processor is used to perform operations other than sending and receiving. For example, when the second network device executes the method described in the second aspect, the communication interface is used to receive a third message and a fourth message from the first network device. The processor is used to decrypt the third message based on the encryption policy corresponding to the third message to obtain the first message. The processor is also used to decrypt the fourth message based on the encryption policy corresponding to the fourth message to obtain the second message.

[0044] In a ninth aspect, the present application provides a communication system, comprising the first network device described in any one of the third, fifth or seventh aspects above, and the second network device described in any one of the fourth, sixth or eighth aspects above.

[0045] In the tenth aspect, the present application provides a computer-readable storage medium, comprising computer-readable instructions, which, when executed on a computer, causes the computer to execute the method in the above-mentioned first aspect, the second aspect, any possible design of the first aspect, or any possible design of the second aspect.

[0046] In the eleventh aspect, the present application provides a computer program product, including a computer program. When the program is run on a computer, the computer executes the method in the above-mentioned first aspect, the second aspect, any possible design of the first aspect, or any possible design of the second aspect.

[0047] In a twelfth aspect, an embodiment of the present application provides a method for secure communication, which is executed by a controller, and the method includes:

[0048] The controller receives a plurality of second public keys sent by the second network device, and a plurality of policy information respectively associated with the plurality of second public keys, wherein the policy information is used to indicate a key exchange method and an encryption algorithm, and the plurality of second public keys and the plurality of policy information are in a one-to-one correspondence relationship;

[0049] The controller sends the multiple second public keys and the multiple policy information to the first network device, and the multiple second public keys and the multiple policy information are used to generate a first encryption policy group. The first encryption policy group includes multiple encryption policies. The multiple encryption policies included in the first encryption policy group are used to encrypt different messages in the same traffic.

[0050] In a thirteenth aspect, an embodiment of the present application provides a method for secure communication, which is executed by a controller, and the method includes:

[0051] The controller receives a plurality of second public keys sent by the second network device;

[0052] The controller sends the multiple second public keys to the first network device, and the second public keys are used together with the policy information associated with the multiple second public keys stored by the first network device itself to generate a first encryption policy group, wherein the first encryption policy group includes multiple encryption policies, and the multiple encryption policies included in the first encryption policy group are used to encrypt different messages in the same traffic.

[0053] In a fourteenth aspect, an embodiment of the present application provides a controller for executing the method described in the second aspect or the thirteenth aspect.

[0054] In the fifteenth aspect, the present application provides a communication system, comprising the first network device described in any one of the third, fifth or seventh aspects above, and the second network device described in any one of the fourth, sixth or eighth aspects above, and the controller described in the twelfth or thirteenth aspect.

[0055] In the sixteenth aspect, the present application provides a computer-readable storage medium, comprising computer-readable instructions, which, when executed on a computer, enable the computer to execute the method described in the twelfth or thirteenth aspect above.

[0056] In the seventeenth aspect, the present application provides a computer program product, including a computer program, which, when executed on a computer, enables the computer to execute the method in the above-mentioned twelfth aspect or thirteenth aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0057] Figure 1 A system architecture diagram of a communication system provided in an embodiment of the present application;

[0058] Figure 2 A schematic diagram of a controller-based key negotiation provided in an embodiment of the present application;

[0059] Figure 3 A flow chart of a method for sending traffic provided in an embodiment of the present application;

[0060] Figure 4 A flowchart of another method for sending traffic provided in an embodiment of the present application;

[0061] Figure 5 A flowchart of a method for negotiating an encryption policy group provided in an embodiment of the present application;

[0062] Figure 6 A flowchart of a method for obtaining a public key provided in an embodiment of the present application;

[0063] Figure 7 A flowchart of another method for obtaining a public key provided in an embodiment of the present application;

[0064] Figure 8 A flowchart of a method for generating an encryption strategy provided in an embodiment of the present application;

[0065] Fig. 9 A flowchart of another method for generating an encryption strategy provided in an embodiment of the present application;

[0066] Fig.10 A flow chart of a method for associating traffic with an encryption policy group provided in an embodiment of the present application;

[0067] Fig.11 A flowchart of a method for classifying and associating traffic and encryption policies based on algorithm strength provided in an embodiment of the present application;

[0068] Fig.12 A flowchart of a secure communication method provided in an embodiment of the present application;

[0069] Fig.13 A schematic diagram of the structure of a network device provided in an embodiment of the present application;

[0070] Fig.14 A schematic diagram of the structure of a network device provided in an embodiment of the present application;

[0071] Fig.15 A schematic diagram of the structure of a network device provided in an embodiment of the present application;

[0072] Fig.16 A schematic diagram of the structure of a network device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0073] In order to facilitate the clear description of the technical solutions of the embodiments of the present application, in the embodiments of the present application, ordinal numbers such as "first", "second", "third", "fourth" and "fifth" are used to distinguish the same items or similar items with basically the same functions and effects. For example, the first network device and the second network device are only used to distinguish different network devices, and their order is not limited. Those skilled in the art can understand that the words "first", "second" and the like do not limit the quantity and execution order, and the words "first", "second" and the like do not necessarily limit them to be different.

[0074] It should be noted that, in this application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or descriptions. Any embodiment or design described as "exemplary" or "for example" in this application should not be interpreted as being more preferred or more advantageous than other embodiments or designs. Specifically, the use of words such as "exemplary" or "for example" is intended to present related concepts in a specific way.

[0075] In the present application, "at least one" means one or more, and "plurality" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can mean: a, b, c, ab, ac, bc, or abc, where a, b, c can be single or multiple.

[0076] The system architecture and business scenarios described in the embodiments of this application are intended to more clearly illustrate the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided by the embodiments of this application. It is known to those skilled in the art that with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided by the embodiments of this application are also applicable to similar technical problems. Before introducing the embodiments of this application, the names involved in the embodiments of this application are first explained as follows:

[0077] 1) Traffic refers to a collection of multiple messages that meet the same traffic differentiation rules.

[0078] In the present application, all messages that meet the same traffic differentiation rule belong to the same traffic. In the present application, traffic can be differentiated based on different dimensions such as access control list (ACL), virtual private network (VPN) and / or interface, quintuple, flow identifier, etc. For example: the rules for traffic division may include but are not limited to one or more of the following rules: matching the same ACL, matching a specified ACL range, belonging to the same VPN, belonging to a specified range of VPNs, receiving from the same inbound interface, receiving from a certain interface range, sending from the same outbound interface, or sending from a certain interface range.

[0079] As a specific implementation: all packets matching the same ACL belong to the same flow, or packets matching the specified ACL range belong to the same flow. For example, if packets 1 and 2 match the same ACL, then packets 1 and 2 belong to the same flow. For example, if the specified ACL range is ACL1 to ACL3, if packet 1 comes from ACL1 and packet 2 comes from ACL3, then packets 1 and 2 can also be considered to belong to the same flow.

[0080] As a specific implementation: all packets belonging to the same VPN or the same VPN instance belong to the same flow. Or, all packets belonging to a specified VPN range belong to the same flow.

[0081] As a specific implementation: all packets received or sent by the same interface belong to the same flow, or packets received within a certain interface range (for example, interface 1 to interface 5) belong to the same flow, or packets sent within a certain interface range (for example, interface 3 to interface 5) belong to the same flow.

[0082] The above-mentioned various rules can also be combined to form a traffic differentiation rule, for example, the traffic differentiation rule is: the packets belong to the same VPN and are sent using the same outbound interface. Specifically, if packets 1 and 2 belong to the same VPN and are sent by the same interface, then packets 1 and 2 belong to the same traffic. If packets 1 and 2 belong to the same VPN but are sent by different interfaces, then packets 1 and 2 do not belong to the same traffic.

[0083] Those skilled in the art can understand that the flow differentiation rules described above are only exemplary and should not be understood as limiting the flow differentiation rules described in this application. Based on the existing technical knowledge of those skilled in the art, there can be any flow differentiation rules, and messages following the same flow differentiation rules belong to the same flow.

[0084] 2) A group of flows refers to a collection of multiple flows, and different flows in the multiple flows may have different flow differentiation rules.

[0085] As a possible implementation method: multiple flows in a group of flows in the embodiment of the present application can be associated with the same encryption policy group. For example, a group of flows includes flow 1, flow 2, and flow 3, where flow 1, flow 2, and flow 3 are all associated with encryption policy group A. Or flow 1 and flow 2 are associated with encryption policy group A, while flow 3 is associated with encryption policy group B and encryption policy group A.

[0086] As another possible implementation: In the embodiment of the present application, different flows in a group of flows are associated with different encryption policy groups. For example, flow 1 and flow 2 are associated with encryption policy group A, while flow 3 is associated with encryption policy group B. When different flows in a group of flows are associated with different encryption policy groups, the encryption policies included in different encryption policy groups may have an intersection. For example: flow 1 is associated with encryption policy group 1, and flow 2 is associated with encryption policy group 2. Encryption policy group 1 includes encryption policy 1, encryption policy 2, and encryption policy 3. Encryption policy group 2 includes the encryption policy 1 and the encryption policy 2. Among them, the intersection between encryption policy group 1 and encryption policy group 2 includes the encryption policy 1 and the encryption policy 2.

[0087] 3) Encryption policy, also known as encryption connection policy or secure connection policy or security policy. This encryption policy is used to specify the encryption algorithm and session key used to encrypt the message. The session key, also known as the conversation key, conference key, conversation key or session key in Chinese, is a one-time symmetric key used for encryption in the session. All members use the same key to encrypt plaintext and decrypt ciphertext.

[0088] As a specific implementation, the encryption policy may also specify an authentication algorithm, which may be, for example, a digital signature algorithm for authenticating the identity of the sending device.

[0089] 4) Encryption policy group refers to a collection of multiple encryption policies.

[0090] 5) Encrypted connection: An encrypted connection is a connection that uses encryption algorithms, session keys, etc. to encrypt transmitted messages.

[0091] The encryption policy refers to the properties of the encrypted connection, such as the encryption algorithm used and the session key.

[0092] 6) Key exchange method, used to generate session keys. In the present application, the key exchange method may be based on, for example, a DH (Diffie-Hellman) key exchange algorithm or an ECDH (Elliptic-curve Diffie-Hellman) key exchange algorithm.

[0093] The method provided in the embodiment of the present application can be applied to the following scenarios:

[0094] Scenario 1: Figure 1 As shown, Figure 1 A schematic diagram of a network architecture used in an embodiment of the present application is shown in FIG. Figure 1As shown, the network 100 includes a network device 1, a network device 2 and a controller 3, wherein the controller 3 communicates with the network device 1 and the network device 2. The network device 1 and the network device 2 perform IPSEC negotiation through the controller.

[0095] Figure 1 The communication system shown can be applied to software-defined wide area network (SD-WAN), which is a service formed by applying software defined network (SDN) technology to wide area network scenarios. This service is used to connect enterprise networks, data centers, Internet applications and cloud services over a wide geographical range. The typical feature of this service is to "cloudify" or virtualize network control capabilities through software, and support the opening of application-perceived network capabilities. SD-WAN is a simpler, more flexible, and better business performance wide area interconnection solution that can provide on-demand interconnection capabilities in all scenarios between branches and branches, and between branches and headquarters / data centers.

[0096] There are many network devices in SD-WAN. In order to ensure the security of traffic, the traffic between network devices can usually be encrypted using encryption technology (for example, Internet Protocol Security (IPSec)).

[0097] In addition, as a specific implementation, Figure 1 As shown, there may be one or more paths (e.g., path 1, path 2, and path 3) between network device 1 and network device 2 in the network 100. Each of the one or more paths includes one or more devices. Among them, one or more devices may be used to transfer messages between network device 1 and network device 2. For example, path 1 includes network device 4, and network device 1 may first send a message to be sent to network device 2 to network device 4, so that network device 4 may send the message to network device 2 through network device 5. For example, path 2 includes network device 5, and path 3 includes network device 6 and network device 7.

[0098] Of course, the messages transmitted between network device 1 and network device 2 may not be forwarded by the intermediate network device, and this embodiment of the present application does not limit this. Network 100 may not include a controller, and network device 1 and network device 2 may directly perform IPSEC negotiation.

[0099] In the present application, network device 1 and network device 2 may be routers, switches, gateway devices, packet switching devices, terminal devices, base stations, etc., and the present application does not make any specific limitation on this.

[0100] exist Figure 1 In the scenario shown, when network device 1 and network device 2 transmit traffic, when network device 1 and network device 2 communicate with each other, one possible technology is to use the same encryption strategy for all messages in the same traffic. Figure 2 A possible communication method 100 is described, the method comprising:

[0101] Step 1: Network device 1 and network device 2 respectively establish secure connections with the controller.

[0102] Step 2: Network device 1 generates a public-private key pair (including public key a and private key a corresponding to public key a). Network device 2 generates a public-private key pair (including public key b and private key b corresponding to public key b).

[0103] Step 3: Network device 1 and network device 2 send their respective public keys to the controller.

[0104] Step 4: The controller sends the public key a of network device 1 to network device 2, and sends the public key b of network device 2 to network device a.

[0105] Step 5: Network device 1 generates a session key by combining private key a, public key a, public key b, and the key exchange method. Network device 2 generates a session key by combining private key b, public key b, public key a, and the key exchange method. The key exchange method ensures that the two network devices can negotiate a matching session key. Step 6: All subsequent traffic between network device 1 and network device 2 is encrypted and decrypted using the session key.

[0106] In the communication method 100, since all messages in the same flow between node devices are encrypted using one encryption strategy, which has only one encryption algorithm and session key, etc., an attacker can accelerate the cracking of the security connection by actively constructing messages to encrypt, observing the encrypted messages, and analyzing the rules. Once the attacker understands the cracking rules, even if the update of the session key of the security connection is accelerated, the attacker can quickly crack it.

[0107] It should be noted that in method 100, network device 1 and network device 2 exchange public keys through a controller and negotiate to generate a new session key. Those skilled in the art will appreciate that network device 1 and network device 2 may also directly exchange public keys to generate a session key. This application does not specifically limit whether a controller is used.

[0108] In view of the technical problems existing in method 100, the following is combined with Figure 3A method 300 for secure communication provided in an embodiment of the present application is described in detail. The network architecture of the application method 300 includes a network device 1 and a network device 2. The network device 1 and the network device 2 are peers of secure communication. For example, when the network architecture of the application method 300 is a VPN network, the network device 1 and the network device 2 can be PE devices respectively. Figure 1 In the network 100 shown, the network device 1 may be Figure 1 The network device 1 and the network device 2 shown can be Figure 1 The network device 2 shown in the figure can be Figure 1 The network architecture shown in FIG.

[0109] Step 301: Network device 1 receives message 1 and message 2.

[0110] Among them, message 1 and message 2 belong to the same flow 1. All messages included in flow 1 have the same flow differentiation rule, that is, all messages in flow 1 match flow differentiation rule 1. The flow rule can be, for example, any of the flow differentiation rules described above. It should be understood that flow 1 can also include other messages besides message 1 and message 2.

[0111] Step 302: Network device 1 encrypts message 1 based on encryption policy 1, and encrypts message 2 based on encryption policy 2.

[0112] Specifically, encryption policy group 1 is a collection of multiple encryption policies. Encryption policy group 1 includes at least the encryption policy 1 and encryption policy 2, and encryption policy 1 and encryption policy 2 are different encryption policies. Traffic 1 is associated with encryption policy group 1, or in other words, traffic 1 and encryption policy group 1 have a one-to-one correspondence. Specifically, when network device 1 receives a message included in traffic 1, it will use an encryption policy in encryption policy group 1 to encrypt it. Traffic 1 includes multiple messages, encryption policy group 1 includes multiple encryption policies, and one traffic is associated with multiple encryption policies. After network device 1 receives the message included in traffic 1, it uses the encryption policy in encryption policy group 1 to encrypt each message included in traffic 1 according to the mapping relationship between traffic 1 and encryption policy group 1. The above-mentioned mapping relationship between traffic 1 and encryption policy group 1 can also be understood as the mapping relationship between traffic differentiation rule 1 and encryption policy group 1, and the two express the same meaning. That is, after network device 1 receives each message included in traffic 1, it identifies that the message belongs to traffic 1, matches traffic differentiation rule 1, and selects the encryption policy in encryption policy group 1 for encryption of the message according to the mapping relationship between traffic differentiation rule 1 and the first encryption policy group.

[0113] As a specific implementation, the encryption policy used by any message in traffic 1 except message 1 and message 2 may be encryption policy 1 or encryption policy 2, which is not limited in the embodiment of the present application.

[0114] Step 303 : Network device 1 sends message 1 encrypted based on encryption policy 1 and message 2 encrypted based on encryption policy 2 to network device 2 , so that network device 2 receives encrypted message 1 and encrypted message 2 from network device 1 .

[0115] The embodiment of the present application provides a secure communication method. In this method, since there is a mapping relationship between flow 1 and encryption policy group 1, network device 1 can encrypt different messages in flow 1 using different encryption policies in encryption policy group 1. For example, message 1 in flow 1 is encrypted based on encryption policy 1, and message 2 in flow 1 is encrypted using encryption policy 2. In this way, different messages in the same flow can be encrypted using different encryption policies, which increases the difficulty of cracking by attackers and improves communication security.

[0116] As a specific implementation, in the embodiment of the present application, there is a mapping relationship between the flow and the encryption policy group, so each message in the flow can be encrypted using the encryption policy included in the encryption policy group. For specific information on how to select an encryption policy for each message in the flow, please refer to the description in the following embodiment.

[0117] As a specific implementation, in the embodiment of the present application, the encrypted message may carry an identifier of an encryption policy. The identifier of the encryption policy is used by network device 2 to encrypt the message. Furthermore, network device 2 can determine the encryption policy for decrypting the message. For example, encrypted message 1 carries identifier 1 of encryption policy 1, and encrypted message 2 carries identifier 2 of encryption policy 2.

[0118] like Figure 4 As shown, a method 300 for sending traffic provided in an embodiment of the present application may also include:

[0119] Step 401: Network device 1 receives message 3 and message 4 included in traffic 2.

[0120] All packets included in traffic 2 have the same traffic differentiation rule. Traffic differentiation rules for traffic 1 and traffic 2 are different. For example, traffic 2 matches traffic differentiation rule 2.

[0121] Step 402: Network device 1 encrypts message 3 based on encryption policy 3 and message 4 based on encryption policy 4. The encryption policy 3 used by message 3 is different from the encryption policy 4 used by message 4. Of course, it is understandable that message 5 may also exist in traffic 2, and the encryption policy used by message 5 may be the same as or different from the encryption policy used by message 4. Alternatively, the encryption policy used by message 5 may be the same as or different from the encryption policy used by message 3.

[0122] As a possible implementation, in the embodiment of the present application, traffic 2 and traffic 1 are associated with the same encryption policy group 1, that is, the network device 1 encrypts each message in the received traffic 2 based on at least one encryption policy among the multiple encryption policies included in the encryption policy group 1. For example, the network device 1 can use encryption policy 1 to encrypt message 3, and use encryption policy 2 to encrypt message 4. At this time, encryption policy 1 and encryption policy 3 are the same encryption policy, and encryption policy 2 and encryption policy 4 are the same encryption policy. Of course, those skilled in the art can understand that encryption policy 3 and / or encryption policy 4 can be encryption policies that are different from encryption policy 1 and encryption policy 2, and encryption policy group 1 also includes the encryption policy 3 and the encryption policy 4.

[0123] As another possible implementation, in the embodiment of the present application, traffic 2 and traffic 1 are associated with different encryption policy groups. For example, traffic 2 is associated with encryption policy group 2, and the encryption policy used by message 3 and the encryption policy used by message 4 belong to the encryption policy in encryption policy group 2. When traffic 2 and traffic 1 are associated with different encryption policy groups, the encryption policy parts contained in encryption policy group 2 and encryption policy group 1 are the same or completely different. In one possible way, there is an intersection between encryption policy group 1 and encryption policy group 2, for example, the intersection includes the above-mentioned encryption policy 1 and / or encryption policy 2; in one possible way, encryption policy group 2 can be a subset of encryption policy group 1; in one possible way, the intersection between encryption policy group 1 and encryption policy group 2 is empty. It can be understood by those skilled in the art that the "group" in the encryption policy group described in the present application is a logical concept, for example: traffic 1 is associated with encryption policy group 1, and encryption policy group 1 can actually be a collection of several encryption policy groups, which are logically bundled and regarded as a whole, and are associated with traffic 1 as an encryption policy group. The above-mentioned encryption policy groups can also be associated with other different traffic respectively.

[0124] In order to improve the reliability of secure transmission of all messages in a flow, in the embodiments of the present application, at least two or more messages in the same flow use different encryption strategies. For example, the encryption strategy used by message 3 is different from the encryption strategy used by message 4.

[0125] Step 403 : Network device 1 sends encrypted message 3 and encrypted message 4 to network device 2 , so that network device 2 receives encrypted message 3 and encrypted message 4 .

[0126] It should be noted that Figure 4 Any of the steps 401 to 403 shown and Figure 3 There is no particular order in which any of the steps 301 to 303 are performed. For example, step 401 may be performed before or after step 301, or step 401 and step 301 may be performed simultaneously, which is not limited in the present embodiment of the present application.

[0127] In summary, this application combines Figure 3 and Figure 4 The illustrated embodiment illustrates that different flows (eg, flow 1 and flow 2) can use encryption policies in the same encryption policy group to encrypt messages.

[0128] In a specific embodiment, before step 301 or step 401, the method may further include: network device 1 and network device 2 negotiate an encryption policy group (eg, encryption policy group 1).

[0129] In a specific implementation, network device 1 and network device 2 may statically configure encryption policy group 1 .

[0130] Exemplarily, the network device 1 or the network device 2 is configured with an encryption algorithm and an encryption key corresponding to each encryption policy in the encryption policy group 1 .

[0131] In another specific implementation, the network device 1 and the network device 2 can dynamically negotiate the encryption policy group 1. Figure 5 Taking the generation of encryption policy by network device 1 as an example, a method 500 for negotiating an encryption policy group provided in an embodiment of the present application is specifically described. The method includes:

[0132] Step 501: Network device 1 obtains public key list 2 of network device 2 and policy information associated with each public key in public key list 2.

[0133] The public key list 2 includes multiple public keys generated by the network device 2. The public key list 1 includes multiple public keys generated by the network device 1.

[0134] The specific implementation process of the network device 1 obtaining the public key list 2 and the policy information associated with each public key in the public key list 2 can be referred to the description in the following embodiment, which will not be repeated here.

[0135] Step 502: Network device 1 synthesizes session keys and generates multiple encryption policies according to each public key included in public key list 2, policy information associated with each public key in public key list 2, and Key Pair list 1 stored by itself.

[0136] For the specific implementation of step 502, please refer to the following embodiment. Figure 7 or Figure 8 The description is not repeated here.

[0137] It should be noted that in the embodiment of the present application, when network device 1 and network device 2 negotiate multiple encryption policies, they can also determine the identifier of each encryption policy. For example, when network device 1 generates multiple encryption policies, network device 1 can assign an identifier to each of the multiple encryption policies. After network device 1 generates multiple encryption policies, network device 1 can send multiple encryption policies and the identifier of each of the multiple encryption policies to network device 2. Or network device 1 and network device 2 jointly negotiate the identifier of each encryption policy. For example, network device 2 indicates to network device 1 the identifier of each encryption policy generated by network device 1. Alternatively, network device 1 and network device 2 negotiate that the identifier associated with the encryption policy generated by network device 1 includes parameters assigned by network device 1 and parameters assigned by network device 2.

[0138] As a specific implementation, the method provided in the embodiment of the present application may further include before step 501: network device 1 generates Key Pair (public-private key pair) list 1, and network device 2 generates Key Pair (public-private key pair) list 2.

[0139] The Key Pair list includes multiple Key Pairs, each of which includes a public key and a private key corresponding to the public key.

[0140] For example, the specific content of Key Pair List 1 is shown in Table 1:

[0141] Table 1 Specific contents of Key Pair List 1

[0142]

[0143]

[0144] As another specific implementation, the policy information may further include an authentication algorithm, and the specific content of the Key Pair list 1 is shown in Table 2:

[0145] Table 2 Specific contents of Key Pair List 1

[0146]

[0147] It can be understood that, in the case where the policy information includes an authentication algorithm, the network device 1 and the network device 2 can negotiate the authentication algorithm when creating the encryption policy.

[0148] As a possible implementation, the policy information (such as key exchange method, encryption algorithm, authentication algorithm, etc.) associated with each Key Pair of network device 1 or network device 2 can be completely the same. For example, the six Key Pairs shown in Table 1 or Table 2 correspond to three types of policy information: the policy information of Key Pair 1 is completely the same as the policy information of Key Pair 2. The policy information associated with Key Pair 3, the policy information associated with Key Pair 4, and the policy information associated with Key Pair 5 are completely the same.

[0149] As a possible implementation, the policy information associated with each Key Pair of the network device 1 or the network device 2 is partially the same. For example, the policy information associated with Key Pair 2 is partially the same as the policy information associated with Key Pair 3 (the key exchange method is the same).

[0150] As a possible implementation, the policy information associated with each Key Pair of network device 1 or network device 2 is completely different. For example, the policy information associated with Key Pair 6 is completely different from the policy information associated with Key Pair 1. The policy information associated with Key Pair 6 is completely different from the policy information associated with Key Pair 2.

[0151] As a specific implementation, in the embodiment of the present application, network device 1 and network device 2 may configure the policy information associated with each Key Pair in the following manner, but not limited to the following manner.

[0152] Method 1-1: static configuration or negotiated configuration.

[0153] For example, policy information associated with each Key Pair is configured in network device 1. Policy information associated with each Key Pair is configured in network device 2. When network device 1 and network device 2 establish a control link, they negotiate the policy information associated with each Key Pair in Key Pair list 1 and the policy information associated with each Key Pair in Key Pair list 2.

[0154] Mode 1-2: configured by controller 3.

[0155] The controller 3 configures one or more policy information for the network device 1 or the network device 2. For example, the one or more policy information includes policy information 1 to policy information 3. Among them, policy information 1 is (Key Exchange Method 1, Encryption Algorithm 1, Authentication Algorithm 1). Policy information 2 is (Key Exchange Method 1, Encryption Algorithm 2, Authentication Algorithm 2). Policy information 3 is (Key Exchange Method 3, Encryption Algorithm 3, Authentication Algorithm 3). In this way, when the network device 1 generates the Key Pair list 1, it can select a policy information from policy information 1 to policy information 3 for each Key Pair in the Key Pair list 1. Similarly, when the network device 2 generates the Key Pair list 2, it can select a policy information from policy information 1 to policy information 3 for each Key Pair in the Key Pair list 2.

[0156] Method 1-3: Combined configuration.

[0157] The network device (e.g., network device 1 or network device 2) has one or more key exchange methods, one or more encryption algorithms, and one or more authentication algorithms supported by the network device. The network device can combine the one or more key exchange methods, one or more encryption algorithms, and one or more authentication algorithms to generate multiple policy information.

[0158] For example, the multiple key exchange methods supported by network device 1 or network device 2 are Key Exchange Method 1 and Key Exchange Method 2, and the multiple encryption algorithms supported by network device 1 or network device 2 are Encryption Algorithm 1 and Encryption Algorithm 2. For example, the multiple authentication algorithms supported by network device 1 or network device 2 are Authentication Algorithm 1 and Authentication Algorithm 2. In this way, when network device 1 or network device 2 generates a Key Pair list, it can randomly combine Key Exchange Method 1 and Key Exchange Method 2, Encryption Algorithm 1 and Encryption Algorithm 2, and Authentication Algorithm 1 and Authentication Algorithm 2, and associate a policy information for each Key Pair in the Key Pair list.

[0159] As a specific implementation manner, one or more key exchange methods, one or more encryption algorithms, and one or more authentication algorithms supported by the network device 1 or the network device 2 may be configured locally on the network device 1 or the network device 2 .

[0160] As another specific implementation manner, one or more key exchange methods, one or more encryption algorithms, and one or more authentication algorithms supported by the network device 1 or the network device 2 can be configured by the controller 3 for the network device 1 or the network device 2.

[0161] As another specific implementation, the network device 1 or the network device 2 may obtain from the first device one or more key exchange methods, one or more encryption algorithms, and one or more authentication algorithms supported by the network device 1 or the network device 2. The first device stores one or more key exchange methods, one or more encryption algorithms, and one or more authentication algorithms supported by the network device 1 or the network device 2.

[0162] Exemplarily, network device 1 or network device 2 combines Key Exchange Method 1, Key Exchange Method 2, Authentication Algorithm 1, Authentication Algorithm 2, Encryption Algorithm 1, and Encryption Algorithm 2 to generate four types of policy information as shown in Table 3:

[0163] Table 3

[0164] Policy Information Key exchange method Encryption Algorithm Strategy Information 1 Key Exchange Method1 Encryption Algorithm 1 Strategy Information 2 Key Exchange Method1 Encryption Algorithm 2 Strategy Information 3 Key Exchange Method2 Encryption Algorithm 1 Strategy Information 4 Key Exchange Method2 Encryption Algorithm 2

[0165] Exemplarily, network device 1 or network device 2 combines Key Exchange Method 1, Key Exchange Method 2, Authentication Algorithm 1, Authentication Algorithm 2, Encryption Algorithm 1, and Encryption Algorithm 2 to generate 8 types of policy information as shown in Table 4:

[0166] Table 4

[0167]

[0168] Method 1-4: Combined configuration.

[0169] The network device 1 is configured with multiple key exchange methods, and each key exchange method is configured with an encryption algorithm that can be used. In this way, the network device 1 can generate policy information according to the multiple key exchange methods and encryption algorithms.

[0170] As a specific implementation manner, the controller 3 may configure multiple key exchange methods and encryption algorithms for the network device 1 .

[0171] For example, network device 1 is configured with Key Exchange Method 1, Key Exchange Method 2, and Key Exchange Method 3. The encryption algorithms of Key Exchange Method 1 are Encryption Algorithm 1, Encryption Algorithm 2, and Encryption Algorithm 3. The encryption algorithms configured for Key Exchange Method 2 are Encryption Algorithm 2 and Encryption Algorithm 3. The encryption algorithm configured for Key Exchange Method 3 is Encryption Algorithm 3.

[0172] In summary, network device 1 can generate policy information 1 (Key Exchange Method 1, Encryption Algorithm 1), policy information 2 (Key Exchange Method 1, Encryption Algorithm 2), policy information 3 (Key Exchange Method 1, Encryption Algorithm 3), policy information 4 (Key Exchange Method 2, Encryption Algorithm 2), policy information 5 (Key Exchange Method 2, Encryption Algorithm 3), and policy information 6 (Key Exchange Method 3, Encryption Algorithm 3).

[0173] It is understandable that multiple encryption algorithms and key exchange methods associated with each of the multiple encryption algorithms may also be configured in advance in the network device 1. In this way, the network device 1 may also generate policy information.

[0174] It should be noted that the above example omits the authentication algorithm in the policy information. If the authentication algorithm is to be considered, an associated authentication algorithm can be configured for each encryption algorithm. The specific combination process can also refer to the above example, and the embodiments of the present application will not go into details.

[0175] As a specific implementation, Figure 6 Taking network device 1 obtaining a public key list of network device 2 as an example, a method 600 for obtaining a public key is described. The method may be located after step 501. The method 600 corresponds to the process of obtaining a public key list 2 of network device 2 in step 501. The method includes:

[0176] Step 601 : The network device 2 sends a public key list 2 of the network device 2 to the controller 3 . The public key list 2 includes multiple public keys of the network device 2 (eg, public key 6 to public key 11 ), so that the controller 3 receives the public key list 2 of the network device 2 .

[0177] Step 602 : The controller 3 sends the public key list 2 to the network device 1 , so that the network device 1 receives the public key list 2 .

[0178] Understandably, Figure 6 The method shown may also include: the network device 1 sends the public key list 1 to the controller 3 , and the controller 3 sends the public key list 1 to the network device 2 .

[0179] Figure 7 Taking network device 1 obtaining a public key list of network device 2 as an example, a method 700 for obtaining a public key is described. The method may be located after step 501. The method 700 corresponds to the process of obtaining a public key list 2 of network device 2 in step 501. The method includes:

[0180] Step 701 : Network device 2 sends a public key list 2 of network device 2 to network device 1 . Public key list 2 includes multiple public keys (eg, public key 6 to public key 11 ), so that network device 1 receives public key list 2 .

[0181] Figure 7 The embodiments shown and Figure 6 The embodiment shown differs in that Figure 6 The public key list 2 of network device 2 is forwarded by controller 3 to network device 1, and in Figure 7 In the illustrated embodiment, the public key list 2 of the network device 2 may be directly sent to the network device 1 .

[0182] In the embodiment of the present application, when the local device (for example, network device 1) generates an encryption policy, in addition to knowing the public key of the opposite device (for example, network device 2), it is also necessary to know the policy information associated with each public key of the opposite device. The following takes network device 1 as an example, and describes the process of network device 1 obtaining the policy information associated with each public key in public key list 2 through any one of method 2-1, method 2-2, or method 2-3. Among them, any one of method 2-1, method 2-2, or method 2-3 can correspond to the process of network device 1 obtaining the policy information associated with each public key of multiple public keys of network device 2 in the above step 502.

[0183] Method 2-1: The public key and the policy information associated with the public key are published together.

[0184] That is, step 601 can be implemented in the following manner: when network device 2 sends public key list 2 to controller 3, it also carries policy information associated with each public key in public key list 2. Correspondingly, step 502 in the embodiment of the present application can be implemented in the following manner: network device 1 receives public key list 2 from controller 3 and policy information associated with each public key in public key list 2.

[0185] That is, step 701 can be implemented in the following manner: network device 2 sends public key list 2 and policy information associated with each public key in public key list 2 to network device 1. Correspondingly, step 502 in the embodiment of the present application can be implemented in the following manner: network device 1 receives public key list 2 from network device 2 and policy information associated with each public key in public key list 2.

[0186] For example, taking the multiple public keys of the network device 2 as public key 6 to public key 11 as an example, Table 5 shows the specific implementation of step 601 or step 701:

[0187] Table 5: When publishing a public key, each public key corresponds to a policy information

[0188]

[0189] Among them, Key_Exch is Key Exchange, which indicates the key exchange method. Encr_Alg is EncryptionAlgorithm, which indicates the encryption algorithm. Auth_Alg is Authentication Algorithm, which indicates the authentication algorithm.

[0190] Method 2-2: Release policy information in the form of a group.

[0191] That is, network device 1 or network device 2 can classify multiple public keys with the same policy information into the same public key group. Public keys in the same public key group have the same policy information, and public keys in different public key groups are associated with different policy information. Each public key group is associated with one policy information.

[0192] For example, taking network device 2 as an example, network device 2 divides public keys 6 to 11 into public key group 1, public key group 2, and public key group 3 according to Table 5. Among them, public keys 6 and 7 belong to public key group 1 and have the same policy information. Public keys 8, 9, and 10 belong to public key group 2 and have the same policy information. Public key 11 belongs to public key group 3. As shown in Table 6:

[0193] Table 6: Public key and policy information published in group form

[0194]

[0195] In mode 2-2, step 601 can be specifically implemented in the following manner: network device 2 sends public key group 1 and policy information associated with public key group 1, public key group 2 and policy information associated with public key group 2, and public key group 3 and policy information associated with public key group 3 to controller 3. Correspondingly, network device 1 can receive public key group 1 and policy information associated with public key group 1, public key group 2 and policy information associated with public key group 2, and public key group 3 and policy information associated with public key group 3 from controller 3.

[0196] In mode 2-2, step 701 can be specifically implemented in the following manner: network device 2 sends public key group 1 and policy information associated with public key group 1, public key group 2 and policy information associated with public key group 2, and public key group 3 and policy information associated with public key group 3 to network device 1. Correspondingly, network device 1 can receive public key group 1 and policy information associated with public key group 1, public key group 2 and policy information associated with public key group 2, and public key group 3 and policy information associated with public key group 3 from network device 2.

[0197] Method 2-3: The local device is configured with policy information associated with each public key of the peer device.

[0198] When network device 1 or network device 2 publishes their respective public keys, they may not carry the policy information associated with each public key. However, it is possible to ensure that network device 1 knows the policy information associated with each public key of network device 2 through configuration. And it is possible to ensure that network device 2 knows the policy information associated with each public key of network device 1.

[0199] For example, the policy information associated with public key 6 and public key 7 configured in network device 1 is policy information 1 (as shown in Table 3 or Table 4), the policy information associated with public key 8, public key 9 and public key 10 is policy information 2 (as shown in Table 3 or Table 4), and the policy information associated with public key 11 is policy information 3 (as shown in Table 3 or Table 4).

[0200] Taking the case where network device 2 sends the public key in mode 2-3 as an example, step 701 or step 601 can be implemented by Table 7:

[0201] Table 7: No policy is carried when publishing a public key

[0202] Public Key 11 Public Key 12 Public Key 13 Public Key 14 Public Key 15 Public Key 16

[0203] The embodiment of the present application does not limit the method by which network device 1 or network device 2 pairs the public key, the policy information corresponding to the public key, and the KeyPair list. As long as network device 1 and network device 2 know and use them together, it can be ensured that the encryption policies generated by network device 1 and network device 2 match. For example, step 502 in the embodiment of the present application can be performed as follows: Figure 8 The method shown or Fig. 9 The method implementation shown:

[0204] As a specific implementation, Figure 8 A method 800 for generating an encryption policy provided by an embodiment of the present application is introduced by taking network device 1 as an example. The method 800 corresponds to the above step 502, and the method includes:

[0205] Step 801: Network device 1 compares the policy information of each public key in Key Pair list 1 with the policy information of each public key in Key Pair list 2 according to the order of each public key in Key Pair list 1 and the order of each public key in Key Pair list 2.

[0206] It is understandable that the network device 1 can determine the order of each public key in the Key Pair list 2 in the following manner: 1) When the network device 2 sends the Key Pair list 2, the Key Pair list 2 carries the order of each public key. 2) The network device 1 determines the order of each public key carried in the Key Pair list 2 according to the order of parsing each public key in the Key Pair list 2. As for the order of each public key in the Key Pair list 1, it can be determined by the network device 1 autonomously. Or it can be determined by the network device 1 according to the generation order of each public key in the Key Pair list 1.

[0207] Step 802: If the policy information associated with the yth Key Pair in Key Pair list 1 is the same as the policy information associated with the yth Key Pair in Key Pair list 2, network device 1 generates an encryption policy.

[0208] Step 803: If the policy information associated with the yth Key Pair in Key Pair list 1 is different from the policy information associated with the yth Key Pair in Key Pair list 2, the network device compares the policy information associated with the y+1th Key Pair in Key Pair list 1 with the policy information associated with the y+1th Key Pair in Key Pair list 2.

[0209] For example, Key Pair List 1 of Network Device 1 and Key Pair List 2 of Network Device 2 are shown in Table 8 below: Key Pair List 1 includes Key Pair 1 to Key Pair 5, using a total of 4 types of policy information. Key Pair List 2 includes Key Pair 6 to Key Pair 11, using a total of 3 types of policy information.

[0210] Table 8

[0211]

[0212] For example, network device 1 selects a Key Pair from Key Pair list 1 and Key Pair list 2 respectively according to the order of the public keys in the Key Pair lists to which they belong. Network device 1 compares whether the policy information associated with the Key Pair selected from Key Pair list 1 and the policy information associated with the Key Pair selected from Key Pair list 2 are the same. If the policy information associated with the Key Pair selected from Key Pair list 1 and the policy information associated with the Key Pair selected from Key Pair list 2 are the same, network device 1 combines and calculates the session key and generates the encryption policy.

[0213] For example, the pairing process in combination with Table 8 above is as follows:

[0214] Network device 1 compares the policy information associated with the first Key Pair (e.g., Key Pair 1) in Key Pair list 1 with the policy information associated with the first Key Pair (e.g., Key Pair 6) in Key Pair list 2. Referring to Table 8, it can be seen that the policy information associated with Key Pair 1 is the same as the policy information associated with Key Pair 6, and network device 1 believes that Key Pair 1 and Key Pair 6 can be paired successfully. Therefore, network device 1 can calculate the session key and generate the encryption policy based on Key Pair 1 and Key Pair 6.

[0215] Similarly, network device 1 compares the policy information associated with the second Key Pair (e.g., Key Pair2) in Key Pair list 1 with the policy information associated with the second Key Pair (e.g., Key Pair7) in Key Pair list 2. The policy information associated with Key Pair2 is the same as the policy information associated with Key Pair7, and network device 1 can calculate the session key and generate the encryption policy based on Key Pair2 and Key Pair7.

[0216] Network device 1 compares the policy information associated with the third Key Pair (e.g., Key Pair 3) in Key Pair list 1 with the policy information associated with the third Key Pair (e.g., Key Pair 8) in Key Pair list 2. The policy information associated with Key Pair 3 is the same as the policy information associated with Key Pair 8, and network device 1 can calculate the session key and generate the encryption policy based on Key Pair 3 and Key Pair 8.

[0217] However, since the policy information associated with the fourth Key Pair (e.g., Key Pair 4) in Key Pair List 1 is different from the policy information associated with the fourth Key Pair (e.g., Key Pair 9) in Key Pair List 2 (the encryption algorithms are different), network device 1 determines that the pairing of Key Pair 4 and Key Pair 9 has failed. Network device 1 abandons the use of Key Pair 4 and Key Pair 9 to generate encryption policies.

[0218] Next, network device 1 continues to compare the policy information associated with the fifth Key Pair (e.g., Key Pair 5) in Key Pair List 1 with the policy information associated with the fifth Key Pair (e.g., Key Pair 10) in Key Pair List 2. The policy information associated with Key Pair 5 is the same as the policy information associated with Key Pair 10, and the pairing is successful. Network device 1 can generate an encryption policy based on Key Pair 5 and Key Pair 10.

[0219] In addition, for the Key Pair 11 of the network device 2, since the Key Pair to be compared does not exist in the Key Pair list of the network device 1, the network device 1 determines that the pairing of the Key Pair 11 fails.

[0220] Finally, network device 1 and network device 2 generate a total of 4 encryption policies, as shown in Table 9 below. (N / A in Table 9 indicates that no encryption policy is actually generated because pairing fails).

[0221] Table 9

[0222]

[0223] Fig. 9 A method 900 for generating an encryption policy provided by an embodiment of the present application is introduced by taking network device 1 as an example. The method 900 corresponds to the above step 502, and the method includes:

[0224] Step 901: Network device 1 determines n1 Key Pairs associated with first policy information in Key Pair list 1. The first policy information is any one of all policy information included in Key Pair list 1.

[0225] Step 902: Network device 1 determines n2 public keys in Key Pair list 2 that are associated with the first policy information.

[0226] Step 903: Network device 1 combines n1 key pairs in Key Pair list 1 and n2 public keys in Key Pair list 2 to generate n1×n2 encryption policies.

[0227] For example, as shown in Table 8, Table 8 shows the Key Pair list 1 of network device 1 and the Key Pair list 2 of network device 2.

[0228] That is, Fig. 9 It mainly describes that when pairing the public key, the policy information associated with the public key and the Key Pair list, the network device 1 first screens according to the policy information, combines the Key Pair in the Key Pair list 1 and the Key Pair in the Key Pair list 2 with the same policy information, and then calculates the session key and generates the encryption policy.

[0229] Combined with Table 8, the network device pairs the public key, the policy corresponding to the public key, and the Key Pair list as follows:

[0230] Take the first policy information as policy information 1 (Key_Exch_1, Encr_Alg_1, Auth_Alg_1) as an example, combined with Figure 8 It can be seen that Key Pair 1, Key Pair 2, Key Pair 6 and Key Pair 7 all use the policy information 1, so the network device 1 combines Key Pair 1, Key Pair 2, Key Pair 6 and Key Pair 7, and finally obtains 4 combination results, so 4 encryption policies can be generated.

[0231] Specifically, network device 1 generates an encryption policy by combining Key Pair 1 and Key Pair 6. It generates an encryption policy by combining Key Pair 1 and Key Pair 7. Network device 1 generates an encryption policy by combining Key Pair 2 and Key Pair 6. It generates an encryption policy by combining Key Pair 2 and Key Pair 7.

[0232] Taking the first policy information as policy information 2 (Key_Exch_1, Encr_Alg_2, Auth_Alg_2) as an example, both Key Pair 3 and Key Pair 8 use the policy information 2, and the network device 1 combines Key Pair 3 and Key Pair 8 to finally obtain a combination result, so an encryption policy can be generated. That is, the network device 1 generates an encryption policy based on Key Pair 3 and Key Pair 8.

[0233] Taking the first policy information as policy information 3 (Key_Exch_2, Encr_Alg_2, Auth_Alg_2) as an example, if only KeyPair4 uses the policy information 3, pairing is impossible, that is, the network device 1 gives up using Pair4 to generate an encryption policy.

[0234] Taking the first policy information as policy information 4 (Key_Exch_2, Encr_Alg_3, Auth_Alg_2) as an example, KeyPair5, KeyPair9, and KeyPair10 all use the policy information 4, and the network device 1 combines KeyPair5 with KeyPair9 to generate an encryption policy. The network device 1 combines KeyPair5 with KeyPair10 to generate an encryption policy.

[0235] Taking the first policy information as policy information 5 (Key_Exch_3, Encr_Alg_3, Auth_Alg_3) as an example, if only KeyPair11 uses policy information 5, pairing is impossible.

[0236] Finally, 7 encryption policies are generated by pairing network device 1 and network device 2, as shown in Table 10 below:

[0237] Table 10

[0238]

[0239]

[0240] In a specific embodiment, before step 301 or step 401 , the process may further include: network device 1 associating traffic 1 or traffic 2 with encryption policy group 1 .

[0241] It should be noted that the above example takes the policy information including the authentication algorithm as an example. When the policy information does not include the authentication algorithm, the combination pairing method can refer to the above process, and the embodiments of the present application will not be repeated here. For example, taking the policy information X including Key_Exch_1, Encr_Alg_3, and Auth_Alg_3 as an example, at this time, if Key Pair A in Key Pair List 1 and Key Pair B in Key Pair List 2 are both associated with policy information X. Network device 1 can generate an encryption policy based on Key Pair A and Key Pair B. However, when policy information X includes Key_Exch_1 and Encr_Alg_3, it is possible that Key Pair A and Key Pair B and Key Pair C in Key Pair List 2 are all associated with policy information X. Therefore, network device 1 can generate an encryption policy based on Key Pair A and Key Pair B, and generate an encryption policy based on Key Pair A and Key Pair C.

[0242] As a specific implementation, the network device 1 can associate flow 1 or flow 2 with encryption policy group 1 by Fig.10 The method shown is implemented as Fig.10 As shown, taking network device 1 and traffic 1 as an example, a method 1000 for associating traffic with an encryption policy group is described. The method 1000 includes:

[0243] Step 1001: Network device 1 determines a traffic differentiation rule associated with each of a plurality of encryption policies in encryption policy group 1.

[0244] As a specific implementation: a traffic differentiation rule can be associated with two or more encryption policies.

[0245] For example, network device 1 may associate ACL 1 with encryption policy 1, and ACL 1 with encryption policy 2. Network device 1 may associate VPN 1 with encryption policy 2 and encryption policy 3. Network device 1 may associate interface 1 with encryption policy 3 and encryption policy 2.

[0246] As a specific implementation, different traffic differentiation rules can have the same encryption policy.

[0247] For example, taking the autonomous configuration of network device 1 as an example, network device 1 can configure traffic matching ACL A and ACL B to use encryption policy 1, encryption policy 2, and encryption policy 3. Network device 1 configures traffic within home VPN C to use encryption policy 2, encryption policy 3, and encryption policy 4. Network device 1 configures traffic within interface D to use encryption policy 5, encryption policy 6, and encryption policy 7. Therefore, if traffic 1 matches ACL A, network device 1 can associate traffic 1 with encryption policy 1, encryption policy 2, and encryption policy 3.

[0248] As a possible implementation, the network device 1 can determine the traffic differentiation rules associated with each encryption policy independently or through negotiation with the network device 2. Of course, the traffic differentiation rules associated with each encryption policy can also be configured by the controller 3 for the network device 1, which is not limited in the embodiment of the present application.

[0249] Step 1002: Network device 1 determines a traffic differentiation rule of traffic 1.

[0250] As a specific implementation, the network device 1 may determine the traffic differentiation rule of the traffic 1 according to the condition satisfied by each message included in the traffic 1.

[0251] Step 1003: Network device 1 associates traffic 1 with the encryption policy associated with the traffic differentiation rule according to the traffic differentiation rule of traffic 1.

[0252] For example, if traffic X matches ACL A and is forwarded via interface D, traffic X may be associated with encryption policy 1, encryption policy 2, and encryption policy 3, as well as encryption policy 5, encryption policy 6, and encryption policy 7.

[0253] Since different key exchange methods, authentication algorithms, encryption algorithms, etc. may have different strengths, high-strength algorithms are difficult to crack, but generally have an impact on performance. Low-strength algorithms can achieve high performance, but may be less difficult to crack than high-strength algorithms. Therefore, for different services, the algorithm strengths required may also be different. Based on this, as a specific implementation, such as Fig.11 As shown, Fig.11 A method 1100 for classifying and associating traffic and encryption policies based on algorithm strength is shown. The method 1100 corresponds to the description of the network device 1 associating traffic 1 or traffic 2 with encryption policy group 1, and includes:

[0254] Step 1101: The network device 1 determines the priority level of each encryption strategy among multiple encryption strategies according to the strength of the algorithm, wherein different encryption strategies have different encryption priorities.

[0255] For example, network device 1 can generate an encryption priority for a generated encryption policy by specifying the priority of a policy or algorithm, or can generate an encryption priority by specifying the weights of each algorithm, calculating the sum of the weights of each algorithm in the encryption policy, and comparing the sum of the weights of each encryption policy, or distinguish encryption priorities by other means, which is not limited to the embodiments of the present application.

[0256] For example, distinguish the priority of encryption policies: the algorithms are represented as "red", "yellow" and "green" according to their strength, and the network device 1 can determine that the priority of the encryption policy containing the "red" algorithm is "red". Network device 1 can determine that the priority of the encryption policy that does not contain the "red" algorithm but contains the "yellow" algorithm is "yellow". Network device 1 can determine that the priority of the encryption policy that contains the "green" algorithm but does not include the "red" algorithm and the "yellow" algorithm is "green". Among them, red represents high, yellow represents medium, and green represents low. As an implementation, the strength of the algorithm, high, medium and low can also be represented by ABC or 123. Among them, A or 1 represents high, B or 2 represents medium, and C or 3 represents low. Of course, the strength of the algorithm, high, medium and low can also be identified in other ways, and the embodiments of the present application are not limited to this.

[0257] Step 1102 : Network device 1 determines the priority of traffic 1 .

[0258] For example, network device 1 may determine that the required strength for VPN1 traffic is red, the required strength for VPN2 traffic is yellow, and the required strength for VPN3 traffic is green. Then the traffic of VPN1, VPN2, and VPN3 may use encryption policies corresponding to different priorities.

[0259] Step 1103: Network device 1 associates an encryption policy having the same priority as traffic 1 with traffic 1 among multiple encryption policies according to the priority of traffic 1.

[0260] For example, if encryption policy 1, encryption policy 2, and encryption policy 3 all include the "red" algorithm, network device 1 can determine that the priorities of encryption policy 1, encryption policy 2, and encryption policy 3 are "red". In addition, if traffic 1 belongs to VPN 1, network device 1 can determine that traffic 1 is associated with encryption policy 1, encryption policy 2, and encryption policy 3, that is, encryption policy 1 to encryption policy 3 belong to the encryption policies in the above encryption policy group 1.

[0261] As a specific embodiment, the method provided in the embodiment of the present application may further include, before step 302 or step 402: network device 1 determines the encryption policy used by each message in flow 1 or flow 2. As a specific implementation, network device 1 autonomously configures the encryption policy used by each message in flow 1 in encryption policy group 1.

[0262] As a specific implementation, network device 1 determines the encryption policy used by each message in traffic 1 in encryption policy group 1 according to the first rule.

[0263] The following example 2-1 describes a method for selecting an encryption strategy for a message provided by an embodiment of the present application. The example 2-1 corresponds to the above-mentioned network device 1 determining the encryption strategy used by each message in the traffic 1 in the encryption strategy group 1 according to the first rule. The method includes: for each message in the received traffic 1, according to a certain message sorting rule, the network device 1 selects an encryption strategy for encrypting the message from the encryption strategy group 1 in sequence according to the order of the encryption strategy. The sorting rule of the above-mentioned message can be, for example, according to the order of receiving the message, according to the order of sending the message, according to the interface ID of the received message, according to the interface ID of the sent message, according to the order in which the processor processes the message, etc., to select the corresponding encryption strategy for the message. The above-mentioned network device 1 selects encryption strategies for the messages in sequence, which means selecting encryption strategies for each message according to the order of the encryption strategies. According to the order of the encryption strategies, for example, the encryption strategies can be sorted based on the identification ID of the encryption strategies, or the network device 1 itself sorts the encryption strategies according to the order in which the encryption strategies are generated, or sorts them according to the index of the encryption strategies, and the present application does not make specific restrictions on this. For example, the message sequence of the traffic 1 to be sent between the network device 1 and the network device 2 includes messages 11 to 16, as shown in the following Table 11: (sent in order from left to right):

[0264] Table 11

[0265] Message 1 Message 2 Message 3 Message 4 Message 5

[0266] For example, encryption policy group 1 associated with traffic 1 includes encryption policy 1, encryption policy 2, and encryption policy 3. Network device 1 determines the storage order of encryption policies in encryption policy group 1 as encryption policy 1, encryption policy 2, and encryption policy 3 according to the sorting rule. The order of each message in traffic 1 is shown in Table 11. Network device 1 can determine to encrypt message 1 based on encryption policy 1. Network device 1 can encrypt message 12 based on encryption policy 2. Network device 1 can encrypt message 13 based on encryption policy 3. Network device 1 can encrypt message 14 based on encryption policy 1 and encrypt message 5 based on encryption policy 2. It can be understood that when the number of encryption policies is less than the number of messages in traffic 1, the encryption policies can be used cyclically according to the sorting rule.

[0267] The following example 2-2 describes a method for selecting an encryption strategy for a message provided by an embodiment of the present application. The example 2-2 corresponds to the above-mentioned network device 1 determining the encryption strategy used by each message in flow 1 or flow 2 in encryption strategy group 1 according to the first rule. The example 2-2 includes: the network device 1 can use a random algorithm to randomly select an encryption strategy from multiple encryption strategies for each message in the received flow 1. That is, the network device 1 randomly uses these encryption strategies to encrypt each message in flow 1, and the order in which each encryption strategy is used is random.

[0268] For each message in flow 1, network device 1 uses a random algorithm to randomly select an encryption policy in encryption policy group 1. This method can increase the disorder of message selection encryption policy.

[0269] Taking the message and encryption strategy shown in Table 11 as an example, network device 1 randomly selects an encryption strategy from encryption strategy 1, encryption strategy 2, and encryption strategy 3 for message 1 according to the random algorithm, and randomly selects an encryption strategy from encryption strategy 1, encryption strategy 2, and encryption strategy 3 for message 2, and so on. It can be understood that if network device 1 uses a random algorithm to select an encryption strategy from multiple encryption strategies for each message, there may be different messages using the same encryption strategy. Of course, network device 1 can also use a different random algorithm to select an encryption strategy each time. Or if a certain encryption strategy A has been selected, encryption strategy A may not be included in the encryption strategy set to be selected in the next selection, and so on.

[0270] The following examples 2-3 describe a method for selecting an encryption policy for a message provided in an embodiment of the present application. The examples 2-3 correspond to the above-mentioned network device 1 determining the encryption policy used by each message in traffic 1 in encryption policy group 1 according to the first rule. The method includes: the network device 1 determines the encryption policy used by every N messages (N is greater than 1) in message 1 to message m in sequence according to the order of the encryption policies in encryption policy group 1.

[0271] Assuming N is 2, and taking traffic 1 including packets 1 to 6 as an example, network device 1 determines that packets 1 and 2 use encryption policy 1. Network device 1 determines that packets 3 and 4 use encryption policy 2. Network device 1 determines that packets 5 and 6 use encryption policy 3, and so on.

[0272] The following examples 2-4 describe a method for a network device to select an encryption policy for a message provided by an embodiment of the present application. The examples 2-4 correspond to the above-mentioned network device 1 determining the encryption policy used by each message in traffic 1 or traffic 2 in encryption policy group 1 according to the first rule. The method includes: the network device 1 uses a random algorithm to randomly select an encryption policy to be used from encryption policies 1 to 3 associated with traffic 1. The network device 1 determines that the 1st to Nth messages use the encryption policy to be used. Afterwards, the network device 1 uses a random algorithm to randomly select the next encryption policy from encryption policies 1 to 3, and the network device 1 determines that the (N+1)th to (2N+1)th messages use the next encryption policy, and so on.

[0273] For example, network device 1 uses a random algorithm to randomly select encryption policy 2 from encryption policies 1 to 3 to encrypt message 1 and message 2. After that, network device 1 uses a random algorithm to randomly select encryption policy 3 from encryption policies 1 to 3 to encrypt message 3 and message 4. Finally, network device 1 uses a random algorithm to randomly select encryption policy 3 from encryption policies 1 to 3 to encrypt message 5 and message 6.

[0274] It is understandable that if network device 1 uses a random algorithm to randomly select an encryption strategy 2 to be used from encryption strategies 1 to 3 associated with traffic 1 to encrypt the 1st to Nth messages, then when network device 1 uses the random algorithm again, it can select an encryption strategy to be used from encryption strategy 1 and encryption strategy 3 to encrypt the (N+1)th to (2N+1)th messages. This can avoid the same encryption strategy selected for different messages when using the random algorithm. N is a positive integer.

[0275] The following examples 2-5 describe a method for a network device to select an encryption policy for a message provided in an embodiment of the present application. Examples 2-5 correspond to the above-mentioned network device 1 determining the encryption policy used for each message in traffic 1 or traffic 2 in encryption policy group 1 according to the first rule. The method includes: network device 1 selects an encryption policy from encryption policies 1 to encryption policies 3 associated with traffic 1 in turn to encrypt a random number of messages.

[0276] For example, network device 1 first uses encryption strategy 1 to encrypt P messages. P is randomly generated by network device 1 using a random algorithm or is a preset value. Network device 1 then uses encryption strategy 2 to encrypt L messages. L is randomly generated by network device 1 again using a random algorithm. Network device 1 then uses encryption strategy 3 to encrypt Q messages. Q is randomly generated by network device 1 again using a random algorithm, and so on, until all messages of flow 1 are encrypted. Q is a positive integer.

[0277] The following examples 2-6 describe a method for a network device to select an encryption policy for a message provided in an embodiment of the present application. The examples 2-6 correspond to the above-mentioned network device 1 determining the encryption policy used by each message in traffic 1 in encryption policy group 1 according to the first rule. The method includes: the network device 1 determines the encryption policy randomly selected by the network device 1 from encryption policy group 1 for a random number of messages in traffic 1 according to the sequence of the messages in traffic 1.

[0278] That is, the network device 1 randomly selects a to-be-encrypted policy from the encryption policy group 1 each time to encrypt a random number of messages in the traffic 1 until all messages have corresponding encryption policies.

[0279] For example, network device 1 uses a random algorithm to randomly select an encryption strategy 2 to be used from encryption strategies 1 to 3, and network device 1 determines that a random number of messages from messages 1 to m use encryption strategy 2. After that, network device 1 uses a random algorithm to randomly select the next encryption strategy 3, and network device 1 determines that a random number of messages from messages 1 to m use encryption strategy 3, and so on, until all messages of flow 1 are encrypted. It should be noted that the randomly selected messages are different each time.

[0280] The following example 2-7 describes a method provided by an embodiment of the present application for a network device to select an encryption policy for a message. The example 2-7 corresponds to the above-mentioned network device 1 determining the encryption policy used by each message in flow 1 or flow 2 in encryption policy group 1 according to the first rule. The method includes: the network device 1 associates an encryption priority with each encryption policy in encryption policy group 1. In addition, the network device 1 can determine the encryption policy used by each message according to the encryption priority corresponding to each message in flow 1. The encryption priority is used to indicate the encryption priority of the encryption policy used to encrypt the message.

[0281] For example, the encryption priority may include one or more levels. For example, level 1, level 2, and level 3. For example, level 1 may be low level. Level 2 may be medium level. Level 3 may be high level. Of course, the "color" field may also be used to identify the encryption priority. For example, the encryption priority is divided into three levels: red, yellow, and green. It should be understood that the embodiment of the present application takes the encryption priority including three levels as an example.

[0282] As a specific implementation, the encryption priority identifier corresponding to each message can be the corresponding encryption priority identifier carried by the message. The encryption priority identifier can be, for example, the priority identified by the DSCP field in the IP message, or it can be the information carried by a separately set encryption priority field. The encryption priority corresponding to each message can be associated with one or more encryption policies. Each encryption policy can also be associated with one or more encryption priorities. For example, the encryption priority corresponding to message 1 is 1, and the encryption priorities associated with encryption policies 1, 2, and 3 are all 1, then network device 1 can select a corresponding encryption policy for message 1 between encryption policies 1 and 3. For another example, encryption policy 1 can be associated with encryption priority 1 and encryption priority 2 at the same time, then for another message, for example, message 2, the encryption priority corresponding to message 2 is 2, and message 2 can also be encrypted based on confidentiality policy 1.

[0283] If the encryption priority identifier 1 corresponding to the message 1 in the flow 1 indicates that the encryption priority of the encryption policy of the encrypted message 1 is level 1. If the encryption priority associated with the encryption policy 1 is also 1, the network device 1 can encrypt the message 1 using the encryption policy 1.

[0284] For example, network device 1 allocates multiple encryption policies of three levels, red, yellow, and green, to the traffic of interface 1. Network device 1 sets the encryption policy level corresponding to each message of traffic 1. For example, the control channel message of FTP protocol is set to level red, and the data channel message of FTP protocol is set to level green. After interface 1 receives message X, the network device identifies the "color" field in the packet header of message X. Network device 1 selects the encryption policy corresponding to the "color" field to encrypt message X. For example, if the "color" field is red, the encryption policy associated with the red level is selected for message X. For example, if the "color" field is yellow, the encryption policy associated with the yellow level is selected for message X. For example, if the "color" field is green, the encryption policy associated with the green level is selected for message X.

[0285] As another specific example, the encryption priority corresponding to each message can be a statically configured encryption priority. For example. In the case where the messages forwarded within a certain interface range belong to the same flow, for example, the messages forwarded by interface 1, interface 2, and interface 3 belong to the same flow, but the encryption priority associated with the message forwarded by interface 1 is the highest, the encryption priority associated with the message forwarded by interface 2 is the second highest, and the encryption priority associated with the message forwarded by interface 3 is the lowest. Then, when network device 1 receives a message forwarded through interface 1 in flow 1, it will select encryption policy 1 corresponding to encryption priority 1 according to encryption priority 1 associated with interface 1 to encrypt the message forwarded through interface 1 in flow 1. Similarly, when the network device receives a message forwarded by interface 2 in flow 1, it will select encryption policy 2 corresponding to encryption priority 2 according to encryption priority 2 associated with interface 2 to encrypt the message forwarded through interface 2 in flow 1. And so on, no further description is given. By statically configuring the encryption priority corresponding to the message, it is possible to make a more detailed distinction in message encryption based on the flow division rules and the granularity of the message. Make secure communication more flexible. For example, for messages with lower security levels, you can configure the corresponding encryption priority to be low, which can save network overhead. For messages with higher security requirements, you can configure a higher encryption priority to increase the security of message transmission.

[0286] It should be noted that if multiple encryption policies are used only by flow 1, packets 1 to m in flow 1 can select an encryption policy to use according to one of the methods described in Examples 2-1 to 2-7 above. Fig.12 As shown, in the embodiment of the present application, multiple encryption strategies between network device 1 and network device 2 can be distributed on different paths. That is, different encryption strategies can correspond to the same path or different paths. When distributed on different paths, the difficulty and cost of an attacker intercepting all messages increases, which can reduce the risk of all messages being cracked and improve security.

[0287] Combination Figure 1 ,like Fig.12 As shown, there are four encryption policies between network device 1 and network device 2, namely, encryption policy 1 to encryption policy 4. Among them, encryption policy 1 is associated with path 1 (network device 1 → network device 4 → network device 5 → network device 2). Encryption policy 2 and encryption policy 3 are associated with path 2 (network device 1 → network device 5 → network device 2). Encryption policy 4 corresponds to path 3 (network device 1 → network device 6 → network device 7 → network device 2). Encryption policy 1, encryption policy 2 and encryption policy 3 have different paths from encryption policy 4. Encryption policy 2 and encryption policy 3 have the same path.

[0288] The following examples 2-8 describe a method for a network device to select an encryption policy for a message provided in an embodiment of the present application. The examples 2-8 correspond to the above-mentioned network device 1 determining the encryption policy used by each message in traffic 1 or traffic 2 in encryption policy group 1 according to the first rule. The method includes: the network device 1 determines that the encryption policy used by each message in traffic 1 is the encryption policy corresponding to the path of each message.

[0289] Therefore, if network device 1 sends message 1 to network device 2 via path 1, network device 1 may use encryption strategy 1 corresponding to path 1 to encrypt message 1. If network device 1 sends message 12 to network device 2 via path 2, network device 1 may use encryption strategy 2 or encryption strategy 3 corresponding to path 2 to encrypt message 2. It should be noted that if a path corresponds to two or more encryption strategies, network device 1 may select an encryption strategy from the two or more encryption strategies corresponding to the path randomly or according to the order of the encryption strategies to encrypt the message transmitted through the path.

[0290] If multiple encryption policies are used by traffic 1 and traffic 2: Network device 1 can specify that different traffic within traffic 1 and traffic 2 use multiple encryption policies according to one of the methods described in Examples 2-1 to 2-8 above. Different traffic will not affect each other and will not affect the selection of encryption policies for other traffic. The methods used by these different traffic can be the same or different. 2) Network device 1 treats all the messages to be sent in traffic 1 and traffic 2 as a whole, and then selects an encryption policy for each of all the messages to be sent in traffic 1 and traffic 2 according to one of the methods described in Examples 2-1 to 2-8 above.

[0291] Fig.12 1 is a flow chart of a secure communication method 1200 provided in an embodiment of the present application. The network architecture of the application method 1200 includes at least a first network device and a second network device. For example, the first network device may be Figure 1 The network device 1 shown, the second network device can be Figure 1 The network device 2 is shown. Fig.12 The method shown can be specifically implemented in combination with Figure 3-Figure 12 The method shown in any of the embodiments described. For example, Fig.12 The first network device and the second network device may be respectively Figure 3 The network device 1 and the network device 2 in the method 300 are shown. Fig.12 The illustrated method 1200 includes the following.

[0292] Step 1201: A first network device receives a first message and a second message.

[0293] The first message and the second message belong to a first flow, and all messages included in the first flow match a first flow differentiation rule.

[0294] For example, Fig.12 The first message in the method shown corresponds to Figure 3 In the message 1, the second message corresponds to Figure 3 The first flow corresponds to the message 2. Figure 3 The flow rate in 1.

[0295] Step 1202: The first network device encrypts the first message based on the first encryption policy to obtain a third message according to the mapping relationship between the first traffic and the first encryption policy group, and encrypts the second message based on the second encryption policy to obtain a fourth message.

[0296] The first encryption policy group includes the second encryption policy and the first encryption policy, and the first encryption policy and the second encryption policy are different encryption policies.

[0297] For example, Fig.12 The first encryption strategy in the method shown corresponds to Figure 3 The encryption strategy 1 in the second encryption strategy corresponds to Figure 3 The first encryption policy group corresponds to Figure 3 Encryption policy group 1 in.

[0298] Step 1203: The first network device sends a third message and a fourth message to the second network device.

[0299] For example, Fig.12 The third message in the method shown corresponds to Figure 3 The fourth message corresponds to the message 1 encrypted based on encryption strategy 1. Figure 3 Message 2 encrypted based on encryption policy 2.

[0300] Step 1204: The second network device receives the third message and the fourth message from the first network device.

[0301] Step 1205: The second network device encrypts the third message to obtain the first message. The second network device decrypts the fourth message to obtain the second message.

[0302] The embodiment of the present application provides a secure communication method. In this method, since there is a mapping relationship between the first flow and the first encryption policy group, the first network device can encrypt different messages in the first flow using different encryption policies in the first encryption policy group. For example, the first message in the first flow is encrypted based on the first encryption policy, and the second message in the first flow is encrypted using the second encryption policy. In this way, different messages in the same flow can be encrypted using different encryption policies, which increases the difficulty of cracking by attackers and improves communication security.

[0303] In a specific implementation, the third message carries a first encryption policy identifier. The fourth message carries a second encryption policy identifier. The first encryption policy identifier is used by the second network device to identify that the third message is a message encrypted by the first encryption policy. The second encryption policy identifier is used by the second network device to identify that the fourth message is a message encrypted based on the second encryption policy.

[0304] In this way, the second network device can determine the encryption strategy for decrypting the third message based on the first encryption strategy identifier, and then use the encryption strategy for decrypting the third message to decrypt the third message to obtain the first message. The second network device can determine the encryption strategy for decrypting the fourth message based on the second encryption strategy identifier, and then use the encryption strategy for decrypting the fourth message to decrypt the fourth message to obtain the second message.

[0305] In method 1200, before step 1202, the method may further include: the first network device determines the encryption policy corresponding to each message in the received first traffic in one of the following ways:

[0306] Method 1: The first network device selects an encryption policy from the first encryption policy group in sequence according to the order of each encryption policy in the first encryption policy group, and determines it as the encryption policy for each message in the received first traffic in turn.

[0307] For example, the specific implementation of method 1 can refer to Example 2-1, which will not be repeated here.

[0308] Method 2: The first network device randomly selects an encryption policy from the first encryption policy group, and encrypts each message in the received first traffic.

[0309] For example, the specific implementation of method 2 can refer to example 2-2, which will not be repeated here.

[0310] Method three: The first network device encrypts N messages in the first traffic based on a first encryption strategy, and encrypts P messages in the first traffic other than the N messages based on the second encryption strategy, the N messages include the first message, the P messages include the second message, and N and P are positive integers.

[0311] For example, the specific implementation of method three can refer to example 2-3, which will not be repeated here.

[0312] When P and N are equal, and P and N are specified values ​​or preconfigured values, and the first encryption policy is placed before the second encryption policy in the first encryption policy group, the specific implementation of method three can refer to example 2-3 and will not be repeated here.

[0313] When P and N are equal, and P and N are specified values ​​or preconfigured values, the first encryption policy is randomly selected by the first network device from the first encryption policy group, and the second encryption policy is randomly selected by the first network device from the first encryption policy group, the specific implementation of method three can refer to example 2-4, which will not be repeated here.

[0314] When P and N are values ​​randomly generated by the first network device, and the first encryption policy is placed before the second encryption policy in the first encryption policy group, the specific implementation of method three can refer to example 2-5 and will not be repeated here.

[0315] When P and N are values ​​randomly generated by the first network device, randomly selected by the first network device from the first encryption policy group, and the second encryption policy is randomly selected by the first network device from the first encryption policy group, the specific implementation of method three can refer to example 2-6, which will not be repeated here.

[0316] In a specific implementation manner, the encryption priority of the first encryption policy is higher than the encryption priority of the second encryption policy.

[0317] For example, the encryption priority may correspond to the three levels of red, yellow, and green in the above example 2-7.

[0318] In a specific implementation manner, the first network device encrypts the first message based on the first encryption policy to obtain a third message according to the mapping relationship between the first traffic and the first encryption policy group, and encrypts the second message based on the second encryption policy to obtain a fourth message, including:

[0319] The first network device determines a first encryption priority corresponding to the first message, and determines to use the first encryption policy to encrypt the first message to obtain the third message according to the association between the first encryption priority and the first encryption policy;

[0320] The first network device determines a second encryption priority corresponding to the second message, and determines to use the second encryption policy to encrypt the second message to obtain the fourth message based on an association between the second encryption priority and the second encryption policy.

[0321] In a specific implementation, the first message includes a first encryption priority identifier, and the first encryption priority identifier indicates the first encryption priority. The encryption priority of the first encryption policy corresponds to the first encryption priority. The second message includes a second encryption priority identifier, and the second encryption priority identifier indicates a second encryption priority. The encryption priority of the second encryption policy corresponds to the second encryption priority. In a specific implementation, the first network device sends the third message and the fourth message to the second network device, including: the first network device sends the third message to the second network device through a first path, and sends the fourth message to the second network device through a second path; wherein the first path is associated with the first encryption policy, and the second path is associated with the second encryption policy.

[0322] For example, the first path may correspond to Fig.12 Path 1 in . The second path can correspond to Fig.12 Path 2 in .

[0323] In the method 1200, before step 1202, the method may further include: the first network device creates the first encryption policy group. For a specific implementation of the first network device creating the first encryption policy group, please refer to the above method 500.

[0324] As a specific implementation, the first network device creates the first encryption policy group including:

[0325] a) The first network device obtains multiple second public keys of the second network device.

[0326] b) The first network device obtains policy information associated with each of the multiple second public keys; the policy information includes: key exchange method information and encryption algorithm information.

[0327] c) The first network device creates the first encryption policy group according to the multiple second public keys and the policy information associated with each of the multiple second public keys.

[0328] As a specific implementation: the first network device obtains multiple second public keys of the second network device, including: the first network device obtains the multiple second public keys through the third network device.

[0329] As a specific implementation: the first network device obtains the policy information associated with each second public key among the multiple second public keys, including: the first network device obtains the policy information associated with each second public key locally, or;

[0330] The first network device receives the policy information associated with each second public key through the third network device.

[0331] As a specific implementation, the first network device obtains multiple second public keys of the second network device, and the first network device obtains policy information associated with each second public key in the multiple second public keys, including:

[0332] The first network device obtains at least one first public key group and policy information associated with each first public key group in the at least one first public key group, wherein the at least one first public key group includes the plurality of second public keys.

[0333] As a specific implementation: the first network device creates the first encryption policy group according to the multiple second public keys and the policy information associated with each second public key, including: the first network device determines n1 public-private key pairs associated with the first policy information; the first policy information includes: key exchange method information and encryption algorithm information; the first network device determines n2 public keys associated with the first policy information among the multiple second public keys; the first network device generates the first encryption policy group according to the n1 public-private key pairs, the n2 public keys and the first policy information, the first encryption policy group including n1×n2 encryption policies, n1 and n2 are positive integers greater than 1.

[0334] As a specific implementation: the first network device creates the first encryption policy group based on the multiple second public keys and the policy information associated with each second public key, including: the policy information associated with the Yth first public-private key pair in the first public-private key pair list is the same as the policy information associated with the Yth second public key in the multiple second public keys; the first network device generates an encryption policy based on the Yth first public-private key pair and the Yth second public key, where Y is an integer greater than or equal to 1.

[0335] The method in method 1200 also includes:

[0336] d) The first network device receives second traffic, where the second traffic includes a fifth message and a sixth message, and all messages included in the second traffic match the second traffic differentiation rule.

[0337] e) The first network device encrypts the fifth message and the sixth message according to the mapping relationship between the second traffic and the first encryption policy group and based on the corresponding encryption policy in the first encryption policy group; the first network device sends the encrypted fifth message and the encrypted sixth message to the second network device.

[0338] when Fig.12 The method 1200 is shown for implementing Figure 3-Figure 12When any of the figures corresponds to the method, the first flow and the second flow may correspond to, for example, the flow 1 and the flow 2 described in the aforementioned method embodiments. The first flow differentiation rule and the second flow differentiation rule may correspond to, for example, the flow differentiation rule 1 and the flow differentiation rule 2 described in the aforementioned method examples. For the specific introduction of the first flow, the second flow, the first flow differentiation rule, the first flow differentiation rule, and the specific implementation of each step in method 1200, please refer to the relevant description of the corresponding steps in the aforementioned method embodiments, which will not be repeated here.

[0339] Combine the following Fig.13 , a network device 700 provided in an embodiment of the present application is introduced. The network device 700 can be applied to Figure 1 For example, the network device 700 may be the network device 1 or the network device 2 described in the present application, and is used to perform the above Figure 3-Figure 12 The network device 700 may also be the first network device or the second network device described in the present application, for executing Fig.12 The network device 700 includes a transceiver unit 701 and a processing unit 702. The transceiver unit 701 is used to perform transceiver operations, and the processing unit is used to perform operations other than transceiver operations. For example, when the network device 700 is used as a first network device to perform Fig.12 In the method 1200 shown, the transceiver unit 701 can receive a first message and a second message, wherein the first message and the second message belong to a first flow, and all messages included in the first flow match the first flow differentiation rule. The processing unit 702 can be used to encrypt the first message based on the first encryption policy to obtain a third message, and encrypt the second message based on the second encryption policy to obtain a fourth message according to the mapping relationship between the first flow and the first encryption policy group; wherein the first encryption policy group includes the second encryption policy and the first encryption policy, and the first encryption policy and the second encryption policy are different encryption policies. The transceiver unit 701 is also used to send the third message and the fourth message to the second network device.

[0340] For example, when the network device 700 is executed as the first network device Fig.12 In the method 1200 shown, the transceiver unit 701 may receive a third message and a fourth message. The processing unit 702 may be configured to encrypt the third message to obtain a first message. The second network device may decrypt the fourth message to obtain a second message.

[0341] Combine the following Fig.14 , another network device 800 provided in an embodiment of the present application is introduced. The network device 800 can be applied to Figure 1For example, the network device 800 may be the network device 1 or the network device 2 described in the present application, and is used to perform the above Figure 3-Figure 12 The operations performed by the network device 1 or the network device 2 in the method of the embodiment corresponding to any of the figures. The network device 800 may also be the first network device or the second network device described in the present application, performing Fig.12 The corresponding method is an operation performed by the first network device or the second network device. The network device 800 includes a communication interface 801 and a processor 802 connected to the communication interface. The communication interface 801 is used to perform transceiver operations, and the processor 802 is used to perform operations other than transceiver operations. For example, when the network device 800 performs as the first network device Fig.12 In the method 1200 shown, the communication interface 801 can receive a first message and a second message, wherein the first message and the second message belong to a first flow, and all messages included in the first flow match the first flow differentiation rule. The processor 802 can be used to encrypt the first message based on the first encryption policy to obtain a third message, and encrypt the second message based on the second encryption policy to obtain a fourth message according to the mapping relationship between the first flow and the first encryption policy group; wherein the first encryption policy group includes the second encryption policy and the first encryption policy, and the first encryption policy and the second encryption policy are different encryption policies. The communication interface 801 is also used to send the third message and the fourth message to the second network device.

[0342] For example, when the network device 800 is executed as the first network device Fig.12 In the method 1200 shown, the communication interface 801 may receive a third message and a fourth message. The processor 802 may be configured to encrypt the third message to obtain a first message. The second network device may decrypt the fourth message to obtain a second message.

[0343] Combine the following Fig.15 , another network device 900 provided in an embodiment of the present application is introduced. The network device 900 can be applied to Figure 1 For example, the network device 900 may be the network device 1 or the network device 2 described in the present application, and is used to perform the above Figure 3-Figure 12 The operations performed by the network device 1 or the network device 2 in the method of the embodiment corresponding to any of the figures. The network device 900 may also be the first network device or the second network device described in the present application, performing Fig.12 The corresponding method is an operation performed by the first network device or the second network device. The network device 900 includes a memory 901 and a processor 902 connected to the memory. The memory 901 stores instructions, and the processor 902 reads the instructions so that the network device 900 performs Figure 3-Figure 12In any embodiment corresponding to any of the figures, the method executed by the network device 1 or the network device 2, the latter executing Fig.12 The method is executed by the first network device or the second network device in the corresponding embodiment.

[0344] Combine the following Fig.16 , another network device 1000 provided in an embodiment of the present application is introduced. The network device 1000 can be applied to Figure 1 For example, the network device 1000 may be the network device 1 or the network device 2 described in the present application, and is used to perform the above Figure 3-Figure 12 The operations performed by the network device 1 or the network device 2 in the method of the embodiment corresponding to any of the figures. The network device 1000 may also be the first network device or the second network device described in the present application, performing Fig.12 The corresponding method is an operation performed by the first network device or the second network device. Fig.16 As shown, the network device 1000 includes a processor 1010, a memory 1020 coupled to the processor, and a communication interface 1030. In a specific embodiment, the memory 1020 stores computer-readable instructions, and the computer-readable instructions include multiple software modules, such as a sending module 1021, a processing module 1022, and a receiving module 1023. After the processor 1010 executes each software module, it can perform corresponding operations according to the instructions of each software module. In this embodiment, the operation performed by a software module actually refers to the operation performed by the processor 1010 according to the instructions of the software module. For example, when the network device 1000 is executed as the first network device Fig.12 In the method shown, the sending module 1021 is used to receive a first message and a second message, wherein the first message and the second message belong to a first flow, and all messages included in the first flow match the first flow differentiation rule. The processing module 1022 is used to encrypt the first message based on the first encryption policy to obtain a third message, and to encrypt the second message based on the second encryption policy to obtain a fourth message according to the mapping relationship between the first flow and the first encryption policy group; wherein the first encryption policy group includes the second encryption policy and the first encryption policy, and the first encryption policy and the second encryption policy are different encryption policies. In addition, after the processor 1010 executes the computer-readable instructions in the memory 1020, it can execute all operations that can be executed by the network device 1, the network device 2, the first network device or the second network device according to the instructions of the computer-readable instructions. For example, when the network device 1000 acts as the network device 1 or the network device 2, it can respectively execute Figure 3-Figure 12All operations performed by network device 1 or network device 2 in the corresponding embodiment; when network device 1000 acts as the first network device or the second network device, it can respectively perform Fig.12 All operations performed by the first network device or the second network device in the corresponding embodiment.

[0345] The processor mentioned in the present application may be a central processing unit (CPU), a network processor (NP) or a combination of a CPU and a NP. The processor may also be an application-specific integrated circuit (ASIC), a programmable logic device (PLD) or a combination thereof. The above-mentioned PLD may be a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL) or any combination thereof. Processor 1010 may refer to one processor or may include multiple processors. The memory mentioned in this application may include volatile memory (English: volatile memory), such as random access memory (English: random-access memory, abbreviated: RAM); the memory may also include non-volatile memory (English: non-volatile memory), such as read-only memory (English: read-only memory, abbreviated: ROM), flash memory (English: flash memory), hard disk drive (English: hard disk drive, abbreviated: HDD) or solid-state drive (English: solid-state drive, abbreviated: SSD); the memory may also include a combination of the above types of memory. The memory may refer to one memory or include multiple memories.

[0346] The embodiment of the present application also provides a communication system, including a first network device and a second network device, wherein the first network device and the second network device can be Figures 13 to 15 Any network device described in any one of the preceding claims, configured to execute Figures 1 to 12 For the method in any corresponding embodiment.

[0347] The present application also provides a computer program product, including a computer program, which, when executed on a computer, enables the computer to execute Figures 1 to 12 A method executed by network device 1 and / or network device 2 in any corresponding embodiment.

[0348] The present application also provides a computer program product, including a computer program, which, when executed on a computer, enables the computer to execute Fig.12 The method in the corresponding embodiment is executed by the first network device and / or the second network device.

[0349] The present application provides a computer-readable storage medium, including computer instructions, which, when executed on a computer, enables the computer to execute Figures 1 to 11 A method executed by network device 1 and / or network device 2 in any corresponding embodiment.

[0350] The present application provides a computer-readable storage medium, including computer instructions, which, when executed on a computer, enables the computer to execute Fig.12 The method in the corresponding embodiment is executed by the first network device and / or the second network device.

[0351] Those skilled in the art will appreciate that the modules and method operations of the various examples described in the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application.

[0352] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and modules described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0353] In the above embodiments, it can be implemented in whole or in part by hardware, firmware or any combination thereof. When software is involved in the specific implementation process, it can be embodied in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from a website site, computer, server or data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) mode to another website site, computer, server or data center. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrated. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state hard disk Solid State Disk (SSD)), etc.

[0354] Each part of this specification is described in a progressive manner, and the same or similar parts between the various embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the device and system embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the description of the method embodiment part.

Claims

1. A secure communication method, It is characterized in that The method comprises: The first network device receives a first message and a second message, wherein the first message and the second message belong to a first flow, and all messages included in the first flow match a first flow differentiation rule; The first network device encrypts the first message based on the first encryption policy to obtain a third message according to the mapping relationship between the first traffic and the first encryption policy group, and encrypts the second message based on the second encryption policy to obtain a fourth message; wherein the first encryption policy group includes the first encryption policy and the second encryption policy, and the first encryption policy and the second encryption policy are different encryption policies; The first network device sends the third message and the fourth message to the second network device; The first network device obtains multiple second public keys of the second network device; The first network device obtains policy information associated with each second public key in the plurality of second public keys; the policy information includes key exchange method information and encryption algorithm information; The first network device creates the first encryption policy group according to the multiple second public keys and the policy information associated with each of the multiple second public keys.

2. The method according to claim 1, It is characterized in that The method further comprises: The first network device determines the encryption policy corresponding to each message in the received first traffic in one of the following ways: Mode 1: The first network device selects an encryption policy from the first encryption policy group in sequence according to the order of each encryption policy in the first encryption policy group, and encrypts each message in the received first traffic; Mode 2: When receiving a message in the first traffic, the first network device randomly selects an encryption policy from the first encryption policy group to encrypt the received message; Method three: The first network device encrypts N messages in the first traffic based on the first encryption strategy, and encrypts P messages in the first traffic based on the second encryption strategy, the N messages include the first message, the P messages include the second message, and N and P are positive integers.

3. The method according to claim 1 or 2, It is characterized in that The first network device encrypts the first message based on the first encryption policy to obtain a third message according to the mapping relationship between the first traffic and the first encryption policy group, and encrypts the second message based on the second encryption policy to obtain a fourth message, including: The first network device determines a first encryption priority corresponding to the first message, and determines to use the first encryption policy to encrypt the first message to obtain the third message according to the association between the first encryption priority and the first encryption policy; The first network device determines a second encryption priority corresponding to the second message, and determines to use the second encryption policy to encrypt the second message to obtain the fourth message based on an association between the second encryption priority and the second encryption policy.

4. The method according to claim 3, It is characterized in that The first message includes a first encryption priority identifier, which is used to indicate the first encryption priority; the second message includes a second encryption priority identifier, which is used to indicate the second encryption priority.

5. The method according to claim 1 or 2, It is characterized in that The first network device sending the third message and the fourth message to the second network device includes: The first network device sends the third message to the second network device via a first path, and sends the fourth message to the second network device via a second path; wherein the first path is associated with the first encryption policy, and the second path is associated with the second encryption policy.

6. The method according to claim 1 or 2, It is characterized in that The first network device obtains multiple second public keys of the second network device, including: The first network device obtains multiple second public keys of the second network device through the third network device.

7. The method according to claim 1 or 2, It is characterized in that The first network device obtains policy information associated with each second public key in the plurality of second public keys, including: The first network device obtains the policy information associated with each second public key locally, or; The first network device obtains the policy information associated with each second public key through the third network device.

8. The method according to claim 1 or 2, It is characterized in that The first network device acquires multiple second public keys of the second network device, and the first network device acquires policy information associated with each of the multiple second public keys, including: The first network device obtains at least one first public key group and policy information associated with each first public key group in the at least one first public key group, wherein the at least one first public key group includes the plurality of second public keys.

9. The method according to claim 1 or 2, It is characterized in that The first network device creates the first encryption policy group according to the multiple second public keys and the policy information associated with each second public key, including: The first network device determines n1 public-private key pairs associated with first policy information; the first policy information includes: first key exchange method information and first encryption algorithm information; The first network device determines n2 public keys associated with the first policy information among the plurality of second public keys; The first network device generates the first encryption policy group according to the n1 public-private key pairs, the n2 public keys and the first policy information, where the first encryption policy group includes n1×n2 encryption policies, where n1 and n2 are integers greater than 1.

10. The method according to claim 1 or 2, It is characterized in that The method further comprises: The first network device receives second traffic, the second traffic includes a fifth message and a sixth message, all messages included in the second traffic match a second traffic differentiation rule, and the first traffic differentiation rule is different from the second traffic differentiation rule; The first network device encrypts the fifth message and the sixth message according to the mapping relationship between the second traffic and the first encryption policy group and based on the corresponding encryption policies in the first encryption policy group; The first network device sends the encrypted fifth message and the encrypted sixth message to the second network device.

11. A first network device, It is characterized in that include: A memory storing instructions; as well as A processor in communication with the memory, wherein the processor executes the instructions so that the first network device executes the method according to any one of claims 1 to 10.

12. A first network device, It is characterized in that include: communication interface, and a processor in communication with the communication interface; Through the communication interface and the processor, the first network device executes the method according to any one of claims 1 to 10.

13. A communication system, It is characterized in that The communication system comprises a first network device and a second network device, wherein the first network device is used to execute the method according to any one of claims 1 to 10.

14. A computer-readable storage medium, It is characterized in that The storage medium stores a computer program or instruction, and when the computer program or instruction is executed by the communication device, the method according to any one of claims 1 to 10 is implemented.

Citation Information

Patent Citations

  • Method and system for transmitting signaling information over a data transport network

    US20120008778A1