Dynamic Label Generation and Sharing Mechanism Method and Apparatus for Source and Path Verification
By configuring control servers to generate and distribute dynamic tags within the network management domain, the problem of large-scale computing and communication overhead in source and path verification process in large-scale network interdomain communication is solved, and more efficient and reliable source and path verification is achieved.
Patent Information
- Application Number
- CN202111266285.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-10-28
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2041-10-28
AI Technical Summary
In the prior art, when communication between large-scale network domains is communicated, the generation and sharing of tags for device identity between users and routing devices during source and path verification have problems such as high computing and communication overhead and low reliability.
A dynamic tag generation and sharing mechanism method is proposed. By configuring a control server for each management domain, a dynamic tag representing the identity of the device is generated and sent to the user and the routing device, the dynamic tag information of the routing device node is written in advance, reducing the overhead of generating dynamic tags for each data packet.
By managing the hierarchical trust system within the domain and writing dynamic tags in advance, the overhead of routing devices in generating dynamic tags for each data packet is reduced, and the reliability and efficiency of source and path verification are improved.
Smart Images

Figure CN114238880B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of computer networks, and particularly to a method and device for dynamic label generation and sharing mechanism for source and path verification. Background Art
[0002] The Internet has the characteristics of "simple core and complex edge", resulting in untrusted behaviors of its transmission path nodes, thus bringing security problems such as routing hijacking and traffic eavesdropping. The reliable and trustworthy communication between the source and destination nodes of the Internet depends on the mutual trust between the source and destination nodes and the intermediate routing nodes. However, the lack of verification of the authenticity of the identity of the intermediate routing nodes in the initial architecture design of the Internet provides favorable conditions for path deception. Attackers can change the data packet transmission path and implement attacks such as transmission path tampering and traffic eavesdropping. As long as the data packet is finally handed over to the destination end routing node, the destination end cannot audit, supervise, and trace the actual transmission path of the data packet. The lack of verification of the data packet transmission path, and the fact that attackers can forge data packets at will, result in defects in the authenticity and auditability of network communication services.
[0003] Regarding the authenticity verification problem generated in the above data packet forwarding process, the existing research work mainly generates a data packet verification structure based on the expected path information, that is, authenticates the source and the predetermined path strategy of the session, determines whether the data packet is legal, and whether it is correctly sent to the destination end according to the predetermined path.
[0004] Since a management domain can be regarded as a trust community, real path verification mainly considers the inter-domain source and path verification scenarios. The existing inter-domain source and path verification technologies mainly include: OPT, ICING, PPV, EPIC. For OPT, ICING, and PPV, asymmetric encryption technology needs to be used for key negotiation before communication (the dynamic label generation and sharing realizes the key negotiation function in these technologies), which brings a great deal of overhead. Although EPIC adopts a key server and derives keys for each routing device based on the master key of each AS, its derivation is based on each flow rather than on the routing device, resulting in the dynamic key finally used for verification code generation needing to be temporarily generated by the routing device for each data packet, and an additional key generation operation needs to be completed for each data packet, bringing a great deal of computational overhead. In this application, this key is uniformly referred to as a dynamic label. The dynamic label is unique and can be used to generate a verification code or as a symmetric encryption key, which preferably solves these problems and can provide dynamic labels for users and routing devices for efficient and reliable source and path verification, and improves the security and trustworthiness of the data transmission process. Summary of the Invention
[0005] The present invention aims to solve at least one of the technical problems in the related technologies to some extent.
[0006] To this end, an object of the present invention is to overcome the problems existing in the prior art, such as large computational and communication overheads and low reliability when generating and sharing tags for device identities between users and routing devices during the source and path verification processes in large-scale inter-domain network communications. A dynamic tag generation and sharing mechanism method for source and path verification is proposed to solve the problems of large computational and communication overheads and low reliability in the dynamic tag calculation of devices in the prior art, and is particularly applicable to the dynamic tag sharing for source and path verification during data transmission between users and inter-domain routing nodes.
[0007] Another object of the present invention is to propose a dynamic tag generation and sharing mechanism device for source and path verification.
[0008] To achieve the above object, on the one hand, the present invention proposes a dynamic tag generation and sharing mechanism method for source and path verification, which configures a control server for each administrative domain, including configuring routing device information, tag generation, and tag distribution. Among them, the routing device information is to share all border routing device nodes and node neighbor information; tag generation is to generate a dynamic tag representing the device identity for generating verification codes or session encryption through the control server; tag distribution is to issue corresponding dynamic tags to users and routing devices. The tag distribution writes the end-node sharing of the routing node itself and the routing device dynamic tags shared by the routing node into the routing device nodes in advance, and distributes the routing device dynamic tags of the neighbor routing devices of each routing node to each routing node. Before each communication, the source and destination users obtain the routing device dynamic tags and the source and destination user session dynamic tags based on the tag distribution of the control server in their own domain, and realize the addition and verification of verification codes based on the routing device dynamic tags and the user session dynamic tags.
[0009] The border routing device of the administrative domain of the present invention obtains the corresponding dynamic tag information of this device from the control server and stores it locally. The source and destination users obtain the tags corresponding to all routing device nodes on this path and the tags used in the current session of the source and destination users before each communication. The source and destination users and the routing device nodes on the path can use the dynamic tags and data packet header information to generate verification codes for realizing source and path verification and improving the security of the data transmission process.
[0010] In addition, the dynamic tag generation and sharing mechanism method for source and path verification according to the above embodiments of the present invention may further have the following additional technical features:
[0011] Further, in an embodiment of the present invention, the tag generation is based on a basic key to derive a fixed key for each routing device, where the key corresponds to each routing device and the control server.
[0012] Further, in an embodiment of the present invention, the routing device information includes a routing device identifier and a neighbor device identifier, and the label generation, label distribution, and storage are dynamic labels corresponding to the routing device.
[0013] Further, in an embodiment of the present invention, the issuing of the corresponding dynamic labels to the user and the routing device includes: end-node sharing and routing-node sharing; wherein,
[0014] The end-node sharing: is a label jointly owned by the routing device node and the end node, and is used for generating and verifying verification codes between the routing device node and the end node;
[0015] The routing-node sharing: is a label jointly owned by the routing node and the routing node, and is used for the routing node to generate and verify verification codes for the routing node.
[0016] Further, in an embodiment of the present invention, based on the end-node sharing and routing-node sharing, the label generation generates a session for each source and destination user, and generates a dynamic label corresponding to the source and destination users for their encrypted communication or verification code generation.
[0017] Further, in an embodiment of the present invention, the label generation includes:
[0018] The label generation of each management domain shares the domain base key DK. If the routing device identifier is id i , and it is located in domain I, then the base key is DK I , and the fixed key RK of the routing device is derived i :
[0019]
[0020] where DK I is the base key of the management domain I where the routing device id i is located, and MAC(.) is a verification code operation.
[0021] Further, in an embodiment of the present invention, generating session dynamic labels for the user and the routing device includes:
[0022]
[0023] wherein, AD N is the number of the domain (N) where the nth neighbor node is located as the previous hop, indicator m is the mth indicator, and "||" represents a way of concatenating strings.
[0024] Further, in an embodiment of the present invention, the session dynamic tags "tag" of the source and destination users sd are divided into two cases: end-node sharing and routing-node sharing. Among them,
[0025] For end-node sharing: Calculate according to the IP address of the end node and the combination of the IDs of the routing devices on the transmission path from the source to the destination user:
[0026]
[0027] For routing-node sharing: Calculate according to the combination of the IDs of the source and destination routing nodes and the ID of the intermediate routing node:
[0028]
[0029] Among them, indicator 1 is the indicator used for the first data packet of the source and destination users.
[0030] The source and destination obtain the tags corresponding to the session. Based on the tags corresponding to the session obtained by the source and destination, the source user obtains the "tag" sd and indicator 1 from the label distribution of the source management domain before communication. After receiving the first data packet, the destination user obtains the corresponding "tag" 1 from the label distribution of the destination management domain according to the indicator sd in the packet header and the source user IP address information.
[0031] To achieve the above object, on the other hand, the present invention proposes a dynamic label generation and sharing mechanism device for source and path verification, including: a configuration module for configuring a control server for each management domain, including configuring routing device information, label generation, and label distribution; wherein, the routing device information is to share all border routing device nodes and the neighbor information of the nodes; the label generation is to generate a dynamic label representing the device identity for generating a verification code or session encryption through the control server; the label distribution is to generate dynamic labels for users and routing devices and issue the corresponding labels; a distribution module for the label distribution to write the end-node sharing and routing-node sharing routing device dynamic labels of the routing node itself into the routing device node in advance, and distribute the routing-node sharing routing device dynamic labels of the neighbor routing devices of each routing node to each routing node; a verification module for the source and destination users to obtain the routing device dynamic labels and the source and destination user session dynamic labels based on the label distribution of the control server in their respective domains before each communication, and to implement the addition and verification of the verification code based on the routing device dynamic labels and the user session dynamic labels.
[0032] The device of the dynamic label generation and sharing mechanism for source and path verification in the embodiment of the present invention configures a control server for each administrative domain, including configuring routing device information, label generation, and label distribution. Label distribution writes the end-node sharing of the routing node itself and the routing device dynamic label of the routing node sharing into the routing device node in advance, and distributes the routing device dynamic label of the neighbor routing device of each routing node to each routing node. Before each communication, the source and destination users obtain the routing device dynamic label and the source and destination user session dynamic label based on the label distribution of the control server in this domain, and realize the addition and verification of the verification code based on the routing device dynamic label and the user session dynamic label. The present invention overcomes the problems of large computational and communication overhead and low reliability in generating and sharing labels for device identities between users and routing devices during the source and path verification process in large-scale inter-domain communication.
[0033] The beneficial effects of the present invention are as follows:
[0034] 1) Through the dynamic label derivation method based on the administrative domain, the present invention establishes a hierarchical trust system between domains and within domains with the control server taking the administrative domain as a unit, and provides a method for generating and sharing the routing device dynamic label between domains.
[0035] 2) The present invention writes the label in advance on the control plane of the routing device, and does not require the routing device to generate a dynamic label for each data packet, reducing the overhead of the routing device generating a dynamic label for each data packet.
[0036] 3) The present invention pre-sets the dynamic label for the routing device based on the neighbor and indicator, provides a way for the user to embed an indicator in the packet header, so as to realize the sharing of the dynamic label between the user and the routing node, and reduces the overhead of the user negotiating the dynamic label with the routing device.
[0037] The additional aspects and advantages of the present invention will be partly given in the following description, partly will become obvious from the following description, or will be understood through the practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] The above and / or additional aspects and advantages of the present invention will become obvious and easy to understand from the following description of the embodiments in conjunction with the drawings, where:
[0039] Figure 1 It is a flowchart of the method for the dynamic label generation and sharing mechanism for source and path verification according to the embodiment of the present invention;
[0040] Figure 2 It is a schematic diagram of the connection of network nodes according to the embodiment of the present invention;
[0041] Figure 3 It is a schematic diagram of the control server and the routing device according to the embodiment of the present invention;
[0042] Figure 4 Schematic diagram of the neighbor information storage format of a routing device according to an embodiment of the present invention;
[0043] Figure 5 Schematic diagram of the dynamic label storage format according to an embodiment of the present invention;
[0044] Figure 6 Schematic diagram of the label generation process according to an embodiment of the present invention;
[0045] Figure 7 Schematic diagram of the device structure of the dynamic label generation and sharing mechanism for source and path verification according to an embodiment of the present invention. Detailed implementation manners
[0046] The embodiments of the present invention will be described in detail below. Examples of the embodiments are shown in the drawings, where the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the drawings are exemplary and are intended to explain the present invention, and should not be construed as limiting the present invention.
[0047] The method and device of the dynamic label generation and sharing mechanism for source and path verification according to an embodiment of the present invention will be described below with reference to the drawings. First, the method of the dynamic label generation and sharing mechanism for source and path verification according to an embodiment of the present invention will be described with reference to the drawings.
[0048] Figure 1 Flowchart of the method of the dynamic label generation and sharing mechanism for source and path verification according to an embodiment of the present invention.
[0049] As Figure 1 shown, the method of the dynamic label generation and sharing mechanism for source and path verification includes the following steps:
[0050] Step S1, configure a control server for each administrative domain, including configuring routing device information, label generation, and label distribution; wherein, the routing device information is to share all border routing device nodes and node neighbor information; label generation is to generate a dynamic label representing the device identity for generating verification codes or session encryption through the control server; label distribution is to issue the corresponding dynamic label to users and routing devices.
[0051] As an example, step S1 of the present invention is further elaborated.
[0052] S101, configure three modules of routing device information, label generation, and label distribution in the control server of the administrative domain.
[0053] S102, The routing device information module shares all border routing device nodes and their neighbor information.
[0054] S103, Based on DK, the label generation module derives a fixed routing device key RK for each routing device. This key is known only to the routing device and the control server.
[0055] S104, Generate dynamic labels for users and routing devices.
[0056] It can be understood that, according to the application scenario, as Figure 2 (a) shows, it is divided into two types of dynamic labels: sharing between end-host nodes and routing device nodes (abbreviated as end-node sharing), and sharing between routing device nodes (abbreviated as routing-node sharing):
[0057] End-node sharing: The label jointly owned by the routing device node and the end node, which is used to generate and verify verification codes between the routing device node and the end node. According to the domain where the RKj of the previous-hop neighbor node of RKi is located, and an indicator for distinguishing different dynamic labels, the dynamic label tagi_n_m of this routing device is obtained (i represents node i, n represents the nth neighbor's management domain, and m represents the mth indicator). The corresponding relationship is as Figure 4 shown. For the first hop on the path (i.e., the management domain where the source end node is located), there is no previous-hop neighbor node. Therefore, only the corresponding label needs to be calculated according to RKi and the indicator (the data required for the management domain corresponding to RKj is set to 0). Therefore, assuming that routing device i has N neighbor management domains, for M indicators, (N + 1) * M labels need to be calculated (* represents multiplication).
[0058] Routing-node sharing: The label jointly owned by routing nodes, which is used to generate and verify verification codes between routing nodes. The calculation method of the routing-node sharing label is the same as that of the end-node sharing label. For the same routing node, the values of the end-node sharing label and the routing-node sharing label tag i_n_m calculated can be the same or different. In the case of being different, the two labels are distinguished by the indicator (or other) field and do not interfere with each other. In this application, 32-bit indicator is used for distinction. The first bit being 0 indicates end-node sharing, and the first bit being 1 indicates routing-node sharing. Different indicators result in different calculated dynamic labels. For distinction, this application defaults that the end-node sharing label and the routing-node sharing label are different, and uses tag i_n_m to represent the end-node sharing label, and rTag i_n_m to represent the routing-node sharing label.
[0059] In addition, whether it is a shared end node or a routing node, for each session between a source user and a destination user, the label generation module generates a session dynamic label tag corresponding to the source and destination users sd , which is used for their encrypted communication or verification code generation.
[0060] It should be noted that the above boundary routing devices are all the ingress boundary routing devices of the management domain. For example, there may be other routing devices between R1 and R2, but it does not affect the dynamic label of this application because the neighbor relationship stored in this application is based on the management domain, as Figure 4 shown.
[0061] As an example, in the control server of the management domain, three modules, namely the routing device information module, the label generation module, and the label distribution module, are configured. The routing device information module stores routing device information, including the routing device identifier (id) and the neighbor device identifier. The label generation and label distribution modules store the dynamic label (tag) corresponding to the routing device. Each two management domain label generation modules share a base key DK (domain key), and this key is changed once every certain period (such as every day) and is only shared by each control server, and no other entity can obtain it. Further, the schematic diagram of the control server and the routing device is as Figure 3 shown.
[0062] As an example, the routing device information module shares all the boundary routing device nodes and their neighbor information. As Figure 4 shown, the stored information includes the routing device id, its neighbor routing device id, and the management domain (domain) where they are located.
[0063] As an example, the process of generating a label is as Figure 6 (a), (b) shown. Each management domain label generation module shares the DK of each domain (one DK is used between every two management domains and is only shared by the control servers). For example, if the routing device R i (identified as id i ) is located in domain I, when the base key is DK I , the RK i of the routing device is derived as follows:
[0064]
[0065] where MAC(.) is a verification code operation, including but not limited to various encryption operations such as AES encryption and SIPHASH that can be used for verification code generation.
[0066] As an example, the method for generating the dynamic label of a routing device is:
[0067]
[0068] Among them, AD N is the number of the domain (N) where the nth neighbor node is located when it serves as the previous hop (information such as the IP address prefix can also be used, and the management domain number is used in this application), and indicator m is the mth indicator. "||" represents a method of concatenating strings, and "exclusive OR" is used in this application. In particular, when RK i has no neighbors, that is, when it serves as the first-hop routing device for verification, AD 0 is all zeros.
[0069] The dynamic labels for end-node sharing and routing-node sharing are calculated using the same formula. The two can be distinguished by indicator. For example, the label calculated when the first bit of the indicator in binary is zero is the end-node sharing label tag i_n_m and the label calculated when the first bit is 1 is the routing-node sharing label rTag i_0_m . The update frequencies of the two dynamic labels are also different. For example, for the label used for end-node sharing, due to the large number of end nodes, in order to ensure that the label is not faked by other nodes, a higher update frequency (such as several minutes or even several seconds) can be adopted. The update frequency can be flexibly adjusted in practice. For example, if the update frequency of rTag is 10 times that of the end-node label, then the two can share one indicator for indication through modulo-ten operation when taking the value of indicator. For example, the update time slot units of the end-node sharing label are 1, 2, 3..., 10, 11, 12..., and the update time slot units of the routing-node sharing label are 10, 20, 30.... It should be noted that when indicator is in units of time slots, each control server needs to maintain synchronization at the granularity of the indicator time slot interval, and generally write the labels corresponding to 2 (or more) time slots at the same time to ensure that the routing device can retrieve the correct label according to indicator when the time slot jumps.
[0070] The session dynamic labels tag of the source and destination users sd are divided into two cases: end-node sharing and routing-node sharing:
[0071] End-node sharing: It is calculated based on the combination of the IP address of the end node and the id of the routing device on the transmission path from the source to the destination user:
[0072]
[0073] Among them, indicator 1 is the indicator used for the first data packet of the source and destination users.
[0074] Routing node sharing: Calculate based on the combination of the IDs of the source and destination routing nodes and the ID of the intermediate routing node:
[0075]
[0076] The only difference between the two is the addresses (or identifiers) of the source and destination users. Among them, indicator 1 is the indicator of the first data packet. In this application, tag sd does not change during this session because, except for the control server, tag sd is only owned by the sender and receiver and does not need to be replaced in each session.
[0077] Step S2, The label distribution writes in advance the end-node sharing of the routing node itself and the routing device dynamic label to the routing device node, and distributes the routing device dynamic label of each neighbor routing device of each routing node to each routing node.
[0078] Specifically, the label distribution module writes in advance the end-node sharing of the routing node itself and the routing node sharing device dynamic labels tag i_n_m and rTag i_n_m to the routing device node; and distributes the routing node sharing device dynamic label rTag i+1_n_m of its neighbor routing device i + 1 to each routing node i.
[0079] As an example, a label preset module is configured at the routing device node at the management domain boundary to receive the routing device dynamic label of the storage node itself from the control plane. The label distribution module writes tag i_n_m and rTag i_n_m in advance to the routing device node. As shown in Figure 5 are the tag i_n_m and rTag i_n_m stored by R1.
[0080] Step S3, Before each communication, the source and destination users obtain the routing device dynamic label and the source and destination user session dynamic label based on the label distribution of the control server in this domain, and implement the verification code addition and verification based on the routing device dynamic label and the user session dynamic label.
[0081] Specifically, before each communication, the source user obtains the routing device dynamic label and the source and destination user session dynamic label tag sd from the label distribution module of the control server in this domain. The destination user obtains the routing device dynamic label and tag sd from the label distribution module of the control server in this domain when receiving the first data packet. Based on the routing device dynamic label and the session dynamic label tag sd, it can implement the addition and verification of verification codes, providing a basis for realizing source and path verification.
[0082] As an example, the source and the destination obtain the tags corresponding to this session. For the intermediate nodes R1 - R2 - R3 - R4 in Figure 2 (b), respectively obtain the tags corresponding to R1 (no previous hop neighbor), R2 (previous hop neighbor R1, in domain domain1), R3 (previous hop neighbor R2, in domain domain2), and R4 (previous hop neighbor R3, in domain domain3). i_n_m . According to actual requirements, the source can only obtain the end - node shared tag of the first - hop node (R1), and the destination can only obtain the end - node shared tag of the last - hop node (R4).
[0083] For the source and destination session tags, the source user obtains the tag sd and the indicator 1 from the source management domain label distribution module before communication. The destination end - node user obtains the corresponding tag 1 from the destination management domain label distribution module according to the information such as the indicator sd in the packet header and the source user's IP address.
[0084] In summary, after the source, destination users, and routing devices obtain the corresponding dynamic tags, the source and destination users know the dynamic tags of the routing devices of all routing nodes on this path in this session, and the intermediate routing nodes know the dynamic tags of the routing devices of the neighbor nodes. Based on this, the source and destination users can generate verification codes by combining the packet information to realize source and path verification. At the same time, the source and destination users can also realize mutual verification or encrypted communication according to the shared tag sd .
[0085] According to the present invention, a dynamic label generation and sharing mechanism method for source and path verification is provided. By configuring a control server for each administrative domain, including configuring routing device information, label generation, and label distribution; wherein, the routing device information shares all border routing device nodes and node neighbor information; label generation generates a dynamic label representing the device identity for generating verification codes or session encryption through the control server; label distribution issues the corresponding dynamic labels to users and routing devices; label distribution pre-writes the end-node sharing of the routing node itself and the routing device dynamic labels shared by the routing nodes to the routing device nodes, and distributes the routing device dynamic labels of the neighbor routing devices of each routing node to each routing node; before each communication, the source and destination users obtain the routing device dynamic labels and the source and destination user session dynamic labels based on the label distribution of the control server in the local domain, and based on the routing device dynamic labels and the user session dynamic labels, the verification code addition and verification are realized. The present invention overcomes the problems of large computational and communication overheads and low reliability when generating and sharing labels for device identities between users and routing devices during the source and path verification process in large-scale inter-domain communications.
[0086] The following is a further explanation of the embodiments of the present invention through exemplary embodiments described with reference to the accompanying drawings, but not limited thereto.
[0087] This embodiment provides an embodiment of a dynamic label generation and sharing mechanism for source and path verification using the method of the present invention, and the main parameters are as follows:
[0088] In this embodiment, as Figure 2 (b) shows, the source user is H1, the destination user is H2, and the expected transmission path is R1 - R2 - R3 - R4. In this embodiment, session distribution dynamic labels (routing device labels and session labels) are established for H1 and H2 through the transmission path R1 - R2 - R3 - R4.
[0089] In this embodiment, the update frequency of DK is 24 hours, the indicator is identified in time slots, each time slot has a length of 3 minutes, and there are 480 time slots in 24 hours; the indicator uses a 32-bit identifier, the last 10 bits are used to represent the time slot, and the highest bit being 0 indicates end-host label sharing, and the highest bit being 1 indicates routing node label sharing (the middle 21 bits are reserved); in this embodiment, the indicator value refers to the time slot read from the indicator, such as 200 represents the 200th time slot, and 201 represents the 201st time slot.
[0090] In this embodiment, the MAC verification code algorithm uses AES, and the dynamic label length is 128 bits.
[0091] Exemplarily, the device identifiers corresponding to R1, R2,..., R8 are id 1, id 2 , ……, id 8 , the base key of the management domain where it is located is DK 1 , DK 2 , ……, DK 8 , the corresponding management domain number is AD 1 , AD 2 , ……, AD 8 .
[0092] Exemplarily, the control server obtains the neighbor node information of R1, R2, ……, R8, and stores the neighbor node information of R1 as Figure 4 shown.
[0093] Exemplarily, let the management domain numbers where R1, R2, R3, and R4 are located be respectively:[[]]
[0094] AD1 = 0x11111111111111111111111111111111,
[0095] AD2 = 0x22222222222222222222222222222222,
[0096] AD3 = 0x33333333333333333333333333333333,
[0097] AD4 = 0x44444444444444444444444444444444,
[0098] The identifiers of each routing device are respectively: id 1 = 0x10000001, id 2 = 0x10000002, id 3 = 0x10000003, id 4 = 0x10000004. The source user H1 needs to complete communication through R1, R2, R3, and R4, and implement shared dynamic labels with each routing node. First, derive the RK of each routing device according to formula (1):
[0099] RK 1 = 0x1f3d980e21821ffaf8222775ee4639b0,
[0100] RK 2 = 0xdeb5a4d0edc3837f89ed20c4841aafb5,
[0101] RK 3 = 0x0ea7fe91f209e7e01480d410691d6637,
[0102] RK 4 = 0x518dc387c64a1df77dc2f4760216d6c7.
[0103] R5 - R8 are also calculated in the same way.
[0104] Exemplarily, for R1, there are a total of 3 neighbors, R2, R3, R6. For time slots 200 and 201, taking time slot 200 as an example, as the first-hop node, the dynamic label of the routing device shared with the end-node user H1 is:
[0105]
[0106] For the previous hop in the domain domain2 where neighbor R2 is located, then:
[0107]
[0108] The label generation module generates corresponding dynamic labels of the routing device for R1, R2... R8 in the same way. And calculates the dynamic label rTag of the routing node sharing the routing device in the same calculation method.
[0109] This embodiment also needs to generate the session dynamic labels of hosts H1 and H2. According to formula (3):
[0110]
[0111] Let IP1 be 0x10000101, IP2 be 0x40000101, indicator 1 Take 200 and calculate the corresponding label tag 12 .
[0112] Exemplarily, R1, R2,..., R8 receive and store the dynamic labels of the routing device. Taking R1 as an example, the dynamic label of the routing device shared by the end-node corresponding to indicator 200 is tag 1_0_200 , tag 1_2_200 , tag 1_3_200 , tag 1_6_200 , the dynamic label of the routing device corresponding to 201 is tag 1_0_201 , tag 1_2_201 , tag 1_3_201 , tag 1_6_201 ; the label of the routing node sharing the dynamic label of the routing device corresponding to indicator 200 is rTag 1_0_200 , rTag 1_2_200 , rTag 1_3_200 , rTag 1_6_200, the tag corresponding to 201 is rTag 1_0_201 , rTag 1_2_201 , rTag 1_3_201 , rTag 1_6_201 .
[0113] Each node also stores the routing device dynamic tags shared by the routing nodes of the neighbor nodes. For example, R1 stores the rTag of R2 2_1_200 , rTag 2_1_201 ; R2 stores the rTag of R3 3_2_200 , rTag 3_2_201 ; and so on.
[0114] Exemplarily, before the source node user H1 communicates, it requests the session tags tag of the source and destination users from the domain control server in the local domain 12 , and the end-node shared tags of the path R1, R2, R3, R4 on this path (depending on the verification requirements, or only the tag of the first hop R1 is required). Taking the case where only the tag of R1 is required as an example, the source node user H1 stores 2 tags, tag 1_0_200 and tag 1_0_201 , indicating that this is the first hop of the path, the previous hop is 0, and the corresponding time slots are 200 and 201.
[0115] When the user H2 receives the first data packet, according to the indicator (200) and the source node user address inside, and the path information of R1, R2, R3, R4, it sends a request to the tag distribution module of the management domain control server where H2 is located, and obtains tag12 and the end-node shared tags of R1, R2, R3, R4 (depending on the verification requirements, or only the tag of the last hop R4 is required).
[0116] In summary, the users H1 and H2 and the nodes R1, R2, R3, R4 on the path have common dynamic tags. Among them, except for the control server, the session dynamic tag tag of H1 and H2 12 is only known to H1 and H2. For the routing device dynamic tags of R1, R2, R3, R4, H1 and H2 only know the part related to the current call path; in addition, the routing node R1 stores the routing node shared routing device dynamic tag of R2, R2 stores that of R3, and R3 stores that of R4. According to these shared tags, mutual verification or encrypted communication between entities can be realized, laying a foundation for source and path verification.
[0117] Secondly, a dynamic tag generation and sharing mechanism device for source and path verification according to an embodiment of the present invention will be described with reference to the accompanying drawings.
[0118] Figure 7 is a schematic structural diagram of a dynamic tag generation and sharing mechanism device for source and path verification according to an embodiment of the present invention.
[0119] As Figure 7 shown, the dynamic label generation and sharing mechanism device 10 for source and path verification includes: a configuration module 100, a distribution module 200, and a verification module 300.
[0120] The configuration module 100 is used to configure a control server for each management domain, including configuring routing device information, label generation, and label distribution; wherein, the routing device information is to share all border routing device node and node neighbor information; label generation is to generate a dynamic label representing the device identity for generating verification codes or session encryption through the control server; label distribution is to send the corresponding dynamic label to users and routing devices;
[0121] The distribution module 200 is used for label distribution to pre-write the end-node sharing of the routing node itself and the routing device dynamic label shared by the routing node to the routing device node, and to distribute the routing device dynamic label of the neighbor routing device of each routing node to each routing node;
[0122] The verification module 300 is used for the source and destination users to obtain the routing device dynamic label and the source and destination user session dynamic label based on the label distribution of the control server of the local domain before each communication, and to implement verification code addition and verification based on the routing device dynamic label and the user session dynamic label.
[0123] It should be noted that the foregoing explanation of the method embodiment of the dynamic label generation and sharing mechanism for source and path verification also applies to this device, and will not be elaborated here.
[0124] The device for the dynamic label generation and sharing mechanism for source and path verification proposed according to the embodiment of the present invention configures a control server for each management domain, including configuring routing device information, label generation, and label distribution; wherein, the routing device information is to share all border routing device node and node neighbor information; label generation is to generate a dynamic label representing the device identity for generating verification codes or session encryption through the control server; label distribution is to send the corresponding dynamic label to users and routing devices; label distribution pre-writes the end-node sharing of the routing node itself and the routing device dynamic label shared by the routing node to the routing device node, and distributes the routing device dynamic label of the neighbor routing device of each routing node to each routing node; before each communication, the source and destination users obtain the routing device dynamic label and the source and destination user session dynamic label based on the label distribution of the control server of the local domain, and implement verification code addition and verification based on the routing device dynamic label and the user session dynamic label. The present invention overcomes the problems of large computational and communication overhead and low reliability in generating and sharing labels for device identities between users and routing devices during the source and path verification process in large-scale inter-domain communication.
[0125] In addition, the terms "first" and "second" are for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, features defined with "first" and "second" may explicitly or implicitly include at least one such feature. In the description of the present invention, "a plurality of" means at least two, such as two, three, etc., unless otherwise specifically defined.
[0126] In the present invention, unless otherwise clearly specified and defined, terms such as "mounted", "connected", "coupled", "fixed", etc. shall be construed in a broad sense. For example, it may be a fixed connection, a detachable connection, or integrated; it may be a mechanical connection or an electrical connection; it may be directly connected or indirectly connected through an intermediate medium, and it may be the internal communication of two elements or the interaction relationship between two elements, unless otherwise clearly defined. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.
[0127] In the present invention, unless otherwise clearly specified and defined, the first feature being "on" or "under" the second feature may be that the first and second features are in direct contact, or the first and second features are indirectly in contact through an intermediate medium. Moreover, the first feature being "above", "over" and "on top of" the second feature may be that the first feature is directly above or obliquely above the second feature, or merely indicates that the first feature has a higher horizontal height than the second feature. The first feature being "under", "beneath" and "underneath" the second feature may be that the first feature is directly below or obliquely below the second feature, or merely indicates that the first feature has a lower horizontal height than the second feature.
[0128] In the description of this specification, the description with reference to terms such as "one embodiment", "some embodiments", "example", "specific example", or "some examples", etc. means that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described may be combined in a suitable manner in any one or more embodiments or examples. In addition, without contradiction, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.
[0129] Although the embodiments of the present invention have been shown and described above, it can be understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Those of ordinary skill in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present invention.
Claims
1. A dynamic label generation and sharing mechanism method for source and path verification, characterized in that, it includes the following steps: Configure a control server for each administrative domain, including configuring routing device information, label generation, and label distribution; wherein, the routing device information is to share all border routing device nodes and the neighbor information of the nodes; the label generation is to generate, by the control server, a dynamic label representing the device identity for generating verification codes or session encryption; the label distribution is to issue the corresponding dynamic labels to users and routing devices; The label distribution pre-writes the end-node sharing and routing-node sharing routing device dynamic labels of the routing device node itself into the routing node, and distributes the routing device dynamic labels of the neighbor routing devices of each routing node to each routing node; Before each communication, the source and destination users obtain the routing device dynamic labels and the source and destination user session dynamic labels based on the label distribution of the control server in their own domain, and implement verification code addition and verification based on the routing device dynamic labels and the user session dynamic labels; The label generation includes: The label generation of each management domain shares the domain-based basic key DK. If the routing device identifier is id i , and it is located in domain I, the basic key is DK I , and the fixed key RK of the routing device is derived i : Among them, DK I is the routing device ID i is the base key of the management domain I where it is located, and MAC(.) is a verification code operation; Generate session dynamic labels for users and routing devices, including: Among them, AD N is the number of the domain (N) where the nth neighbor node is located when it is the previous hop, and indicator m is the mth indicator, and "||" represents a way to concatenate strings.
2. The dynamic label generation and sharing mechanism method for source and path verification according to claim 1, characterized in that, The label generation is based on a basic key to derive a fixed key for each routing device, where the key corresponds to each routing device and the control server.
3. The dynamic label generation and sharing mechanism method for source and path verification according to claim 2, characterized in that, The routing device information includes a routing device identifier and a neighbor device identifier, and the label generation and label distribution are stored as dynamic labels corresponding to the routing device.
4. The dynamic label generation and sharing mechanism method for source and path verification according to claim 3, characterized in that, The issuing of the corresponding dynamic labels to users and routing devices includes: end-node sharing and routing-node sharing; wherein, The end-node sharing: a label jointly owned by the routing device node and the end node, used for generating and verifying verification codes between the routing device node and the end node; The routing-node sharing: a label jointly owned by the routing node and the routing node, used for the routing node to generate and verify verification codes for the routing node.
5. The dynamic label generation and sharing mechanism method for source and path verification according to claim 4, characterized in that, Based on the end-node sharing and routing-node sharing, the label generation generates, for each session of the source and destination users, a dynamic label corresponding to the source and destination users, which is used for their encrypted communication or verification code generation.
6. The dynamic label generation and sharing mechanism method for source and path verification according to claim 1, characterized in that, The session dynamic tag "tag" of the source and destination users sd It is divided into two cases: end-node sharing and routing-node sharing. Among them, The end-node sharing: calculated according to the IP address of the end node and the combination of the IDs of the routing devices on the transmission path between the source and the destination users; The routing-node sharing: calculated according to the combination of the IDs of the source and destination routing nodes and the ID of the intermediate routing node; Among them, indicator 1 is an indicator used for the first data packet of the source and destination users.
7. The method for dynamic label generation and sharing mechanism for source and path verification according to claim 1, characterized in that, The source and destination obtain the session dynamic label corresponding to the session, and distribute and obtain the label corresponding to the session based on the source and destination labels. The source user obtains a tag from the label distribution of the source management domain before communication. sd and indicator 1 , and the destination user obtains the corresponding tag from the label distribution of the destination management domain according to the indicator in the packet header 1 and the source user IP address information. sd .
8. An apparatus for dynamic label generation and sharing mechanism for source and path verification using the method according to claim 1, characterized in that, comprising: a configuration module, configured to configure a control server for each administrative domain, including configuring routing device information, label generation, and label distribution; wherein, the routing device information is to share all border routing device nodes and the neighbor information of the nodes; the label generation is to generate, by the control server, a dynamic label representing the device identity for generating a verification code or session encryption; the label distribution is to generate dynamic labels for users and routing devices and distribute corresponding labels; a distribution module, configured to, for the label distribution, pre-write the end-node sharing of the routing node itself and the routing device dynamic label shared by the routing node to the routing device node, and distribute the routing device dynamic label of the neighbor routing device of each routing node to each routing node; a verification module, configured to, before each communication, the source and destination users obtain the routing device dynamic label and the source and destination user session dynamic label based on the label distribution of the control server in the domain, and implement the addition and verification of the verification code based on the routing device dynamic label and the user session dynamic label.
Citation Information
Patent Citations
Source verification and path authentication method and device
CN105847034A
Reconfigurable dynamic path verification method based on authentication fragments
CN111541611A