A message forwarding method, apparatus, network node, and storage medium
By introducing security authentication instructions into the target SID function field of the SRv6 message and performing corresponding processing, the problem of poor security in the SRv6 forwarding path is solved, and higher data transmission security is achieved.
Patent Information
- Application Number
- CN202180001694.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-06-29
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2041-06-29
AI Technical Summary
The SRv6 forwarding path may contain unsecure network nodes or unsecure links, resulting in poor security problems when forwarding SRv6 packets.
The target SID function field of the SRv6 message includes a security authentication instruction, obtains the target parameters, and performs a security authentication process on the SRv6 message based on this parameter, such as encapsulation or decapsulation processing, to ensure that the message is securely authenticated before forwarding.
The security of SRv6 packets in the forwarding path is improved, and the security of data transmission is enhanced by performing security authentication of packets.
Smart Images

Figure CN113615134B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network technologies, and in particular, to a packet forwarding method, apparatus, network node, and storage medium. Background Art
[0002] The SRv6 (Segment Routing IPv6) technology is a source routing technology. The SRv6 technology enables the source network node of the SRv6 forwarding path to insert the segmentation information of the SRv6 forwarding path into the packet. For the sake of description, the packet after inserting the segmentation information is referred to as an SRv6 packet. The segmentation information of the SRv6 forwarding path indicates the order in which each network node included in the path forwards the packet. In this way, after receiving the SRv6 packet, other network nodes can forward the packet according to the segmentation information carried in the SRv6 packet.
[0003] However, the SRv6 forwarding path may include insecure network nodes or insecure links, resulting in poor security when forwarding SRv6 packets along the SRv6 forwarding path. Summary of the Invention
[0004] The purpose of the embodiments of this application is to provide a packet forwarding method and apparatus to improve the security of forwarding SRv6 packets. The specific technical solutions are as follows:
[0005] In a first aspect, the embodiments of this application provide a packet forwarding method applied to a network node. The method includes:
[0006] Obtain an SRv6 packet;
[0007] If the function field of the target segment identifier SID includes a security authentication instruction, obtain target parameters according to the operation indicated by the security authentication instruction, and perform security authentication processing on the SRv6 packet based on the target parameters, where the target SID is: the SID corresponding to the network node in the segmentation list carried in the packet header of the SRv6 packet, and the target parameter is: the parameter of the security authentication instruction recorded in the packet header;
[0008] Forward the processed SRv6 packet to the next-hop device.
[0009] In an embodiment of this application, the SRv6 packet is generated by the source network node of the SRv6 packet through the following method:
[0010] Receive an original packet;
[0011] If it is determined that there is an insecure network node in the SRv6 forwarding path that needs to forward the original message, obtain the parameters of the security authentication instruction, where the security authentication instruction indicates that the insecure network node performs security authentication processing on the SRv6 message;
[0012] Determine whether the data volume of the parameters of the security authentication instruction is greater than the maximum data volume of the parameter field of the SID;
[0013] If so, for the insecure network node, generate an SID whose function field contains the security authentication instruction and whose parameter field contains the first parameter, and generate the SRv6 message based on the original message, where the extended field in the message header of the SRv6 message contains the second parameter, and the security authentication instruction also indicates that the parameters of the security authentication instruction are stored in the parameter field and the extended field in the message header, the first parameter is: part of the parameters of the security authentication instruction whose data volume is less than or equal to the maximum data volume, and the second parameter is: the parameters of the security authentication instruction other than the first parameter;
[0014] If not, for the insecure network node, generate an SID whose function field contains the security authentication instruction and whose parameter field contains the parameters of the security authentication instruction, and generate the SRv6 message based on the original message, where the security authentication instruction also indicates that the parameters of the security authentication instruction are stored in the parameter field.
[0015] In one embodiment of the present application, obtaining the target parameter according to the operation indicated by the security authentication instruction includes:
[0016] If the security authentication instruction indicates that the parameters of the security authentication instruction are stored in the parameter field, obtain the target parameter from the parameters included in the parameter field of the target SID;
[0017] If the security authentication instruction indicates that the parameters of the security authentication instruction are stored in the parameter field and the extended field of the message header, obtain the target parameter from the parameters included in the parameter field of the target SID and the parameters included in the extended field of the message header.
[0018] In one embodiment of the present application, the security authentication instruction includes: an encapsulation instruction, and the encapsulation instruction indicates performing encapsulation processing on the payload of the SRv6 message;
[0019] Performing security authentication processing on the SRv6 message according to the target parameter includes:
[0020] Performing encapsulation processing on the payload of the SRv6 message according to the target parameter.
[0021] In one embodiment of the present application, the security authentication instruction includes: a decapsulation instruction, and the decapsulation instruction instructs to perform decapsulation processing on the payload of the SRv6 packet.
[0022] Performing security authentication processing on the SRv6 packet according to the target parameter includes:
[0023] Performing decapsulation processing on the payload of the SRv6 packet according to the target parameter.
[0024] In a second aspect, an embodiment of the present application provides a packet forwarding device applied to a network node. The device includes:
[0025] A packet obtaining module, configured to obtain an SRv6 packet;
[0026] A security processing module, configured to, if a security authentication instruction is included in the function field of the target SID, obtain a target parameter according to the operation indicated by the security authentication instruction, and perform security authentication processing on the SRv6 packet according to the target parameter, where the target SID is: the SID corresponding to the network node in the segment list carried in the packet header of the SRv6 packet, and the target parameter is: the parameter of the security authentication instruction recorded in the packet header;
[0027] A packet forwarding module, configured to forward the processed SRv6 packet to the next-hop device.
[0028] In one embodiment of the present application, the SRv6 packet is generated by the source network node of the SRv6 packet in the following manner:
[0029] Receiving an original packet;
[0030] If it is determined that there is an insecure network node in the SRv6 forwarding path for forwarding the original packet, obtaining the parameter of the security authentication instruction, where the security authentication instruction instructs: the insecure network node performs security authentication processing on the SRv6 packet;
[0031] Judging whether the data volume of the parameter of the security authentication instruction is greater than the maximum data volume of the parameter field of the SID;
[0032] If the judgment result of the data volume judgment sub-module is yes, for the insecure network node, generate an SID whose function field contains the security authentication instruction and whose parameter field contains a first parameter, and generate the SRv6 packet based on the original packet, where a second parameter is included in the extended field in the packet header of the SRv6 packet, and the security authentication instruction further indicates that the parameters of the security authentication instruction are stored in the parameter field and the extended field in the packet header; the first parameter is: part of the parameters of the security authentication instruction whose data volume is less than or equal to the maximum data volume; the second parameter is: the parameters of the security authentication instruction other than the first parameter;
[0033] If the judgment result of the data volume judgment sub-module is no, for the insecure network node, generate an SID whose function field contains the security authentication instruction and whose parameter field contains the parameters of the security authentication instruction, and generate the SRv6 packet based on the original packet, where the security authentication instruction further indicates that the parameters of the security authentication instruction are stored in the parameter field.
[0034] In one embodiment of the present application, the security processing module is specifically configured to:
[0035] If the function field of the target SID includes a security authentication instruction, and if the security authentication instruction indicates that the parameters of the security authentication instruction are stored in the parameter field, obtain the target parameter from the parameters included in the parameter field of the target SID;
[0036] If the function field of the target SID includes a security authentication instruction, and if the security authentication instruction indicates that the parameters of the security authentication instruction are stored in the parameter field and the extended field of the packet header, obtain the target parameter from the parameters included in the parameter field of the target SID and the parameters included in the extended field of the packet header;
[0037] Perform security authentication processing on the SRv6 packet according to the target parameter.
[0038] In one embodiment of the present application, the security authentication instruction includes: an encapsulation addition instruction, and the encapsulation addition instruction indicates to perform encapsulation addition processing on the payload of the SRv6 packet;
[0039] The security processing module is specifically configured to:
[0040] If the function field of the target SID includes a security authentication instruction, obtain the target parameter according to the operation indicated by the security authentication instruction;
[0041] Perform encapsulation addition processing on the payload of the SRv6 packet according to the target parameter.
[0042] In one embodiment of the present application, the security authentication instruction includes: a de-encapsulation instruction, and the de-encapsulation instruction instructs to perform de-encapsulation processing on the payload of the SRv6 packet;
[0043] The security processing module is specifically configured to:
[0044] If the function field of the target SID includes a security authentication instruction, obtain target parameters according to the operation indicated by the security authentication instruction;
[0045] Perform de-encapsulation processing on the payload of the SRv6 packet according to the target parameters.
[0046] In a third aspect, an embodiment of the present application provides a network node, including: a processor and a machine-readable storage medium, where the machine-readable storage medium stores machine-executable instructions that can be executed by the processor, and the processor is prompted by the machine-executable instructions to: implement any of the method steps in the first aspect.
[0047] In a fourth aspect, an embodiment of the present application provides a machine-readable storage medium, storing machine-executable instructions, which, when called and executed by a processor, cause the processor to: implement any of the method steps in the first aspect.
[0048] Beneficial effects of the embodiments of the present application:
[0049] When a network node forwards a packet by applying the solution provided in the embodiment of the present application, after obtaining an SRv6 packet, if the function field of the target SID corresponding to the above network node includes a security authentication instruction, then according to the operation indicated by the security authentication instruction, obtain target parameters, and perform security authentication processing on the SRv6 packet according to the target parameters, and then forward the processed SRv6 packet to the next-hop device in the SRv6 forwarding path.
[0050] As can be seen from the above, if the function field of the target SID corresponding to the network node includes a security authentication instruction, in this case, the network node does not directly forward the SRv6 packet, but performs the security authentication processing indicated by the security authentication instruction on the SRv6 packet according to the target parameters, and then forwards the SRv6 packet that has undergone security authentication processing. Since the network node performs the security authentication processing indicated by the security authentication instruction on the SRv6 packet, the security of the SRv6 packet can be improved. Therefore, when the network node applies the solution provided in the embodiment of the present application to forward the SRv6 packet that has undergone security authentication processing, the security of forwarding the SRv6 packet can be improved. Description of the Drawings
[0051] To more clearly illustrate the technical solutions of the embodiments of the present application and the prior art, the following briefly introduces the drawings required in the embodiments and the prior art. Obviously, the drawings in the following description are only some embodiments of the present application, and those of ordinary skill in the art can also obtain other drawings based on these drawings.
[0052] Figure 1 Schematic flow chart of the first packet forwarding method provided by the embodiment of the present application;
[0053] Figure 2 Schematic diagram of an SRv6 forwarding path provided by the embodiment of the present application;
[0054] Figure 3 Schematic diagram of an SRv6 packet after encapsulation processing provided by the embodiment of the present application;
[0055] Figure 4 Schematic diagram of an SRv6 packet after decapsulation processing provided by the embodiment of the present application;
[0056] Figure 5 Schematic flow chart of an SRv6 packet generation method provided by the embodiment of the present application;
[0057] Figure 6 Schematic flow chart of the second packet forwarding method provided by the embodiment of the present application;
[0058] Figure 7 Schematic structural diagram of a packet forwarding device provided by the embodiment of the present application;
[0059] Figure 8 Schematic structural diagram of a network node provided by the embodiment of the present application. Detailed implementation manners
[0060] To make the purpose, technical solutions, and advantages of the present application clearer, the following further elaborates on the present application with reference to the accompanying drawings and by way of examples. Obviously, the described embodiments are only some of the embodiments of the present application, rather than all of them. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application fall within the scope of protection of the present application.
[0061] In the prior art, when forwarding an SRv6 packet along an SRv6 forwarding path that includes insecure network nodes or insecure links, there is a technical problem of poor security. To solve this technical problem, the embodiments of the present application provide a packet forwarding method, device, network node, and storage medium.
[0062] In one embodiment of the present application, a packet forwarding method is provided, which is applied to a network node. The method includes:
[0063] Obtain an SRv6 packet;
[0064] If the function field of the target SID includes a security authentication instruction, according to the operation indicated by the security authentication instruction, obtain the target parameter, and based on the target parameter, perform security authentication processing on the SRv6 packet. Wherein, the target SID is the SID corresponding to the network node in the segment list carried in the packet header of the SRv6 packet, and the target parameter is the parameter of the security authentication instruction recorded in the packet header;
[0065] Forward the processed SRv6 packet to the next-hop device.
[0066] As can be seen from the above, if the function field of the target SID corresponding to the network node includes a security authentication instruction, in this case, the network node does not directly forward the SRv6 packet, but based on the target parameter, performs the security authentication processing indicated by the security authentication instruction on the SRv6 packet, and then forwards the SRv6 packet after the security authentication processing. Since the network node performs the security authentication processing indicated by the security authentication instruction on the SRv6 packet, the security of the SRv6 packet can be improved. Therefore, when the network node applies the solution provided in the embodiment of the present application to forward the SRv6 packet after the security authentication processing, the security of forwarding the SRv6 packet can be improved.
[0067] Next, in combination with Figure 1 and Figure 2 , the packet forwarding method provided in the embodiment of the present application will be described.
[0068] Figure 1 FIG.
[0069] is a schematic flowchart of the first packet forwarding method provided in the embodiment of the present application, and this method is applied to a network node.
[0070] Figure 2 Among them, the network node may be a router, a switch, etc.
[0070] Figure 2 FIG.
[0071] As Figure 2 shown, the network includes network nodes R1 - R7. The solid line connections between the network nodes indicate that the network nodes at both ends of the solid line connection are interconnected, Figure 2 and the dotted arrows in
[0072] Specifically, Figure 2 the SRv6 forwarding path shown is R1 - R2 - R3 - R5 - R6 - R7.
[0073] For example, R1-R3 can be called the first path segment, R3-R5 the second path segment, and R5-R7 the third path segment.
[0074] The execution entity of the solution provided by the embodiments of this application can be any network node in the SRv6 forwarding path except the source network node. Based on this, Figure 2 in the SRv6 forwarding path shown above, R2-R7 except the source network node R1 can all be used as the execution entity of the solution provided by the embodiments of this application.
[0075] The above message forwarding method includes the following steps S101-S103.
[0076] S101: Obtain an SRv6 message.
[0077] Specifically, the SRv6 message obtained by the network node can be: the SRv6 message forwarded by the network node adjacent to and before this network node in the SRv6 forwarding path. For example, the SRv6 message obtained by network node R3 can be the SRv6 message forwarded by network node R2.
[0078] Among them, the above SRv6 message contains a message header and a payload, and the above message header is an SRH (Segment Identifier Header, segment routing message header).
[0079] Specifically, the message header of the above SRv6 message contains a segment list. The above segment list includes the SIDs corresponding to other network nodes in the SRv6 forwarding path except the source network node, and the arrangement order of the SIDs corresponding to each network node in the segment list is opposite to the arrangement order of the network nodes in the SRv6 forwarding path.
[0080] Among them, the above SID contains a Locator (location field), a Function (function field), and an Arguments (parameter field).
[0081] The above Locator is used to identify the position of the network node corresponding to the above SID in the SRv6 forwarding path. The Locator contains a Locator Block (location block field) and a Locator Node (location node field).
[0082] The above Function includes the message processing instructions that the network node corresponding to the above SID needs to execute on the SRv6 message. Specifically, the above Function can contain one or more message processing instructions.
[0083] The parameters in the above Arguments include the parameters of the above message processing instructions.
[0084] In addition, the message header of the SRv6 message further includes other fields except the fragmentation list, and the information included in the other fields is the same as that in the prior art, which will not be elaborated in the embodiments of the present application.
[0085] Furthermore, the above payload is the field other than the message header in the above SRv6 message, which contains the data transmitted by the SRv6 message.
[0086] In an embodiment of the present application, the message header further includes a number field for recording the number of the SID corresponding to the above network node, and the above number field can be represented by SL (Segments Left).
[0087] S102: If the function field of the target SID includes a security authentication instruction, obtain the target parameter according to the operation indicated by the above security authentication instruction, and perform security authentication processing on the above SRv6 message according to the above target parameter.
[0088] Wherein, the above target SID is: the SID corresponding to the above network node in the fragmentation list carried in the message header of the above SRv6 message. The above target parameter is: the parameter of the above security authentication instruction recorded in the above message header.
[0089] Specifically, the SID numbered as the number recorded in the above number field in the fragmentation list can be determined as the above target SID.
[0090] In an embodiment of the present application, the target parameter can be obtained from the position indicated by the above security authentication instruction in the message header. Specifically, reference can be made to steps S102A - S102B below, which will not be elaborated here for the time being.
[0091] In addition, the above security authentication instruction can be an encapsulation instruction for instructing to perform encapsulation processing on the payload of the SRv6 message, or a decapsulation instruction for instructing to perform decapsulation processing on the payload of the SRv6 message.
[0092] Specifically, the above security authentication instruction can be an instruction for instructing the network node to perform security authentication processing on the SRv6 message based on IPsec (Internet Protocol Security) and / or HMAC (Hash-based Message Authentication Code).
[0093] Among them, the IPsec protocol mainly consists of three parts: AH (Authentication Header), ESP (Encapsulating Security Payload), and SA (Secure Association).
[0094] The above AH can provide functions such as data integrity check, data source authentication, and protection against replay attacks for SRv6 packets. The above ESP can provide functions such as data encryption, data source authentication, data integrity verification, and protection against replay attacks for SRv6 packets. SA is used to establish a one-way security relationship between network nodes at both ends of the communication and specify information such as the algorithms and parameters required by IPsec.
[0095] Specifically, SA can be established through the IKE (Internet Key Exchange) protocol. It can also be established through other means. During the process of performing security authentication on SRv6 packets, the above AH or ESP can be used alone to perform security authentication on SRv6 packets, or AH and ESP can be used together to perform security authentication on SRv6 packets.
[0096] Among them, the above IPsec protocol is a protocol in the prior art, and this is not elaborated in the embodiments of this application.
[0097] In an embodiment of this application, when the above security authentication instruction includes the above encapsulation instruction, the above SRv6 packet can be subjected to security authentication processing through step A shown below, which will not be elaborated here for the time being.
[0098] In another embodiment of this application, when the above security authentication instruction includes the above decapsulation instruction, the above SRv6 packet can be subjected to security authentication processing through step B shown below, which will not be elaborated here for the time being.
[0099] S103: Forward the processed SRv6 packet to the next-hop device.
[0100] Among them, the above next-hop device is a node that is located after the above network node and adjacent to the above network node in the above SRv6 forwarding path.
[0101] For example, referring to Figure 2 , for the network node R3, the above network node R5 is the above next-hop device in the SRv6 forwarding path.
[0102] In one embodiment of the present application, the number recorded in the number field of the above message header can be decremented by 1 to obtain the number of the SID corresponding to the next-hop device in the above SRv6 forwarding path, thereby determining the SID corresponding to the next-hop device within the SRv6 forwarding path in the fragmentation list. Update the destination address of the above SRv6 message to the SID corresponding to the next-hop device in the above SRv6 forwarding path, and forward the SRv6 message with the changed destination address according to the routing table recorded by the above network node.
[0103] Specifically, the above network node can publish the SRv6 message after security authentication processing to the network based on IGP (Interior Gateway Protocols).
[0104] As can be seen from the above, if the function field of the target SID corresponding to the network node includes a security authentication instruction, in this case, the network node does not directly forward the SRv6 message, but performs the security authentication processing indicated by the security authentication instruction on the SRv6 message according to the target parameters, and then forwards the SRv6 message after security authentication processing. Since the network node performs the security authentication processing indicated by the security authentication instruction on the SRv6 message, the security of the SRv6 message can be improved. Therefore, when the network node applies the solution provided in the embodiment of the present application to forward the SRv6 message after security authentication processing, the security of forwarding the SRv6 message can be improved.
[0105] In addition, network nodes other than the source network node in the above SRv6 forwarding path can perform security authentication processing on the SRv6 message through the embodiment shown above. Figure 1 If the source network node determines that it is an insecure network node, it can directly perform security authentication processing on the payload of the original message and then generate and send the above SRv6 message.
[0106] Specifically, since the above source network node is the starting node of the above SRv6 forwarding path, there is no network node in front of the above source network node in the SRv6 forwarding path to perform encapsulation processing on the payload of the message. Therefore, the security authentication processing performed by the above source network node is often encapsulation processing, and subsequent decapsulation processing is performed by other network nodes in the SRv6 forwarding path.
[0107] In one embodiment of the present application, the above SRv6 message can be subjected to security authentication processing through step A.
[0108] Step A: Perform encapsulation processing on the payload of the above SRv6 message according to the above target parameters.
[0109] Specifically, the above payload can be encapsulated based on the IPsec protocol and / or HMAC. During the process of encapsulating the payload using the IPsec protocol, the payload can be encapsulated using only AH, only ESP, or both AH and ESP together.
[0110] See Figure 3 , which is a schematic diagram of an SRv6 packet after encapsulation provided by an embodiment of the present application.
[0111] Corresponding to the foregoing Figure 2 The above Figure 3 is an SRv6 packet obtained after encapsulating the payload of the SRv6 packet by the network node R3. Each rectangle in the figure represents a field in the SRv6 packet obtained after encapsulation.
[0112] Among them, SA (Source Address) = R1 indicates that the source address of the SRv6 packet is the address of the network node R1, and DA (Destination or Target Address) = R5 indicates that the destination address of the SRv6 packet forwarded according to the SRv6 forwarding path is the address of the network node R5.
[0113] The R7 field, R5 field, and R3 field indicate that the path segments included in the above SRv6 forwarding path are R1 - R3, R3 - R5, and R5 - R7 respectively.
[0114] The HMAC field, AH field, and ESP field are fields added to the above SRv6 packet after R3 encapsulates the payload using HMAC, AH, and ESP together. The ESP trailer field is the ESP trailer field corresponding to the ESP field, and the ESP ICV (Integrity check value) field is a parameter required for packet authentication.
[0115] In addition, the above Figure 3 is a schematic diagram of the SRv6 packet obtained after encapsulation. The actually obtained SRv6 packet also includes other fields in addition to Figure 3 the fields shown.
[0116] In another embodiment of the present application, the above SRv6 packet can be securely authenticated through the following step B.
[0117] Step B: Decapsulate the payload of the above SRv6 packet according to the above target parameters.
[0118] Specifically, the payload included in the above SRv6 packet has been encapsulation processed. Then, the payload needs to be decapsulated using a decapsulation method corresponding to the encapsulation method used for the above encapsulation processing.
[0119] See Figure 4 , which is a schematic diagram of an SRv6 packet after decapsulation processing provided by an embodiment of the present application.
[0120] Among them, the above decapsulation processing can be Figure 2 performed by the network node R5 shown in Figure 3 . Compared with the embodiment shown in Figure 3 , the HMAC field, AH field, ESP field, ESP trailer field, and ESP ICV field are removed after decapsulation processing. And, according to the SRv6 forwarding path, the packet forwarded by the network node R5 needs to be forwarded to the network node R7. Therefore, the DA recorded in the above SRv6 packet after decapsulation processing is the address of the network node R7.
[0121] In addition, the above Figure 4 is a schematic diagram of the SRv6 packet obtained after decapsulation processing. The actually obtained SRv6 packet also includes other fields in addition to the Figure 4 shown fields.
[0122] In an embodiment of the present application, the above SRv6 packet can be generated by the source network node of the SRv6 packet, and the above source network node can be the starting node in the SRv6 forwarding path.
[0123] For example, see Figure 2 , the above source network node can be the network node R1.
[0124] See Figure 5 , which is a schematic flowchart of a method for generating an SRv6 packet provided by an embodiment of the present application. The above source network node can generate an SRv6 packet through the following steps S501 - S505.
[0125] S501: Receive the original packet.
[0126] Specifically, the above original packet may include a payload and a packet header of the original packet.
[0127] Among them, the above original packet can be a packet sent by other devices or a packet generated by the above source network node.
[0128] S502: If it is determined that there is an insecure network node in the SRv6 forwarding path for forwarding the above original packet, obtain the parameters of the security authentication instruction.
[0129] Among them, the above security authentication instruction indicates that the above insecure network node performs security authentication processing on the SRv6 message.
[0130] Specifically, the above security authentication instruction may include an encapsulation instruction and a decapsulation instruction.
[0131] In addition, the above insecure network node may be a network node with a risk of data leakage itself, or a network node connected to an insecure link with a risk of data leakage.
[0132] Specifically, the above insecure link may be an insecure path segment with a risk of data leakage, and the above insecure network node may be a network node located at the starting position and the ending position of the insecure path segment.
[0133] For example, referring to Figure 2 , if the path segment of the above network nodes R3 - R5 is an insecure path segment, the above insecure network nodes may be network node R3 and network node R5.
[0134] In an embodiment of the present application, the above source network node may determine the insecure network nodes included in the above SRv6 forwarding path through information indicating the insecure network nodes. This information may be manually issued by the administrator to the above source network node, or issued by a centralized controller or a control node outside the above source network node to the above source network node, or determined by the above source network node itself. The process of the source network node determining the insecure network nodes belongs to the process executed by the control layer of the above source network node, and can be completed independently of the message forwarding process.
[0135] Specifically, the above insecure network node may be a preset network node. It may also determine, based on the historical forwarding information of each network node in the above SRv6 forwarding path, the network node with a relatively large number of data leakage occurrences as the above insecure network node.
[0136] In another embodiment of the present application, the parameters of the above security authentication instruction may be generated by the above source network node itself after determining the above insecure network nodes, or issued by a centralized controller or a control node to the above source network node, or manually issued by the administrator to the above source network node.
[0137] In addition, the security authentication process for the above SRv6 packet can include two processes: encapsulation processing of the SRv6 packet and decapsulation processing of the SRv6 packet. Therefore, a pair of network nodes included in the SRv6 forwarding path need to perform encapsulation processing and decapsulation processing on the SRv6 packet respectively, so insecure network nodes can appear in pairs in the above SRv6 forwarding path. In the SRv6 forwarding path, the network node that performs encapsulation processing on the SRv6 packet is located before the network node that performs decapsulation processing on the SRv6 packet.
[0138] S503: Determine whether the data volume of the parameter of the above security authentication instruction is greater than the maximum data volume of the parameter field of the SID.
[0139] Specifically, the total data volume of the above SID preset in the SRv6 packet is 128 bit. The 128-bit data volume can be divided into Locator, Function, and Arguments in advance. The maximum data volume of the above parameter field is the data volume divided into Arguments.
[0140] If the data volume of the parameter of the above security authentication instruction is greater than the parameter field of the SID, it is difficult for the parameter of the above security authentication instruction to be completely stored in the above parameter field, and step S504 can be executed. If the data volume of the parameter of the above security authentication instruction is less than or equal to the parameter field of the SID, the parameter of the above security authentication instruction can be completely stored in the above parameter field, and step S505 can be executed.
[0141] S504: For the above insecure network node, generate an SID whose function field contains the above security authentication instruction and whose parameter field contains the first parameter, and generate the above SRv6 packet based on the above original packet.
[0142] Among them, the extended field in the above packet header of the above SRv6 packet contains the second parameter.
[0143] The above security authentication instruction also indicates that the parameter of the above security authentication instruction is stored in the above parameter field and the extended field in the above packet header.
[0144] Since the parameters of the above security authentication instruction are stored in the parameter field and the extended field respectively, the above security authentication instruction can also indicate that the parameters are stored in the parameter field and the extended field, so that the above insecure network node can obtain the parameters of the above security authentication instruction from the above parameter field and the extended field after obtaining the above security authentication instruction.
[0145] In addition, the first parameter is: part of the parameters in the security authentication instruction whose data volume is less than or equal to the maximum data volume. The second parameter is: the parameters in the security authentication instruction other than the first parameter.
[0146] Specifically, since the data volume of the parameters of the security authentication instruction is greater than the maximum data volume, it is difficult for the parameter field to store the parameters of the security authentication instruction completely. The first parameter whose data volume is less than or equal to the maximum data volume in the above parameters can be stored in the parameter field of the SID. And the second parameter, which is difficult to be stored in the parameter field in the parameters of the security authentication instruction and is other than the first parameter, is stored in the extended field in the message header.
[0147] Among them, the first parameter can be any data in the parameters of the security authentication instruction whose data volume is less than or equal to the maximum data volume. It can also be the data whose data volume is less than or equal to the maximum data volume composed of consecutive bytes starting from the starting byte of the parameters of the security authentication instruction.
[0148] The second parameter stored in the above extended field can be data in TLV (Type Length Value) format, where the extended field records the second parameter, the type of the parameter corresponding to the second parameter, the length of the second parameter, and the identifier of the second parameter.
[0149] Referring to Table 1, a TLV format data group provided by an embodiment of the present application is shown.
[0150] Table 1
[0151]
[0152] Among them, the above Type represents the type of the parameter corresponding to the second parameter, the above Length represents the length of the second parameter, and the identifier represents the identifier of the second parameter.
[0153] In an embodiment of the present application, the generated SID can be inserted into the fragmentation list in the message header of the original message according to the position of the above insecure network node in the SRv6 forwarding path to generate the above SRv6 message. Specifically, the arrangement order of the SIDs in the fragmentation list is opposite to the arrangement order of the network nodes corresponding to the SIDs in the SRv6 forwarding path.
[0154] In another embodiment of the present application, the identifier of the above encapsulation instruction can be END.SE, and the instruction with the identifier END.SE is used to instruct the network node to perform encapsulation processing on the SRv6 message. The identifier of the above decapsulation instruction can be END.SD, and the instruction with the identifier END.SD is used to instruct the network node to perform decapsulation processing on the SRv6 message.
[0155] For example, the function field in the SID corresponding to the first network node generated may include the identifier END.SE to indicate that the first network node performs encapsulation processing on the SRv6 packet. The function field in the SID corresponding to the second network node generated may include the identifier END.SD to indicate that the second network node performs decapsulation processing on the SRv6 packet.
[0156] S505: For the above-mentioned insecure network node, generate an SID whose function field contains the above-mentioned security authentication instruction and whose parameter field contains the parameters of the above-mentioned security authentication instruction, and generate the above-mentioned SRv6 packet based on the above-mentioned original packet.
[0157] Among them, the above-mentioned security authentication instruction also indicates that the parameters of the above-mentioned security authentication instruction are stored in the above-mentioned parameter field.
[0158] Specifically, since the data volume of the parameters of the above-mentioned security authentication instruction is less than or equal to the above-mentioned maximum data volume, the above-mentioned parameter field can store the parameters of the above-mentioned security authentication instruction completely. Therefore, an SID whose function field contains the security authentication instruction and whose parameter field contains the parameters of the security authentication instruction can be directly generated. And insert the generated SID into the fragmentation list in the packet header of the above-mentioned original packet to generate the above-mentioned SRv6 packet.
[0159] In addition, the above-mentioned step S505 is similar to the foregoing step S504, and the embodiments of the present application will not elaborate on this.
[0160] As can be seen from the above, since the maximum data volume that the parameter field of the SID can accommodate is limited, among the parameters of the security authentication instruction corresponding to the above-mentioned insecure network node, some parameters can be stored in the above-mentioned parameter field, and the other part of the parameters can be stored in the extended field included in the packet header of the SRv6 packet. Therefore, even if the data volume of the security authentication instruction is greater than the maximum data volume of the parameter field, in most cases, the above-mentioned security authentication instruction can be completely stored in the above-mentioned SRv6 packet and sent to the above-mentioned insecure network node completely, so that the above-mentioned insecure network node can obtain the complete parameters of the security authentication instruction and complete the security authentication processing on the SRv6 packet based on the complete parameters.
[0161] See Figure 6 , which is a schematic flowchart of the second packet forwarding method provided by the embodiment of the present application. Compared with the embodiment shown in the foregoing Figure 1 , in the above-mentioned step S102, it can be implemented through the following steps S102A-S102B.
[0162] S102A: If the function field of the target SID includes a security authentication instruction, and the above security authentication instruction indicates that the parameters of the above security authentication instruction are stored in the above parameter field, then obtain the target parameter from the parameters included in the parameter field of the above target SID, and perform security authentication processing on the above SRv6 packet according to the above target parameter.
[0163] Since the above security authentication instruction indicates that the parameters of the above security authentication instruction are stored in the parameter field of the target SID, the target parameter can be obtained from the parameter field of the target SID.
[0164] Specifically, the above parameter field is at a fixed position in the above target SID and has a fixed data length. Therefore, the parameter field in the target SID can be directly determined, and then the target parameter can be obtained from the parameter field.
[0165] In addition, performing security authentication processing on the above SRv6 packet according to the above target parameter is similar to the embodiment shown in the foregoing step S102, and the embodiments of the present application will not repeat it here.
[0166] S102B: If the function field of the target SID includes a security authentication instruction, and the above security authentication instruction indicates that the parameters of the above security authentication instruction are stored in the above parameter field and the packet header extension field, then obtain the target parameter from the parameters included in the parameter field of the above target SID and the parameters included in the extension field in the above packet header, and perform security authentication processing on the above SRv6 packet according to the above target parameter.
[0167] Since the above security authentication instruction indicates that the parameters of the above security authentication instruction are stored in the parameter field of the target SID and the extension field of the SRv6 packet header, the parameters can be obtained separately from the parameters included in the parameter field of the target SID and the parameters included in the extension field. And the parameters obtained from the parameter field and the parameters obtained from the extension field are merged to obtain the target parameter.
[0168] In addition, performing security authentication processing on the above SRv6 packet according to the above target parameter is similar to the embodiment shown in the foregoing step S102, and the embodiments of the present application will not repeat it here.
[0169] As can be seen from the above, since the parameters of the security authentication instruction corresponding to the above network node can be completely stored in the parameter field, or partially stored in the above parameter field and the other part stored in the extension field included in the packet header of the SRv6 packet. The storage location of the above parameters can be determined based on the indication of the security authentication instruction, and the target parameter can be obtained from the storage location indicated by the security authentication instruction, so that the SRv6 packet can be subjected to security authentication processing based on the completed target parameter.
[0170] Corresponding to the foregoing message forwarding method, an embodiment of the present application further provides a message forwarding device.
[0171] See Figure 7 , which is a schematic structural diagram of a message forwarding device provided by an embodiment of the present application, applied to a network node. The above device includes:
[0172] A message obtaining module 701, configured to obtain an SRv6 message;
[0173] A security processing module 702, configured to, if a security authentication instruction is included in the function field of the target SID, obtain target parameters according to the operation indicated by the security authentication instruction, and perform security authentication processing on the SRv6 message according to the target parameters, where the target SID is: the SID corresponding to the network node in the segment list carried in the message header of the SRv6 message, and the target parameter is: the parameter of the security authentication instruction recorded in the message header;
[0174] A message forwarding module 703, configured to forward the processed SRv6 message to the next-hop device.
[0175] As can be seen from the above, if a security authentication instruction is included in the function field of the target SID corresponding to the network node, in this case, the network node does not directly forward the SRv6 message, but performs security authentication processing indicated by the security authentication instruction on the SRv6 message according to the target parameters, and then forwards the SRv6 message after security authentication processing. Since the network node performs security authentication processing indicated by the security authentication instruction on the SRv6 message, the security of the SRv6 message can be improved. Therefore, when the network node applies the solution provided by the embodiment of the present application to forward the SRv6 message after security authentication processing, the security of forwarding the SRv6 message can be improved.
[0176] In an embodiment of the present application, the SRv6 message is generated by the source network node of the SRv6 message in the following manner.
[0177] Receive the original message;
[0178] If it is determined that there is an insecure network node in the SRv6 forwarding path for forwarding the original message, obtain the parameters of the security authentication instruction, where the security authentication instruction indicates that the insecure network node performs security authentication processing on the SRv6 message;
[0179] Judge whether the data volume of the parameters of the security authentication instruction is greater than the maximum data volume of the parameter field of the SID;
[0180] If it is yes, then for the insecure network node, generate an SID whose function field contains the security authentication instruction and whose parameter field contains a first parameter, and generate the SRv6 packet based on the original packet, where a second parameter is included in the extended field in the packet header of the SRv6 packet, and the security authentication instruction further indicates that the parameters of the security authentication instruction are stored in the parameter field and the extended field in the packet header; the first parameter is: part of the parameters of the security authentication instruction whose data volume is less than or equal to the maximum data volume; the second parameter is: the parameters of the security authentication instruction other than the first parameter.
[0181] If it is no, then for the insecure network node, generate an SID whose function field contains the security authentication instruction and whose parameter field contains the parameters of the security authentication instruction, and generate the SRv6 packet based on the original packet, where the security authentication instruction further indicates that the parameters of the security authentication instruction are stored in the parameter field.
[0182] As can be seen from the above, since the maximum data volume that the parameter field of the SID can accommodate is limited, therefore, among the parameters of the security authentication instruction corresponding to the above insecure network node, part of the parameters can be stored in the above parameter field, and the other part of the parameters can be stored in the extended field included in the packet header of the SRv6 packet. Therefore, even if the data volume of the security authentication instruction is greater than the maximum data volume of the parameter field, in most cases, the above security authentication instruction can be completely stored in the above SRv6 packet and sent to the above insecure network node completely, so that the above insecure network node can obtain the complete parameters of the security authentication instruction and complete the security authentication process for the SRv6 packet based on the complete parameters.
[0183] In an embodiment of the present application, the above security processing module 702 is specifically configured to:
[0184] If the function field of the target SID includes a security authentication instruction, and if the security authentication instruction indicates that the parameters of the security authentication instruction are stored in the parameter field, then obtain the target parameter from the parameters included in the parameter field of the target SID;
[0185] If the function field of the target SID includes a security authentication instruction, and if the security authentication instruction indicates that the parameters of the security authentication instruction are stored in the parameter field and the packet header extended field, then obtain the target parameter from the parameters included in the parameter field of the target SID and the parameters included in the extended field in the packet header;
[0186] Perform security authentication processing on the SRv6 packet according to the target parameter.
[0187] As can be seen from the above, since the parameters of the security authentication instruction corresponding to the above network node can be completely stored in the parameter field, or partially stored in the above parameter field and the other part stored in the extended field included in the header of the SRv6 packet. The storage location of the above parameters can be determined based on the indication of the security authentication instruction, and the target parameters can be obtained from the storage location indicated by the security authentication instruction, so that the SRv6 packet can be subjected to security authentication processing based on the completed target parameters.
[0188] In one embodiment of the present application, the security authentication instruction includes: an encapsulation addition instruction, and the encapsulation addition instruction instructs to perform encapsulation addition processing on the payload of the SRv6 packet;
[0189] The security processing module 702 is specifically configured to:
[0190] If the function field of the target SID includes a security authentication instruction, obtain target parameters according to the operation indicated by the security authentication instruction;
[0191] Perform encapsulation addition processing on the payload of the SRv6 packet according to the target parameters.
[0192] In one embodiment of the present application, the security authentication instruction includes: a decapsulation instruction, and the decapsulation instruction instructs to perform decapsulation processing on the payload of the SRv6 packet;
[0193] The security processing module 702 is specifically configured to:
[0194] If the function field of the target SID includes a security authentication instruction, obtain target parameters according to the operation indicated by the security authentication instruction;
[0195] Perform decapsulation processing on the payload of the SRv6 packet according to the target parameters.
[0196] The embodiments of the present application further provide a network node, as Figure 8 shown, including a processor 801 and a machine-readable storage medium 802. The machine-readable storage medium 802 stores machine-executable instructions that can be executed by the processor 801, and the processor 801 is prompted by the machine-executable instructions to: implement the method steps of any one of the above packet forwarding methods.
[0197] When using the network node provided in the embodiment of the present application for packet forwarding, if the function field of the target SID corresponding to the network node includes a security authentication instruction, in this case, the network node does not directly forward the SRv6 packet. Instead, according to the target parameters, after performing the security authentication process indicated by the security authentication instruction on the SRv6 packet, it then forwards the SRv6 packet that has undergone the security authentication process. Since the network node performs the security authentication process indicated by the security authentication instruction on the SRv6 packet, the security of the SRv6 packet can be improved. Therefore, when the network node applies the solution provided in the embodiment of the present application to forward the SRv6 packet after security authentication processing, the security of forwarding the SRv6 packet can be improved.
[0198] The machine-readable storage medium may include a Random Access Memory (RAM), or may also include a Non-Volatile Memory (NVM), such as at least one disk storage. Optionally, the memory may also be at least one storage device located far from the aforementioned processor.
[0199] The aforementioned processor may be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc.; it may also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field-Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.
[0200] In another embodiment provided by the present application, a computer-readable storage medium is also provided. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the steps of any of the above packet forwarding methods applied to a network node.
[0201] When forwarding a message by executing the computer program stored in the computer-readable storage medium provided by the embodiments of the present application, if the function field of the target SID corresponding to the network node includes a security authentication instruction, in this case, the network node does not directly forward the SRv6 message. Instead, according to the target parameters, after performing the security authentication process indicated by the security authentication instruction on the SRv6 message, it then forwards the SRv6 message that has undergone the security authentication process. Since the network node performs the security authentication process indicated by the security authentication instruction on the SRv6 message, the security of the SRv6 message can be improved. Therefore, when the network node applies the solution provided by the embodiments of the present application to forward the SRv6 message that has undergone the security authentication process, the security of forwarding the SRv6 message can be improved.
[0202] In another embodiment provided by the present application, there is also provided a computer program product containing instructions, which when running on a computer, causes the computer to execute any of the message forwarding methods applied to the network node in the above embodiments.
[0203] When forwarding a message by executing the computer program stored in the computer-readable storage medium provided by the embodiments of the present application, if the function field of the target SID corresponding to the network node includes a security authentication instruction, in this case, the network node does not directly forward the SRv6 message. Instead, according to the target parameters, after performing the security authentication process indicated by the security authentication instruction on the SRv6 message, it then forwards the SRv6 message that has undergone the security authentication process. Since the network node performs the security authentication process indicated by the security authentication instruction on the SRv6 message, the security of the SRv6 message can be improved. Therefore, when the network node applies the solution provided by the embodiments of the present application to forward the SRv6 message that has undergone the security authentication process, the security of forwarding the SRv6 message can be improved.
[0204] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more integrated available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid state disk (SSD)).
[0205] It should be noted that in this document, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise", or any other variant thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or device that includes a series of elements includes not only those elements but also other elements that are not explicitly listed, or also includes elements that are inherent to such process, method, article, or device. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of additional identical elements in the process, method, article, or device that includes the element.
[0206] Each embodiment in this specification is described in a related manner. The same or similar parts between the embodiments can be referred to each other, and the differences between each embodiment and other embodiments are emphasized. In particular, for devices, electronic devices, computer-readable storage media, and computer program products, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can refer to the partial description of the method embodiments.
[0207] The foregoing are only the preferred embodiments of the present application and are not intended to limit the scope of protection of the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application are all included within the scope of protection of the present application.
Claims
1. A message forwarding method, characterized in that, Applied to a network node, the method includes: Obtain an SRv6 packet; If a security authentication instruction is included in the function field of the target segment identifier (SID), obtain target parameters according to the operation indicated by the security authentication instruction, and perform security authentication processing on the SRv6 packet based on the target parameters, where the target SID is: the SID corresponding to the network node in the segment list carried in the packet header of the SRv6 packet, and the target parameters are: the parameters of the security authentication instruction recorded in the packet header; The security authentication instruction includes: an encapsulation addition instruction, and the encapsulation addition instruction indicates to perform encapsulation addition processing on the payload of the SRv6 packet; The performing security authentication processing on the SRv6 packet based on the target parameters includes: Performing encapsulation addition processing on the payload of the SRv6 packet based on the target parameters; or The security authentication instruction includes: a decapsulation instruction, and the decapsulation instruction indicates to perform decapsulation processing on the payload of the SRv6 packet; The performing security authentication processing on the SRv6 packet based on the target parameters includes: Performing decapsulation processing on the payload of the SRv6 packet based on the target parameters; Forward the processed SRv6 packet to the next-hop device.
2. The method according to claim 1, wherein The SRv6 packet is generated by the source network node of the SRv6 packet in the following manner: Receive an original packet; If it is determined that there is an insecure network node in the SRv6 forwarding path for forwarding the original packet, obtain the parameters of the security authentication instruction, where the security authentication instruction indicates that the insecure network node performs security authentication processing on the SRv6 packet; Judge whether the data volume of the parameters of the security authentication instruction is greater than the maximum data volume of the parameter field of the SID; If it is, then for the insecure network node, generate an SID whose function field includes the security authentication instruction and whose parameter field includes the first parameter, and generate the SRv6 packet based on the original packet, where the extended field in the packet header of the SRv6 packet includes the second parameter, and the security authentication instruction also indicates that the parameters of the security authentication instruction are stored in the parameter field and the extended field in the packet header, the first parameter is: a part of the parameters of the security authentication instruction whose data volume is less than or equal to the maximum data volume, and the second parameter is: the parameters of the security authentication instruction other than the first parameter; If it is not, then for the insecure network node, generate an SID whose function field includes the security authentication instruction and whose parameter field includes the parameters of the security authentication instruction, and generate the SRv6 packet based on the original packet, where the security authentication instruction also indicates that the parameters of the security authentication instruction are stored in the parameter field.
3. The method according to claim 2, wherein The obtaining target parameters according to the operation indicated by the security authentication instruction includes: If the security authentication instruction indicates that the parameters of the security authentication instruction are stored in the parameter field, obtain a target parameter from the parameters included in the parameter field of the target SID; If the security authentication instruction indicates that the parameters of the security authentication instruction are stored in the parameter field and the extended field of the message header, obtain a target parameter from the parameters included in the parameter field of the target SID and the parameters included in the extended field in the message header.
4. A message forwarding device, characterized in that, Applied to a network node, the apparatus includes: A message obtaining module, configured to obtain an SRv6 message; A security processing module, configured to, if a security authentication instruction is included in the function field of a target SID, obtain a target parameter according to the operation indicated by the security authentication instruction, and perform security authentication processing on the SRv6 message according to the target parameter, where the target SID is: the SID corresponding to the network node in the segmentation list carried in the message header of the SRv6 message, and the target parameter is: the parameter of the security authentication instruction recorded in the message header; The security authentication instruction includes: an encapsulation addition instruction, and the encapsulation addition instruction indicates to perform encapsulation addition processing on the payload of the SRv6 message; performing security authentication processing on the SRv6 message according to the target parameter includes: performing encapsulation addition processing on the payload of the SRv6 message according to the target parameter; Or The security authentication instruction includes: a decapsulation instruction, and the decapsulation instruction indicates to perform decapsulation processing on the payload of the SRv6 message; performing security authentication processing on the SRv6 message according to the target parameter includes: performing decapsulation processing on the payload of the SRv6 message according to the target parameter; A message forwarding module, configured to forward the processed SRv6 message to a next-hop device.
5. The device according to claim 4, characterized in that The SRv6 message is generated by a source network node of the SRv6 message in the following manner: Receiving an original message; If it is determined that there is an insecure network node in the SRv6 forwarding path for forwarding the original message, obtain the parameters of the security authentication instruction, where the security authentication instruction indicates that the insecure network node performs security authentication processing on the SRv6 message; Determine whether the data volume of the parameters of the security authentication instruction is greater than the maximum data volume of the parameter field of the SID; If so, generate, for the insecure network node, an SID whose function field includes the security authentication instruction and whose parameter field includes a first parameter, and generate the SRv6 message based on the original message, where a second parameter is included in the extended field in the message header of the SRv6 message, and the security authentication instruction further indicates that: the parameters of the security authentication instruction are stored in the parameter field and the extended field in the message header, the first parameter is: a partial parameter of the parameters of the security authentication instruction whose data volume is less than or equal to the maximum data volume, and the second parameter is: the parameter of the security authentication instruction other than the first parameter; If the answer is no, then for the insecure network node, generate an SID whose function field contains the security authentication instruction and whose parameter field contains the parameters of the security authentication instruction, and generate the SRv6 packet based on the original packet, where the security authentication instruction further indicates that the parameters of the security authentication instruction are stored in the parameter field.
6. The device according to claim 5, characterized in that The security processing module is specifically configured to: If the function field of the target SID includes a security authentication instruction, and if the security authentication instruction indicates that the parameters of the security authentication instruction are stored in the parameter field, then obtain the target parameters from the parameters included in the parameter field of the target SID; If the function field of the target SID includes a security authentication instruction, and if the security authentication instruction indicates that the parameters of the security authentication instruction are stored in the parameter field and the extended field of the packet header, then obtain the target parameters from the parameters included in the parameter field of the target SID and the parameters included in the extended field of the packet header; Perform security authentication processing on the SRv6 packet according to the target parameters.
7. A network node, characterized in that, Including: A processor and a machine-readable storage medium, the machine-readable storage medium stores machine-executable instructions that can be executed by the processor, and the processor is prompted by the machine-executable instructions to implement the method steps of any one of claims 1-3.
8. A machine-readable storage medium, characterized in that, Stores machine-executable instructions, and when called and executed by a processor, the machine-executable instructions prompt the processor to implement the method steps of any one of claims 1-3.
Citation Information
Patent Citations
Segment routing using security segment identifiers
CN112189323A