Communication Control Method, Communication Terminal, and Storage Medium

By generating characteristic information when establishing a security alliance between communication terminals and carrying the negotiation message of the information during reauthentication, the problem that both parties of the communication cannot identify the source of the negotiation message is solved, and processing efficiency and data security are improved.

CN114448747BActive Publication Date: 2025-06-10NANJING ZHONGXING XIN SOFTWARE CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202011120129.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-10-19
Publication Date
2025-06-10
Estimated Expiration
2040-10-19

AI Technical Summary

Technical Problem

Under the IPSec protocol, both parties to the communication cannot identify the source of the negotiation message during reauthentication, resulting in data security risks.

Method used

When the first communication terminal establishes a security alliance with the second communication terminal, a negotiation message of characteristic information is generated and a negotiation message carrying the characteristic information during reauthentication. After receiving it, the second communication terminal recognizes the source of the message through the characteristic information.

Benefits of technology

Improve processing efficiency, eliminate data security risks, and ensure security and accuracy during re-authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114448747B_ABST
    Figure CN114448747B_ABST
Patent Text Reader

Abstract

The communication control method, communication terminal, and storage medium provided by the embodiments of the present application. In this method, when a first communication terminal establishes a first security alliance with a second communication terminal, the first communication terminal can generate feature information, where the feature information can be used to identify the first security alliance. Thus, when the first communication terminal initiates re-authentication, the first communication terminal can send a first negotiation message carrying the first feature information to the second communication terminal. In this way, when the second communication terminal receives the first negotiation message sent by the first communication terminal, it can determine whether the negotiation message carries feature information. If so, the second communication terminal can determine that the negotiation message is a message sent by the first communication terminal due to re-authentication and directly re-establish a second security alliance with the first communication terminal. Therefore, the embodiments of the present application not only improve the processing efficiency but also do not have the problem of data security risks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technologies, and in particular, to a communication control method, a communication terminal, and a storage medium. Background Art

[0002] The Internet Protocol Security (IPSec) protocol family is a series of protocols defined by the Internet Engineering Task Force (IETF), which can provide cryptographic protection for Internet Protocol (IP) data packets.

[0003] Currently, if both communication parties want to use IPSec to protect data transmission, they can use the Internet Key Exchange Protocol (IKE) to negotiate and establish a Security Association (SA), and then use the security association to establish an IPSec tunnel and perform data transmission in the IPSec tunnel. During the life cycle of the security association, when either of the two communication parties causes the initiator to initiate re-authentication for some reason, for example, when one party believes that the security of data transmission is insufficient and causes the initiator to initiate re-authentication, the initiator will send a corresponding negotiation message to the responder for negotiation and re-establish the security association. However, when the responder receives the negotiation message, it cannot identify whether the message is sent by the initiator due to a re-authentication request, so there is a problem of data security risks. Summary of the Invention

[0004] Based on this, embodiments of this application provide a communication control method, a communication terminal, and a storage medium, so that when the second communication terminal receives a negotiation message sent by the first communication terminal, it can identify whether the negotiation message is sent by the first communication terminal due to re-authentication.

[0005] In a first aspect, an embodiment of this application provides a communication control method for a first communication terminal, and the method includes:

[0006] Generate feature information when establishing a first security association with a second communication terminal, where the feature information is used to identify the first security association;

[0007] When re - authentication is initiated to the second communication terminal, a first negotiation message carrying the feature information is sent to the second communication terminal, so that the second communication terminal determines whether the first negotiation message carries the feature information. If so, the second communication terminal determines that the first negotiation message is a message sent by the first communication terminal due to re - authentication and re - establishes a second security alliance with the first communication terminal.

[0008] In addition, an embodiment of the present application further provides a communication control method for a second communication terminal. The method includes:

[0009] When receiving a first negotiation message sent by a first communication terminal, determine whether the first negotiation message carries feature information, where the feature information is information generated by the first communication terminal when establishing a first security alliance with the second communication terminal for identifying the first security alliance;

[0010] If so, determine that the first negotiation message is a message sent by the first communication terminal due to re - authentication and re - establish a second security alliance with the first communication terminal.

[0011] In a second aspect, an embodiment of the present application provides a communication terminal, including a processor and a memory; the memory is used to store a computer program; the processor is used to execute the computer program and implement the communication control method as described in the first aspect when executing the computer program.

[0012] In a third aspect, an embodiment of the present application provides a computer - readable storage medium. The computer - readable storage medium stores a computer program, and when the computer program is executed by a processor, the processor is caused to implement the communication control method as described in the first aspect.

[0013] In the communication control method, communication terminal and storage medium provided by the embodiments of the present application, when the first communication terminal and the second communication terminal establish a first security alliance, the first communication terminal can generate feature information, where the feature information can be used to identify the first security alliance. Thus, when the first communication terminal initiates re - authentication, the first communication terminal can send a first negotiation message carrying the first feature information to the second communication terminal. In this way, when the second communication terminal receives the first negotiation message sent by the first communication terminal, it can determine whether the negotiation message carries feature information. If so, the second communication terminal can determine that the negotiation message is a message sent by the first communication terminal due to re - authentication and directly re - establish a second security alliance with the first communication terminal. Therefore, the embodiments of the present application not only improve the processing efficiency but also have no problem of data security risks. Description of the Drawings

[0014] Figure 1An optional application scenario schematic diagram for each embodiment of the present application;

[0015] Figure 2 An interaction schematic diagram for negotiation between a first communication terminal and a second communication terminal;

[0016] Figure 3 A flowchart schematic diagram of the communication control method provided by the embodiments of the present application;

[0017] Figure 4 An interaction schematic diagram of the communication control method in the embodiments of the present application;

[0018] Figure 5 A schematic diagram for generating feature information according to first Cookie data and second Cookie data in the embodiments of the present application;

[0019] Figure 6 An interaction schematic diagram for re - authentication negotiation between a first communication terminal and a second communication terminal in the embodiments of the present application;

[0020] Figure 7 A flowchart schematic diagram when the communication control method provided by the embodiments of the present application is applied to a first communication terminal;

[0021] Figure 8 A flowchart schematic diagram when the communication control method provided by the embodiments of the present application is applied to a second communication terminal;

[0022] Figure 9 A schematic block diagram of the structure of the communication terminal provided by the embodiments of the present application. Detailed implementation manners

[0023] Next, the technical solutions in the embodiments of this specification will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of this specification. Obviously, the described embodiments are some, but not all, of the embodiments of this specification. Based on the embodiments in this specification, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this specification.

[0024] The flowchart shown in the accompanying drawings is only an example illustration, and does not necessarily include all contents and operations / steps, nor does it necessarily need to be executed in the described order. For example, some operations / steps can also be decomposed, combined, or partially merged. Therefore, the actual execution order may be changed according to the actual situation.

[0025] Next, some embodiments of this specification will be described in detail in conjunction with the accompanying drawings. Without conflict, the following embodiments and the features in the embodiments can be combined with each other.

[0026] The communication control method described in the embodiments of the present application can be applied to a scenario as shown in Figure 1 . In this scenario, data transmission can be carried out between a first communication terminal and a second communication terminal. Among them, the first communication terminal and the second communication terminal can include, but are not limited to, routers, network switches, base stations, base station controllers, firewalls, or load balancers.

[0027] In the prior art, if the first communication terminal and the second communication terminal want to use IPSec to protect data transmission, they can use IKE V2 to negotiate and establish a first security association, and then use the first security association to establish an IPSec tunnel. In this way, the two communication parties can carry out data transmission within this tunnel. Among them, the IPSec tunnel can be understood as a communication channel. For the convenience of narration, the entire process of establishing the first security association is called the original negotiation. The following briefly describes this process: As shown in Figure 2 . The original negotiation can be divided into two stages. The first stage is the security association initial exchange (IKE_SA_INIT). The result of the negotiation in this stage is to establish an IKE SA. The second stage is the IKE authentication exchange (IKE_SA_AUTH). This stage is protected by the cryptographic elements defined in the IKE SA. Both parties complete identity authentication at the same time and negotiate to establish a security association (IPSec SA). Based on this, if the first communication terminal initiates re-authentication during the life cycle of the first security association, for example, the first communication terminal determines that the security of data transmission is insufficient and initiates re-authentication, then the first communication terminal and the second communication terminal will use IKE V2 to negotiate again and re-establish a second security association. For the convenience of narration, the entire process of establishing the second security association is called the re-authentication negotiation. However, since the two processes of the original negotiation and the re-authentication negotiation are the same, when the second communication terminal receives the negotiation message during the re-authentication negotiation, it does not know for what reason the first communication terminal sent this message. For example, whether the message was sent due to re-authentication, or whether it was sent due to an attack, or whether it was sent due to device anomalies, etc. That is, the second communication terminal cannot identify whether the message is sent by the first communication terminal due to re-authentication. Therefore, there is a problem of data security risks.

[0028] Based on this, the communication control method provided in the embodiments of the present application, as shown in Figure 3 , this method includes, but is not limited to, steps S10 to S30.

[0029] Step S10: When the first communication terminal and the second communication terminal establish a first security association, the first communication terminal generates characteristic information.

[0030] Among them, the establishment of the first security alliance between the first communication terminal and the second communication terminal can be achieved through IKE V2. The specific implementation is as described above and will not be elaborated here. Similarly, for the convenience of description, the entire process of establishing the first security alliance is referred to as the original negotiation. Of course, the establishment of the first security alliance between the first communication terminal and the second communication terminal can also be achieved through IKE V1 or other methods, and the embodiments of the present application do not make any restrictions. It can be understood that the feature information can be used to identify the first security alliance, that is, the feature information can be used to identify the original negotiation. In some embodiments, the first security alliance has a lifecycle, that is, the duration of the existence of the first security alliance. This lifecycle can be set based on time or based on traffic.

[0031] Step S20: When the first communication terminal initiates re-authentication to the second communication terminal, the first communication terminal sends a first negotiation message carrying the feature information to the second communication terminal.

[0032] Step S30: When the second communication terminal receives the first negotiation message sent by the first communication terminal, it determines whether the first negotiation message carries the feature information. If so, it determines that the first negotiation message is a message sent by the first communication terminal due to re-authentication and re-establishes the second security alliance with the first communication terminal.

[0033] After the first communication terminal and the second communication terminal establish the first security alliance, they can establish an IPSec tunnel based on the first security alliance. In this way, the two terminals can transmit data within this IPSec tunnel. Based on this, within the lifecycle of the first security alliance, the first communication terminal can initiate re-authentication to the second communication terminal, so that the first communication terminal and the second communication terminal negotiate again to establish a new second security alliance. For the convenience of description, the entire process of establishing the second security alliance is referred to as re-authentication negotiation. Among them, the first communication terminal initiating re-authentication to the second communication terminal can include but is not limited to the following methods:

[0034] 1) The first communication terminal determines that the security of data transmission is insufficient and actively initiates re-authentication.

[0035] 2) The second communication terminal determines that the security of data transmission is insufficient and notifies the first communication terminal, and the first communication terminal then initiates re-authentication.

[0036] To enable the second communication terminal to recognize that the first negotiation message is sent by the first communication terminal due to re-authentication, the first communication terminal can make the first negotiation message carry characteristic information, that is, associate the first negotiation message with the first security association, or associate the first negotiation message with the original negotiation. Based on this, when the second communication terminal receives the first negotiation message sent by the first communication terminal, it can determine whether the first negotiation message carries the characteristic information. If so, it means that the first negotiation message is the negotiation message sent by the first communication terminal due to re-authentication. Thus, the second communication terminal can directly re-establish the second security association with the first communication terminal, that is, no other additional processing is required for the second communication terminal. In this way, not only the processing efficiency is improved, but also there is no problem of data security risks. If not, it can be determined that the first negotiation message is not sent by the first communication terminal due to re-authentication. Therefore, the second communication terminal still needs to perform further processing, such as security authentication, etc., to identify whether the message is sent due to device anomalies or being attacked, etc.

[0037] In summary, it can be understood that when the first communication terminal and the second communication terminal establish the first security association, the first communication terminal can generate corresponding characteristic information. Thus, when the first communication terminal initiates re-authentication, the first communication terminal can send the first negotiation message carrying the characteristic information to the second communication terminal. In this way, when the second communication terminal receives the first negotiation message sent by the first communication terminal, it can determine whether the negotiation message carries the characteristic information. If so, it determines that the negotiation message is the negotiation message sent by the first communication terminal due to re-authentication and directly re-establishes the second security association with the first communication terminal. Therefore, the embodiments of the present application not only improve the processing efficiency but also have no problem of data security risks.

[0038] Exemplarily, such as Figure 4As shown, the first communication terminal and the second communication terminal can establish a first security association according to IKE V2. When establishing the first security association, the first communication terminal can generate characteristic information. Then, both parties can establish an IPSec tunnel according to the first security association and conduct data transmission. After that, when the first communication terminal initiates re-authentication to the second communication terminal, the first communication terminal sends a first negotiation message carrying the characteristic information to the second communication terminal. For example, the characteristic information is carried in the IKE_SA_INIT request negotiation message in the first stage. In this way, when the second communication terminal receives the first negotiation message sent by the first communication terminal, it can determine whether the negotiation message carries the characteristic information. If so, it determines that the negotiation message is sent by the first communication terminal due to re-authentication and directly re-establishes a second security association with the first communication terminal. Furthermore, it re-establishes an IPSec tunnel according to the second security association and conducts data transmission. It can be understood that through the embodiments of the present application, not only the processing efficiency is improved, but also there is no problem of data security risks.

[0039] In some embodiments, step S10 may include but is not limited to step S101.

[0040] Step S101: When the first communication terminal and the second communication terminal establish a first security association, the first communication terminal generates characteristic information according to a characteristic generation policy.

[0041] Among them, the characteristic generation policy may be a preset policy, that is, a policy pre-agreed by the first communication terminal and the second communication terminal. Or, the characteristic generation policy may be a policy determined by the first communication terminal and / or the second communication terminal. That is, the characteristic generation policy may be determined by the first communication terminal or the second communication terminal, or may be jointly determined by both parties. In this way, the characteristic information generated by the first communication terminal according to the characteristic generation policy when establishing the first security association can be used to identify the first security association, that is, it can be used to identify the original negotiation.

[0042] In some implementation manners, the characteristic generation policy is a policy determined by the first communication terminal and / or the second communication terminal. Based on this, step S101 may include but is not limited to step S102 and step S103.

[0043] Step S102: When the first communication terminal and the second communication terminal establish a first security association, the first communication terminal determines the characteristic generation policy according to the policy information in the second negotiation message.

[0044] Step S103: The first communication terminal generates characteristic information according to the characteristic generation policy.

[0045] During the negotiation process between the first communication terminal and the second communication terminal, there will be exchanges of multiple negotiation messages. These negotiation messages all include a message header and various types of payloads. The Notify Payload is one type of payload used to inform the other party of some information data. Based on this, in some embodiments, in the original negotiation, that is, during the process of establishing the first security association between the first communication terminal and the second communication terminal, the first communication terminal and / or the second communication terminal can set the policy information in the Notify Payload of the second negotiation message. In this way, the first communication terminal can determine the feature generation policy according to the policy information. For example, as Figure 2 shown, the first communication terminal and the second communication terminal can establish the first security association according to IKEv2. Since there is encryption protection in the second stage of the original negotiation, the first communication terminal and / or the second communication terminal can set the policy information in the Notify Payload of the IKE_SA_AUTH request message and the IKE_SA_AUTH response message. For example, if the first communication terminal sets the policy information in the Notify Payload of the IKE_SA_AUTH request message, the policy information set by the first communication terminal is the feature generation policy, that is, the feature generation policy is the policy determined by the first communication terminal; or if the second communication terminal sets the policy information in the Notify Payload of the IKE_SA_AUTH response message, the policy information set by the second communication terminal is the feature generation policy, that is, the feature generation policy is the policy determined by the second communication terminal; or if the first communication terminal sets the first policy information in the Notify Payload of the IKE_SA_AUTH request message and the second communication terminal sets the second policy information in the Notify Payload of the IKE_SA_AUTH response message, then the first policy information plus the second policy information is the feature generation policy, that is, the feature generation policy is the policy jointly determined by the first communication terminal and the second communication terminal.

[0046] Exemplarily, the feature generation policy can be to generate feature information according to the first Cookie data and the second Cookie data. Among them, the first Cookie data is the Cookie data corresponding to the first communication terminal when establishing the first security association, and the second Cookie data is the Cookie data corresponding to the second communication terminal when establishing the first security association. The determination method of the feature generation policy will not be elaborated here.

[0047] First, a brief description of the Cookie data is as follows: The first communication terminal and the second communication terminal can negotiate to establish a security alliance multiple times, and the Cookie data for each negotiation between the two parties is basically different. Specifically, the Cookie data for each negotiation can be generated through operations based on user data such as the username and password entered by the user, device data such as the IP address, MAC address, and ID value of the device, and random data such as time. Therefore, the Cookie data for each negotiation between the two parties is basically different. For example, the Cookie data during the original negotiation between the two parties is different from the Cookie data during the re-authentication negotiation. In addition, in each negotiation between the two parties, the first communication terminal corresponds to one Cookie data, and the second communication terminal corresponds to one Cookie data. Therefore, it can be understood that the first Cookie data plus the second Cookie data can identify the original negotiation between the first communication terminal and the second communication terminal, that is, it can identify the first security alliance. Based on this, the characteristic information generated according to the first Cookie data and the second Cookie data can also identify the original negotiation, that is, it can also identify the first security alliance.

[0048] Among them, generating characteristic information according to the first Cookie data and the second Cookie data may include: extracting partial data from the first Cookie data and partial data from the second Cookie data and combining them into characteristic information. For example, as Figure 5 shown, extract the first byte (R1) and the second byte (R2) from the second Cookie data as the first byte and the second byte of the characteristic information, extract the first byte (I1) and the second byte (I2) from the first Cookie data as the third byte and the fourth byte of the characteristic information, extract the seventh byte (R7) and the eighth byte (R8) from the second Cookie data as the fifth byte and the sixth byte of the characteristic information, and the seventh byte and the eighth byte of the characteristic information are randomly generated. In this way, the characteristic information can be obtained. Of course, the seventh byte and the eighth byte of the characteristic information can also be determined by the first Cookie data and / or the second Cookie data.

[0049] In some embodiments, step S20 may include but is not limited to step S201.

[0050] Step S201: When the first communication terminal initiates re-authentication to the second communication terminal, the first communication terminal sets the Cookie data corresponding to the first communication terminal in the first negotiation message according to the characteristic information, and sends the set first negotiation message to the second communication terminal.

[0051] In some embodiments, step S30 may include but is not limited to step S301.

[0052] Step S301: When the second communication terminal receives the first negotiation message sent by the first communication terminal, the second communication terminal determines whether the Cookie data corresponding to the first communication terminal in the first negotiation message corresponds to the characteristic information. If it corresponds, it is determined that the first negotiation message carries the characteristic information.

[0053] In the prior art, when the first communication terminal and the second communication terminal perform re-authentication negotiation, both the first communication terminal and the second communication terminal randomly generate a Cookie data. However, in the embodiments of the present application, in order to enable the second communication terminal to recognize that the first negotiation message is a message sent by the first communication terminal due to re-authentication, therefore, the first communication terminal can set the Cookie data corresponding to itself in the first negotiation message as the characteristic information. In this way, the first negotiation message is associated with the original negotiation, that is, the first negotiation message is associated with the first security association. Based on this, when the second communication terminal receives the first negotiation message, it can determine whether the Cookie data corresponding to the first communication terminal in the first negotiation message corresponds to the characteristic information. If it can correspond, it means that the first negotiation message is a message sent by the first communication terminal due to re-authentication, so that the second communication terminal can directly negotiate with the first communication terminal to establish a second security association. In some embodiments, it can be understood from the foregoing that the second communication terminal also knows the characteristic generation strategy. Therefore, the second communication terminal can generate a verification information that is consistent with the characteristic information. In this way, if the Cookie data corresponding to the first communication terminal in the first negotiation message corresponds to the verification information, it means that the Cookie data corresponds to the characteristic information, otherwise it does not correspond.

[0054] Exemplarily, the first communication terminal and the second communication terminal can perform re-authentication negotiation according to IKE V2. As Figure 6 shown, the first communication terminal can set the Cookie data (I_cookie) corresponding to the first communication terminal in the first negotiation message (IKE_SA_INIT request) as the characteristic information (X1), and at this time, the first communication terminal can set the Cookie data (R_cookie) corresponding to the second communication terminal in the first negotiation message as O, that is, set it as invalid data. In this way, when the second communication terminal receives the first negotiation message, it can determine that the I_cookie in the first negotiation message corresponds to the characteristic information (X1). Therefore, it can be determined that the first negotiation message is a message sent by the first communication terminal due to re-authentication, so that it can directly negotiate with the first communication terminal to establish a second security association. It should be noted that there is no restriction on the Cookie data corresponding to the second communication terminal during re-authentication negotiation. Moreover, those skilled in the art can know the specific process of re-authentication negotiation in combination with the foregoing discussion, which will not be elaborated here.

[0055] Based on the above discussion, the communication control method provided in the embodiments of the present application can be applied to a first communication terminal, such as Figure 7 as shown, this method may include but is not limited to steps A10 to step A20.

[0056] Step A10: Generate feature information when establishing a first security alliance with a second communication terminal.

[0057] Among them, the feature information is used to identify the first security alliance.

[0058] Step A20: When initiating re-authentication to the second communication terminal, send a first negotiation message carrying the feature information to the second communication terminal, so that the second communication terminal determines whether the first negotiation message carries the feature information. If so, the second communication terminal determines that the first negotiation message is a message sent by the first communication terminal due to re-authentication and re-establishes a second security alliance with the first communication terminal.

[0059] In some embodiments, step A10 may include but is not limited to step A101.

[0060] Step A101: When establishing a first security alliance with a second communication terminal, generate feature information according to a feature generation policy.

[0061] Among them, the feature generation policy is a preset policy or a policy determined by the first communication terminal and / or the second communication terminal.

[0062] In some embodiments, the feature generation policy is a policy determined by the first communication terminal and / or the second communication terminal. Based on this, step A101 may include but is not limited to steps A102 to A103.

[0063] Step A102: When establishing a first security alliance with a second communication terminal, determine the feature generation policy according to the policy information in the second negotiation message.

[0064] Among them, the second negotiation message is the message used when establishing the first security alliance.

[0065] Step A103: Generate feature information according to the feature generation policy.

[0066] In some embodiments, step A20 may include but is not limited to step A201.

[0067] Step A201: Set the Cookie data corresponding to the first communication terminal in the first negotiation message according to the feature information, and send the set first negotiation message to the second communication terminal, so that the second communication terminal determines whether the Cookie data corresponding to the first communication terminal in the first negotiation message corresponds to the feature information. If it corresponds, the second communication terminal determines that the first negotiation message carries the feature information.

[0068] The specific implementation process can be referred to the previous discussion and will not be elaborated here.

[0069] In addition, the communication control method provided by the embodiments of the present application can be applied to the second communication terminal, such as Figure 8 as shown, the method may include but is not limited to steps B10 to step B20.

[0070] Step B10: When receiving the first negotiation message sent by the first communication terminal, determine whether the first negotiation message carries feature information.

[0071] Wherein, the feature information is the information generated by the first communication terminal when establishing the first security alliance with the second communication terminal for identifying the first security alliance.

[0072] Step B20: If so, determine that the first negotiation message is the message sent by the first communication terminal due to re - authentication and re - establish the second security alliance with the first communication terminal.

[0073] In some embodiments, the feature information is the information generated by the first communication terminal according to the feature generation policy when establishing the first security alliance with the second communication terminal, wherein the feature generation policy is a preset policy or a policy determined by the first communication terminal and / or the second communication terminal.

[0074] In some embodiments, the feature generation policy is a policy determined by the first communication terminal and / or the second communication terminal, and the feature information is the information generated by the first communication terminal according to the feature generation policy determined according to the policy information in the second negotiation message when establishing the first security alliance with the second communication terminal, wherein the second negotiation message is the message used when establishing the first security alliance.

[0075] In some embodiments, step B10 may include but is not limited to steps B101 to step B102.

[0076] Step B101: When receiving the first negotiation message sent by the first communication terminal, determine whether the Cookie data corresponding to the first communication terminal in the first negotiation message corresponds to the feature information.

[0077] Wherein, the Cookie data corresponding to the first communication terminal in the first negotiation message is the data set by the first communication terminal according to the feature information.

[0078] Step B102: If they correspond, determine that the first negotiation message carries the feature information.

[0079] The specific implementation process can be referred to the previous discussion and will not be elaborated here.

[0080] The embodiments of the present application also provide a communication terminal, such asFigure 9 As shown, it includes a processor and a memory, where the memory is used to store computer programs; the processor is used to execute the computer programs and implement any network flow sampling method provided by the embodiments of the present application when executing the computer programs.

[0081] It should be understood that the processor can be a Central Processing Unit (CPU), and the processor can also be other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. Among them, the general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc.

[0082] An embodiment of the present application also provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the processor is enabled to implement any network flow sampling method provided by the embodiments of the present application.

[0083] Those of ordinary skill in the art can understand that all or some of the steps in the methods disclosed above, and the functional modules / units in the systems and devices can be implemented as software, firmware, hardware, and their appropriate combinations. In the hardware implementation, the division between the functional modules / units mentioned above does not necessarily correspond to the division of physical components; for example, a physical component can have multiple functions, or a function or step can be executed by several physical components in cooperation. Some physical components or all physical components can be implemented as software executed by a processor, such as a central processor, a digital signal processor, or a microprocessor, or can be implemented as hardware, or can be implemented as an integrated circuit, such as an application specific integrated circuit. Such software can be distributed on a computer-readable storage medium, which can include a computer-readable storage medium (or non-transitory medium) and a communication medium (or transitory medium).

[0084] As is well known to those of ordinary skill in the art, the term computer-readable storage medium includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information such as computer-readable instructions, data structures, program modules, or other data. Computer-readable storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disks (DVDs) or other optical disk storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and that can be accessed by a computer. Additionally, as is well known to those of ordinary skill in the art, communication media typically embodies computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transmission mechanism, and can include any information delivery media.

[0085] Exemplarily, the computer-readable storage medium may be the internal storage unit of the communication terminal described in the foregoing embodiments, such as the hard disk or memory of the communication terminal. The computer-readable storage medium may also be the external storage device of the communication terminal, such as the plug-in hard disk, Smart Media Card (SMC), Secure Digital (SD) card, Flash Card, etc. equipped on the communication terminal.

[0086] The above are only the specific embodiments of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of various equivalent modifications or substitutions, and these modifications or substitutions should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims.

Claims

1. A communication control method, characterized in that, for a first communication terminal, the method includes: generating feature information when establishing a first security association with a second communication terminal, where the feature information is used to identify that there is an original negotiation between the first communication terminal and the second communication terminal; when initiating re-authentication to the second communication terminal, sending a first negotiation message carrying the feature information to the second communication terminal, so that the second communication terminal determines whether the first negotiation message carries the feature information. If so, the second communication terminal determines that the first negotiation message is a message sent by the first communication terminal due to re-authentication and re-establishes a second security association with the first communication terminal; if not, it is determined that the first negotiation message is not a message sent by the first communication terminal due to re-authentication.

2. The method according to claim 1, characterized in that, the generating feature information when establishing a first security association with a second communication terminal includes: when establishing a first security association with a second communication terminal, generating the feature information according to a feature generation policy, where the feature generation policy is a preset policy or a policy determined by the first communication terminal and / or the second communication terminal.

3. The method according to claim 2, characterized in that, the feature generation policy is a policy determined by the first communication terminal and / or the second communication terminal; the generating the feature information according to a feature generation policy when establishing a first security association with a second communication terminal includes: when establishing a first security association with a second communication terminal, determining the feature generation policy according to the policy information in a second negotiation message, where the second negotiation message is a message used when establishing the first security association; generating the feature information according to the feature generation policy.

4. The method according to any one of claims 1-3, characterized in that, the sending a first negotiation message carrying the feature information to the second communication terminal so that the second communication terminal determines whether the first negotiation message carries the feature information includes: setting the Cookie data corresponding to the first communication terminal in the first negotiation message according to the feature information, and sending the set first negotiation message to the second communication terminal, so that the second communication terminal determines whether the Cookie data corresponding to the first communication terminal in the first negotiation message corresponds to the feature information. If so, the second communication terminal determines that the first negotiation message carries the feature information.

5. A communication control method, characterized in that, for a second communication terminal, the method includes: when receiving a first negotiation message sent by a first communication terminal, determining whether the first negotiation message carries feature information, where the feature information is feature information generated by the first communication terminal when establishing a first security association with the second communication terminal and is used to identify that there is an original negotiation between the first communication terminal and the second communication terminal. If so, determine that the first negotiation message is a message sent by the first communication terminal due to re-authentication and re-establish a second security association with the first communication terminal; If not, determine that the first negotiation message is not a message sent by the first communication terminal due to re-authentication.

6. The method according to claim 5, wherein, the feature information is information generated by the first communication terminal according to a feature generation policy when establishing a first security association with the second communication terminal, wherein the feature generation policy is a preset policy or a policy determined by the first communication terminal and / or the second communication terminal.

7. The method according to claim 6, wherein, the feature generation policy is a policy determined by the first communication terminal and / or the second communication terminal, and the feature information is information generated by the first communication terminal according to the feature generation policy determined according to the policy information in the second negotiation message when establishing the first security association with the second communication terminal, wherein the second negotiation message is a message used when establishing the first security association.

8. The method according to any one of claims 5-7, wherein, when receiving a first negotiation message sent by a first communication terminal, determining whether the first negotiation message carries feature information includes: when receiving the first negotiation message sent by the first communication terminal, determining whether the Cookie data corresponding to the first communication terminal in the first negotiation message corresponds to the feature information, wherein the Cookie data corresponding to the first communication terminal in the first negotiation message is data set by the first communication terminal according to the feature information; if they correspond, determine that the first negotiation message carries the feature information.

9. A communication terminal, wherein, it includes a processor and a memory; the memory is used to store a computer program; the processor is used to execute the computer program and implement the communication control method according to any one of claims 1 to 4 when executing the computer program, or implement the communication control method according to any one of claims 5 to 8.

10. A computer-readable storage medium, wherein, the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the processor is caused to implement the communication control method according to any one of claims 1 to 4, or implement the communication control method according to any one of claims 5 to 8.

Citation Information

Patent Citations

  • Update method and system of session key

    CN102014382A