A data message verification transmission method

By calculating and verifying the staining value of IP packets, the problems of integrity verification, anti-replay attacks and service classification identification during IP packet transmission are solved, and efficient secure transmission and service identification are achieved.

CN115412317BActive Publication Date: 2025-05-20SHENZHEN FORWARD IND CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210994586.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-18
Publication Date
2025-05-20
Estimated Expiration
2042-08-18

AI Technical Summary

Technical Problem

The prior art is difficult to achieve integrity verification, anti-playback attacks and service classification identification during IP message transmission, especially after IPsec tunnel encryption, intermediate nodes cannot detect and confirm.

Method used

By calculating the staining value of the IP message, including the calculation of the sampling hash and message verification code, the last 4 bits of UTC time and the final verification code are embedded into the staining value, and the staining value is verified at the receiving end to ensure the integrity of the transmission and anti-replay attacks.

Benefits of technology

It effectively avoids replay attacks, ensures the integrity of message transmission, and uses light and severe staining to balance the calculation cost and security, achieving service type identification and service quality assurance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115412317B_ABST
    Figure CN115412317B_ABST
Patent Text Reader

Abstract

The invention discloses a data message verification transmission method, comprising the following steps: S1, obtaining a coloring value of an IP message according to the load content of the IP message; S2, encapsulating the load content of the IP message into a tunnel, marking the coloring value and transmitting the same to a receiving end gateway; S3, verifying the coloring value at the receiving end gateway; S4, restoring the verified IP message encapsulated in the tunnel; the invention solves the problems of integrity, anti-replay attack and service classification of existing IP network transmission, and has a light calculation amount.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of IP message communication technology, and in particular to a data message verification transmission method. Background Technology

[0002] During the communication process, in order to ensure security and improve service quality, IP messages generally need to distinguish the service categories they carry, identify the legitimacy of the source of the message, and protect the data integrity to prevent tampering. Although the IPsec tunnel encryption technology can complete the source legitimacy verification and data integrity protection, after the IPsec tunnel is encrypted, the original message source, service category, HMAC check code for data integrity protection and other information are encrypted and encapsulated, and can only be obtained after decryption at the receiving end. All communication intermediate nodes cannot perform corresponding detection and confirmation.

[0003] In order to improve the quality of service and the ability to finely control services in IP communication networks, it is necessary to accurately identify the service categories carried by IP packets. Generally, services are distinguished by their upper layer protocols (UDP and TCP) and port numbers. More detailed service type classification may require further analysis of the message payload.

[0004] On the other hand, for the integrity and concealment of transmission, VPN encapsulation messages (such as IPsec, etc.) are usually used. After the VPN tunnel is encrypted and encapsulated, these service category information cannot be obtained. When the IP message is not encrypted, the computational cost of obtaining these service-related information is also relatively high, or it is inconvenient to analyze the service content due to user service sensitivity or privacy protection, and it is also difficult to adapt to the ever-changing scenarios of new services.

[0005] There is also a method that only protects the integrity of transmission. It uses cryptographic means to calculate a check value for the data under the action of the key, that is, the key-related hash operation message authentication code (HMAC) scheme. Although the integrity and source legitimacy of the data are guaranteed, on the one hand, the HMAC verification code cannot provide semantic information such as business type identification, and on the other hand, there is also a problem with the key update cycle: if the update cycle is too short, the key negotiation will consume a large amount of network communication bandwidth and terminal computing power; if the update cycle is too long, it will be difficult to prevent risks such as message replay attacks. SUMMARY OF THE INVENTION

[0006] Aiming at the above-mentioned deficiencies in the prior art, the present invention provides a data message verification transmission method that solves the existing problems of integrity, anti-replay attack and service classification in the message transmission process.

[0007] In order to achieve the above-mentioned invention object, the technical solution adopted by the present invention is: a data message verification transmission method, comprising the following steps:

[0008] S1. Obtain the coloring value of the IP packet according to the payload content of the IP packet;

[0009] S2. Encapulate the payload content of the IP packet into a tunnel, label it with the coloring value, and then transmit it to the receiving gateway;

[0010] S3. Verify the coloring value at the receiving gateway;

[0011] S4. Restore the IP packet encapsulated in the tunnel that passes the verification.

[0012] Further, the step S1 includes the following sub-steps:

[0013] S11. Take the first 16 bytes of the IP packet as the IP header IPH1;

[0014] S12. Take the first 15 bytes of the IP packet payload, pad with 0 to 15 bytes if insufficient, and fill a byte of the payload length at the end as the payload header PL1;

[0015] S13. Calculate the sampling hash SH1 according to the IP header IPH1 and the payload header PL1, SH1 = Hash(HashFactor, IPH1|PL1), where Hash() is the hash function, HashFactor is the hash factor, and | is the string addition operation;

[0016] S14. Calculate the sampling message authentication code SM1 according to the sampling hash SH1, SM1 = MAC(ConfuseFactor, SH1|TSN|ID), where MAC() is the message authentication code function, ConfuseFactor is the confusion factor, TSN is the UTC time, and ID is the identity identifier of the IP packet;

[0017] S15. Take the first 4 bytes of the sampling message authentication code SM1 as the SM1 header SR1;

[0018] S16. Take the SM1 header SR1 as a 32-bit unsigned integer, and determine whether the SM1 header SR1 as a 32-bit unsigned integer is less than 2 32 *R. If so, jump to step S19; if not, jump to step S17, where R is the heavy coloring sampling rate;

[0019] S17. Take the last digit byte of the sampling message authentication code SM1 as the light coloring check CK1;

[0020] S18. Take the light coloring check CK1 as the final check CK3 and jump to step S23;

[0021] S19. Calculate the hash value PH1 of the IP packet, PH1 = Hash(HashFactor, IP packet);

[0022] S20. Calculate the message authentication code PM1 of the IP packet based on the hash value PH1 of the IP packet, PM1 = MAC(ConfuseFactor, PH1|TSN|ID);

[0023] S21. Take the last byte of the message authentication code PM1 of the IP packet as the checksum CK2 for heavy coloring;

[0024] S22. Take the checksum CK2 for heavy coloring as the final checksum CK3;

[0025] S23. Embed the last 4 bits of the UTC time TSN, the final checksum CK3, and the identity identifier ID of the IP packet into the coloring mark to obtain the coloring value STAIN of the IP packet.

[0026] The above further beneficial effects are as follows:

[0027] 1. The hash function uses a hash factor. Without the attacker knowing the hash factor, it is difficult to construct original data with the same hash value. At the same time, using the hash simplifies the HMAC calculation amount.

[0028] 2. Using the UTC time TSN to calculate the message authentication code improves security.

[0029] 3. Only the last 4 bits of the UTC time TSN are transmitted instead of the complete content, which improves the transmission efficiency.

[0030] Further, the step S3 includes the following sub-steps:

[0031] S31. At the receiving end gateway, when the IP packet is obtained, obtain the UTC time TSN of the receiving gateway itself, and take the last 4 bits of TSN as the received UTC time LTSN; recover the coloring value STAIN from the IP packet, and take the last 4 bits of the UTC time at the time of sending carried by the coloring value STAIN as the packet UTC time PTSN;

[0032] S32. Determine whether the packet UTC time PTSN is equal to the received UTC time LTSN. If so, assign the UTC time TSN to the time parameter TSN2 and jump to step S35. If not, jump to step S33;

[0033] S33. Determine whether the UTC time PTSN of the message is equal to (LTSN + 15) mod 16. If so, subtract one from the UTC time TSN and assign the result to the time parameter TSN2, then jump to step S35. If not, jump to step S34, where mod is the modulo operation;

[0034] S34. Determine whether the UTC time PTSN of the message is equal to (LTSN + 1) mod 16. If so, add 1 to the UTC time TSN and assign the result to the time parameter TSN2, then jump to step S35. If not, it indicates a time error;

[0035] S35. Take the first 16 bytes of the IP message as the IP header IPH2;

[0036] S36. Take the first 15 bytes of the IP message payload. Pad with 0s to 15 bytes if insufficient, and append a byte representing the payload length at the end as the payload header PL2;

[0037] S37. Calculate the sampled hash SH2 based on the IP header IPH2 and the payload header PL2, SH2 = Hash(HashFactor, IPH2|PL2);

[0038] S38. Calculate the sampled message authentication code SM2 based on the sampled hash SH2, SM2 = MAC(ConfuseFactor, SH2|TSN2|ID);

[0039] S39. Take the first 4 bytes of the sampled message authentication code SM2 as the SM2 header SR2;

[0040] S40. Treat the SM2 header SR2 as a 32-bit unsigned integer. Determine whether the SM2 header SR2, treated as a 32-bit unsigned integer, is less than 2 32 *R. If so, jump to step S43. If not, jump to step S41;

[0041] S41. Take the last digit byte of the sampled message authentication code SM2 as the lightweight coloring check CK4;

[0042] S42. Take the lightweight coloring check CK4 as the final check CK6 and jump to step S47;

[0043] S43. Calculate the IP message hash PH2, PH2 = Hash(HashFactor, IP message);

[0044] S44. Calculate the IP message authentication code PM2 based on the IP message hash PH2, PM2 = MAC(ConfuseFactor, PH2|TSN2|ID);

[0045] S45. Take the last byte of the IP packet message authentication code PM2 as the check CK5 for heavy staining.

[0046] S46. Take the check CK5 for heavy staining as the final check CK6.

[0047] S47. If the final check CK3 extracted from the staining value STAIN is the same as the final check CK6 calculated by the receiving party, the staining value verification passes.

[0048] The above further beneficial effect is: By utilizing the characteristic that the time of the receiving end and the sending end is basically synchronized but may have errors, by comparing the current time, the previous time, and the next time, it is ensured that a small time error does not affect the verification and does not affect the verification efficiency.

[0049] The beneficial effects of the present invention are:

[0050] 1. By comparing the last 4 bits of the UTC time carried in the IP packet and the UTC time in the staining value, if they are the same or differ little, the IP packet passes the first part of the verification. At the same time, the UTC time carried in the IP packet and the UTC time in the staining value are both updated in real time, increasing the difficulty of the IP packet being attacked, thus effectively avoiding replay attacks.

[0051] 2. The mixed use of light staining and heavy staining balances the computational cost and security.

[0052] 3. Whether it is light staining or heavy staining, it plays the role of a message authentication code (MAC), ensuring the integrity of the packet transmission.

[0053] 4. When staining, a specific identity identifier ID is given to each IP packet according to the packet characteristics, and the identity identifier ID is embedded in the staining value, which can enable the intermediate transmission device to perceive the packet classification without leaking privacy information.

[0054] 5. Through packet classification, it is beneficial for the intermediate transmission device to improve capabilities such as security protection, service quality guarantee, service type identification, and service situation awareness. BRIEF DESCRIPTION OF THE DRAWINGS

[0055] Figure 1 It is a flowchart of a data packet verification and transmission method. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0056] The following describes the specific embodiments of the present invention to facilitate those skilled in the art of the present technology to understand the present invention. However, it should be clear that the present invention is not limited to the scope of the specific embodiments. For those of ordinary skill in the art of the present technology, as long as various changes are within the spirit and scope of the present invention defined and determined by the appended claims, these changes are obvious, and all inventions created using the concept of the present invention are within the scope of protection.

[0057] As Figure 1 shown, a method for verifying and transmitting data packets includes the following steps:

[0058] S1. Obtain the coloring value of the IP packet according to the payload content of the IP packet;

[0059] The sub-steps of step S1 are executed at the sending end.

[0060] The said step S1 includes the following sub-steps:

[0061] S11. Take the first 16 bytes of the IP packet as the IP header IPH1;

[0062] S12. Take the first 15 bytes of the IP packet payload, fill with 0 to 15 bytes if insufficient, and fill a byte of the payload length at the end as the payload header PL1;

[0063] S13. Calculate the sampling hash SH1 according to the IP header IPH1 and the payload header PL1, SH1 = Hash(HashFactor, IPH1|PL1), where Hash() is a hash function, HashFactor is a hash factor, and | is a string addition operation;

[0064] S14. Calculate the sampling message authentication code SM1 according to the sampling hash SH1, SM1 = MAC(ConfuseFactor, SH1|TSN|ID), where MAC() is a message authentication code function, ConfuseFactor is a confusion factor, TSN is the UTC time, and ID is the identity identifier of the IP packet;

[0065] S15. Take the first 4 bytes of the sampling message authentication code SM1 as the SM1 header SR1;

[0066] S16. Take the SM1 header SR1 as a 32-bit unsigned integer, and determine whether the SM1 header SR1 as a 32-bit unsigned integer is less than 2 32 *R. If so, jump to step S19; if not, jump to step S17, where R is the heavy coloring sampling rate;

[0067] S17. Take the last byte of the sampling message authentication code SM1 as the light coloring check CK1;

[0068] S18. Take the light coloring check CK1 as the final check CK3 and jump to step S23;

[0069] S19. Calculate the IP packet hash PH1, PH1 = Hash(HashFactor, IP packet);

[0070] S20. Calculate the IP packet message authentication code PM1 according to the IP packet hash PH1, PM1 = MAC(ConfuseFactor, PH1|TSN|ID);

[0071] S21. Take the last byte of the IP packet message authentication code PM1 as the heavy coloring check CK2;

[0072] S22. Take the heavy coloring check CK2 as the final check CK3;

[0073] S23. Embed the last 4 bits of the UTC time TSN, the final check CK3, and the identity identifier ID of the IP packet into the coloring mark to obtain the coloring value STAIN of the IP packet.

[0074] S2. Encapsulate the payload content of the IP packet into a tunnel, label it with the coloring value, and then transmit it to the receiving gateway;

[0075] S3. At the receiving gateway, verify the coloring value;

[0076] The sub-steps of step S3 are executed at the receiving end.

[0077] The said step S3 includes the following sub-steps:

[0078] S31. At the receiving gateway, when an IP packet is obtained, the receiving gateway's own UTC time TSN, take the last 4 bits of TSN as the received UTC time LTSN; recover the coloring value STAIN from the IP packet, and take the last 4 bits of the UTC time at the time of transmission carried by the coloring value STAIN as the packet UTC time PTSN;

[0079] S32. Judge whether the packet UTC time PTSN is equal to the received UTC time LTSN. If so, assign the UTC time TSN to the time parameter TSN2 and jump to step S35. If not, jump to step S33;

[0080] S33. Determine whether the UTC time PTSN of the message is equal to (LTSN + 15) mod 16. If so, assign the value obtained by subtracting 1 from the UTC time TSN to the time parameter TSN2, and jump to step S35. If not, jump to step S34, where mod is the modulo operation;

[0081] S34. Determine whether the UTC time PTSN of the message is equal to (LTSN + 1) mod 16. If so, assign the value obtained by adding 1 to the UTC time TSN to the time parameter TSN2, and jump to step S35. If not, it indicates a time error;

[0082] After a time error, do not continue with the subsequent steps and can jump to step S31 to obtain the IP message again.

[0083] S35. Take the first 16 bytes of the IP message as the IP header IPH2;

[0084] S36. Take the first 15 bytes of the IP message payload. Pad with 0s to 15 bytes if insufficient, and append a byte of the payload length at the end as the payload header PL2;

[0085] S37. Calculate the sampled hash SH2 based on the IP header IPH2 and the payload header PL2, SH2 = Hash(HashFactor, IPH2|PL2);

[0086] S38. Calculate the sampled message authentication code SM2 based on the sampled hash SH2, SM2 = MAC(ConfuseFactor, SH2|TSN2|ID);

[0087] S39. Take the first 4 bytes of the sampled message authentication code SM2 as the SM2 header SR2;

[0088] S40. Treat the SM2 header SR2 as a 32-bit unsigned integer and determine whether the SM2 header SR2 as a 32-bit unsigned integer is less than 2 32 *R. If so, jump to step S43. If not, jump to step S41;

[0089] S41. Take the last digit byte of the sampled message authentication code SM2 as the lightweight coloring check CK4;

[0090] S42. Take the lightweight coloring check CK4 as the final check CK6 and jump to step S47;

[0091] S43. Calculate the IP message hash PH2, PH2 = Hash(HashFactor, IP message);

[0092] S44. Calculate the IP message verification code PM2 according to the IP message hash PH2, PM2 = MAC (ConfuseFactor, PH2 | TSN2 | ID);

[0093] S45, take the last digit of the IP message verification code PM2 as the heavy coloring check CK5;

[0094] S46, take the heavy dyeing check CK5 as the final check CK6;

[0095] S47, if the final check CK3 taken from the dye value STAIN is the same as the final check CK6 calculated by the receiver, the dye value verification is passed.

[0096] In step S3, if the time verification in step S34 is wrong and the time verification in step S47 is different, the color value verification fails. At this time, the IP message is at risk of being attacked and needs to be notified or alarmed.

[0097] S4. Restore the IP message encapsulated in the tunnel that has passed the verification. If the verification is passed, the IP message encapsulated in the tunnel can be unpacked.

[0098] The beneficial effects of the present invention are:

[0099] 1. The present invention verifies the UTC time carried by the IP message and the last 4 bits of the UTC time in the coloring value. If the two are the same or not much different, the IP message passes the first part of the verification. At the same time, the UTC time carried by the IP message and the UTC time in the coloring value are updated in real time, which increases the difficulty of IP messages being attacked, thereby effectively avoiding replay attacks.

[0100] 2. Mixing light and heavy coloring balances computational cost and security.

[0101] 3. Whether light or heavy coloring, it plays the role of message authentication code (MAC) to ensure the integrity of message transmission.

[0102] 4. When coloring, give each IP message a specific ID through message characteristics, and embed the ID into the coloring value, so that the intermediate transmission equipment can perceive the message classification without leaking privacy information.

[0103] 5. Message classification helps intermediate transmission equipment improve security protection, service quality assurance, business type identification and business situation awareness capabilities.​

Claims

1. A data message verification transmission method, characterized in that: The following steps are involved: S1. Obtaining a coloring value of the IP message according to the payload content of the IP message; the step S1 comprises the following sub-steps: S11, take the first 16 bytes of the IP message as the IP header IPH1; S12, take the first 15 bytes of the IP message payload, fill the insufficient 15 bytes with 0 to 15 bytes, and fill the last byte with the effective payload length as the payload header PL1; S13. Calculate the sample hash SH1 according to the IP header IPH1 and the payload header PL1, SH1=Hash(HashFactor,IPH1|PL1), where Hash() is the hash function, HashFactor is the hash factor, and | is a string addition operation; S14. Calculate the sampled message authentication code SM1 according to the sampled hash SH1, SM1=MAC(ConfuseFactor, SH1|TSN|ID), where MAC() is the message authentication code function, ConfuseFactor is the confusion factor, TSN is the UTC time, and ID is the identity identifier of the IP packet; S15, taking the first 4 bytes of the sampled message verification code SM1 as the SM1 header SR1; S16, take the SM1 header SR1 as a 32-bit unsigned integer, and determine whether the SM1 header SR1 as a 32-bit unsigned integer is less than 2 32 *R, if yes, jump to step S19, if no, jump to step S17, where R is the heavy staining sampling rate; S17, taking the last digit of the sampled message verification code SM1 as the light color check CK1; S18, taking the lightly stained check CK1 as the final check CK3, and jumping to step S23; S19, calculate the IP message hash PH1, PH1 = Hash (HashFactor, IP message); S20, calculate the IP message verification code PM1 according to the IP message hash PH1, PM1 = MAC (ConfuseFactor, PH1 | TSN | ID); S21, take the last digit of the IP message verification code PM1 as the heavy coloring check CK2; S22, taking the heavy dyeing check CK2 as the final check CK3; S23, embed the last 4 bits of the UTC time TSN, the final check CK3 and the identity ID of the IP message into the coloring mark to obtain the coloring value STAIN of the IP message; S2, encapsulate the payload content of the IP message into the tunnel, mark it with a color value, and transmit it to the receiving gateway; S3, at the receiving end gateway, verify the dyeing value; the step S3 includes the following sub-steps: S31. At the receiving end gateway, when the IP message is obtained, the receiving gateway's own UTC time TSN is used, and the last 4 bits of TSN are used as the receiving UTC time LTSN; the coloring value STAIN is recovered from the IP message, and the last 4 bits of the UTC time at the time of sending carried by the coloring value STAIN are taken out as the message UTC time PTSN; S32, determine whether the message UTC time PTSN is equal to the received UTC time LTSN, if so, assign the UTC time TSN to the time parameter TSN2, and jump to step S35, if not, jump to step S33; S33, determine whether the UTC time PTSN of the message is equal to (LTSN+15) mod 16. If so, subtract one from the UTC time TSN and assign it to the time parameter TSN2, and jump to step S35. If not, jump to step S34, where mod is a modulus operation; S34, determine whether the UTC time PTSN of the message is equal to (LTSN+1) mod 16. If so, add 1 to the UTC time TSN and assign it to the time parameter TSN2, and jump to step S35. If not, the time is wrong. S35, take the first 16 bytes of the IP message as the IP header IPH2; S36, take the first 15 bytes of the IP message payload, fill the insufficient 15 bytes with 0 to 15 bytes, and fill the last byte with the effective payload length as the payload header PL2; S37. Calculate the sampling hash SH2 according to the IP header IPH2 and the payload header PL2, SH2=Hash(HashFactor,IPH2|PL2); S38. Calculate the sampled message authentication code SM2 according to the sampled hash SH2, SM2=MAC(ConfuseFactor, SH2|TSN2|ID); S39, taking the first 4 bytes of the sampled message verification code SM2 as the SM2 header SR2; S40, taking the SM2 header SR2 as a 32-bit unsigned integer, and determining whether the SM2 header SR2 as a 32-bit unsigned integer is less than 2 32 *R, if yes, jump to step S43, if no, jump to step S41; S41, taking the last digit of the sampled message verification code SM2 as the light color check CK4; S42, taking the lightly stained check CK4 as the final check CK6, and jumping to step S47; S43, calculate the IP message hash PH2, PH2 = Hash (HashFactor, IP message); S44, calculate the IP message message verification code PM2 according to the IP message hash PH2, PM2 = MAC (ConfuseFactor, PH2 | TSN2 | ID); S45, taking the last digit of the IP message verification code PM2 as the heavy coloring check CK5; S46, taking the heavy dyeing check CK5 as the final check CK6; S47. If the final checksum CK3 taken from the coloring value STAIN is the same as the final checksum CK6 calculated by the receiver, the coloring value verification is passed; S4. Restore the verified IP message encapsulated in the tunnel.

Citation Information

Patent Citations

  • Data message dyeing and detection method and device

    CN114629679A