A message processing method and device

By carrying application information and performing integrity verification in non-IP packets, the problem of not being able to provide quality of service in non-IP networks is solved, and effective resource protection for applications is achieved.

CN113810290BActive Publication Date: 2026-01-27HUAWEI TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202010669854.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-06-12
Filing Date
2020-07-13
Publication Date
2026-01-27
Estimated Expiration
2040-07-13

AI Technical Summary

Technical Problem

Existing technologies cannot provide the corresponding quality of service for applications in non-IP networks, resulting in the inability to effectively guarantee the business needs of applications.

Method used

Application information is carried in non-IP packets and its integrity is verified by network devices to ensure its legitimacy. Based on the application information, network resources are determined for forwarding to achieve the corresponding quality of service.

Benefits of technology

It ensures the quality of service for applications in non-IP networks, preventing the misuse of network resources due to application information theft.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113810290B_ABST
    Figure CN113810290B_ABST
Patent Text Reader

Abstract

Embodiments of the present application disclose a message processing method, which can be executed by a first communication device. In an example, the first communication device can obtain a first message, the first message comprising application information, wherein the first message can be a service message of a first application, the application information comprising related information of the first application, and the first message is not an IP message. After obtaining the first message, the first communication device can send the first message to a second communication device. In the embodiments of the present application, for the first message which is not an IP message, since the first message carries the application information of the first application, a network device obtaining the first message can determine corresponding network resources based on the application information, and forward the first message by using the determined network resources, so as to provide corresponding quality of service for the service corresponding to the first message. Therefore, by using the present application, the non-IP network can provide corresponding quality of service for the application.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application claims priority to Chinese Patent Application No. 202010538369.3, filed on June 12, 2020, entitled "A method, apparatus and system for security verification of application information carried in a message", the entire contents of which are incorporated herein by reference. Technical Field

[0002] This application relates to the field of communications, and more particularly to a message processing method and apparatus. Background Technology

[0003] With the development of computer software and communication technologies, more and more applications (APPs) have emerged. Applications can also be called application programs or application software.

[0004] How to provide the corresponding quality of service (QoS) for applications is a problem that remains to be solved. Summary of the Invention

[0005] This application provides a message processing method that can provide corresponding quality of service for applications.

[0006] Firstly, embodiments of this application provide a message processing method, which can be executed by a first communication device. In one example, the first communication device can acquire a first message, which includes application information. The first message may be a service message of a first application, and the application information includes relevant information about the first application. The first message is not an Internet Protocol (IP) message. After acquiring the first message, the first communication device can send it to a second communication device. In this embodiment, for a first message that is not an IP message, since the first message carries application information of the first application, the network device that acquires the first message can determine the corresponding network resources based on the application information and forward the first message using the determined network resources to provide the corresponding quality of service for the service corresponding to the first message. Therefore, this solution enables non-IP networks to provide corresponding quality of service for applications.

[0007] In one implementation, the first communication device acquires the first message, for example, by acquiring a first data message, then encapsulating the first data message and adding application information to obtain a first message including the application information. In another implementation, the first communication device can directly receive the first message from a third communication device.

[0008] In one implementation, the application information is carried in the header of the first message.

[0009] In one implementation, the first message is a Multiprotocol Label Switching (MPLS) message.

[0010] In one implementation, the application information is carried in a tag value field.

[0011] In one implementation, the application information is carried in an extended type length value (TLV) field.

[0012] In one implementation, the first message is a Generic Router Encapsulated (GRE) message.

[0013] In one implementation, the application information is carried in a keyword field.

[0014] In one implementation, the first message is a Virtual Extended Local Area Network (VXLAN) message.

[0015] In one implementation, the application information is carried in a network identifier field.

[0016] In one implementation, the application information is carried in a reserved field.

[0017] In one implementation, the first message is a Network Virtualization General Router Encapsulated NVGRE message.

[0018] In one implementation, the application information is carried in a stream identifier field.

[0019] In one implementation, the application information is carried in a virtual network identifier field.

[0020] In one implementation, the application information is carried in a reserved field.

[0021] In one implementation, the first message is a Geneve message encapsulated by general network virtualization.

[0022] In one implementation, the application information is carried in a reserved field.

[0023] In one implementation, the application information is carried in a variable-length option field.

[0024] In one implementation, the application information includes any one or more of the following: Service Level Agreement (SLA) level, application identifier, user identifier, flow identifier, and reserved parameters.

[0025] In one implementation, the first communication device is a network device.

[0026] In one implementation, the first communication device includes: an access ACC device, or a customer premises premises CPE device, or a home gateway RG, or a data center server access leaf device, or a data center egress gateway DCGW, or an autonomous system border router ASBR, or a base station, or a user plane function UPF device, or a broadband network gateway BNG, or an operator edge PE device.

[0027] In one implementation, the first communication device includes a server or user equipment. Specifically, the server or user equipment can obtain a first message including application information and forward the first message to a second communication device. This allows the network device forwarding the first message to determine the corresponding network resources based on the application information and utilize those resources to forward the first message, thereby providing the corresponding quality of service for the service corresponding to the first message.

[0028] In one implementation, the second communication device includes a network device.

[0029] In one implementation, the second communication device includes: a server or a user equipment.

[0030] In one implementation, when the first communication device is a network device, it can determine the network resources for forwarding the first packet based on the application information. Accordingly, it uses these network resources to send the first packet to the second communication device, thereby providing the corresponding quality of service for the service corresponding to the first packet.

[0031] In one implementation, the first message may include first verification information in addition to application information. The first verification information is used to verify the integrity of the application information. When the first communication device is a network device, the first communication device can also use the first verification information to verify the integrity of the application information, thereby preventing the application information from being stolen, which could lead to the theft of network resources corresponding to the application information.

[0032] In one implementation, the first communication device verifies the integrity of the application information based on the first verification information. Specifically, the first communication device can obtain second verification information based on a target field in the first message, wherein the target field includes the application information. After obtaining the second verification information, the first communication device performs a matching verification between the second verification information and the first verification information. This matching verification can, for example, compare the first verification information and the second verification information; if they are the same, the matching verification passes; if they are different, the matching verification fails. Using this method, the integrity of the application information can be verified.

[0033] In one implementation, the first communication device verifies the integrity of the application information based on the first verification information. In a specific implementation, the first communication device may, for example, verify the integrity of the application information based on a first verification method and the first verification information.

[0034] In one implementation, the first verification method is a key-related hash message authentication code (HMAC) verification.

[0035] In one implementation, when the first verification method is HMAC verification, the first verification information included in the first message can be first HMAC verification information. This first HMAC verification information can be obtained by performing HMAC calculation on the target field in the first message. In this case, the first communication device verifies the integrity of the application information based on the first verification method and the first verification information. Specifically, the first communication device can perform HMAC calculation on the target field in the first message to obtain second HMAC verification information; then, it can perform matching verification between the first HMAC verification information and the second HMAC verification information to achieve integrity verification of the application information.

[0036] In one implementation, the first verification method is digital signature verification.

[0037] In one implementation, when the first verification method is digital signature authentication, the first verification information is a digital signature obtained by signing the target field in the first message using a first private key and a first hash calculation. In this case, the first communication device verifies the integrity of the application information based on the first verification method and the first verification information. Specifically, the first communication device can decrypt the digital signature using a first public key to obtain a first plaintext; and perform a second hash calculation on the target field to obtain a second plaintext, wherein the first hash calculation and the second hash calculation use the same hash algorithm; then, the first communication device performs a matching verification between the first plaintext and the second plaintext.

[0038] In one implementation, the first message further includes a digital certificate, which includes the first public key. In this embodiment, the digital certificate may be the digital certificate of the device sending the first message, and this digital certificate can be considered as proof of identity of the device sending the first message. When the first public key is carried in the digital certificate, the legitimacy of the first public key can be guaranteed.

[0039] In one implementation, the digital certificate further includes a decryption algorithm for decrypting the digital signature, and / or the hash algorithm. When the decryption algorithm is included in the digital signature, the legitimacy of the decryption algorithm is guaranteed; when the hash algorithm is included in the digital signature, the legitimacy of the hash algorithm is guaranteed.

[0040] In one implementation, the method further includes verifying the legitimacy of the digital certificate. It is understood that verifying the legitimacy of the digital certificate can verify the legitimacy of the sending device of the first message. Correspondingly, if the digital certificate also carries other information, such as the aforementioned first public key, or a decryption algorithm for decrypting the digital signature, and / or the hash algorithm, the legitimacy of other information carried in the digital certificate can also be verified.

[0041] In one implementation, the first message includes a digital certificate, and the application information and the first verification information are carried in the digital certificate.

[0042] In one implementation, when application information and first verification information are carried in a digital certificate, the first communication device verifies the integrity of the application information based on the first verification information. In a specific implementation, the first communication device may verify the legality of the digital certificate.

[0043] In one implementation, the first verification method is an integrity verification based on Internet Protocol Security (IPSEC). The IPSEC-based integrity verification includes AH verification and ESP verification.

[0044] In one implementation, when the first verification method is AH verification, the first verification information is the first AH verification information, which can be calculated using an AH verification algorithm on the target field in the first message. In this case, the first communication device verifies the integrity of the application information based on the first verification method and the first verification information. Specifically, the first communication device can use the AH verification algorithm to calculate the target field in the first message to obtain the second AH verification information; and then perform matching verification between the first AH verification information and the second AH verification information.

[0045] In one implementation, when the first verification method is ESP verification, the first verification information is first ESP verification information, which can be calculated using the ESP verification algorithm on the target field in the first message. In this case, the first communication device verifies the integrity of the application information based on the first verification method and the first verification information. Specifically, the first communication device can use the ESP verification algorithm to calculate the target field in the first message to obtain second ESP verification information; and then perform matching verification between the first ESP verification information and the second ESP verification information.

[0046] In one implementation, after the first communication device verifies the integrity of the application information, if the application information passes the verification, it indicates that the application information in the first message is legitimate, and therefore the first communication device can forward the first message.

[0047] In one implementation, after the first communication device verifies the integrity of the application information, if the application information fails verification, it indicates that the application information in the first message is invalid, and therefore the first communication device can discard the first message. This prevents the network resources corresponding to the application information from being misused.

[0048] In one implementation, the first message may include second verification information in addition to the first verification information. The second verification information is used to verify the integrity of the application information. When the first communication device is a network device, in addition to using the first verification information to verify the integrity of the application information, the first communication device may also use the second verification information to verify the integrity of the application information, thereby achieving multiple verifications of the application information and preventing the application information from being stolen, which could lead to the theft of network resources corresponding to the application information.

[0049] In a second aspect, embodiments of this application provide a first communication device, including: a communication interface; and a processor connected to the communication interface; the first communication device is used to execute the method described in the first aspect and any one of the first aspects, according to the communication interface and the processor.

[0050] Thirdly, embodiments of this application provide a first communication device, the first communication device including a memory and a processor; the memory is used to store program code; the processor is used to execute instructions in the program code, causing the first communication device to perform the method described in the first aspect and any one of the first aspects.

[0051] Fourthly, embodiments of this application provide a computer-readable storage medium storing instructions that, when executed on a computer, cause the computer to perform the methods described in the first aspect and any one of the first aspects. Attached Figure Description

[0052] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0053] Figure 1 This is a schematic diagram illustrating an exemplary application scenario provided in an embodiment of this application;

[0054] Figure 2 This is yet another exemplary network scenario diagram provided in the embodiments of this application;

[0055] Figure 3 A signaling interaction diagram of a message processing method provided in an embodiment of this application;

[0056] Figure 4 A flowchart illustrating a message processing method provided in an embodiment of this application;

[0057] Figure 5 This is a schematic diagram of the structure of a communication device provided in an embodiment of this application;

[0058] Figure 6 This is a schematic diagram of the structure of a communication device provided in an embodiment of this application;

[0059] Figure 7 This is a schematic diagram of the structure of a communication device provided in an embodiment of this application. Detailed Implementation

[0060] This application provides a message processing method that can provide corresponding quality of service for applications.

[0061] The applications described in this application are software that provides the functions required to provide services, including computer programs that perform one or more specific tasks, and typically require interaction with the user. Each application may belong to multiple services and may run on one or more servers or on the user's device. In the embodiments of this application, the application may be, for example, an app related to games, videos, email, instant messaging, traffic information, weather forecasts, etc. Applications are typically installed on terminal devices.

[0062] To facilitate understanding, the possible application scenarios of the embodiments of this application will be introduced first.

[0063] exist Figure 1 In the application scenario shown, user device 101 with the application installed can send service message A to the server 102 of the application via network 100. Of course, server 102 can also send service message B to user device 101 via network 100.

[0064] Figure 1 The application scenarios shown can be used in network scenarios such as government and enterprise dedicated lines, home broadband, and mobile networks. User equipment 101 can be an Internet of Things (IoT) device or a terminal device. The terminal devices mentioned here can be mobile phones, personal computers (PCs), such as tablet PCs, laptops, super mobile PCs, personal digital assistants, etc.

[0065] like Figure 1 The application scenario shown is applied to government and enterprise leased lines. In this case, network 100 may include, for example, customer premises equipment (CPE), access network (ACC) equipment, data center gateway (DC GW), data center server access equipment leaf, autonomous system boundary router (ASBR), and other equipment.

[0066] like Figure 1 The application scenario shown applies to home bandwidth, and network 100 may include, for example, a residential gateway (RG), an access network ACC device, a DC GW, a data center server access device leaf, and an ASBR, etc.

[0067] like Figure 1 The application scenario shown is applied to a mobile network. In this case, network 100 may include mobile network base stations, user plane function (UPF) equipment of the core network, ACC equipment of the access network, DC GW, or data center server access equipment such as leaf and ASBR.

[0068] In some embodiments, network 100 may include an access network, an aggregation network, and a data center network. See also Figure 2 This figure is another exemplary network scenario diagram provided in the embodiments of this application. Figure 2 The network scenarios shown can be applied to home broadband or enterprise dedicated lines. The network scenarios corresponding to mobile networks will not be described in detail here.

[0069] exist Figure 2 In the scenario shown, user device 101 with the APP installed can generate service message A for the APP, which is then transmitted sequentially through device 105, access device ACC 106 of the access network, aggregation (AGG) device 107 of the aggregation network, ASBR 108, DC GW 109, data center server access device spine 110, and data center server access device leaf 111 to the application server 102. Similarly, server 102 can generate service message B for the APP, which is then transmitted through data center server access device leaf 111, data center server access device spine 110, DC GW 109, ASBR 108, AGG 107, ACC 106, and device 105 to user device 101. For home bandwidth scenarios, device 105 can be an RG (Regulator), while for enterprise private line network scenarios, device 105 can be a CPE (Customer Premises Equipment).

[0070] In order to enable network 100 to provide the quality of service corresponding to the APP when forwarding service message A or service message B, this application embodiment provides a message processing method, which will be described below with reference to the accompanying drawings.

[0071] See Figure 3 This figure is a signaling interaction diagram of a message processing method provided in an embodiment of this application.

[0072] Figure 3 The message processing method 100 shown can be executed by communication device 1 and communication device 2. Communication device 1 can be applied to... Figure 1 The user equipment 101 and communication device 1 shown can also be applied to Figure 1The server 102 and communication device 1 shown can also be applied to Figure 1 The network devices in network 100 shown. Communication device 2 can be applied to downstream nodes of communication device 1. For example, when communication device 1 is applied to user equipment 101, communication device 2 can be applied to devices in network 100, or communication device 2 can be applied to server 102; when communication device 1 is applied to server 102, communication device 2 can be applied to devices in network 100, or communication device 2 can be applied to user equipment 101; when communication device 1 is applied to devices in network 100, communication device 2 can be applied to devices in network 100, user equipment 101, and server 102.

[0073] It should be noted that, unless otherwise specified, in the following descriptions of the embodiments of this application, descriptions such as hash algorithm n, public key n, and private key n, using the format "object + sequence number," are used to distinguish similar objects, not to limit a specific order or sequence. Furthermore, for the same object, its content is not directly related to the sequence number; objects with different sequence numbers may have the same or different content, and this application does not impose specific limitations. For example, hash algorithm 1 and hash algorithm 2 may be the same algorithm or different algorithms. It should also be noted that the communication device mentioned in the embodiments of this application may be a network device such as a switch or router, or a component of a network device, such as a single board, line card, or a functional module on the network device. The communication device may also be a user device or a server, or a component of a user device or server. This application does not impose specific limitations.

[0074] In the following description of the embodiments of this application, when a communication device is applied to a device, the communication device may be a component of the device or the device itself. For example, when a communication device 1 is applied to a user equipment 101, the communication device 1 may be the user equipment 101 or may be a component of the user equipment 101.

[0075] Figure 3 The method 100 shown can be implemented by the following steps S101-S102.

[0076] S101: Communication device 1 receives message 1, which includes application information 1.

[0077] In this application, application information 1 refers to the application information corresponding to the APP. In one implementation, the application information may include one or more of the following: service-level agreement (SLA) level, application identifier, user identifier, flow ID, and reserved parameters. The application identifier identifies the application; the user identifier identifies the user using the application; for example, the user identifier may be the identifier of the account logged into the application; and the flow ID identifies the business message corresponding to the application.

[0078] In some embodiments, when the communication device 1 is applied to the user equipment 101 or the server 102, in the specific implementation of S101, the communication device 1 can, for example, acquire data packet 1, which is the data packet corresponding to the aforementioned APP. In addition to acquiring data packet 1, the communication device 1 can also acquire application information 1, and encapsulate data packet 1 using application information 1, adding application information 1 to data packet 1, thereby obtaining packet 1 including application information 1.

[0079] In some embodiments, when communication device 1 is applied to a device in network 100, in specific implementations of S101, communication device 1 may, for example, receive a message 1 including application information 1 from communication device 3. In one example, when communication device 1 is applied to an edge node in network 100, communication device 3 may be user equipment 101 or server 102. In another example, when communication device 1 is applied to an intermediate node in network 100, such as node 1, communication device 3 may be an upstream node of node 1, wherein the upstream node of node 1 is also a node in network 100. The node mentioned here may be a network device such as a router or switch.

[0080] Currently, apart from IP networks, other networks cannot provide the corresponding quality of service (QoS) for applications. To ensure that application service packets can still provide the corresponding QoS when transmitted over non-IP networks, this embodiment of the application can carry application information within the non-IP packets. This allows network devices in the non-IP network to provide the corresponding QoS based on the application information. In other words, in one implementation of this embodiment, packet 1 can be a packet other than an IP packet.

[0081] In one implementation, message 1 can be a Multi-Protocol Label Switching (MPLS) message.

[0082] When message 1 is an MPLS message, application information 1 can be carried in the message header, for example. As an example, application information 1 can be carried in the tag stack within the message header, such as in the tag value field. For instance, application information 1 can be carried in each tag value field, and the node receiving the MPLS message can obtain application information 1 from its associated tag value field. As yet another example, application information 1 can be carried in the extended type length value (TLV) field of the MPLS message.

[0083] For details on the structure of MPLS messages and the meaning of each field, please refer to the relevant descriptions in draft-song-mpls-extension-header-02 and request for comments (RFC) 3031. These details will not be elaborated here.

[0084] In one implementation, message 1 can be a generic routing encapsulation (GRE) message.

[0085] When message 1 is a GRE message, application information 1 can be included in the message header of that GRE message. As an example, application information 1 can be included in the key field of the message header.

[0086] For details on the structure of the GRE message and the meaning of each field, please refer to the relevant description in RFC 2890. It will not be elaborated here.

[0087] In one implementation, message 1 can be a Virtual Extensible Local Area Network (VXLAN) message.

[0088] When message 1 is a VXLAN message, application information 1 can be carried in the VXLAN message header. As an example, application information 1 can be carried in a reserved field in the header. As yet another example, application information 1 can be carried in the Virtual Network Identifier (VNI) field in the header. When application information 1 is carried in the VNI field, the VNI field can be divided into multiple parts, one part for carrying the VNI and another part for carrying application information 1.

[0089] For details on the structure of VXLAN messages and the meaning of each field, please refer to the relevant description in RFC 7348. These details will not be elaborated here.

[0090] In one implementation, message 1 can be a network virtual generic routing encapsulation (NVGRE) message.

[0091] When message 1 is an NVGRE message, application information 1 can be carried in the NVGRE message header. As an example, application information 1 can be carried in a reserved field in the header. As another example, application information 1 can be carried in the VNI field in the header. When application information 1 is carried in the VNI field, the VNI field can be divided into multiple parts, one part for carrying the VNI and another part for carrying application information 1. As yet another example, application information 1 can be carried in the flow ID field in the header. When application information 1 is carried in the flow ID field, the flow ID field can be divided into multiple parts, one part for carrying the flow ID and another part for carrying application information 1.

[0092] For details on the structure of NVGRE messages and the meaning of each field, please refer to the relevant description in RFC 7637. These details will not be elaborated here.

[0093] In one implementation, message 1 can be a generic network virtualization encapsulation (Geneve) message.

[0094] When message 1 is a Geneve message, application information 1 can be carried in the header of the Geneve message. As an example, application information 1 can be carried in a reserved field in the header. As yet another example, application information 1 can be carried in a variable length options field in the header.

[0095] For details on the structure of the Geneve message and the meaning of each field, please refer to the relevant description in draft-ietf-nvo3-geneve-16. It will not be elaborated here.

[0096] S102: Communication device 1 sends message 1 to communication device 2.

[0097] After receiving message 1, communication device 1 can send message 1 to communication device 2.

[0098] In one implementation, if communication device 1 is applied to network devices in network 100, then before executing S102, communication device 1 can determine the network resources for forwarding message 1 based on application information 1. Accordingly, when executing S102, message 1 can be sent to communication device 102 using the network resources for forwarding message 1. For example, communication device 1 determines high-bandwidth, low-latency network resources based on application information 1, and forwards message 1 using a forwarding path with high bandwidth and low latency.

[0099] In one implementation, if the communication device 1 is applied to user equipment 101 or server 102, since message 1 includes application information 1, when message 1 is forwarded in network 100, all devices forwarding the message 100 can obtain the application information 1. Accordingly, they can determine the corresponding network resources based on the application information 1 and use the determined network resources to forward message 1, so as to provide the corresponding quality of service for message 1.

[0100] Regarding the specific implementation method of the network device determining the network resources for forwarding message 1 based on application information 1, this application embodiment does not impose specific limitations. In one example, the network device may pre-store the correspondence between application information and network resources. In this way, when the network device obtains application information 1, it can determine the network resources corresponding to application information 1 based on the correspondence. This correspondence may be statically configured on the network device or may be issued to the network device by the control and management device; this application embodiment does not impose specific limitations.

[0101] As can be seen from the above description of method 100, in this embodiment of the application, since message 1 includes application information 1, the network device that obtains message 1 can determine the corresponding network resources based on the application information 1, and use the determined network resources to forward message 1, so as to provide the corresponding quality of service for the application corresponding to message 1.

[0102] Since network devices can provide the corresponding quality of service for the service corresponding to message 1 based on application information 1, if application information 1 is used improperly, such as being stolen, it may lead to improper use of network resources.

[0103] To prevent improper use of network resources, in one implementation of this application embodiment, message 1 may include verification information 1 in addition to application information 1. Verification information 1 is used to check the integrity of application information 1. Integrity verification of application information 1 includes verifying whether the application information 1 is lost, has encountered errors, has been tampered with, or has been forged.

[0104] In this embodiment, when communication device 1 is a network device, the first message may be sent from communication device 3 to communication device 1. After receiving message 1, communication device 1 can use the verification information 1 in message 1 to perform integrity verification on application information 1. In one example, communication device 3 is the communication device that generates message 1; in another example, communication device 3 is not the communication device that generates message 1, but rather a communication device between the communication device that generates message 1 and communication device 1. In the following embodiments, communication device 3 is used as an example of the communication device that generates message 1 for explanation.

[0105] In some embodiments, the communication device 1 uses the verification information 1 in message 1 to perform integrity verification on the application information 1. Specifically, the communication device 1 can, for example, calculate the fields in message 1 to obtain verification information 2, and then perform a matching verification between verification information 1 and verification information 2. In one example, the matching verification between verification information 1 and verification information 2 involves comparing them. If verification information 1 and verification information 2 are the same, the matching verification is successful; if they are different, the matching verification fails. In one implementation of this application embodiment, the communication device 1 calculates the fields in message 1, for example, using verification algorithm 1. The fields in message 1 include application information 1.

[0106] In one example, verification algorithm 1 could be key-based hash-based message authentication code (HMAC) verification.

[0107] When verification algorithm 1 is HMAC verification, verification information 1 can be obtained in the following way:

[0108] In one implementation, the communication device 3 can append key 1 to field 1 as input to hash algorithm 1 to obtain verification information 1. Appending key 1 to field 1 can be done by appending key 1 to the end of field 1, adding key 1 to the beginning of field 1, inserting key 1 in the middle of field 1, etc. In one example, field 1 may only include application information 1. In yet another example, field 1 may include application information 1 as well as other fields from message 1.

[0109] In another implementation, communication device 1 obtains parameters 1 and 2, which have the same number of bits, for example, both parameters 1 and 2 are 64 bits. Communication device 1 adds a value to the beginning or end of key 2, for example, by adding 0, so that the number of bits in key 2 after adding the value is the same as that in parameter 1. Communication device 1 performs calculations on key 2 and parameter 1 after adding the value, for example, by performing an XOR operation, to obtain key 2'. Then, communication device 1 appends key 2' to field 1 as input to hash algorithm 2, to obtain HMAC 1. Communication device 1 performs calculations on key 2 and parameter 2 after adding the value, for example, by performing an XOR operation, to obtain key 2''. Then, communication device 1 appends key 2'' to HMAC 1 as input to hash algorithm 2, to obtain HMAC 2, which is the verification information 1. For descriptions of "appending key 2' to field 1" and "appending key 2'' to HMAC 1", please refer to the description of "appending key 1 to field 1" above, which will not be elaborated here.

[0110] In one implementation of this application, when the aforementioned field 1 only includes application information 1, the verification information 1 can also be calculated by the control and management device based on the application information 1. For example, the communication device 3 sends the application information 1 to the control and management device, which uses the HMAC algorithm to calculate the application information 1 to obtain the verification information 1, and then sends the verification information 1 to the communication device 3. In this way, the communication device 3 obtains the verification information 1.

[0111] The control and management device in this application embodiment can be, for example, a device running network management software, or a controller; this application embodiment does not make any specific limitation.

[0112] When verification algorithm 1 is HMAC verification, communication device 1 uses verification information 1 to perform integrity verification on application information 1. Specifically, communication device 1 can append key 1 to field 1 as input to hash algorithm 1, thus obtaining verification information 2. Then, verification information 1 and verification information 2 are matched and verified. Here, key 1 can be pre-negotiated between communication device 1 and communication device 3. Hash algorithm 1 can also be pre-negotiated between communication device 1 and communication device 3.

[0113] Since key 1 and hash algorithm 1 can be pre-negotiated between communication device 1 and communication device 3, or in other words, pre-negotiated between APP 1 on communication device 3 and communication device 1, other APPs on communication device 3 cannot obtain key 1 and hash algorithm 1, nor can APPs installed on other devices. Therefore, even if other APPs on communication device 3 or APPs on other devices steal application information 1, they cannot generate verification information 1 because they cannot obtain key 1 and hash algorithm 1. Consequently, the message a generated by the APP that steals application information 1 does not include verification information 1. Therefore, when communication device 1 receives message a, the integrity verification of application information 1 fails, thus preventing the theft of network resources due to the theft of application information 1.

[0114] When verification algorithm 1 is HMAC verification, communication device 1 uses verification information 1 to perform integrity verification on application information 1. Specifically, communication device 1 obtains parameters 1 and 2. Communication device 1 uses a numerical supplementation method agreed upon with communication device 3 to supplement values ​​at the beginning or end of key 2, for example, by adding 0s, so that the number of bits in key 2 after supplementation is the same as parameter 1. Communication device 1 uses a calculation method agreed upon with communication device 3 to calculate the supplemented key 2 and parameter 1, for example, by performing an XOR operation, to obtain key 2'. Then, communication device 1 appends key 2' to field 1 as input to hash algorithm 2, obtaining HMAC 1'. Communication device 1 uses a calculation method agreed upon with communication device 3 to calculate the supplemented key 2 and parameter 2, for example, by performing an XOR operation, to obtain key 2''. Then, communication device 1 appends key 2'' to HMAC 1' as input to hash algorithm 2, obtaining HMAC 2', which is the verification information 2. After calculating verification information 2, communication device 1 can perform matching and verification between verification information 1 and verification information 2. Parameter 1, parameter 2, key 2, and hash algorithm 2 can all be pre-negotiated between communication device 1 and communication device 3.

[0115] In this embodiment, since parameters 1, 2, key 2, and hash algorithm 2 can be pre-negotiated between communication device 1 and communication device 3, or in other words, pre-negotiated between APP 1 on communication device 3 and communication device 1, other APPs on communication device 3 cannot obtain parameters 1, 2, key 2, and hash algorithm 2, nor can APPs installed on other devices. Therefore, even if other APPs on communication device 3 or APPs on other devices steal application information 1, they cannot generate verification information 1 because they cannot obtain parameters 1, 2, key 2, and hash algorithm 2. Accordingly, the message b generated by the APP that steals application information 1 does not include verification information 1. Therefore, when communication device 1 receives message b, the integrity verification of application information 1 fails, thereby preventing the theft of network resources due to the theft of application information 1.

[0116] In one example, verification algorithm 1 could be digital signature verification.

[0117] When verification algorithm 1 is a digital signature verification, verification information 1 can be obtained in the following way:

[0118] Communication device 3 can perform a hash operation on field 2 in message 1 using hash algorithm 3 to obtain hash digest 1. Then, communication device 3 uses private key 1 and encryption algorithm 1 to encrypt hash digest 1 to obtain digital signature 1, thereby obtaining verification information 1. The verification information 1 mentioned here is digital signature 1. In one example, field 2 may only include application information 1. In another example, field 2 may include application information 1, as well as other fields from message 1.

[0119] In one implementation of this application, when the aforementioned field 2 only includes application information 1, the verification information 1 can also be calculated by the control and management device based on the application information 1. For example, the communication device 3 sends the application information 1 to the control and management device, which uses a digital signature algorithm to calculate the application information 1 to obtain the verification information 1, and then sends the verification information 1 to the communication device 3. In this way, the communication device 3 obtains the verification information 1.

[0120] In one implementation of this application, when the verification algorithm 1 is a digital signature verification, the message 1 may include, in addition to application information 1 and verification information 1, a digital certificate 1 of the communication device 3. This digital certificate 1 includes a public key 1, which, along with the aforementioned private key 1, forms an asymmetric key pair. In other words, the public key 1 can be used to decrypt the digital signature 1. In some embodiments, the digital certificate 1, in addition to the public key 1, also includes a hash algorithm 3 and a decryption algorithm 1. The decryption algorithm 1 mentioned here corresponds to the aforementioned encryption algorithm 1 and is used to decrypt the digital signature 1.

[0121] In this embodiment, the digital certificate 1 of the communication device 3 may be sent to the communication device 3 by a certificate authority (CA) device. The CA device mentioned here may be, for example, a control and management device, or a CA server. The process by which the communication device 3 obtains the digital certificate 1 is briefly described below. First, the communication device 3 sends its own identity information and other information to the CA device, where the communication device 3's own identity information and other information constitute an untrusted digital certificate. The CA device uses hash algorithm 4 to perform a hash calculation on the untrusted digital certificate to obtain a hash digest 2. Then, the CA device uses its own private key 2 to encrypt the hash digest 2 to obtain an encrypted digest 1. Afterwards, the CA institution sends its own identity information, encrypted digest 1, and the untrusted digital certificate to the communication device 3, whereby the CA institution's identity information, encrypted digest 1, and the untrusted digital certificate constitute the trusted digital certificate 1 of the communication device 3.

[0122] It should be noted that the other information sent by the aforementioned communication device 3 to the CA device may include one or more of the aforementioned public key 1, decryption algorithm 1, and hash algorithm 3. The identity information of the aforementioned communication device 3 may include, for example, the device identifier of the communication device 3, or it may include the aforementioned application information 1; this embodiment does not specifically limit this. In this embodiment, when the identity information of the communication device 3 includes application information 1, the application information 1 in message 1 may, for example, be carried in the digital certificate 1.

[0123] When verification algorithm 1 is a digital signature verification, communication device 1 uses verification information 1 to perform integrity verification on application information 1. Specifically, communication device 1 can, for example, use hash algorithm 3 to perform a hash operation on field 2 in message 1 to obtain hash digest 1'. Communication device 1 then uses public key 1 and decryption algorithm 1 to decrypt digital signature 1, obtaining hash digest 1''. Finally, communication device 1 performs a matching verification between hash digest 1' and hash digest 1''.

[0124] In some embodiments, the aforementioned public key 1 may be pre-negotiated between communication device 1 and communication device 3, and the aforementioned decryption algorithm 1 and hash algorithm 3 may also be pre-negotiated between communication device 1 and communication device 3. In yet other embodiments, the aforementioned public key 1 may be carried in message 1, for example, as mentioned above, message 1 includes digital certificate 1, and digital certificate 1 carries public key 1. Additionally, the aforementioned decryption algorithm 1 and hash algorithm 3 may be carried in message 1, for example, within digital certificate 1.

[0125] In this embodiment, since the public key 1, decryption algorithm 1, and hash algorithm 3 can be pre-negotiated between communication device 1 and communication device 3, or in other words, pre-negotiated between APP 1 on communication device 3 and communication device 1, other APPs on communication device 3 cannot obtain the public key 1, decryption algorithm 1, and hash algorithm 3, nor can APPs installed on other devices. Therefore, even if other APPs on communication device 3 or APPs on other devices steal application information 1, they cannot generate verification information 1 because they cannot obtain the public key 1, decryption algorithm 1, and hash algorithm 3. Accordingly, the message c generated by the APP that steals application information 1 does not include verification information 1. Therefore, when communication device 1 receives message c, the integrity verification of application information 1 fails, thereby preventing the theft of network resources due to the theft of application information 1.

[0126] In one implementation of this application, message 1 includes a digital certificate 1 of communication device 1, allowing communication device 1 to verify the legitimacy of the digital certificate. Once digital certificate 1 is verified, it indicates that message 1 originates from a trusted sender. Furthermore, if public key 1 is carried in digital certificate 1, and digital certificate 1 is verified, the legitimacy of public key 1 is also guaranteed. Similarly, if decryption algorithm 1 and hash algorithm 3 are carried in digital certificate 1, and digital certificate 1 is verified, the legitimacy of decryption algorithm 1 and hash algorithm 3 is also guaranteed.

[0127] Furthermore, as mentioned earlier, digital certificate 1 includes the identity information of communication device 1. When the identity information of communication device 1 includes application information 1, the application information 1 in message 1 can be carried in digital certificate 1. In this case, if digital certificate 1 is verified, the legitimacy of application information 1 in digital certificate 1 is also guaranteed, thereby achieving multiple verifications of application information 1.

[0128] In another implementation of this application, if message 1 includes digital certificate 1, and digital certificate 1 includes application information 1 and verification information 1, the communication device 1 uses verification information 1 to perform integrity verification on application information 1. In specific implementation, the legality verification of digital certificate 1 can be performed directly. As long as digital certificate 1 is legal, it means that verification information 1 and application information 1 are legal. Regarding the legality verification of digital certificate, for example, hash algorithm 4 can be used to perform hash calculation on the untrusted digital certificate mentioned above to obtain hash digest 2', and the public key 2 of the CA institution can be used to decrypt the encrypted digest 1 in the digital certificate to obtain hash digest 2''. Then, hash digest 2' and hash digest 2'' are matched and verified. If they are the same, digital certificate 1 is determined to be legal; otherwise, digital certificate 1 is determined to be illegal. Of course, when verifying digital certificate 1, the identity of the CA certification authority can also be further authenticated. Regarding the specific implementation method of authenticating the identity of the CA certification authority, traditional authentication methods can be referred to, which will not be detailed here.

[0129] In one example, verification algorithm 1 could be an IPSec-based integrity verification. This IPSec-based integrity verification could include integrity verification based on the authentication header (AH) and integrity verification based on the encapsulating security payload (ESP).

[0130] When verification algorithm 1 is based on AH integrity verification, verification information 1 can be obtained in the following way:

[0131] When verification algorithm 1 is based on AH integrity verification and message 1 is encapsulated in transport mode, in one implementation, communication device 3 can use AH verification algorithm 1 to calculate field 3 in message 1 to obtain AH verification information 1, i.e., obtain verification information 1. Field 3 includes IP header, IP extension header, AH, Transmission Control Protocol (TCP) header, and data. Application information 1 can be carried in the IP extension header, which can be, for example, the IPv6 extension header. The AH verification algorithm 1 mentioned here can be, for example, the HMAC message-digest algorithm (MD5) or the HMAC secure hash algorithm (SHA1).

[0132] When verification algorithm 1 is based on AH integrity verification and message 1 is encapsulated in tunnel mode, in one implementation, communication device 3 can use AH verification algorithm 2 to calculate field 4 in message 1 to obtain AH verification information 2, i.e., obtain verification information 1. Field 4 includes the new IP header, AH, IP header, IP extension header, TCP header, and data. Application information 1 can be carried in the IP extension header; the IP extension header mentioned here could be, for example, the IPv6 extension header. The AH verification algorithm 2 mentioned here could be, for example, HMAC MD5 or HMAC SHA1.

[0133] When verification algorithm 1 is based on ESP integrity verification, message 1 can adopt tunnel encapsulation mode. In one implementation, communication device 3 can use ESP verification algorithm 1 to calculate field 5 in message 1 to obtain ESP verification information 1, i.e., obtain verification information 1. Field 5 includes ESP header, IP header, IP extension header, TCP header, data, and ESP tail. Application information 1 can be carried in the IP extension header, which, for example, can be the IPv6 extension header. The ESP verification algorithm 1 mentioned here can be, for example, HMAC MD5 or HMAC SHA1.

[0134] When verification algorithm 1 is based on AH integrity verification and message 1 is encapsulated in transmission mode, communication device 1 uses verification information 1 to perform integrity verification on application information 1. Specifically, communication device 1 uses AH verification algorithm 1 to calculate field 3 in message 1 to obtain AH verification information 3, which is also verification information 2. Then, communication device 1 performs matching verification on verification information 1 and verification information 2. Matching verification on verification information 1 and verification information 2 is equivalent to matching verification on the aforementioned AH verification information 1 and AH verification information 3. It should be noted that the AH verification algorithm 1 mentioned here can be pre-agreed upon by communication device 1 and communication device 3.

[0135] In this embodiment, since the AH verification algorithm 1 can be pre-negotiated between communication device 1 and communication device 3, or in other words, pre-negotiated between APP 1 on communication device 3 and communication device 1, other APPs on communication device 3 cannot obtain the AH verification algorithm 1, nor can APPs installed on other devices obtain the AH verification algorithm 1. Therefore, even if other APPs on communication device 3 or APPs on other devices steal application information 1, they cannot generate verification information 1 because they cannot obtain the AH verification algorithm 1. Accordingly, the message d generated by the APP that steals application information 1 does not include verification information 1. Therefore, when communication device 1 receives message d, the integrity verification of application information 1 fails, thereby preventing the theft of network resources due to the theft of application information 1.

[0136] When verification algorithm 1 is based on AH integrity verification and message 1 is encapsulated in tunnel mode, communication device 1 uses verification information 1 to perform integrity verification on application information 1. Specifically, communication device 1 uses AH verification algorithm 2 to calculate field 4 in message 1 to obtain AH verification information 4, which is verification information 2. Then, communication device 1 performs a matching verification between verification information 1 and verification information 2. This matching verification of verification information 1 and verification information 2 is equivalent to matching verification between the aforementioned AH verification information 2 and AH verification information 4. It should be noted that the AH verification algorithm 2 mentioned here can be pre-agreed upon by communication device 1 and communication device 3.

[0137] In this embodiment, since the AH verification algorithm 2 can be pre-negotiated between communication device 1 and communication device 3, or in other words, pre-negotiated between APP 1 on communication device 3 and communication device 1, other APPs on communication device 3 cannot obtain the AH verification algorithm 2, nor can APPs installed on other devices. Therefore, even if other APPs on communication device 3 or APPs on other devices steal application information 1, they cannot generate verification information 1 because they cannot obtain the AH verification algorithm 2. Accordingly, the message e generated by the APP that steals application information 1 does not include verification information 1. Therefore, when communication device 1 receives message e, the integrity verification of application information 1 fails, thereby preventing the theft of network resources due to the theft of application information 1.

[0138] When verification algorithm 1 is based on ESP integrity verification, communication device 1 uses verification information 1 to perform integrity verification on application information 1. Specifically, communication device 1 can use ESP verification algorithm 1 to calculate field 5 in message 1 to obtain ESP verification information 2. Then, communication device 1 performs matching verification on verification information 1 and verification information 2. Matching verification on verification information 1 and verification information 2 means matching verification on the aforementioned ESP verification information 1 and ESP verification information 2. It should be noted that the ESP verification algorithm 1 mentioned here can be pre-agreed upon by communication device 1 and communication device 3.

[0139] In this embodiment, since the ESP verification algorithm 1 can be pre-negotiated between communication device 1 and communication device 3, or in other words, pre-negotiated between APP 1 on communication device 3 and communication device 1, other APPs on communication device 3 cannot obtain the ESP verification algorithm 1, nor can APPs installed on other devices. Therefore, even if other APPs on communication device 3 or APPs on other devices steal application information 1, they cannot generate verification information 1 because they cannot obtain the ESP verification algorithm 1. Accordingly, the message f generated by the APP that steals application information 1 does not include verification information 1. Therefore, when communication device 1 receives message f, the integrity verification of application information 1 fails, thereby preventing the theft of network resources due to the theft of application information 1.

[0140] In one implementation of this application, the verification information used to verify the integrity of application information 1 in message 1 may include one or more. Correspondingly, in addition to verifying the integrity of application information 1 based on verification information 1, communication device 1 may also verify the integrity of application information 1 based on other verification information. In other words, in this application embodiment, message 1 may include verification information 3 in addition to verification information 1. Verification information 3 may be calculated by communication device 3 from the fields in message 1. As an example, verification information 3 may be calculated using verification algorithm 2 from the fields in message 1.

[0141] Verification algorithm 2 is a different verification algorithm from verification algorithm 1. However, similar to verification algorithm 1, verification algorithm 2 can also be one of the following: HMAC algorithm, digital signature algorithm, or IPSec-based integrity verification. For details on verification algorithm 2, please refer to the description of verification algorithm 1 above; it will not be elaborated here. Regarding the specific implementation of communication device 3 using verification algorithm 2 to obtain verification information 3, please refer to the description of communication device 3 obtaining verification information 1 based on verification algorithm 1 above; it will not be elaborated here. Correspondingly, regarding the specific implementation of communication device 1 using verification information 3 to perform integrity verification of application information 1, please refer to the description of communication device 1 using verification information 1 to perform integrity verification of application information 1; it will not be repeated here.

[0142] This application also provides a message processing method 200, see [link to relevant documentation]. Figure 4 The figure is a flowchart illustrating a message processing method provided in an embodiment of this application.

[0143] Figure 4 The method 200 shown can be executed by a first communication device, such as the communication device 1 mentioned in the above embodiments. Figure 4 The method 200 shown can be applied to the method 100 mentioned in the above embodiments to perform the steps executed by the communication device 1 in the above method 100. The method 200 may include, for example, the following S201-S202.

[0144] S201: Obtain the first message, which includes application information.

[0145] S202: Send the first message to the second communication device, wherein the first message is not an Internet Protocol (IP) message.

[0146] The first message in method 200 can correspond to message 1 in method 100; the application information in method 200 can correspond to application information 1 in method 100; the second communication device in method 200 can correspond to communication device 2 in method 100.

[0147] In one implementation, obtaining the first message includes:

[0148] Obtain the first data packet, encapsulate the first data packet, add the application information, and obtain the first packet.

[0149] The first data packet in method 300 can correspond to data packet 1 in method 100.

[0150] In one implementation, obtaining the first message includes:

[0151] Receive the first message sent by the third communication device.

[0152] The third communication device in method 300 can correspond to the communication device 3 in method 100.

[0153] In one implementation, the application information is carried in the header of the first message.

[0154] In one implementation, the first message is a Multiprotocol Label Switching (MPLS) message.

[0155] In one implementation, the application information is carried in a tag value field.

[0156] In one implementation, the application information is carried in an extended type length value (TLV) field.

[0157] In one implementation, the first message is a Generic Router Encapsulated (GRE) message.

[0158] In one implementation, the application information is carried in a keyword field.

[0159] In one implementation, the first message is a Virtual Extended Local Area Network (VXLAN) message.

[0160] In one implementation, the application information is carried in a network identifier field.

[0161] In one implementation, the application information is carried in a reserved field.

[0162] In one implementation, the first message is a Network Virtualization General Router Encapsulated NVGRE message.

[0163] In one implementation, the application information is carried in a stream identifier field.

[0164] In one implementation, the application information is carried in a virtual network identifier field.

[0165] In one implementation, the application information is carried in a reserved field.

[0166] In one implementation, the first message is a Geneve message encapsulated by general network virtualization.

[0167] In one implementation, the application information is carried in a reserved field.

[0168] In one implementation, the application information is carried in a variable-length option field.

[0169] In one implementation, the application information includes any one or more of the following:

[0170] Service Level Agreement (SLA) level, application identifier, user identifier, flow identifier, and reserved parameters.

[0171] In one implementation, the first communication device is a network device.

[0172] In one implementation, the first communication device includes:

[0173] Access ACC device, or CPE device at user premises, or RG home gateway, or leaf device for data center server access, or DC GW for data center egress gateway, or ASBR for Autonomous System Border Router, or base station, or UPF device for User Plane Function, or BNG for Broadband Network Gateway, or PE device for Carrier Edge.

[0174] In one implementation, the first communication device includes a server or a user equipment.

[0175] In one implementation, the second communication device includes a network device.

[0176] In one implementation, the second communication device includes:

[0177] Server or user equipment.

[0178] In one implementation, when the first communication device is a network device, the method further includes:

[0179] The network resources for forwarding the first message are determined based on the application information.

[0180] In one implementation, sending the first message to the second communication device includes:

[0181] The first message is sent to the second communication device using the network resources.

[0182] In one implementation, when the first communication device is a network device, the first message may include, in addition to application information, first authentication information, which is used to verify the integrity of the application information. Correspondingly, the first communication device may also perform integrity verification of the application information based on the first authentication information.

[0183] The first verification information in method 300 can correspond to verification information 1 in method 100.

[0184] In one implementation, verifying the integrity of the application information based on the first verification information includes:

[0185] Based on the target field in the first message, obtain the second verification information, the target field including the application information; and perform matching and verification between the second verification information and the first verification information.

[0186] The target field in method 300 can correspond to field 1, field 2, field 3, field 4, or field 5 in method 100. The second verification information in method 300 can correspond to verification information 2 in method 100.

[0187] In one implementation, verifying the integrity of the application information based on the first verification information includes:

[0188] The integrity of the application information is verified based on the first verification method and the first verification information.

[0189] The first verification method in method 300 can correspond to verification algorithm 1 in method 100.

[0190] In one implementation, the first verification method is a key-related hash message authentication code (HMAC) verification.

[0191] In one implementation, the first verification information includes first HMAC verification information, and the verification of the integrity of the application information based on the first verification method and the first verification information includes:

[0192] Perform HMAC calculation on the target field in the first message to obtain the second HMAC verification information;

[0193] The first HMAC verification information and the second HMAC verification information are matched and verified.

[0194] When the first verification method is HMAC verification, the target field in method 300 corresponds to field 1 in method 100.

[0195] In one implementation, the first HMAC verification information in method 300 can correspond to the verification information 1 obtained in method 100 by appending key 1 to field 1 as input to hash algorithm 1. Correspondingly, the second HMAC verification information can correspond to the verification information 2 obtained in method 100 by appending key 1 to field 1 as input to hash algorithm 1.

[0196] In one implementation, the first HMAC verification information in method 300 can correspond to HMAC2 in method 100, and correspondingly, the second HMAC verification information can correspond to HMAC 2' in method 100.

[0197] In one implementation, the first verification method is digital signature verification.

[0198] In one implementation, the first verification information is a digital signature obtained by signing the target field in the first message using a first private key and a first hash calculation. The step of verifying the integrity of the application information based on the first verification method and the first verification information includes:

[0199] The digital signature is decrypted using the first public key to obtain the first plaintext;

[0200] A second hash calculation is performed on the target field to obtain the second plaintext. The first hash calculation and the second hash calculation use the same hash algorithm.

[0201] Perform a matching verification between the first plaintext and the second plaintext.

[0202] When the first verification method is digital signature: the target field corresponds to field 2 in method 100; the first private key corresponds to private key 1 in method 100; the first hash calculation corresponds to hash algorithm 3 in method 100; the digital signature corresponds to digital signature 1 in method 100; the first public key corresponds to public key 1 in method 100; the first plaintext corresponds to hash digest 1'' in method 100; the second hash calculation corresponds to hash algorithm 3 in method 100; and the second plaintext can correspond to hash digest 1'' in method 100.

[0203] In one implementation, the first message further includes a digital certificate, which includes the first public key.

[0204] The digital certificate in method 300 corresponds to digital certificate 1 in method 100, and the first public key corresponds to public key 1 in method 100.

[0205] In one implementation, the digital certificate further includes a decryption algorithm for decrypting the digital signature, and / or the hash algorithm.

[0206] The decryption algorithm mentioned here corresponds to decryption algorithm 1 in method 100; the hash algorithm mentioned here corresponds to hash algorithm 3 in method 100.

[0207] In one implementation, the method further includes:

[0208] The validity of the digital certificate is verified.

[0209] In one implementation, the first message includes a digital certificate, and the application information and the first verification information are carried in the digital certificate.

[0210] In one implementation, verifying the integrity of the application information based on the first verification information includes verifying the legitimacy of the digital certificate.

[0211] In one implementation, the first verification method is an integrity verification based on Internet Protocol Security (IPSEC).

[0212] When the first verification method is IPSEC-based integrity verification, the first verification method can be AH verification or ESP verification.

[0213] In one implementation, the first verification information is a first authentication header (AH) verification information, and the verification of the integrity of the application information based on the first verification method and the first verification information includes:

[0214] The target field in the first message is calculated using the AH verification algorithm to obtain the second AH verification information;

[0215] The first AH verification information and the second AH verification information are matched and verified.

[0216] When the first verification method is AH verification, the first verification information is the first AH verification information, and the second verification information is the second AH verification information. The first AH verification information can correspond to AH verification information 1 or AH verification information 2 in method 100, and the second AH verification information can correspond to AH verification information 3 or AH verification information 4 in method 100.

[0217] In one example, when the first message is encapsulated in transport mode, the first AH verification information corresponds to AH verification information 1 in method 100, the second verification information corresponds to AH verification information 3 in method 100, and the target field can correspond to field 3 in method 100; when the first message is encapsulated in tunnel mode, the first AH verification information corresponds to AH verification information 2 in method 100, the second verification information corresponds to AH verification information 4 in method 100, and the target field can correspond to field 4 in method 100.

[0218] In one implementation, the first verification information is the first encapsulated security payload (ESP) verification information, and the verification of the integrity of the application information based on the first verification method and the first verification information includes:

[0219] The target field in the first message is calculated using the ESP check algorithm to obtain the second ESP check information;

[0220] The first ESP verification information and the second ESP verification information are matched and verified.

[0221] When the first verification method is ESP verification, the first verification information is the first ESP verification information, and the second verification information is the second ESP verification information. The first ESP verification information can correspond to ESP verification information 1 in method 100, the second ESP verification information can correspond to ESP verification information 2 in method 100, and the target field can correspond to field 5 in method 100.

[0222] In one implementation of this application, the first message may include third verification information in addition to the first verification information. The third verification information is used to verify the integrity of the first application information. Accordingly, the first communication device can perform integrity verification of the application information based on both the first and third verification information.

[0223] The third verification information mentioned here can correspond to verification information 3 in method 100. As an example, the third verification information can be obtained by calculating the fields in the first message using the second verification algorithm. The second verification algorithm mentioned here can correspond to verification algorithm 2 in method 100.

[0224] The second verification algorithm is different from the first verification algorithm. However, similar to the first verification algorithm, the second verification algorithm can also be one of the following: HMAC algorithm, digital signature algorithm, or IPSec-based integrity verification. For details on the second verification algorithm, please refer to the description of the first verification algorithm above; it will not be elaborated here. Regarding the specific implementation of the first communication device using the third verification information to verify the integrity of application information, please refer to the description of the first communication device using the first verification information to verify the integrity of application information; it will not be repeated here.

[0225] In addition, this application embodiment also provides a communication device 500, see [link to relevant documentation]. Figure 5 As shown. Figure 5 This is a schematic diagram of a communication device provided in an embodiment of this application. The communication device 500 includes a transceiver unit 501 and a processing unit 502. The communication device 500 can be used to execute method 100 or method 200 in the above embodiments.

[0226] In one example, the communication device 500 can execute method 100 in the above embodiments. When the communication device 500 is used to execute method 100 in the above embodiments, the communication device 500 is equivalent to the communication device 1 in method 100. The transceiver unit 501 is used to execute the transceiver operation performed by the communication device 1 in method 100. The processing unit 502 is used to execute operations other than the transceiver operation performed by the communication device 1 in method 100. For example, the transceiver unit 501 is used to receive message 1, which includes application information 1; the transceiver unit 501 is also used to send message 1 to the communication device 2. As another example, the transceiver unit 501 is used to receive data message 1; the processing unit 502 is used to re-encapsulate the data message 1, add application information 1, and obtain message 1; the transceiver unit 501 is also used to send message 1 to the communication device 2.

[0227] In one example, the communication device 500 can execute method 200 in the above embodiments. When the communication device 500 is used to execute method 200 in the above embodiments, the communication device 500 is equivalent to the first communication device in method 100. The transceiver unit 501 is used to execute the transceiver operation performed by the first communication device in method 200. The processing unit 502 is used to execute operations other than the transceiver operation performed by the first communication device in method 200. For example, the transceiver unit 501 is used to receive a first message, which includes application information; the transceiver unit 501 is also used to send the first message to a second communication device. Another example: the transceiver unit 501 is used to receive a first data packet; the processing unit 502 is used to re-encapsulate the first data packet, add application information, and obtain a first message; the transceiver unit 501 is also used to send the first message to the second communication device.

[0228] In addition, this application embodiment also provides a communication device 600, see [link to relevant documentation]. Figure 6 As shown, Figure 6 This is a schematic diagram of a communication device provided in an embodiment of this application. The communication device 600 includes a communication interface 601 and a processor 602 connected to the communication interface 601. The communication device 600 can be used to execute method 100 or method 200 in the above embodiments.

[0229] In one example, the communication device 600 can execute method 100 in the above embodiments. When the communication device 600 is used to execute method 100 in the above embodiments, the communication device 600 is equivalent to the communication device 1 in method 100. The communication interface 601 is used for the send / receive operations performed by the communication device 1 in method 100; the processor 602 is used for other operations performed by the communication device 1 in method 100 besides the send / receive operations. For example, the communication interface 601 is used to receive message 1, which includes application information 1; the communication interface 601 is also used to send message 1 to the communication device 2. As another example, the communication interface 601 is used to receive data message 1, the processor 602 is used to re-encapsulate the data message 1, add application information 1, obtain message 1, and the communication interface 601 is also used to send message 1 to the communication device 2.

[0230] In one example, the communication device 600 can execute method 200 in the above embodiments. When the communication device 600 is used to execute method 200 in the above embodiments, the communication device 600 is equivalent to the first communication device in method 200. Specifically, the communication interface 601 is used for the send / receive operations performed by the first communication device in method 200; the processor 602 is used for other operations performed by the first communication device in method 200 besides the send / receive operations. For example, the communication interface 601 is used to receive a first message, which includes application information; the communication interface 601 is also used to send the first message to a second communication device. As another example, the communication interface 601 is used to receive a first data packet, the processor 602 is used to re-encapsulate the first data packet, add application information, obtain the first message, and the communication interface 601 is also used to send the first message to the second communication device.

[0231] In addition, this application also provides a communication device 700, see [link to relevant documentation]. Figure 7 As shown, Figure 7 This is a schematic diagram of the structure of a communication device provided in an embodiment of this application.

[0232] The communication device 700 can be used to execute method 100 or method 200 in the above embodiments.

[0233] like Figure 7As shown, the communication device 700 may include a processor 710, a memory 720 coupled to the processor 710, and a transceiver 730. The processor 710 may be a central processing unit (CPU), a network processor (NP), or a combination of a CPU and an NP. The processor may also be an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The PLD may be a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof. The processor 710 may refer to a single processor or may include multiple processors. The memory 720 may include volatile memory, such as random-access memory (RAM); it may also include non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid-state drive (SSD); the memory 720 may also include combinations of the above types of memory. The memory 720 may refer to a single memory or may include multiple memories. In one embodiment, the memory 720 stores computer-readable instructions, which include multiple software modules, such as a sending module 721, a processing module 722, and a receiving module 723. After executing each software module, the processor 710 can perform corresponding operations according to the instructions of each software module. In this embodiment, the operation performed by a software module actually refers to the operation performed by the processor 710 according to the instructions of the software module.

[0234] In one example, the communication device 700 can execute method 100 in the above embodiments. When the communication device 700 executes method 100 in the above embodiments, the communication device 700 is equivalent to communication device 1 in method 100. In one example, the receiving module 723 is used to receive message 1, which includes application information 1. The sending module 721 is used to send message 1 to communication device 2. In another example, the receiving module 723 is used to receive data message 1. The processing module 722 is used to re-encapsulate data message 1, add application information 1, and obtain message 1. The sending module 721 is used to send message 1 to communication device 2.

[0235] In one example, the communication device 700 can execute method 200 in the above embodiments. When the communication device 700 executes method 200 in the above embodiments, the communication device 700 is equivalent to the first communication device in method 200. In one example, the receiving module 723 is used to receive a first message, which includes application information. The sending module 721 is used to send the first message to the second communication device. In another example, the receiving module 723 is used to receive a first data packet. The processing module 722 is used to re-encapsulate the first data packet, add application information, and obtain a first message. The sending module 721 is used to send the first message to the second communication device.

[0236] Furthermore, after the processor 710 executes the computer-readable instructions in the memory 720, it can perform all operations that the communication device 700 can perform, according to the instructions. For example, it can perform all operations that the communication device 1 can perform in method 100; or, for example, it can perform all operations that the first communication device can perform in method 200.

[0237] This application also provides a computer-readable storage medium storing instructions that, when executed on a computer, cause the computer to perform the steps performed by the first communication device in the above embodiments.

[0238] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a particular order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms “comprising” and “having,” and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0239] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0240] In the embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical business division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces, indirect coupling or communication connection between apparatuses or units, and may be electrical, mechanical, or other forms.

[0241] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0242] Furthermore, the various business units in the embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software business unit.

[0243] If the integrated unit is implemented as a software business unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0244] Those skilled in the art will recognize that, in one or more of the examples above, the services described in this invention can be implemented using hardware, software, firmware, or any combination thereof. When implemented in software, these services can be stored in a computer-readable medium or transmitted as one or more instructions or code on a computer-readable medium. Computer-readable media include computer storage media and communication media, wherein communication media include any medium that facilitates the transmission of computer programs from one place to another. Storage media can be any available medium accessible to general-purpose or special-purpose computers.

[0245] The above specific embodiments further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above are merely specific embodiments of the present invention.

[0246] The above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit it. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.

Claims

1. A message processing method, characterized in that, Performed by a first communication device, the method includes: A first message is obtained, which includes application information and first verification information. The first verification information is used to verify the integrity of the application information. The first verification information is calculated from a target field in the first message, which includes the application information. The first message is: a Multiprotocol Label Switching (MPLS) message, or a Virtual Extended Local Area Network (VXLAN) message, or a Network Virtualization Generic Routing Encapsulation (NVGRE) message, or a Generic Network Virtualization Encapsulation (Geneve) message. The application information is used to determine the network resources for forwarding the first message. The first message is forwarded to the second communication device.

2. The method according to claim 1, characterized in that, The acquisition of the first message includes: Obtain the first data packet, encapsulate the first data packet, add the application information and the first verification information to obtain the first packet.

3. The method according to claim 1, characterized in that, The acquisition of the first message includes: Receive the first message sent by the third communication device; Before forwarding the first message to the second communication device, the method further includes: Based on the target field in the first message, obtain the second verification information; The second verification information and the first verification information are matched and verified.

4. The method according to claim 3, characterized in that, The first verification information is the first hash operation message authentication code (HMAC) verification information; The step of obtaining second verification information based on the target field in the first message, and matching and verifying the second verification information and the first verification information includes: Perform HMAC calculation on the target field in the first message to obtain second HMAC verification information; perform matching verification on the first HMAC verification information and the second HMAC verification information.

5. The method according to any one of claims 1-4, characterized in that, The application information is carried in the header of the first message.

6. The method according to any one of claims 1-4, characterized in that, If the first message is an MPLS message, the application information is carried in the tag value field.

7. The method according to any one of claims 1-4, characterized in that, If the first message is an MPLS message, the application information is carried in the Extended Type Length Value (TLV) field.

8. The method according to any one of claims 1-4, characterized in that, If the first message is a VXLAN message, the application information is carried in the network identifier field.

9. The method according to any one of claims 1-4, characterized in that, If the first message is a VXLAN message, the application information is carried in the reserved field.

10. The method according to any one of claims 1-4, characterized in that, If the first message is an NVGRE message, the application information is carried in the flow identifier field.

11. The method according to any one of claims 1-4, characterized in that, If the first message is an NVGRE message, the application information is carried in the virtual network identifier field.

12. The method according to any one of claims 1-4, characterized in that, If the first message is an NVGRE message, the application information is carried in the reserved field.

13. The method according to any one of claims 1-4, characterized in that, If the first message is a Geneve message, the application information is carried in the reserved field.

14. The method according to any one of claims 1-4, characterized in that, If the first message is a Geneve message, the application information is carried in the variable-length option field.

15. The method according to any one of claims 1-4, characterized in that, The application information includes any one or more of the following: Service Level Agreement (SLA) level, application identifier, user identifier, flow identifier, and reserved parameters.

16. The method according to any one of claims 1-4, characterized in that, The first communication device is a network device.

17. The method according to any one of claims 1-4, characterized in that, The first communication device includes: Access ACC device, or CPE device at user premises, or RG home gateway, or leaf device for data center server access, or DC GW for data center egress gateway, or ASBR for Autonomous System Border Router, or base station, or UPF device for User Plane Function, or BNG for Broadband Network Gateway, or PE device for Carrier Edge.

18. The method according to any one of claims 1-4, characterized in that, The first communication device includes: a server or a user equipment.

19. The method according to any one of claims 1-4, characterized in that, The second communication device includes: network equipment.

20. The method according to any one of claims 1-4, characterized in that, The second communication device includes: Server or user equipment.

21. The method according to any one of claims 1-4, characterized in that, When the first communication device is a network device, the method further includes: The network resources for forwarding the first message are determined based on the application information.

22. The method according to claim 21, characterized in that, The forwarding of the first message to the second communication device includes: The first message is forwarded to the second communication device using the network resources.

23. A first communication device, characterized in that, The first communication device includes a memory and a processor; The memory is used to store program code; The processor is configured to run instructions in the program code, causing the first communication device to perform the method described in any one of claims 1-22.

24. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores instructions that, when executed on a computer, cause the computer to perform the method described in any one of claims 1-22.

Citation Information

Patent Citations

  • VXLAN message encapsulation and strategy execution method, equipment and system

    CN110768884A

  • Method for verifying application information and message processing method and device

    CN113810173A

  • Mobile communication system and communication control method

    JP2015089013A