System, Method, Device, Electronic Device and Storage Medium for Tunnel Detection
By comparing information and status detection between the source device and the target device of the IPSec tunnel, the problem of inaccurate detection of IPSec tunnel in the prior art is solved, and the accuracy of detection and the security of data communication are improved.
Patent Information
- Application Number
- CN202210961955.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-11
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2042-08-11
AI Technical Summary
In prior art, when performing IPsec tunnel detection, the detection results are usually inaccurate.
By establishing an IPSec tunnel between the source device and the target device, the source device sends a detection request message containing the source tunnel information, the target device performs comparison and returns a detection response message, and determines the tunnel status based on the comparison results.
Improve the accuracy of tunnel detection and ensure the timely maintenance of IPSec tunnels and the effectiveness and security of data communication.
Smart Images

Figure CN115314308B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technologies, and in particular, to a system, method, device, electronic device, and storage medium for tunnel detection. Background Art
[0002] Internet Protocol Security (IPsec) is used to provide security services at the Internet Protocol (IP) layer to protect one or more paths (i.e., IPsec tunnels) between devices (such as, security gateways). A Security Association (SA) is a logical connection that provides security services for a specific data stream and is used to provide security protection for IPsec data traffic.
[0003] For example, multiple IPsec tunnels are established between a source device and a target device. Each IPsec tunnel corresponds to a pair of IPsec SAs, and a pair of IPsec SAs are respectively the IPsec SA in the source device (i.e., the source IPsec SA) and the IPsec SA in the target device (i.e., the target IPsec SA). During the communication process, it is usually necessary to detect the IPsec tunnels between different devices to confirm whether the IPsec tunnels can communicate.
[0004] In the prior art, usually a probe request message is sent from each source IPsec SA to the corresponding target IPsec SA, and it is respectively determined whether each IPsec tunnel is abnormal according to whether each source IPsec SA receives a probe response message returned by the target IPsec SA. However, in this way, the detection results are usually inaccurate. Summary of the Invention
[0005] The purpose of the embodiments of this application is to provide a system, method, device, electronic device, and storage medium for tunnel detection to improve the accuracy of detection results when performing tunnel detection.
[0006] On the one hand, a tunnel detection system is provided, including a source device and a target device. The target device includes a target IKE negotiation process, a target IPSec SA, and a target security database. The source device includes a source IPSec SA. At least one IPSec tunnel is established between the source device and the target device, and each IPSec tunnel corresponds to a pair of source IPSec SA and target IPSec SA;
[0007] The source device is configured to: obtain source tunnel information of the IPSec tunnel, send a tunnel detection request message including the source tunnel information to the target device, and receive a tunnel detection response message returned by the target device;
[0008] The target device is used to: obtain the source tunnel information in the tunnel detection request message, compare the destination tunnel information of the IPSec tunnel stored locally with the source tunnel information to obtain a first comparison result, and compare the first tunnel state in the target IKE negotiation process with the second tunnel state in the target security database to obtain a second comparison result, and send a tunnel detection response message to the source device based on the first comparison result and the second comparison result. Both the first tunnel state and the second tunnel state are the tunnel states of the detected IPSec tunnel.
[0009] In one implementation, the source device is specifically used to:
[0010] If it is determined that there are multiple IPSec tunnels, send a tunnel detection request message containing the source tunnel information of the multiple IPSec tunnels to the target device;
[0011] Receive a tunnel detection response message returned by the target device and containing the status detection results of each IPSec tunnel.
[0012] In one implementation, the source device further includes a source security database, a source IKE negotiation process, and a first local database; the source device is specifically used to:
[0013] Compare the source tunnel information in the source IKE negotiation process with the first tunnel information in the first local database and the second tunnel information in the source security database respectively;
[0014] If it is determined that at least one of the first tunnel information and the second tunnel information is inconsistent with the source tunnel information, generate tunnel exception information, and send a tunnel detection request message containing the source tunnel information and the tunnel exception information to the target device;
[0015] Otherwise, send a tunnel detection request message containing the source tunnel information to the target device.
[0016] In one implementation, a second local database is further set in the target device. The destination tunnel information includes the third tunnel information in the second local database and the fourth tunnel information in the target security database. The target device is specifically used to:
[0017] Decrypt the tunnel detection request message;
[0018] Obtain the source tunnel information included in the decrypted tunnel detection request message;
[0019] If it is determined that the tunnel detection request message does not contain tunnel exception information of the source tunnel information, compare the source tunnel information with the third tunnel information and the fourth tunnel information respectively to obtain a first comparison result;
[0020] If it is determined that the source tunnel information is consistent with the destination tunnel information according to the first comparison result, then compare the first tunnel state with the second tunnel state to obtain a second comparison result.
[0021] In one implementation, the destination device is further configured to:
[0022] If it is determined that the tunnel detection request message contains tunnel exception information corresponding to the source tunnel information, then delete the destination IPSec SA corresponding to the source tunnel information, and based on the source tunnel information, perform tunnel negotiation again;
[0023] If it is determined that the source tunnel information is inconsistent with the destination tunnel information according to the first comparison result, then based on the source tunnel information, perform tunnel negotiation again;
[0024] If it is determined that the first tunnel state is inconsistent with the second tunnel state according to the second comparison result, then based on the source tunnel information, perform tunnel negotiation again.
[0025] On the one hand, a method for tunnel detection is provided, which is applied to a destination device. The destination device includes a destination IKE negotiation process, a destination IPSec SA, and a destination security database, and includes:
[0026] Receive a tunnel detection request message sent by a source device; the tunnel detection request message contains source tunnel information of an IPSec tunnel established between the source device and the destination device. Each IPSec tunnel corresponds to a pair of source IPSec SA and destination IPSec SA, and the source IPSec SA is located in the source device;
[0027] Obtain the source tunnel information in the tunnel detection request message;
[0028] Compare the destination tunnel information of the IPSec tunnel stored locally with the source tunnel information to obtain a first comparison result;
[0029] Compare the first tunnel state in the destination IKE negotiation process with the second tunnel state in the destination security database to obtain a second comparison result; both the first tunnel state and the second tunnel state are tunnel states of the detected IPSec tunnel;
[0030] Based on the first comparison result and the second comparison result, send a tunnel detection response message to the source device.
[0031] In the above implementation process, tunnel detection is performed through tunnel information and tunnel state, improving the accuracy of tunnel detection.
[0032] In one implementation, comparing the destination tunnel information of the IPSec tunnel stored locally with the source tunnel information to obtain a first comparison result includes:
[0033] If it is determined that there are multiple IPSec tunnels, the source tunnel information and destination tunnel information of each IPSec tunnel are compared respectively to obtain the first comparison result of each IPSec tunnel;
[0034] Compare the first tunnel state in the target IKE negotiation process with the second tunnel state in the target security database to obtain a second comparison result, including:
[0035] If it is determined that there are multiple IPSec tunnels, the first tunnel state and the second tunnel state corresponding to each IPSec tunnel are compared respectively to obtain the second comparison result of each IPSec tunnel.
[0036] In the above implementation process, tunnel detection is performed through the same message containing multiple source tunnel information, reducing the system resources and transmission resources consumed.
[0037] In one implementation, a second local database is also set in the target device. The destination tunnel information includes the third tunnel information in the second local database and the fourth tunnel information in the target security database. Compare the destination tunnel information of the IPSec tunnel stored locally with the source tunnel information to obtain the first comparison result, including:
[0038] Decrypt the tunnel detection request message;
[0039] Obtain the source tunnel information included in the decrypted tunnel detection request message;
[0040] If it is determined that the tunnel detection request message does not include the tunnel exception information corresponding to the source tunnel information, compare the source tunnel information with the third tunnel information and the fourth tunnel information respectively to obtain the first comparison result.
[0041] In the above implementation process, tunnel detection is performed through tunnel information from different channels, ensuring the accuracy and effectiveness of tunnel detection.
[0042] In one implementation, the method further includes:
[0043] If it is determined that the tunnel detection request message includes the tunnel exception information corresponding to the source tunnel information, delete the target IPSec SA corresponding to the source tunnel information, and based on the source tunnel information, perform tunnel negotiation again. The tunnel exception information indicates that the IPSec tunnel is abnormal;
[0044] If it is determined according to the first comparison result that the source tunnel information is inconsistent with the destination tunnel information, perform tunnel negotiation again based on the source tunnel information;
[0045] If it is determined according to the second comparison result that the first tunnel state is inconsistent with the second tunnel state, perform tunnel negotiation again based on the source tunnel information.
[0046] In the above implementation process, when a tunnel anomaly is determined through the comparison result, a new tunnel negotiation is established, realizing the timely maintenance of the tunnel.
[0047] On the one hand, a tunnel detection device is provided, which is applied to a target device. The target device includes a target Internet Key Exchange (IKE) negotiation process, a target Internet Protocol Security (IPSec) Security Association (SA), and a target security database, and includes:
[0048] A receiving unit, configured to receive a tunnel detection request message sent by a source device; the tunnel detection request message includes source tunnel information of an IPSec tunnel established between the source device and the target device, and each IPSec tunnel corresponds to a pair of source IPSec SAs and target IPSec SAs, and the source IPSec SA is located in the source device;
[0049] An obtaining unit, configured to obtain the source tunnel information in the tunnel detection request message;
[0050] A first comparison unit, configured to compare the target tunnel information of the IPSec tunnel stored locally with the source tunnel information to obtain a first comparison result;
[0051] A second comparison unit, configured to compare the first tunnel state in the target IKE negotiation process with the second tunnel state in the target security database to obtain a second comparison result; both the first tunnel state and the second tunnel state are the tunnel states of the detected IPSec tunnel;
[0052] A sending unit, configured to send a tunnel detection response message to the source device based on the first comparison result and the second comparison result.
[0053] In an implementation manner, the first comparison unit is configured to:
[0054] If it is determined that there are multiple IPSec tunnels, the source tunnel information and the target tunnel information of each IPSec tunnel are respectively compared to obtain the first comparison results of each IPSec tunnel;
[0055] Comparing the first tunnel state in the target IKE negotiation process with the second tunnel state in the target security database to obtain a second comparison result includes:
[0056] If it is determined that there are multiple IPSec tunnels, the first tunnel state and the second tunnel state corresponding to each IPSec tunnel are respectively compared to obtain the second comparison results of each IPSec tunnel.
[0057] In one implementation, a second local database is further provided in the target device, and the target tunnel information includes third tunnel information in the second local database and fourth tunnel information in the target security database: The first comparison unit is configured to:
[0058] Decrypt the tunnel detection request message;
[0059] Obtain the source tunnel information included in the decrypted tunnel detection request message;
[0060] If it is determined that the tunnel detection request message does not include the tunnel exception information corresponding to the source tunnel information, the source tunnel information is respectively compared with the third tunnel information and the fourth tunnel information to obtain a first comparison result.
[0061] In one implementation, the sending unit is further configured to:
[0062] If it is determined that the tunnel detection request message includes the tunnel exception information corresponding to the source tunnel information, delete the target IPSec SA corresponding to the source tunnel information, and based on the source tunnel information, perform tunnel negotiation again, where the tunnel exception information indicates an IPSec tunnel exception;
[0063] If it is determined according to the first comparison result that the source tunnel information is inconsistent with the target tunnel information, perform tunnel negotiation again based on the source tunnel information;
[0064] If it is determined according to the second comparison result that the first tunnel state is inconsistent with the second tunnel state, perform tunnel negotiation again based on the source tunnel information.
[0065] On the one hand, an electronic device is provided, including a processor and a memory, where the memory stores computer-readable instructions, and when the computer-readable instructions are executed by the processor, the steps of the method provided in any of the various optional implementation manners of the above-mentioned tunnel detection are run.
[0066] On the one hand, a computer-readable storage medium is provided, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the method provided in any of the various optional implementation manners of the above-mentioned tunnel detection are run.
[0067] On the one hand, a computer program product is provided, and when the computer program product runs on a computer, it causes the computer to execute the steps of the method provided in any of the various optional implementation manners of the above-mentioned tunnel detection.
[0068] Other features and advantages of the present application will be described in the subsequent specification, and part of them will become obvious from the specification, or be understood by implementing the present application. The objectives and other advantages of the present application can be achieved and obtained through the structures specifically pointed out in the written specification, claims, and drawings. Brief Description of the Drawings
[0069] To more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments of the present application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present application, and thus should not be regarded as limiting the scope. For those of ordinary skill in the art, without creative efforts, other relevant drawings can also be obtained based on these drawings.
[0070] Figure 1 Schematic diagram of the architecture of a tunnel detection system provided by an embodiment of the present application;
[0071] Figure 2 Flowchart of a tunnel detection method provided by an embodiment of the present application;
[0072] Figure 3 Interaction diagram of a tunnel detection method provided by an embodiment of the present application;
[0073] Figure 4 Schematic diagram of an application scenario of gateway tunnel detection provided by an embodiment of the present application;
[0074] Figure 5 Block diagram of the structure of a tunnel detection device provided by an embodiment of the present application;
[0075] Figure 6 Schematic diagram of the structure of an electronic device provided by an embodiment of the present application. Detailed Description of the Embodiments
[0076] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, rather than all of them. The components of the embodiments of the present application described and illustrated herein can be arranged and designed in various different configurations. Therefore, the detailed description of the embodiments of the present application provided in the drawings below is not intended to limit the scope of the present application to be protected, but only represents the selected embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts fall within the scope of protection of the present application.
[0077] First, some terms involved in the embodiments of the present application will be described to facilitate understanding by those of ordinary skill in the art.
[0078] Terminal device: It can be a mobile terminal, a fixed terminal or a portable terminal, such as a mobile phone, a site, a unit, a device, a multimedia computer, a multimedia tablet, an Internet node, a communicator, a desktop computer, a laptop computer, a notebook computer, a netbook computer, a tablet computer, a personal communication system device, a personal navigation device, a personal digital assistant, an audio / video player, a digital camera / video camera, a positioning device, a TV receiver, a radio broadcast receiver, an e-book device, a game device or any combination thereof, including accessories and peripherals of these devices or any combination thereof. It is also foreseeable that the terminal device can support any type of user interface (such as a wearable device), etc.
[0079] Server: It can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers. It can also be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, and big data and artificial intelligence platforms.
[0080] IPSec: It provides security services at the IP layer. It enables the system to select security protocols as needed, determine the algorithms used by the services, and place the keys required for the required services in the corresponding positions. IPSec is used to protect the paths between one or more hosts and hosts, between security gateways and security gateways, and between security gateways and hosts. The set of security services that IPSec can provide can include: access control, connectionless integrity, data source authentication, rejection of retransmitted packets (a form of partial sequence integrity), confidentiality, and limited traffic flow confidentiality.
[0081] Internet Key Exchange (IKE): It is a key management protocol standard and needs to be used together with IPSec. IKE operates at the User Datagram Protocol (UDP) layer and provides a secure key exchange and management mechanism. Although IPSec can be used alone, IKE can make IPSec more flexible, easier to configure, and have higher security.
[0082] SA: It is a logical connection that provides security services for a specific data stream. The parameters of this security service include specific security protocols, security algorithms, keys, and data stream descriptions. There are two types: IKE SA and IPSec SA. Among them, IKE SA can be called the IPSec phase 1 SA, which is used to protect the data security during the IKE negotiation phase. IPSec SA can be called the IPSec phase 2 SA, which provides the IPSec protection function for the data. It can be configured manually by the user to establish a connection, or can be established through IKE negotiation for the security protection of IPSec data traffic.
[0083] Dead Peer Detection (DPD): It is used to detect whether the IPSec peer device exists and whether the two can communicate. For example, the source device and the destination device are IPSec peers of each other. By periodically sending DPD probe messages to the IPSec peer device, it is judged whether the IPSec peer device exists according to whether the IPSec peer device replies to the probe message. DPD is associated with the IKE SA. When DPD detection finds that the IPSec peer device does not exist, the SA will be deleted and a new IKE SA and IPSEC SA will be re-attempted to establish to avoid tunnel blockage.
[0084] In order to improve the accuracy of the detection result during tunnel detection, the embodiments of the present application provide a system, method, device, electronic device and storage medium for tunnel detection.
[0085] Refer to Figure 1 As shown, it is a schematic architecture diagram of a system for tunnel detection provided by the embodiments of the present application. The system for tunnel detection includes a source device and a destination device. Both the source device and the destination device can be a server or a terminal device.
[0086] Among them, the source device includes a first local database, a source Internet Key Exchange (IKE) negotiation process, a source IPSec SA, and a source security database. The destination device includes a second local database, a destination IKE negotiation process, a destination IPSec SA, and a destination security database.
[0087] It should be noted that the local database (including the first local database and the second local database) and the security database (including the source security database and the destination security database) are two different databases in the same electronic device. As an example, the security database can be: a Security Policy Database (SPD) and a Security Association Database (SAD). The local database can be a database at the application layer.
[0088] Among them, the first tunnel information for storing IPSec tunnels is in the local database, and the security database is used to store the second tunnel information of the IPSec tunnels. Both the first tunnel information and the second tunnel information are used to indicate the tunnel information of the same IPSec tunnel. Since the update times and the like of the tunnel information of the IPSec tunnels in different databases are different, the tunnel information of the IPSec tunnels in the two may be different. There may be one or more IPSec tunnels, and each IPSec tunnel corresponds to a pair of source IPSec SAs and destination IPSec SAs.
[0089] The source device is used to: obtain the source tunnel information of the IPSec tunnel, send a tunnel detection request message including the source tunnel information to the destination device, and receive the tunnel detection response message returned by the destination device.
[0090] The destination device is used to: obtain the source tunnel information in the tunnel detection request message, compare the destination tunnel information of the IPSec tunnel stored locally with the source tunnel information to obtain a first comparison result, and compare the first tunnel state in the destination IKE negotiation process with the second tunnel state in the destination security database to obtain a second comparison result, and based on the first comparison result and the second comparison result, send a tunnel detection response message to the source device. Both the first tunnel state and the second tunnel state are the tunnel states of the detected IPSec tunnel.
[0091] In one implementation, if it is determined that there are multiple IPSec tunnels, a tunnel detection request message including the source tunnel information of the multiple IPSec tunnels is sent to the destination device; receive the tunnel detection response message returned by the destination device and including the status detection results of each IPSec tunnel.
[0092] In one implementation, the source device is specifically used to: compare the source tunnel information in the source IKE negotiation process with the first tunnel information in the first local database and the second tunnel information in the source security database respectively; if it is determined that at least one of the first tunnel information and the second tunnel information is inconsistent with the source tunnel information, send a tunnel detection request message including the source tunnel information and its corresponding tunnel exception information to the destination device; otherwise, send the tunnel detection request message including the source tunnel information to the destination device.
[0093] In one implementation, the target device is specifically configured to: decrypt the tunnel detection request message; obtain the source tunnel information included in the decrypted tunnel detection request message; if it is determined that the tunnel detection request message does not include the tunnel exception information corresponding to the source tunnel information, compare the source tunnel information with the third tunnel information and the fourth tunnel information respectively to obtain a first comparison result; if it is determined according to the first comparison result that the source tunnel information is consistent with the target tunnel information, compare the first tunnel state and the second tunnel state to obtain a second comparison result.
[0094] In one implementation, the target device is further configured to: if it is determined that the tunnel detection request message includes the tunnel exception information corresponding to the source tunnel information, delete the target IPSec SA corresponding to the source tunnel information, and perform tunnel negotiation again based on the source tunnel information; if it is determined according to the first comparison result that the source tunnel information is inconsistent with the target tunnel information (that is, the source tunnel information is inconsistent with the third tunnel information or the fourth tunnel information), perform tunnel negotiation again based on the source tunnel information; if it is determined according to the second comparison result that the first tunnel state is inconsistent with the second tunnel state, perform tunnel negotiation again based on the source tunnel information.
[0095] See Figure 2 As shown, it is a flowchart of a tunnel detection method provided by an embodiment of the present application, which is applied to Figure 1 the target device in Figure 2 Combined with Figure 1 the tunnel detection method of the tunnel detection system in
[0096] Step 200: Receive a tunnel detection request message sent by a source device; the tunnel detection request message includes the source tunnel information of the IPSec tunnel established between the source device and the target device, and each IPSec tunnel corresponds to a pair of source IPSec SAs and target IPSec SAs; Step 201: Obtain the source tunnel information in the tunnel detection request message; Step 202: Compare the target tunnel information of the IPSec tunnel stored locally with the source tunnel information to obtain a first comparison result; Step 203: Compare the first tunnel state in the target IKE negotiation process with the second tunnel state in the target security database to obtain a second comparison result; both the first tunnel state and the second tunnel state are the tunnel states of the detected IPSec tunnel; Step 204: Based on the first comparison result and the second comparison result, send a tunnel detection response message to the source device.
[0097] In one implementation, if there are multiple IPSec tunnels, to determine whether the detected IPSec tunnel is abnormal, the implementation process of step 202: Compare the source tunnel information and the target tunnel information of each IPSec tunnel respectively to obtain the first comparison results of each IPSec tunnel.
[0098] In one implementation, the source tunnel information is compared with the third tunnel information in the second local database and the fourth tunnel information in the target security database respectively to obtain a first comparison result.
[0099] In one implementation, if there are multiple IPSec tunnels, to determine whether an IPSec tunnel is abnormal, the implementation process of step 203 is as follows:
[0100] The first tunnel state and the second tunnel state corresponding to each IPSec tunnel are compared respectively to obtain a second comparison result for each IPSec tunnel.
[0101] In one implementation, if the tunnel information comparison is inconsistent or the tunnel state comparison is inconsistent, it is determined that the IPSec tunnel is abnormal, and in addition, the abnormal IPSec tunnel can be repaired. The implementation process of the abnormal judgment and tunnel repair of the IPSec tunnel can include at least one of the following methods:
[0102] Method 1: If it is determined that the tunnel detection request message contains tunnel abnormal information corresponding to the source tunnel information, delete the target IPSec SA corresponding to the source tunnel information, and based on the source tunnel information, perform tunnel negotiation again. The tunnel abnormal information indicates that the IPSec tunnel is abnormal;
[0103] Method 2: If it is determined according to the first comparison result that the source tunnel information is inconsistent with the target tunnel information, perform tunnel negotiation again based on the source tunnel information;
[0104] Method 3: If it is determined according to the second comparison result that the first tunnel state is inconsistent with the second tunnel state, perform tunnel negotiation again based on the source tunnel information.
[0105] Refer to Figure 3 As shown, it is an interaction diagram of a tunnel detection method provided by an embodiment of the present application. In combination with Figure 3 For Figure 2 the tunnel detection method in
[0106] S301: The source IKE negotiation process sends a first confirmation request message containing the source tunnel information to the first local database.
[0107] Among them, the first confirmation request message contains the source tunnel information of one or more IPSec tunnels.
[0108] Optionally, the source tunnel information may include tunnel identification information, tunnel algorithms, subnets, etc., which are used to describe the information of the IPSec tunnel.
[0109] S302: The first local database returns the third comparison result between the first tunnel information and the source tunnel information to the source IKE negotiation process.
[0110] Among them, the first tunnel information of one or more IPSec tunnels is stored in the first local database.
[0111] S303: The source IKE negotiation process sends a second confirmation request message of the source tunnel information to the source security database.
[0112] S304: The source security database returns the fourth comparison result between the second tunnel information and the source tunnel information to the source IKE negotiation process.
[0113] S305: The source IKE negotiation process sends a tunnel detection request message to the destination IKE negotiation process.
[0114] Among them, the tunnel detection request message contains the source tunnel information and may also contain tunnel exception information. If the third comparison result or the fourth comparison result is inconsistent, it is determined that the IPSec tunnel is abnormal, a tunnel exception message is generated, and a tunnel detection request message containing the source tunnel information and the tunnel exception information is constructed.
[0115] In one implementation, when it is determined that the third comparison result or the fourth comparison result is inconsistent, the tunnel exception information can also be added to the message data structure (such as, the Notification Data data structure), and then, based on the message data structure and the source tunnel information, a tunnel detection request message is constructed.
[0116] Optionally, the tunnel exception information is used to indicate that the IPSec tunnel is abnormal and may also include the specific reason for the IPSec tunnel abnormality, etc.
[0117] In one implementation, the source IKE negotiation process can construct a DPD message and send a DPD message (i.e., the tunnel detection request message) to the destination IKE negotiation process based on the DPD message.
[0118] In this way, the source tunnel information in the source device can be verified first (i.e., detecting whether the tunnel is abnormal), and then, the tunnel detection request message is sent to the destination device for further tunnel status detection by the destination device.
[0119] Furthermore, the destination IKE negotiation process decrypts the tunnel detection request message to obtain the decrypted tunnel detection request message.
[0120] Specifically, the destination IKE negotiation process decrypts the tunnel detection request message. If the decryption is successful, the decrypted tunnel detection request message is obtained; otherwise, it is determined that the tunnel detection request message is abnormal and the verification fails.
[0121] Furthermore, if it is determined that there is an abnormality in the IPSec tunnel, the abnormal IPSec tunnel can be deleted and recreated. Also, if it is determined that all IPSec tunnels are abnormal, tunnel negotiation is restarted, and S312 is executed.
[0122] In one implementation, if there is only one IPSec tunnel, that is, the tunnel detection request message contains only the source tunnel information of one IPSec tunnel and its corresponding tunnel abnormality information, the target IPSec SA corresponding to this IPSec tunnel is deleted based on the tunnel abnormality information, and tunnel negotiation is performed again. That is, negotiation is initiated actively to recreate the failed target IPSEC SA.
[0123] In one implementation, if there are multiple IPSec tunnels, some of them may be abnormal and some may be normal. For any target IPSec tunnel with an abnormality among the IPSec tunnels, the following steps can be executed: The target IPSec SA corresponding to the target IPSec tunnel is deleted based on the tunnel abnormality information of the target IPSec tunnel, and tunnel negotiation is performed again.
[0124] If it is determined that the tunnel detection request message contains tunnel abnormality information, the abnormal IPSec tunnel is determined according to the tunnel abnormality information.
[0125] S306: The target IKE negotiation process sends a third confirmation request message containing the source tunnel information to the second local database.
[0126] S307: The second local database returns the first comparison and confirmation result between the third tunnel information and the source tunnel information to the target IKE negotiation process.
[0127] Among them, the second local database stores the third tunnel information of the IPSec tunnel. If there are multiple IPSec tunnels, the second local database compares the target tunnel information of each IPSec tunnel with the corresponding source tunnel information respectively.
[0128] S308: The target IKE negotiation process sends a fourth confirmation message containing the source tunnel information to the target security database.
[0129] S309: The target security database returns the second comparison and confirmation result between the fourth tunnel information and the source tunnel information to the target IKE negotiation process.
[0130] It should be noted that the target tunnel information (i.e., the third tunnel information and the fourth tunnel information) and the source tunnel information are both tunnel information used to describe the IPSec tunnel, and can both be tunnel identification information, tunnel algorithms, subnets, etc.
[0131] Specifically, the target IKE negotiation process obtains the first tunnel status stored locally and sends it to the target security database.
[0132] Further, if it is determined according to the first comparison result that the source tunnel information is inconsistent with the target tunnel information, the target IKE negotiation process performs tunnel negotiation again based on the source tunnel information and executes S312.
[0133] S310: The target IKE negotiation process sends a status confirmation message containing the first tunnel status to the target security database.
[0134] S311: The target security database returns the second comparison result between the first tunnel status and the second tunnel status to the target IKE negotiation process.
[0135] In one implementation, if there are multiple IPSec tunnels, the target security database separately compares the first tunnel status and the second tunnel status corresponding to each IPSec tunnel to obtain the second comparison results of each IPSec tunnel.
[0136] S312: The target IKE negotiation process returns a tunnel detection response message to the source IKE negotiation process according to the received comparison results.
[0137] Specifically, the target IKE negotiation process sends a tunnel detection response message to the source device based on the first comparison result (i.e., the first comparison confirmation result and the second comparison confirmation result) and the second comparison result.
[0138] Further, if it is determined according to the first comparison result that the source tunnel information is inconsistent with the target tunnel information, tunnel negotiation is performed again based on the source tunnel information; if it is determined according to the second comparison result that the first tunnel status is inconsistent with the second tunnel status, tunnel negotiation is performed again based on the source tunnel information.
[0139] Refer to Figure 4 shown, which is a schematic diagram of an application scenario for gateway tunnel detection. The following combines Figure 4 to Figure 3 to illustrate the tunnel detection method in Figure 4 includes gateway A (i.e., the source device) and gateway B (i.e., the target device). The source device includes: IPSec SA11, IPSec SA12, and IPSec SA12. The target device includes: IPSec SA21, IPSec SA22, and IPSec SA23.
[0140] The gateway A compares the source tunnel information of IPSec SA11, IPSec SA12, and IPSec SA12 respectively with the first tunnel information in the first local database and the second tunnel information in the source security database. If there is source tunnel information with inconsistent comparison results, corresponding tunnel exception information (such as, IPSEC SA information) is generated and added to the Notification Data notification data structure of the message.
[0141] The gateway A sends a DPD message containing the source tunnel information of IPSec SA11, IPSec SA12, and IPSec SA12, as well as the tunnel exception information corresponding to the source tunnel information with exceptions, to the gateway B.
[0142] The network B decrypts the DPD message according to the IKE SA key. If the DPD message contains tunnel exception information, the IPSEC SA corresponding to the source tunnel information with exceptions (i.e., the invalid IPSEC SA) is deleted from IPSec SA21, IPSec SA22, and IPSec SA23, and negotiation is initiated actively to recreate the invalid IPSEC SA; for the source tunnel information without exceptions, the normal source tunnel information is compared with the third tunnel information in the second local database and the fourth tunnel information in the target security database respectively. If there is source tunnel information with inconsistent comparison results, it is considered that the corresponding tunnel fails, and negotiation is initiated actively to recreate the invalid IPSEC SA. Further, for each source tunnel information, status comparison and detection are performed. If there is source tunnel information with inconsistent status comparison results, it is considered that the corresponding tunnel fails, and negotiation is initiated actively to recreate the invalid IPSEC SA. Obviously, by comparing the tunnel information and the tunnel status of the source tunnel information respectively, if the comparison results are all consistent, it is determined that the corresponding IPSec has no exceptions, that is, it can connect and communicate normally.
[0143] Finally, based on each comparison result, the gateway B generates a tunnel detection result and returns a tunnel detection response message containing the tunnel detection result to the gateway A. If the gateway A does not receive the tunnel detection response message within the response time, it is determined that IPSec SA11, IPSec SA12, and IPSec SA12 are all invalid or do not exist, and the tunnel negotiation process is restarted.
[0144] In the embodiments of the present application, instead of separately sending tunnel detection request messages for each IPSec SA, the same tunnel detection request message is used to detect each IPSec SA, reducing the number of message transmissions, reducing the consumed system resources and network transmission resources, thereby improving network robustness. In addition, anomaly detection can be performed respectively through the backup tunnel information and tunnel status stored in the local local database and security database, that is, tunnel detection can be performed from multiple data sources, improving the effectiveness, accuracy, reliability, and detection efficiency of tunnel detection. Moreover, the tunnel anomaly information is added to the extended information of the message and notified to the target device so that the target device can perform another tunnel negotiation for the abnormal tunnel, ensuring the timely maintenance of the tunnel and improving the effectiveness and security of data communication.
[0145] Based on the same inventive concept, an apparatus for tunnel detection is further provided in the embodiments of the present application. Since the principles of the above apparatus and device for solving problems are similar to those of a method for tunnel detection, the implementation of the above apparatus can refer to the implementation of the method, and the repeated parts will not be elaborated.
[0146] As Figure 5 shown, it is a schematic structural diagram of an apparatus for tunnel detection provided by an embodiment of the present application, including:
[0147] A receiving unit 501, configured to receive a tunnel detection request message sent by a source device; the tunnel detection request message includes source tunnel information of an IPSec tunnel established between the source device and a target device, and each IPSec tunnel corresponds to a pair of source IPSec SA and target IPSec SA, and the source IPSec SA is located in the source device;
[0148] An obtaining unit 502, configured to obtain the source tunnel information in the tunnel detection request message;
[0149] A first comparison unit 503, configured to compare the target tunnel information of the IPSec tunnel stored locally with the source tunnel information to obtain a first comparison result;
[0150] A second comparison unit 504, configured to compare the first tunnel status in the target IKE negotiation process with the second tunnel status in the target security database to obtain a second comparison result; both the first tunnel status and the second tunnel status are the tunnel statuses of the detected IPSec tunnel;
[0151] A sending unit 505, configured to send a tunnel detection response message to the source device based on the first comparison result and the second comparison result.
[0152] In an implementation manner, the first comparison unit 503 is used for:
[0153] If it is determined that there are multiple IPSec tunnels, the source tunnel information and destination tunnel information of each IPSec tunnel are compared respectively to obtain the first comparison result of each IPSec tunnel;
[0154] Compare the first tunnel status in the target IKE negotiation process with the second tunnel status in the target security database to obtain a second comparison result, including:
[0155] If it is determined that there are multiple IPSec tunnels, the first tunnel status and the second tunnel status corresponding to each IPSec tunnel are compared respectively to obtain the second comparison result of each IPSec tunnel.
[0156] In one implementation, a second local database is further set in the target device, and the destination tunnel information includes the third tunnel information in the second local database and the fourth tunnel information in the target security database: The first comparison unit is used for 503:
[0157] Decrypt the tunnel detection request message;
[0158] Obtain the source tunnel information included in the decrypted tunnel detection request message;
[0159] If it is determined that the tunnel detection request message does not include the tunnel exception information corresponding to the source tunnel information, the source tunnel information is compared with the third tunnel information and the fourth tunnel information respectively to obtain the first comparison result.
[0160] In one implementation, the sending unit is further used for 505:
[0161] If it is determined that the tunnel detection request message includes the tunnel exception information corresponding to the source tunnel information, delete the target IPSec SA corresponding to the source tunnel information, and based on the source tunnel information, perform tunnel negotiation again. The tunnel exception information indicates that the IPSec tunnel is abnormal;
[0162] If it is determined according to the first comparison result that the source tunnel information is inconsistent with the destination tunnel information, perform tunnel negotiation again based on the source tunnel information;
[0163] If it is determined according to the second comparison result that the first tunnel status is inconsistent with the second tunnel status, perform tunnel negotiation again based on the source tunnel information.
[0164] In the system, method, device, electronic device and storage medium for tunnel detection provided by the embodiments of the present application, a tunnel detection request message sent by a source device is received; the tunnel detection request message includes source tunnel information of an IPSec tunnel established between the source device and a target device, and each IPSec tunnel corresponds to a pair of a source IPSec SA and a target IPSec SA, and the source IPSec SA is located in the source device; the source tunnel information in the tunnel detection request message is obtained; the target tunnel information of the IPSec tunnel stored locally is compared with the source tunnel information to obtain a first comparison result; the first tunnel state in the target IKE negotiation process is compared with the second tunnel state in the target security database to obtain a second comparison result; both the first tunnel state and the second tunnel state are the tunnel states of the detected IPSec tunnel; a tunnel detection response message is sent to the source device based on the first comparison result and the second comparison result. In this way, tunnel detection is performed through tunnel information and tunnel states, improving the accuracy of tunnel detection.
[0165] Figure 6 FIG. shows a schematic structural diagram of an electronic device 6000. Refer to Figure 6 As shown, the electronic device 6000 includes: a processor 6010 and a memory 6020. Optionally, it may further include a power supply 6030, a display unit 6040, and an input unit 6050.
[0166] The processor 6010 is the control center of the electronic device 6000, connecting each component through various interfaces and lines, and performing various functions of the electronic device 6000 by running or executing software programs and / or data stored in the memory 6020, thereby monitoring the electronic device 6000 as a whole.
[0167] In the embodiments of the present application, when the processor 6010 calls the computer program stored in the memory 6020, it executes each step in the above embodiments.
[0168] Optionally, the processor 6010 may include one or more processing units; preferably, the processor 6010 may integrate an application processor and a modem processor. Among them, the application processor mainly processes the operating system, user interface, applications, etc., and the modem processor mainly processes wireless communication. It can be understood that the above modem processor may not be integrated into the processor 6010. In some embodiments, the processor and the memory may be implemented on a single chip, and in some embodiments, they may also be implemented separately on independent chips.
[0169] The memory 6020 may mainly include a program storage area and a data storage area. Among them, the program storage area may store an operating system, various applications, etc.; the data storage area may store data created according to the use of the electronic device 6000, etc. In addition, the memory 6020 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one magnetic disk storage device, a flash memory device, or other volatile solid-state storage devices, etc.
[0170] The electronic device 6000 further includes a power supply 6030 (such as a battery) for powering each component. The power supply can be logically connected to the processor 6010 through a power management system, so as to implement functions such as management of charging, discharging, and power consumption through the power management system.
[0171] The display unit 6040 can be used to display information input by the user or information provided to the user, as well as various menus of the electronic device 6000, etc. In the embodiments of the present invention, it is mainly used to display the display interfaces of various applications in the electronic device 6000 and objects such as text and pictures displayed in the display interfaces. The display unit 6040 may include a display panel 6041. The display panel 6041 can be configured in the form of a liquid crystal display (LCD), an organic light-emitting diode (OLED), etc.
[0172] The input unit 6050 can be used to receive information such as numbers or characters input by the user. The input unit 6050 may include a touch panel 6051 and other input devices 6052. Among them, the touch panel 6051, also known as a touch screen, can collect touch operations of the user on or near it (such as operations of the user using a finger, a stylus, or any suitable object or accessory on or near the touch panel 6051).
[0173] Specifically, the touch panel 6051 can detect the touch operation of the user, detect the signals brought by the touch operation, convert these signals into contact coordinates, send them to the processor 6010, and receive and execute the commands sent by the processor 6010. In addition, the touch panel 6051 can be implemented in a variety of types, such as resistive, capacitive, infrared, and surface acoustic wave. The other input devices 6052 may include, but are not limited to, one or more of a physical keyboard, function keys (such as volume control keys, power on / off keys, etc.), a trackball, a mouse, a joystick, etc.
[0174] Of course, the touch panel 6051 can cover the display panel 6041. After the touch panel 6051 detects a touch operation on or near it, it is transmitted to the processor 6010 to determine the type of touch event. Subsequently, the processor 6010 provides a corresponding visual output on the display panel 6041 according to the type of touch event. Although in Figure 6 the touch panel 6051 and the display panel 6041 are implemented as two independent components to realize the input and output functions of the electronic device 6000, in some embodiments, the touch panel 6051 and the display panel 6041 can be integrated to realize the input and output functions of the electronic device 6000.
[0175] The electronic device 6000 may further include one or more sensors, such as a pressure sensor, a gravitational acceleration sensor, a proximity light sensor, etc. Of course, according to the needs in specific applications, the above-mentioned electronic device 6000 may further include other components such as a camera. Since these components are not the key components used in the embodiments of the present application, therefore, in Figure 6 they are not shown and will not be described in detail.
[0176] Those skilled in the art can understand that Figure 6 is merely an example of an electronic device and does not constitute a limitation on the electronic device. It may include more or fewer components than shown in the figure, or combine certain components, or different components.
[0177] In the embodiments of the present application, a computer-readable storage medium stores a computer program. When the computer program is executed by a processor, the communication device can execute each step in the above embodiments.
[0178] For the convenience of description, the above parts are divided into respective modules (or units) according to functions and described separately. Of course, when implementing the present application, the functions of the respective modules (or units) can be implemented in the same or multiple software or hardware.
[0179] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program codes.
[0180] This application is described with reference to the flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices produce a means for implementing the functions specified in the Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.
[0181] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory produce a manufactured article including an instruction means that implements the functions specified in the Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.
[0182] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in the Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.
[0183] Although the preferred embodiments of the present application have been described, those skilled in the art can make additional changes and modifications once they know the basic creative concepts. Therefore, the appended claims are intended to be construed to include the preferred embodiments and all changes and modifications that fall within the scope of the present application.
[0184] Obviously, those skilled in the art can make various changes and variations to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these modifications and variations.
Claims
1. A system for tunnel detection, characterized in that, it includes a source device and a target device. The target device contains a target Internet Key Exchange (IKE) negotiation process, a target Internet Protocol Security (IPSec) Security Association (SA), and a target security database. The source device contains a source IPSec SA. At least one IPSec tunnel is established between the source device and the target device, and each IPSec tunnel corresponds to a pair of source IPSec SA and target IPSec SA; The source device is used for: obtaining the source tunnel information of the IPSec tunnel, sending a tunnel detection request message containing the source tunnel information to the target device, and receiving a tunnel detection response message returned by the target device; The target device is used for: obtaining the source tunnel information in the tunnel detection request message, comparing the target tunnel information of the IPSec tunnel stored locally with the source tunnel information to obtain a first comparison result, and comparing the first tunnel state in the target IKE negotiation process with the second tunnel state in the target security database to obtain a second comparison result, and based on the first comparison result and the second comparison result, sending the tunnel detection response message to the source device, where the first tunnel state and the second tunnel state are both the tunnel states of the detected IPSec tunnel.
2. The system according to claim 1, characterized in that, the source device is specifically used for: if it is determined that there are multiple IPSec tunnels, sending a tunnel detection request message containing the source tunnel information of the multiple IPSec tunnels to the target device; receiving a tunnel detection response message returned by the target device and containing the status detection results of each IPSec tunnel.
3. The system according to claim 1, characterized in that, the source device further contains a source security database, a source IKE negotiation process, and a first local database; the source device is specifically used for: comparing the source tunnel information in the source IKE negotiation process with the first tunnel information in the first local database and the second tunnel information in the source security database respectively; if it is determined that at least one of the first tunnel information and the second tunnel information is inconsistent with the source tunnel information, generating tunnel exception information, and sending a tunnel detection request message containing the source tunnel information and the tunnel exception information to the target device; otherwise, sending a tunnel detection request message containing the source tunnel information to the target device.
4. The system according to any one of claims 1 - 3, characterized in that, a second local database is further set in the target device, the target tunnel information includes the third tunnel information in the second local database and the fourth tunnel information in the target security database, and the target device is specifically used for: decrypting the tunnel detection request message; obtaining the source tunnel information contained in the decrypted tunnel detection request message; If it is determined that the tunnel detection request message does not contain the tunnel exception information corresponding to the source tunnel information, the source tunnel information is compared with the third tunnel information and the fourth tunnel information respectively to obtain the first comparison result; If it is determined according to the first comparison result that the source tunnel information is consistent with the target tunnel information, the first tunnel state and the second tunnel state are compared to obtain the second comparison result.
5. The system according to claim 4, wherein, the target device is further configured to: If it is determined that the tunnel detection request message contains the tunnel exception information corresponding to the source tunnel information, delete the target IPSec SA corresponding to the source tunnel information, and based on the source tunnel information, perform tunnel negotiation again; If it is determined according to the first comparison result that the source tunnel information is inconsistent with the target tunnel information, perform tunnel negotiation again based on the source tunnel information; If it is determined according to the second comparison result that the first tunnel state is inconsistent with the second tunnel state, perform tunnel negotiation again based on the source tunnel information.
6. A method for tunnel detection, wherein, applied to a target device, the target device includes a target Internet Key Exchange (IKE) negotiation process, a target Internet Protocol Security (IPSec) Security Association (SA), and a target security database, and includes: Receiving a tunnel detection request message sent by a source device; the tunnel detection request message contains the source tunnel information of the IPSec tunnel established between the source device and the target device, and each IPSec tunnel corresponds to a pair of source IPSec SAs and target IPSec SAs, and the source IPSec SA is located in the source device; Obtaining the source tunnel information in the tunnel detection request message; Comparing the target tunnel information of the IPSec tunnel stored locally with the source tunnel information to obtain a first comparison result; Comparing the first tunnel state in the target IKE negotiation process with the second tunnel state in the target security database to obtain a second comparison result; both the first tunnel state and the second tunnel state are the tunnel states of the detected IPSec tunnel; Based on the first comparison result and the second comparison result, sending a tunnel detection response message to the source device.
7. The method according to claim 6, wherein, the comparing the target tunnel information of the IPSec tunnel stored locally with the source tunnel information to obtain a first comparison result includes: If it is determined that there are multiple IPSec tunnels, the source tunnel information and the target tunnel information of each IPSec tunnel are compared respectively to obtain the first comparison result of each IPSec tunnel; the comparing the first tunnel state in the target IKE negotiation process with the second tunnel state in the target security database to obtain a second comparison result includes: If it is determined that there are multiple IPSec tunnels, the first tunnel status and the second tunnel status corresponding to each IPSec tunnel are respectively compared to obtain the second comparison result of each IPSec tunnel.
8. The method according to claim 6, wherein, a second local database is further set in the target device, the target tunnel information includes the third tunnel information in the second local database and the fourth tunnel information in the target security database, and the comparing the target tunnel information of the IPSec tunnel stored locally with the source tunnel information to obtain a first comparison result includes: Decrypting the tunnel detection request message; Obtaining the source tunnel information included in the decrypted tunnel detection request message; If it is determined that the tunnel detection request message does not include the tunnel exception information corresponding to the source tunnel information, the source tunnel information is respectively compared with the third tunnel information and the fourth tunnel information to obtain the first comparison result.
9. The method according to any one of claims 6-8, wherein, the method further includes: If it is determined that the tunnel detection request message includes the tunnel exception information corresponding to the source tunnel information, the target IPSec SA corresponding to the source tunnel information is deleted, and tunnel negotiation is performed again based on the source tunnel information, where the tunnel exception information indicates that the IPSec tunnel is abnormal; If it is determined according to the first comparison result that the source tunnel information is inconsistent with the target tunnel information, tunnel negotiation is performed again based on the source tunnel information; If it is determined according to the second comparison result that the first tunnel status is inconsistent with the second tunnel status, tunnel negotiation is performed again based on the source tunnel information.
10. A tunnel detection device, wherein, applied to a target device, the target device includes a target key exchange IKE negotiation process, a target Internet Protocol Security IPSec security association SA, and a target security database, and the device includes: a receiving unit, configured to receive a tunnel detection request message sent by a source device; the tunnel detection request message includes the source tunnel information of the IPSec tunnel established between the source device and the target device, and each IPSec tunnel corresponds to a pair of source IPSec SA and target IPSec SA, and the source IPSec SA is located in the source device; an obtaining unit, configured to obtain the source tunnel information in the tunnel detection request message; a first comparison unit, configured to compare the target tunnel information of the IPSec tunnel stored locally with the source tunnel information to obtain a first comparison result; a second comparison unit, configured to compare the first tunnel status in the target IKE negotiation process with the second tunnel status in the target security database to obtain a second comparison result; both the first tunnel status and the second tunnel status are the tunnel status of the detected IPSec tunnel; a sending unit, configured to send a tunnel detection response message to the source device based on the first comparison result and the second comparison result.
11. The device according to claim 10, wherein, the first comparison unit is configured to: if it is determined that there are multiple IPSec tunnels, respectively compare the source tunnel information and the destination tunnel information of each IPSec tunnel to obtain a first comparison result for each IPSec tunnel; The comparing the first tunnel state in the target IKE negotiation process with the second tunnel state in the target security database to obtain a second comparison result includes: if it is determined that there are multiple IPSec tunnels, respectively compare the first tunnel state and the second tunnel state corresponding to each IPSec tunnel to obtain a second comparison result for each IPSec tunnel.
12. The device according to claim 10, wherein, a second local database is further provided in the target device, and the target tunnel information includes third tunnel information in the second local database and fourth tunnel information in the target security database: the first comparison unit is configured to: decrypt the tunnel detection request message; obtain the source tunnel information included in the decrypted tunnel detection request message; if it is determined that the tunnel detection request message does not include tunnel exception information corresponding to the source tunnel information, respectively compare the source tunnel information with the third tunnel information and the fourth tunnel information to obtain the first comparison result.
13. The device according to any one of claims 10-12, wherein, the sending unit is further configured to: if it is determined that the tunnel detection request message includes tunnel exception information corresponding to the source tunnel information, delete the target IPSec SA corresponding to the source tunnel information, and based on the source tunnel information, perform tunnel negotiation again, where the tunnel exception information indicates that the IPSec tunnel is abnormal; if it is determined according to the first comparison result that the source tunnel information is inconsistent with the target tunnel information, perform tunnel negotiation again based on the source tunnel information; if it is determined according to the second comparison result that the first tunnel state is inconsistent with the second tunnel state, perform tunnel negotiation again based on the source tunnel information.
14. An electronic device, wherein, it includes a processor and a memory, and the memory stores computer-readable instructions, and when the computer-readable instructions are executed by the processor, the method according to any one of claims 6-9 is run.
15. A computer-readable storage medium, on which a computer program is stored, wherein, when the computer program is executed by a processor, the method according to any one of claims 6-9 is run.
Citation Information
Patent Citations
A method and apparatus for determining the number of IP secure virtual private network tunnels.
CN102271061A
Method, device and system for maintaining Internet protocol secure tunnel
CN108574589A