Policy execution method, related apparatus, and storage medium
By generating and transmitting security policy information in the control plane functional devices, and then performing corresponding operations in the user plane devices and gateway devices, the security protection problem of the control plane functional devices under DDoS attacks is solved, ensuring the normal operation of user access functions.
Patent Information
- Application Number
- CN202011124155.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-10-20
- Publication Date
- 2025-11-07
- Estimated Expiration
- 2040-10-20
AI Technical Summary
Existing control plane functional devices lack comprehensive security protection in network architectures where control and user planes are separated, making them vulnerable to distributed denial-of-service (DDoS) attacks and affecting normal user access functions.
The control plane function device generates security policy information based on the security status and sends it to the user plane function device or gateway device. The user plane device and gateway device execute corresponding security protection operations according to the policy, including dropping, rate limiting or redirecting abnormal packets, limiting packet rate, etc., to prevent DDoS attacks.
By implementing flexible security policies, the control plane functional devices were able to provide normal user access services, thus avoiding the impact of DDoS attacks on user access functions.
Smart Images

Figure CN114448653B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] Embodiments of the present application relate to the field of network security, and in particular to a policy execution method, related apparatus, and storage medium. BACKGROUND
[0002] With the development of software defined network (SDN) technology and network function virtualization (NFV) technology, the metropolitan area network evolves from a network-centric network architecture to a data-centric network architecture, and the traditional network element device evolves from specialization to generalization. The evolution of the traditional network element device from specialization to generalization mainly solves two decouplings, i.e., decoupling of control and forwarding, and decoupling of software and hardware.
[0003] The control plane function (CP) device is the control plane of the virtual broadband network gateway (VBNG) in the control and user plane separation (CUPS) network architecture. The CP controls the access of home users in the metropolitan area. The CP manages a large number of user plane function (UP) devices. The CP processes user dialing messages and renewal messages sent by the UP. The CP also maintains a large number of north-south management channels and control channels for the UP. The CP also maintains a large number of east-west channels between the remote authentication dial in user service (Radius) server, the dynamic host configuration protocol (DHCP) server, and the primary and backup CPs.
[0004] In the existing technology, the CP lacks complete security protection and is vulnerable to distributed denial of service attack (DDOS), thereby affecting the normal user access function provided by the CP. SUMMARY
[0005] Embodiments of the present application provide a policy execution method, a control plane function device, a user plane function device, and a gateway device, which can ensure that the control plane function device provides normal user access function.
[0006] A first aspect of embodiments of the present application provides a policy execution method:
[0007] In the network architecture of control plane and user plane separation CUPS, the CP manages a large number of UPs, the CP processes user dialing messages and renewal messages sent by the UP, and also manages a large number of UP-oriented control channels, which is easy to be attacked by network attacks. The CP can generate corresponding security policy information according to the perception of the security state, wherein the security policy information includes user identification information and execution policy information. The CP sends the security policy information to the UP, so that the UP can perform corresponding security protection operations according to the security policy information sent by the CP, and avoid the CP from being unable to provide normal user access functions due to network attacks.
[0008] In the embodiments of the present application, the CP can generate corresponding security policy information according to different security states, and send the security policy information to the UP, so that the UP performs corresponding security protection operations, thereby more flexibly ensuring the normal provision of user access functions.
[0009] In combination with the first aspect of the embodiments of the present application, in the first implementation manner of the first aspect of the embodiments of the present application, the CP can determine whether there is an abnormal user according to the current service processing information. If there is an abnormal user, it indicates that the CP may be under DDOS attack, and the CP generates corresponding security policy information. Specifically, the service processing information can include at least one of user access restriction information, user authentication failure information and user online and offline information. The user access restriction information indicates whether the number of users performing dialing authentication under a certain virtual local area network (VLAN) exceeds the maximum allowed number of dialing authentication users. The user authentication failure information indicates whether the number of dialing authentication failures of a certain user is greater than a preset value. The user online and offline information indicates whether a certain user is always frequently switching between online and offline.
[0010] In the embodiments of the present application, the CP can determine whether there is an abnormal user according to the service processing information, and generate corresponding security policy information if there is, thereby improving the realizability of the scheme.
[0011] In combination with the first aspect of the embodiments of the present application, in the second implementation manner of the first aspect of the embodiments of the present application, when the CP determines that there are more than a preset number of abnormal messages in the messages generated by the UP, the CP can generate security policy information.
[0012] With reference to the first aspect of the embodiments of the present application, in the third implementation manner of the first aspect of the embodiments of the present application, the user identifier information includes first user identifier information, the first user identifier information includes an identifier of the UP, or includes an interface identifier of the UP, or includes a VLAN identifier, or includes a media access control (MAC) address of the user equipment. Here, the VLAN identifier can be an identifier of a VLAN accessed by the user equipment. The execution policy information can include a discard instruction, the discard instruction being used to instruct the UP to discard the packet according to the first user identifier information.
[0013] With reference to the first aspect of the embodiments of the present application, in the fourth implementation manner of the first aspect of the embodiments of the present application, if the rate of the packet sent by the UP to the CP is greater than a preset value, it is indicated that there can be a DDOS attack, and the CP can generate corresponding security policy information.
[0014] In the embodiments of the present application, when the rate of the packet sent by the UP is too large, the CP generates the security policy information, and the flexibility of the scheme is improved.
[0015] With reference to the fourth implementation manner of the first aspect of the embodiments of the present application, in the fifth implementation manner of the first aspect of the embodiments of the present application, the user identifier information includes second user identifier information, the second user identifier information includes an identifier of the UP, or includes a protocol type, or includes an interface identifier of the UP, or includes a VLAN identifier, where the protocol type includes an internet protool over ethernet (IPOE) or an internet protool over ethernet (IPOE). The execution policy information can include a rate limiting instruction or a redirection instruction, the rate limiting instruction being used to instruct the UP to limit the rate of the packet sent to the CP according to the second user identifier information, and the redirection instruction being used to instruct the UP to send the packet to a traffic cleaning device to obtain a packet processed by the traffic cleaning device, and then the traffic cleaning device sends the packet processed by the traffic cleaning device to the CP.
[0016] With reference to any one of the first aspect of the embodiments of the present application, the first implementation manner to the fifth implementation manner of the first aspect of the embodiments of the present application, in the sixth implementation manner of the first aspect of the embodiments of the present application, the CP can trigger the step of generating the security policy information according to the security state when it is determined that the system is in an overload state. Specifically, the system state can include at least one of a central processing unit state, a memory state, and a message queue depth state.
[0017] In the embodiments of the present application, the CP triggers the step of generating the security policy information according to the security state again when it is determined that the system is in an overload state, thereby improving the pertinence of the scheme.
[0018] In the seventh implementation manner of the first aspect of the embodiments of the present application, the security policy information generated by the CP and sent to the UP can be viewed through a network management device.
[0019] In the eighth implementation manner of the first aspect of the embodiments of the present application, after the CP sends the security policy information to the UP, the CP can further send a clearing instruction to the UP, where the clearing instruction is used for the UP to clear the previously received security policy information.
[0020] The second aspect of the embodiments of the present application provides a policy execution method.
[0021] In a control plane and user plane separation (CUPS) network architecture, the CP manages a large number of UPs, and the UPs can receive the security policy information sent by the CP, where the security policy information is generated by the CP according to a security state, and the security policy information includes user identifier information and policy execution information. The UPs can perform corresponding security protection operations according to the received security policy information, thereby ensuring that the CP can provide normal user access functions.
[0022] In the embodiments of the present application, the UPs can perform security protection operations according to the security policy information sent by the CP, thereby ensuring that the CP can provide normal user access functions.
[0023] In combination with the second aspect, in the first implementation manner of the second aspect of the embodiments of the present application, when the CP determines that there is an abnormal user according to the current service processing information, the UP can receive the security policy information sent by the CP. Specifically, the service processing information can include at least one of user access restriction information, user authentication failure information, and user online and offline information. The user access restriction information indicates whether the number of users performing dial-up authentication under a VLAN exceeds the maximum number of allowed dial-up authentication users. The user authentication failure information indicates whether the number of times of dial-up authentication failure of a certain user is greater than a preset value. The user online and offline information indicates whether the user frequently switches between online and offline.
[0024] In the embodiments of the present application, when the CP determines that there is an abnormal user according to the service processing information, the UP can receive the corresponding security policy information, thereby improving the realizability of the scheme.
[0025] With reference to the second aspect, in a second implementation of the second aspect of the embodiments of the present application, when the CP determines that there are more than a preset number of abnormal packets in the packets sent by the UP, the UP can receive the security policy information sent by the CP.
[0026] With reference to the first implementation of the second aspect or the second implementation of the second aspect, in a third implementation of the second aspect of the embodiments of the present application, the user identifier information includes first user identifier information, which includes an identifier of the UP, or an interface identifier of the UP, or a VLAN identifier, or a MAC address of a user equipment. The execution policy information can include a discard instruction, which is used to instruct the UP to discard the packets according to the first user identifier information.
[0027] In the embodiments of the present application, when the number of abnormal packets is greater than a preset value, the UP can receive the corresponding security policy information, thereby improving the flexibility of the scheme.
[0028] With reference to the second aspect, in a fourth implementation of the second aspect of the embodiments of the present application, when the rate of the packets sent by the UP to the CP is greater than a preset value, the UP can receive the security policy information sent by the CP.
[0029] With reference to the fourth implementation of the second aspect, in a fifth implementation of the second aspect of the embodiments of the present application, the user identifier information includes second user identifier information, which includes an identifier of the UP, or a protocol type, or an interface identifier of the UP, or a VLAN identifier, wherein the protocol type includes IPOE or IPOE. The execution policy information can include a rate limiting instruction or a redirection instruction, the rate limiting instruction being used to instruct the UP to limit the rate of sending the packets to the CP according to the second user identifier information, and the redirection instruction being used to instruct the UP to send the packets to a traffic cleaning device to obtain cleaned packets, and then the traffic cleaning device sends the cleaned packets to the CP.
[0030] With reference to any one of the first implementation to the fifth implementation of the second aspect, in a sixth implementation of the second aspect of the embodiments of the present application, the security policy information received by the UP can be viewed through a network management device.
[0031] With reference to any one of the first implementation to the sixth implementation of the second aspect, in a seventh implementation of the second aspect of the embodiments of the present application, after receiving the security policy information sent by the CP, the UP can further receive a cleaning instruction sent by the CP, which is used for the UP to clean the previously received security policy information.
[0032] The third aspect of the embodiments of the present application provides a policy execution method.
[0033] The CP can generate security policy information in order to avoid the situation that the traffic caused by the DDOS attack is greater than the expected value. After the security policy information is generated, the CP can send the security policy information to a network function virtualization orchestrator (NFVO). After receiving the security policy information, the NFVO can send the security policy information to a gateway device of the CP. The security policy information can be used by the gateway device of the CP to perform a corresponding security protection operation.
[0034] In the embodiments of the application, the CP can send the security policy information to the gateway device through the NFVO, so that the gateway device performs a corresponding security protection operation, and the system security of the CP is ensured.
[0035] With reference to the third aspect, in the first implementation manner of the third aspect, the NFVO can first send the security policy information to a network controller. After receiving the security policy information, the network controller can send the security policy information to the gateway device.
[0036] With reference to the first implementation manner of the third aspect, in the second implementation manner of the third aspect, the security policy information can include the IP address of the CP, a target IP address, and a rate limiting parameter. The target IP address includes any one of an IP address of a dynamic host configuration protocol server, an IP address of a remote authentication dial-in user service server, and an IP address of a target CP. Alternatively, the security policy information includes the IP address of the CP, a protocol type, and the rate limiting parameter. The protocol type includes any one of a remote authentication dial-in user service protocol, a dynamic host configuration protocol, and a redundant data backup protocol. Alternatively, the security policy information includes the IP address of the CP, the protocol type, the target IP address, a port number of the CP, a target port number, and the rate limiting parameter. The target port number includes any one of a port number of the dynamic host configuration protocol server, a port number of the remote authentication dial-in user service server, and a port number of the target CP. The security policy information can indicate that the gateway device limits the rate of sending a message to the CP.
[0037] With reference to any one of the third aspect, the first implementation manner of the third aspect to the second implementation manner of the third aspect, in the third implementation manner of the third aspect, the CP can also perform the step of generating the security policy information when it is determined that the state of the central processing unit, the state of the memory, and the state of the message queue depth are in an overload state.
[0038] In the embodiments of the present application, the CP generates the security policy information again when it is determined to be in an overload state, thereby improving the pertinence of the scheme.
[0039] In the fourth implementation manner of the third aspect, the security policy information sent by the CP to the NFVO can be viewed through a network management device.
[0040] The fourth aspect of the present application provides a policy execution method.
[0041] The gateway device can receive the security policy information sent by the NFVO, the security policy information being sent by the CP to the NFVO and then sent to the gateway device through the NFVO, and the security policy information can be used for the gateway device to perform a security protection operation.
[0042] In the embodiments of the present application, the gateway device can perform a security protection operation according to the received security policy information, thereby ensuring that the CP provides normal user access functions.
[0043] In combination with the fourth aspect, in the first implementation manner of the fourth aspect of the present application, the NFVO can first send the security policy information to a network controller, and the network controller can send the security policy information to the gateway device after receiving the security policy information.
[0044] In combination with the first implementation manner of the fourth aspect, in the second implementation manner of the fourth aspect of the present application, the security policy information can include an IP address of the CP, a target IP address, and a rate limiting parameter, wherein the target IP address includes any one of an IP address of a dynamic host configuration protocol server, an IP address of a remote authentication dial-in user service server, and an IP address of a target CP, or the security policy information also includes an IP address of the CP, a protocol type, and a rate limiting parameter, wherein the protocol type can include any one of a remote authentication dial-in user service protocol, a dynamic host configuration protocol, and a redundant data backup protocol, or the security policy information also includes the IP address of the CP, the protocol type, the target IP address, a port number of the CP, a target port number, and the rate limiting parameter, wherein the target port number can include any one of a port number of the dynamic host configuration protocol server, a port number of the remote authentication dial-in user service server, and a port number of the target CP. The security policy information can instruct the gateway device to limit the rate of sending messages to the CP.
[0045] In combination with the fourth aspect, in any one of the first implementation manner to the second implementation manner of the fourth aspect of the present application, in the third implementation manner of the fourth aspect of the present application, the security policy information received by the gateway device can be viewed through a network management device.
[0046] The fifth aspect of the embodiments of the present application provides a control plane function device, which has the functions of the control plane function device in the first aspect. The functions can be implemented by hardware, or by hardware executing corresponding software, and the hardware or software includes one or more modules corresponding to the above functions.
[0047] The sixth aspect of the embodiments of the present application provides a user plane function device, which has the functions of the control plane function device in the second aspect. The functions can be implemented by hardware, or by hardware executing corresponding software, and the hardware or software includes one or more modules corresponding to the above functions.
[0048] The seventh aspect of the embodiments of the present application provides a control plane function device, which has the functions of the control plane function device in the third aspect. The functions can be implemented by hardware, or by hardware executing corresponding software, and the hardware or software includes one or more modules corresponding to the above functions.
[0049] The eighth aspect of the embodiments of the present application provides a gateway device, which has the functions of the control plane function device in the fourth aspect. The functions can be implemented by hardware, or by hardware executing corresponding software, and the hardware or software includes one or more modules corresponding to the above functions.
[0050] The ninth aspect of the embodiments of the present application provides a control plane function device, comprising:
[0051] a processor, a memory, and a transceiver;
[0052] The processor is configured to execute a program in the memory, and the processor is configured to execute the method of any one of the first aspect, the first implementation of the first aspect to the eighth implementation of the first aspect according to instructions in the program code.
[0053] The tenth aspect of the embodiments of the present application provides a user plane function device, comprising:
[0054] a processor, a memory, and a transceiver;
[0055] The processor is configured to execute a program in the memory, and the processor is configured to execute the method of any one of the second aspect, the first implementation of the second aspect to the seventh implementation of the second aspect according to instructions in the program code.
[0056] The eleventh aspect of the embodiments of the present application provides a control plane function device, comprising:
[0057] a processor, a memory, and a transceiver;
[0058] The processor is configured to execute a program in the memory, and the processor is configured to execute the method of any one of the third aspect, the first implementation of the third aspect to the fourth implementation of the third aspect according to instructions in the program code.
[0059] The twelfth aspect of the embodiments of the present application provides a gateway device, comprising:
[0060] The processor, the memory, and the transceiver;
[0061] The processor is configured to execute a program in the memory, and the processor is configured to execute the method of any one of the fourth aspect, the first implementation of the fourth aspect to the third implementation of the fourth aspect according to instructions in the program code. BRIEF DESCRIPTION OF DRAWINGS
[0062] Figure 1 It is a schematic diagram of a network framework of CU separation in the embodiments of the present application;
[0063] Figure 2a It is a flowchart of a policy execution method in the embodiments of the present application;
[0064] Figure 2b It is a schematic diagram of a system in the embodiments of the present application;
[0065] Figure 3 It is another schematic diagram of a network framework of CU separation in the embodiments of the present application;
[0066] Figure 4a It is another flowchart of a policy execution method in the embodiments of the present application;
[0067] Figure 4b It is another schematic diagram of a system in the embodiments of the present application;
[0068] Figure 5 It is a structural diagram of a control plane function device in the embodiments of the present application;
[0069] Figure 6 It is a structural diagram of a user plane function device in the embodiments of the present application;
[0070] Figure 7 It is a structural diagram of a control plane function device in the embodiments of the present application;
[0071] Figure 8 It is a structural diagram of a gateway device in the embodiments of the present application;
[0072] Figure 9 It is another structural diagram of a control plane function device in the embodiments of the present application;
[0073] Figure 10 This is another structural schematic diagram of the user plane function device in the embodiments of this application;
[0074] Figure 11 This is another structural schematic diagram of the gateway device in this application embodiment. Detailed Implementation
[0075] This application provides a method for policy enforcement to ensure the normal operation of user access services.
[0076] The embodiments of this application can be used as follows: Figure 1 The network framework shown is as follows: Figure 1 As shown, the CP maintains a large number of north-south control channels to the UP, and east-west channels with the remote authentication dial-in userservice (RADIUS) server, dynamic host configuration protocol (DHCP) server, and backup CP. User equipment in the user network connects to the access network via a digital subscriber line access multiplexer (DSA). The DSA connects to the user plane device (UP). The UP forwards dial-up and lease renewal messages to the CP. The CP authenticates dial-up users with the RDA server via a gateway device. After authentication, the CP assigns IP addresses to the dial-up users through its local address pool, or it can assign IP addresses to the dial-up users via a DHCP server connected to the gateway device. Once assigned an IP address, the dial-up user can connect to the public network.
[0077] A distributed denial-of-service (DDoS) attack refers to an attacker using multiple user terminal devices as attack platforms to launch legitimate service requests that consume excessive network resources, preventing legitimate users from receiving server responses. Since network service providers (CPs) have numerous external connections and process various types of information, a DDoS attack could disrupt the access services of legitimate users. Therefore, comprehensive security measures are necessary for CPs.
[0078] Please see Figure 2a One flow of the strategy execution method in this application embodiment includes:
[0079] 201. CP indicates that the system is in an overload state;
[0080] When the system state of the CP is in an overload state, it means that the service processing capability of the CP has reached the limit, and thus the CP can be subjected to a DDOS attack. Specifically, the system state of the CP can be divided into three aspects, which are described as follows.
[0081] 1) The state of the central processor of the CP. The central processor of the CP is responsible for calculation and processing. For example, when the occupancy of the central processor of the CP reaches 90% or more, it can be considered that the state of the central processor of the CP has reached an overload state.
[0082] 2) The state of the memory of the CP. For example, when the occupancy of the memory of the CP reaches 85% or more, it can be considered that the state of the memory of the CP has reached an overload state.
[0083] 3) The state of the message queue depth of the CP. The CP can obtain messages from the message queue, and the message queue can relieve the pressure of the CP in processing messages. However, when too many messages accumulate in the message queue, it means that the number of messages is more than that in a normal business scenario. For example, when the message queue depth of the CP reaches 10% or more, it can be considered that the message queue depth of the CP has reached an overload state.
[0084] When at least one of the above three aspects is in an overload state, the CP can determine that the system has reached an overload state and can be subjected to a DDOS attack.
[0085] 202, the CP generates security policy information according to the security state information;
[0086] The CP can generate corresponding security policy information according to different security states, so as to ensure the provision of normal user access services, which are described as follows.
[0087] 1) When there is an abnormal user, the CP generates security policy information;
[0088] If the business behavior of a user is abnormal, the user can be a puppet machine controlled by an attacker, and if left unchecked, the abnormal user will continue to occupy the service processing resources of the CP to achieve the purpose of a DDOS attack.
[0089] The CP can determine whether there is an abnormal user according to user online and offline information. Specifically, for example, when a user successfully dials up the network, actively disconnects the network connection in a short time, and then dials up the network again in a short time, the user frequently switches between actively disconnecting the network and dialing up the network, and sends dialing messages to the CP each time the user dials up the network, which occupies the service processing capability of the CP. Thus, the CP can determine the user as an abnormal user and generate corresponding security policy information for the abnormal user.
[0090] The CP can determine whether there is an abnormal user according to the user authentication failure information. Specifically, for example, when a user fails to dial authentication for too many times, the purpose of the user can be to occupy the service processing capacity of the CP by repeatedly sending dial messages, so that the CP can determine that the user is an abnormal user.
[0091] The CP can determine whether there is an abnormal user according to the user access restriction information. Specifically, for example, a certain VLAN only allows access of 1000 users, but there are more than 1000 users dialing to access the Internet under the VLAN. In this case, it can be considered that there are a large number of abnormal users under the VLAN to launch a DDOS attack. The first user identification information can include the VLAN for the abnormal users under the VLAN.
[0092] Specifically, the first user identification information can include an identification of a UP, or a virtual local area network (VLAN) identification, or an interface identification of the UP, or a medium access control (MAC) address of a user equipment, wherein the identification of the UP is the identification of the UP receiving the security policy information, the VLAN identification and the MAC address of the user equipment are the VLAN identification and the MAC address carried in the dial message of the abnormal user, and the interface identification of the UP indicates an interface of the UP to which the dial message of the abnormal user is connected.
[0093] Specifically, when the number of abnormal users is not large, the first user identification information can include the MAC address of the equipment of the abnormal user, so as to accurately limit the dial message of the abnormal user. When the number of abnormal users is too large, the content of the first user identification information can be adjusted according to the distribution of the abnormal users. For example, a large number of abnormal users belong to the same VLAN, so it is not necessary to limit the MAC address of the equipment of each abnormal user, but to directly limit the VLAN. Therefore, the first user identification information can include the identification of the VLAN.
[0094] 2) When there are more than a preset number of abnormal messages in the messages sent by the UP, the CP generates security policy information;
[0095] Specifically, the CP can analyze the message sent by the UP. If there is a message with incorrect protocol type, incorrect length value, incorrect content carried, or incorrect sequence number, or a large number of messages with the same sequence number, the CP can determine these messages as abnormal messages. If the number of abnormal messages exceeds a preset value, the CP can determine the source distribution of the abnormal messages according to the identifier of the UP, the VLAN identifier, the interface identifier of the UP, and the MAC address of the user equipment, and generate security policy information. The security policy information includes first user identifier information and a discard instruction. The discard instruction is used to instruct the UP to discard the dial-up message matched according to the first user identifier information.
[0096] Specifically, if the abnormal messages come from Q MAC addresses, the first user identifier information can include the MAC addresses. The CP generates Q pieces of security policy information for the Q MAC addresses. The UP discards the dial-up messages from the Q MAC addresses according to the Q pieces of security policy information.
[0097] Specifically, if the abnormal messages come from T MAC addresses, but the T MAC addresses all belong to the same VLAN and include most of the MAC addresses under the VLAN, the first user identifier information can include the VLAN identifier. The CP only needs to generate one piece of security policy information for the VLAN. The UP discards all the dial-up messages from the VLAN according to the security policy information.
[0098] Specifically, if the abnormal messages come from T VLANs, but these VLANs all belong to the same interface and include most of the VLANs under the interface, the first user identifier information can include the interface identifier. The CP only needs to generate one piece of security policy information for the interface. The UP discards all the dial-up messages from the interface according to the security policy information.
[0099] Specifically, if the abnormal messages sent by the UP to the CP are not dial-up messages, in which case the abnormal messages do not carry information such as the VLAN identifier and the MAC address of the user equipment, the first user identifier information can include the identifier of the UP. The UP discards all the messages, or the security policy information can not carry user identifier information, but only carry the discard instruction. The UP can also discard all the messages according to the security policy information.
[0100] 3) When the rate of the message sent by the UP is greater than a preset value, the CP generates security policy information.
[0101] The rate of sending messages from the UP to the CP in different service scenarios will be in a stable range. If the rate of sending messages from the UP to the CP is greater than a preset value, it indicates that the current traffic condition does not conform to the service scenario, and the CP can be subjected to a DDOS attack. The CP can generate security policy information, wherein the security policy information includes second user identification information and execution policy information, and the execution policy information includes a rate limiting indication or a redirection indication.
[0102] Specifically, the CP can parse the dial-up message sent by the UP. If the rate of sending messages of the protocol type of point-to-point protocol over Ethernet (PPPOE) is greater than a preset value, the second user identification information includes a PPPOE protocol number. The UP can limit the rate of sending dial-up messages of the protocol type of PPPOE to the CP, or the UP can send the dial-up messages of the protocol type of PPPOE to a traffic cleaning device. The dial-up messages of the protocol type of PPPOE are sent to the CP after being cleaned by the traffic cleaning device.
[0103] Alternatively, if the rate of sending messages of the protocol type of internet protool over Ethernet (IPOE) is greater than a preset value, the second user identification information includes an IPOE protocol number. The UP can limit the rate of sending dial-up messages of the protocol type of IPOE to the CP, or the UP can send the dial-up messages of the protocol type of IPOE to a traffic cleaning device. The dial-up messages of the protocol type of IPOE are sent to the CP after being cleaned by the traffic cleaning device.
[0104] Specifically, on the basis of limiting abnormal messages based on the protocol type, the abnormal messages can be further limited more accurately according to the interface identifier of the UP. For example, when the rate of sending dial-up messages of an interface to the CP is greater than a preset value, the second user identification information can include the protocol type and the interface identifier of the interface. The UP can limit the rate of sending messages from the interface and of the protocol type consistent with the protocol type carried by the second user identification information to the CP, or send these messages to a traffic cleaning device for cleaning.
[0105] Specifically, on the basis of limiting the abnormal packets based on the protocol type, the abnormal packets can be further limited more accurately according to the VLAN, for example, when the rate of the dial-up packets under a VLAN sent to the CP is greater than a preset value, the second user identification information can include the protocol type and the identification of the VLAN, the UP can limit the rate of the packets from the VLAN and having the same protocol type as the protocol type carried by the second user identification information sent to the CP, or send the packets to the traffic cleaning device for cleaning processing.
[0106] Specifically, when the second user identification information includes the interface identification of the UP, the UP can limit the rate of the packets from the interface sent to the CP, or send the packets to the traffic cleaning device for cleaning processing.
[0107] Specifically, when the second user identification information includes the VLAN identification, the UP can limit the rate of the packets from the VLAN sent to the CP, or send the packets to the traffic cleaning device for cleaning processing.
[0108] Specifically, when the second user identification information includes the identification of the UP, the UP limits the rate of all the received packets or redirects them, or the security policy information can not include the second user identification information, but only include the rate limiting indication or the redirection indication, and in this case, the UP can also limit the rate of all the received packets or redirect them.
[0109] It should be noted that the security policy information generated by the CP can be viewed through the network management device.
[0110] It should be noted that the CP can not perform step 201, but directly perform step 202, which is not limited here.
[0111] 203. The CP sends security policy information to the UP.
[0112] After generating the corresponding security policy information according to different security states, the CP sends the security policy information to the UP.
[0113] 204. The UP performs security protection operations according to the security policy information.
[0114] After receiving the security policy information sent by the CP, the UP can perform corresponding security protection operations according to the security policy information, so as to ensure that the CP can normally provide user access services.
[0115] 205. The CP sends a cleaning instruction to the UP.
[0116] After the UP performs security protection operations based on the security policy information sent by the CP for a period of time, the CP can send a clearing instruction to the UP. This instruction is used by the UP to clear the previously received security policy information, and the UP will no longer perform security protection operations based on the security policy information.
[0117] In this embodiment of the application, the CP can send different security policy information for different security states. After receiving the security policy information, the UP can perform corresponding security protection operations, specifically identify the messages sent to the CP, and take corresponding measures to prevent the CP from being attacked by DDoS and unable to provide normal user access services.
[0118] Please see Figure 2b The above Figure 2a The corresponding process can be applied to, for example Figure 2b The system shown includes a control plane function device 201 and a user plane function device 202.
[0119] The embodiments of this application can be applied to, for example... Figure 3 The network framework diagram shown is as follows: Figure 3 As shown, the network framework includes a network function virtualization orchestrator (NFVO), a network service descriptor (NSD), a virtual network functions manager (VNFM), a virtual network functions descriptor (VNFD), a virtual infrastructure manager (VIM), and a network function virtualization infrastructure (NFVI). NFVO uses NSD to define the connection requirements between virtual network functions (VNFs) and external networks, and performs service lifecycle management. VNFM uses VNFD to define the internal network requirements and virtual machine specifications of the VNF, completes network connections within the VNF, and performs VNF lifecycle management.
[0120] VIM includes a cloud operating system, a data center management platform, and a network controller. The cloud operating system can provide resource service interfaces, and the data center management platform can support the creation of virtualization domain controllers and allocate virtual machine resource pools for NFV.
[0121] The NFVI includes a firewall, a gateway device, a top-of-rack switch, and a server, the CP is deployed on the server, and the network controller can issue a configuration to the firewall, the gateway device, and the top-of-rack switch. In one implementation, the gateway device and the firewall device can be combined. In another implementation, the gateway device, the firewall device, and the top-of-rack switch can be combined.
[0122] Referring to Figure 4a Another flow of the policy execution method in the embodiment of the application includes the following steps:
[0123] 401. The CP determines that the system is in an overload state.
[0124] When the system state of the CP is in an overload state, it means that the service processing capability of the CP has reached the limit, and therefore the CP can have suffered a DDOS attack. Specifically, the system state of the CP can be divided into three aspects, which are described as follows:
[0125] 1) The state of the central processor of the CP. The central processor of the CP is the core responsible for calculation and processing. For example, when the occupancy of the central processor of the CP reaches 90% or more, it can be considered that the state of the central processor of the CP has reached an overload state.
[0126] 2) The state of the memory of the CP. For example, when the occupancy of the memory of the CP reaches 85% or more, it can be considered that the state of the memory of the CP has reached an overload state.
[0127] 3) The state of the message queue depth of the CP. The CP can obtain messages from the message queue, and the message queue can alleviate the pressure of the CP in processing messages. However, when too many messages accumulate in the message queue, it means that the number of messages is more than that in a normal service scenario. For example, when the message queue depth of the CP reaches 10% or more, it can be considered that the state of the message queue depth of the CP has reached an overload state.
[0128] When at least one of the above three aspects is in an overload state, the CP can determine that the system has reached an overload state and can have suffered a DDOS attack.
[0129] 402. The CP generates security policy information.
[0130] The rate of messages sent by the dynamic host configuration protocol server, the remote user dial-up authentication server and the backup CP to the CP through the gateway device of the CP will be stable in a normal service scenario, wherein the backup CP is a CP that takes over the user access function of the CP when the CP stops working due to a fault. If the rate of messages sent by the dynamic host configuration protocol server, the remote user dial-up authentication server and the backup CP to the CP through the gateway device of the CP is greater than a preset value, it indicates that the CP may be under a DDOS attack, and a large number of messages will consume the service processing capability of the CP. Therefore, the CP needs to generate security policy information and send the security policy information to the gateway device of the CP, so that the gateway device limits the rate of messages sent by the dynamic host configuration protocol server, the remote user dial-up authentication server and the backup CP to the CP.
[0131] Specifically, the security policy information generated by the CP includes an internet protocol (IP) address of the CP, an IP address of the dynamic host protocol configuration server and a rate limiting parameter, and the security policy information is used for the gateway device of the CP to limit the rate of messages sent by the dynamic host protocol configuration server to the CP according to the rate limiting parameter.
[0132] Specifically, the security policy information generated by the CP includes an IP address of the CP, an IP address of the remote user dial-up authentication server and a rate limiting parameter, and the security policy information is used for the gateway device of the CP to limit the rate of messages sent by the remote user dial-up authentication server to the CP according to the rate limiting parameter.
[0133] Specifically, the security policy information generated by the CP includes an IP address of the CP, an IP address of the backup CP and a rate limiting parameter, and the security policy information is used for the gateway device of the CP to limit the rate of messages sent by the backup CP to the CP according to the rate limiting parameter.
[0134] Alternatively, the security policy information generated by the CP can also include an IP address of the CP, a dynamic host protocol configuration protocol and a rate limiting parameter, and the security policy information is used for the gateway device of the CP to limit the rate of messages sent by the dynamic host protocol configuration server to the CP according to the rate limiting parameter.
[0135] Alternatively, the security policy information generated by the CP can also include an IP address of the CP, a remote user dial-up authentication protocol and a rate limiting parameter, and the security policy information is used for the gateway device of the CP to limit the rate of messages sent by the remote user dial-up authentication server to the CP according to the rate limiting parameter.
[0136] Alternatively, the security policy information generated by the CP can also include an IP address of the CP, a redundant data backup protocol and a rate limiting parameter, and the security policy information is used for the gateway device of the CP to limit the rate of messages sent by the backup CP to the CP according to the rate limiting parameter.
[0137] Alternatively, the security policy information generated by the CP can also include the IP address of the CP, the port number of the CP, the dynamic host protocol configuration protocol, the IP address of the dynamic host configuration protocol server, the port number of the dynamic host configuration protocol server, and the rate limiting parameter, and the security policy information is used for the gateway device of the CP to limit the rate of the messages sent by the dynamic host protocol server to the CP.
[0138] Alternatively, the security policy information generated by the CP can also include the IP address of the CP, the port number of the CP, the remote user dial-up authentication protocol, the IP address of the remote user dial-up authentication server, the port number of the remote user dial-up authentication server, and the rate limiting parameter, and the security policy information is used for the gateway device of the CP to limit the rate of the messages sent by the remote user dial-up authentication server to the CP.
[0139] Alternatively, the security policy information generated by the CP can also include the IP address of the CP, the port number of the CP, the redundant data backup protocol, the IP address of the backup CP, the port number of the backup CP, and the rate limiting parameter, and the security policy information is used for the gateway device of the CP to limit the rate of the messages sent by the backup CP to the CP.
[0140] It should be noted that the rate limiting parameter can be a committed information rate (CIR) parameter and a committed burst size (CBS) parameter.
[0141] It should be noted that the CP can also not perform step 401, and directly perform step 402, which is not limited here.
[0142] 403. The CP sends the security policy information to a network function virtualization orchestrator (NFVO);
[0143] The NFVO is responsible for the overall management of network services, virtualized network functions, and resources, and is the core of the network function virtualization architecture, so the CP needs to send the security policy information to the NFVO.
[0144] 404. The NFVO sends the security policy information to a network controller;
[0145] The network controller is responsible for the issuance of various configurations, so the NFVO sends the security policy information to the network controller.
[0146] 405. The network controller sends the security policy information to a gateway device;
[0147] 406. The gateway device performs a rate limiting operation according to the security policy information.
[0148] The gateway device limits the rate at which corresponding messages are sent to the CP based on the received security policy information. These include authentication response messages and authorization messages sent by the remote user dial-up authentication server, dynamic host configuration protocol messages sent by the dynamic host configuration protocol server, and user backup messages sent by the standby CP.
[0149] In this embodiment, the CP can send security policy information to the gateway device without needing to detect a security threat. The CP can set rate limiting parameters with the dynamic host configuration protocol server, remote user dial-up authentication server, and backup CP according to normal business scenarios. This can defend against possible DDoS attacks without affecting normal business functions.
[0150] Please see Figure 4b The above Figure 4a The corresponding process can be applied to, for example Figure 4b The system includes a control plane function device 401, a network function virtualization orchestrator 402, a network controller 403, and a gateway device 404.
[0151] The control plane functional device in the embodiments of this application is described below:
[0152] Please see Figure 5 In this embodiment, the control plane function device 500 includes a generation unit 502 and a transmission unit 503.
[0153] The generation unit 502 is used to generate security policy information based on the security status. The security policy information includes user identification information and execution policy information.
[0154] The generation unit 502 is specifically used to generate security policy information when the CP determines that there are abnormal users based on the business processing information. The business processing information includes at least one of user access restriction information, user authentication failure information, and user online / offline information. The content of the generated security policy information is the same as described above. Figure 2a The same applies to the embodiments shown, and will not be described in detail here;
[0155] The generation unit 502 is specifically used to generate security policy information when the CP determines that there are more than a preset number of abnormal messages in the messages sent by the UP. The content of the generated security policy information is the same as described above. Figure 2a The same applies to the embodiments shown, and will not be described in detail here;
[0156] The generation unit 502 is specifically used to generate security policy information when the CP determines that the rate at which the UP sends messages is greater than a preset value. The content of the generated security policy information is the same as described above. Figure 2a The same applies to the embodiments shown, and will not be described in detail here;
[0157] The sending unit 503 is configured to send security policy information to the UP, where the security policy information is used to instruct the UP to perform a security protection operation.
[0158] The sending unit 503 is further configured to send a clearing instruction to the UP, where the clearing instruction is used for the UP to clear the received security policy information.
[0159] Based on the control plane function device 500 shown in the foregoing Figure 5 The control plane function device 500 in the embodiment of the present application further includes a determining unit 501.
[0160] The determining unit 501 is configured to determine to perform a step of generating security policy information according to a security state when a system state is in an overload state, where the system state includes at least one of a central processing unit state, a memory state and a message queue depth state.
[0161] Please refer to Figure 6 The user plane function device 600 in the embodiment of the present application includes a receiving unit 601 and an executing unit 602.
[0162] The receiving unit 601 is configured to receive security policy information sent by the CP, where the security policy information is generated by the CP according to a security state, and the security policy information includes user identifier information and execution policy information.
[0163] The executing unit 602 is configured to perform a security protection operation according to the security policy information.
[0164] Optionally, when the CP determines that there is an abnormal user according to the service processing information;
[0165] The receiving unit 601 is specifically configured to receive the security policy information, and the content of the received security policy information is similar to that in the foregoing Figure 2a embodiment, and details are not repeated herein.
[0166] Optionally, when the CP determines that there are more than a preset number of abnormal messages in the messages sent by the UP;
[0167] The receiving unit 601 is specifically configured to receive the security policy information, and the content of the received security policy information is similar to that in the foregoing Figure 2a embodiment, and details are not repeated herein.
[0168] Optionally, when the CP determines that the rate of the messages sent by the UP is greater than a preset value;
[0169] The receiving unit 601 is specifically configured to receive the security policy information, and the content of the received security policy information is similar to that in the foregoing Figure 2a embodiment, and details are not repeated herein.
[0170] Optionally, the execution unit 602 is further configured to clear the received security policy information according to the clearing instruction.
[0171] Referring to Figure 7 , the control plane function device 700 in the embodiment of the application comprises a generation unit 702 and a sending unit 703.
[0172] The generation unit 702 is configured to generate security policy information, and the content of the security policy information is the same as that of the aforementioned Figure 4a The embodiment shown in the figure is similar to the embodiment shown in the figure, and details are not repeated here.
[0173] The sending unit 703 is configured to send the security policy information to the NFVO.
[0174] Based on the control plane function device 700 described above Figure 7 , the control plane function device 700 in the embodiment of the application comprises a determination unit 701.
[0175] The determination unit 701 is configured to determine to perform the step of generating the security policy information according to the security state when the system state is in an overload state, and the system state comprises at least one of a central processor state, a memory state, and a message queue depth state.
[0176] Referring to Figure 8 , the gateway device 800 in the embodiment of the application comprises a receiving unit 801 and an execution unit 802.
[0177] The receiving unit 801 is configured to receive the security policy information sent by the NFVO, and the security policy information is sent by the CP to the NVFO, and is used for the NFVO to send the security policy information to the gateway device.
[0178] The execution unit 802 is configured to perform a security protection operation according to the security policy information.
[0179] Optionally, the execution unit 802 is specifically configured to limit the rate of sending a message to the CP according to the security policy information.
[0180] Figure 9 The control plane function device structure diagram provided by the embodiment of the application, the control plane function device 900 can comprise one or more central processing units (central processing units, CPU) 901 and a memory 905, and the memory 905 stores one or more application programs or data.
[0181] The memory 905 can be volatile memory or non-volatile memory. The programs stored in the memory 905 can include one or more modules, each of which can include a series of instruction operations in the server. Further, the central processor 901 can be configured to communicate with the memory 905 and execute the series of instruction operations in the memory 905 on the control plane function device 900.
[0182] The control plane function device 900 can further include one or more power supplies 902, one or more wired or wireless network interfaces 903, one or more input / output interfaces 904, and / or one or more operating systems, such as Windows Server™, Mac OS X™, Unix™, Linux™, FreeBSD™, etc.
[0183] The central processor 901 can execute the operations performed by the CP in the embodiments described above, and specific details are not repeated here. Figure 2a Or Figure 4a The central processor 901 can execute the operations performed by the CP in the embodiments described above, and specific details are not repeated here.
[0184] Figure 10 The user plane function device 1000 provided by the embodiments of the present application is a structure schematic diagram of a user plane function device. The user plane function device 1000 can include one or more central processing units (CPU) 1001 and a memory 1005, and the memory 1005 stores one or more application programs or data.
[0185] The memory 1005 can be volatile memory or non-volatile memory. The programs stored in the memory 1005 can include one or more modules, each of which can include a series of instruction operations in the server. Further, the central processor 1001 can be configured to communicate with the memory 1005 and execute the series of instruction operations in the memory 1005 on the user plane function device 1000.
[0186] The user plane function device 1000 can further include one or more power supplies 1002, one or more wired or wireless network interfaces 1003, one or more input / output interfaces 1004, and / or one or more operating systems, such as Windows Server™, Mac OS X™, Unix™, Linux™, FreeBSD™, etc.
[0187] The central processor 1001 can execute the operations performed by the UP in the embodiments described above, and specific details are not repeated here. Figure 2a The central processor 1001 can execute the operations performed by the UP in the embodiments described above, and specific details are not repeated here.
[0188] Figure 11is a schematic diagram of a gateway device structure provided in the embodiments of the present application. The gateway device 1100 can include one or more central processing units (CPUs) 1101 and a memory 1105 in which one or more application programs or data are stored.
[0189] The memory 1105 can be volatile storage or persistent storage. The programs stored in the memory 1105 can include one or more modules, each of which can include a series of instruction operations in the server. Further, the central processing unit 1101 can be configured to communicate with the memory 1105 and execute the series of instruction operations in the memory 1105 on the gateway device 1100.
[0190] The gateway device 1100 can also include one or more power supplies 1102, one or more wired or wireless network interfaces 1103, one or more input / output interfaces 1104, and / or one or more operating systems, such as Windows ServerTM, Mac OS XTM, UnixTM, LinuxTM, FreeBSDTM, etc.
[0191] The central processing unit 1101 can execute the operations of the gateway device in the embodiments described above, which will not be described here in detail. Figure 4a The central processing unit 1101 can execute the operations of the gateway device in the embodiments described above, which will not be described here in detail.
[0192] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the foregoing method embodiments, which will not be described here in detail.
[0193] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the foregoing method embodiments, which will not be described here in detail.
[0194] In several embodiments provided in the present application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic, for example, the division of the units is only a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units or components shown or discussed can be indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.
[0195] The units described as separate components may or may not be physically separate, and the components displayed as units may or may not be physical units, that is, may be located in one place, or may be distributed to multiple network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment scheme.
[0196] In addition, each functional unit in each embodiment of the present application can be integrated in one processing unit, or each unit can be physically present alone, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.
[0197] The integrated unit, if realized in the form of a software functional unit and sold or used as an independent product, can be stored in a computer readable storage medium. Based on such understanding, the technical scheme of the present application essentially or the part that contributes to the prior art or the whole or part of the technical scheme can be embodied in the form of a software product. The computer software product is stored in a storage medium, including a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, read-only memory), a random access memory (RAM, random access memory), a magnetic disk or an optical disk, and various program code storage media.
Claims
1. A method of policy enforcement, the method comprising: A control plane (CP) applied to a virtual broadband network gateway (VBNG) with control plane and user plane separated, comprising: The CP generates security policy information according to a security state, wherein the security policy information comprises user identification information and execution policy information; The CP sends the security policy information to a user plane (UP) of the VBNG, wherein the security policy information is used to instruct the UP to perform security protection operations.
2. The policy enforcement method of claim 1, wherein, The CP generates the security policy information according to a security state, comprising: When the CP determines that there is an abnormal user according to service processing information, the CP generates the security policy information, wherein the service processing information comprises at least one of user access restriction information, user authentication failure information and user online and offline information.
3. The policy enforcement method of claim 1, wherein, The CP generates the security policy information according to a security state, comprising: When the CP determines that there are more than a preset number of abnormal packets in the packets sent by the UP, the CP generates the security policy information.
4. The policy enforcement method according to claim 2 or 3, characterized in that, The user identification information comprises first user identification information, wherein the first user identification information comprises an identification of the UP; Or, the first user identification information comprises an interface identification of the UP; Or, the first user identification information comprises a virtual local area network (VLAN) identification; Or, the first user identification information comprises a media access control (MAC) address of a user equipment; The execution policy information comprises a discard instruction, wherein the discard instruction is used for the UP to discard packets according to the first user identification information.
5. The policy enforcement method of claim 1, wherein, The CP generates the security policy information according to a security state, comprising: When the CP determines that the rate of the packets sent by the UP is greater than a preset value, the CP generates the security policy information.
6. The policy enforcement method of claim 5, wherein, The user identification information comprises second user identification information, wherein the second user identification information comprises an identification of the UP; Or, the second user identification information comprises a protocol type; Or, the second user identification information comprises an interface identification of the UP; Or, the second user identification information comprises a VLAN identification; The protocol type comprises an Ethernet Point-to-Point Protocol (PPPOE) or an Ethernet-based Internet Protocol (IPOE); The execution policy information comprises a rate limiting instruction or a redirection instruction, wherein the rate limiting instruction is used to instruct the UP to limit the rate of the packets sent to the CP according to the second user identification information; and the redirection instruction is used to instruct the UP to send the packets to a traffic cleaning device according to the second user identification information to obtain cleaned packets; The traffic cleaning device sends the cleaned packets to the CP. The method further comprises:
7. The policy enforcement method according to any one of claims 1 to 3, wherein, When a system state is in an overload state, the CP determines to execute the step of generating the security policy information according to a security state, wherein the system state comprises at least one of a central processing unit state, a memory state and a message queue depth state. A user plane (UP) applied to a virtual broadband network gateway (VBNG) with control plane and user plane separated, comprising:
8. A policy enforcement method characterized by, The UP receives security policy information sent by a control plane function device CP of the VBNG, the security policy information is generated by the CP according to a security state, and the security policy information includes user identifier information and execution policy information; The UP performs a security protection operation according to the security policy information.
9. The policy enforcement method of claim 8, wherein, When the CP determines that there is an abnormal user according to service processing information, the UP receives the security policy information sent by the CP, and the service processing information includes at least one of user access restriction information, user authentication failure information, and user online and offline information.
10. The policy enforcement method of claim 8, wherein, When the CP determines that there are more than a preset number of abnormal packets in the packet sent by the UP, the UP receives the security policy information sent by the CP.
11. The policy enforcement method according to claim 9 or 10, characterized in that, The user identifier information includes first user identifier information, and the first user identifier information includes an identifier of the UP. Or, the first user identifier information includes an interface identifier of the UP. Or, the first user identifier information includes a virtual local area network (VLAN) identifier. Or, the first user identifier information includes a media access control (MAC) address of a user equipment. The execution policy information includes a discard instruction, and the discard instruction is used for the UP to discard a packet according to the first user identifier information.
12. The policy enforcement method of claim 8, wherein, When the CP determines that the rate of the packet sent by the UP is greater than a preset value, the UP receives the security policy information generated by the CP.
13. The policy enforcement method of claim 12, wherein, The user identifier information includes second user identifier information, and the second user identifier information includes an identifier of the UP. Or, the second user identifier information includes a protocol type. Or, the second user identifier information includes an interface identifier of the UP. Or, the second user identifier information includes a VLAN identifier. The protocol type includes an Ethernet Point-to-Point Protocol (PPPOE) or an Ethernet-based Internet Protocol (IPOE). The execution policy information includes a rate limiting instruction or a redirection instruction, the rate limiting instruction is used to instruct the UP to limit the rate of a packet sent to the CP according to the second user identifier information, and the redirection instruction is used to instruct the UP to send a packet to a traffic cleaning device according to the second user identifier information to obtain a cleaned packet. The traffic cleaning device sends the cleaned packet to the CP. A control plane function device CP applied to a virtual broadband network gateway (VBNG) with a control plane and a user plane separation includes:
14. A method of policy enforcement, the method comprising: The CP generates security policy information; The CP sends the security policy information to a network function virtualization orchestrator (NFVO); The security policy information is also used for the NFVO to send the security policy information to a gateway device of the CP, and the security policy information is used to instruct the gateway device to perform a security protection operation. The security policy information is used for the NFVO to send the security policy information to a network controller, and the security policy information is also used for the network controller to send the security policy information to the gateway device.
15. The policy enforcement method of claim 14, wherein, 16. The policy enforcement method of claim 15, wherein, The security policy information comprises an IP address of the CP, a target IP address, and a rate limiting parameter, the target IP address comprising any one of an IP address of a dynamic host configuration protocol server, an IP address of a remote authentication dial-in user service server, and an IP address of a target CP; Or, the security policy information comprises an IP address of the CP, a protocol type, and a rate limiting parameter, the protocol type comprising any one of a remote authentication dial-in user service protocol, a dynamic host configuration protocol, and a redundant data backup protocol; Or, the security policy information comprises an IP address of the CP, the protocol type, the target IP address, a port number of the CP, a target port number, and a rate limiting parameter, the target port number comprising any one of a port number of a dynamic host configuration protocol server, a port number of a remote authentication dial-in user service server, and a port number of the target CP; The security policy information is used to instruct the gateway device of the CP to limit a rate of sending messages to the CP.
17. The policy enforcement method according to any one of claims 14 to 16, characterized in that, The method further comprises: When a central processing unit state, a memory state, and a message queue depth state are in an overload state, the CP determines to perform the step of generating the security policy information.
18. A method of policy enforcement, the method comprising: A gateway device of a control plane function device (CP) applied to a virtual broadband network gateway (VBNG) system with a control plane and a user plane separation, comprising: The gateway device of the CP receives security policy information sent by a network function virtualization orchestrator (NFVO), the security policy information being generated by the CP and sent to the NFVO, and the security policy information being further used for the NFVO to send the security policy information to the gateway device of the CP.
19. The policy enforcement method of claim 18, wherein, The NFVO sending the security policy information to the gateway device of the CP comprises: The NFVO sends the security policy information to a network controller, and the security policy information is further used for the network controller to send the security policy information to the gateway device of the CP.
20. The policy enforcement method of claim 19, wherein, The security policy information comprises an Internet protocol (IP) address of the CP, a target IP address, and a rate limiting parameter, the target IP address comprising any one of an IP address of a dynamic host configuration protocol server, an IP address of a remote authentication dial-in user service server, and an IP address of a target CP; Or, the security policy information comprises an IP address of the CP, a protocol type, and a rate limiting parameter, the protocol type comprising any one of a remote authentication dial-in user service protocol, a dynamic host configuration protocol, and a redundant data backup protocol; Or, the security policy information comprises an IP address of the CP, the protocol type, the target IP address, a port number of the CP, a target port number, and a rate limiting parameter, the target port number comprising any one of a port number of a dynamic host configuration protocol server, a port number of a remote authentication dial-in user service server, and a port number of the target CP; The security policy information is used to instruct the gateway device to limit a rate of sending messages to the CP.
21. A control plane function device applied in a virtual broadband network gateway (VBNG) with control plane and user plane separation, characterized in that, Comprise: a memory, a transceiver, and a processor; The memory is used to store a program; The processor is configured to execute a program in the memory, and the processor is configured to execute instructions in the code of the program to enable the control plane function device to perform the method in any one of claims 1 to 7.
22. A user plane function device applied to a virtual broadband network gateway (VBNG) in control plane and user plane separation, characterized in that, Comprising: a memory, a transceiver, a processor; wherein the memory is configured to store a program; the processor is configured to execute a program in the memory, and the processor is configured to execute instructions in the code of the program to enable the user plane function device to perform the method in any one of claims 8 to 13.
23. A control plane function device applied in a virtual broadband network gateway (VBNG) with control plane and user plane separation, characterized in that, Comprising: a memory, a transceiver, a processor; wherein the memory is configured to store a program; the processor is configured to execute a program in the memory, and the processor is configured to execute instructions in the code of the program to enable the control plane function device to perform the method in any one of claims 14 to 17.
24. A gateway device applied to a control plane function device CP in a virtual broadband network gateway (VBNG) with control plane and user plane separation, characterized in that, Comprising: a memory, a transceiver, a processor; wherein the memory is configured to store a program; the processor is configured to execute a program in the memory, and the processor is configured to execute instructions in the code of the program to enable the gateway device to perform the method in any one of claims 18 to 20.
25. A communication system, characterized by The communication system comprises a control plane function device CP applied to a virtual broadband network gateway VBNG with control plane and user plane separated, and a user plane function device UP of the VBNG; The CP is configured to generate security policy information according to a security state, wherein the security policy information comprises user identification information and execution policy information; The CP is further configured to send the security policy information to the UP; The UP is configured to receive the security policy information sent by the CP; The UP is further configured to perform a security protection operation according to the security policy information.
26. A communication system, characterized by The communication system comprises a control plane function device CP applied to a virtual broadband network gateway VBNG with control plane and user plane separated, a network function virtualization orchestrator NFVO, a network controller, and a gateway device of the CP; The CP is configured to generate security policy information; The CP is further configured to send the security policy information to the NFVO; The NFVO is configured to send the security policy information to the network controller; The network controller is configured to send the security policy information to the gateway device of the CP; The gateway device of the CP is configured to perform a security protection operation according to the security policy information.
Citation Information
Patent Citations
Security service system and method
CN108092934A
Method and system for user plane traffic characteristics and network security
US20190068625A1