A message sending method and device and a storage medium

By carrying the control plane identifier and CheckSum calculation method in the Hop-by-Hop Options Header of the IPv6 packet extension header, the problem of information carrying in slicing and flow detection technologies is solved, realizing hop-by-hop processing and legitimacy verification, and preventing device paralysis and hacker attacks.

CN115714655BActive Publication Date: 2026-03-27CHINA MOBILE COMM LTD RES INST +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-08-19
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

The existing technology lacks a clear solution for how to carry relevant information in slicing and flow detection technologies, which leads to problems such as excessive processing pressure on network nodes, increased forwarding latency, and device failure.

Method used

The control plane flag is carried in the Hop-by-Hop Options Header of the IPv6 packet extension header, and combined with the CheckSum calculation method, the packet is processed by the control plane or the forwarding plane to ensure that the forwarding plane detects and processes information hop by hop.

Benefits of technology

It achieves hop-by-hop processing capabilities that support packet slicing and flow detection without increasing forwarding latency, verifying packet integrity and legitimacy, and preventing hacker attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115714655B_ABST
    Figure CN115714655B_ABST
Patent Text Reader

Abstract

The application discloses a message sending method and device and a storage medium, and comprises the following steps: receiving a message, the message will be detected and processed by a hop-by-hop network node in a message forwarding path; carrying a control plane identifier for uploading on a message extension header, the control plane identifier is used to indicate that the message is carried on the information of a control plane or a forwarding plane; and sending the message. According to the application, on the basis of supporting existing hop-by-hop processing functions, the ability of processing message information hop by hop on a forwarding plane can also be supported, and the function can meet the needs of new technologies such as slicing and flow detection. The control plane identifier for uploading can be effectively prevented from being tampered with or used by hackers to attack network nodes.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of communication, in particular to a message sending method and device and storage medium. BACKGROUND

[0002] With the emergence of new technologies such as slicing and on-the-fly detection, network devices need to detect and process some information hop by hop. Figure 1 Taking slicing as an example, as shown in the figure, the slicing ID (identifier) information needs to be carried in the message for the network nodes in the forwarding path to match the corresponding link resources according to the slicing ID information, and finally realize the end-to-end network slicing function in combination with the corresponding hard slicing technology.

[0003] The prior art has the disadvantage that there is no solution to determine what way to carry related information in slicing and on-the-fly detection technologies. SUMMARY

[0004] The present application provides a message sending method and device and storage medium to solve the problem that there is no solution to determine what way to carry related information in slicing and on-the-fly detection technologies.

[0005] The present application provides the following technical solutions:

[0006] A message sending method, comprising:

[0007] receiving a message that will be detected and processed by hop-by-hop network nodes in a message forwarding path;

[0008] carrying a control plane identifier for uploading on an extension header of the message, the control plane identifier being used to indicate that the message carries information on processing the message in the control plane or in the forwarding plane;

[0009] sending the message.

[0010] In implementation, the message is an IPv6 message.

[0011] In implementation, the message extension header is an IPv6 message extension header Hop-by-Hop Options Header.

[0012] In implementation, further comprising:

[0013] carrying CheckSum on the message extension header.

[0014] In implementation, further comprising:

[0015] carrying CheckSumId on the message extension header to indicate the algorithm used by CheckSum.

[0016] In implementation, further comprising:

[0017] An algorithm for updating CheckSum at preset time.

[0018] A message sending method, comprising:

[0019] Receiving a message, the message carrying a control plane identification for sending on a message extension header, the control plane identification being information for indicating that the message is carried on a message processed at a control plane or a forwarding plane;

[0020] According to the control plane identification, handing over the IPv6 message to the control plane or the forwarding plane for processing.

[0021] In implementation, the message is an IPv6 message.

[0022] In implementation, the message extension header is an IPv6 message extension header Hop-by-Hop Options Header.

[0023] In implementation, further comprising:

[0024] Carrying a first CheckSum on the message extension header.

[0025] In implementation, further comprising:

[0026] Carrying a CheckSumId on the message extension header, the CheckSumId being used for indicating an algorithm for the CheckSum.

[0027] In implementation, further comprising:

[0028] Comparing a second CheckSum calculated according to the algorithm indicated by the CheckSumId with the first CheckSum carried by the message, to determine whether the message is a legal message.

[0029] In implementation, further comprising:

[0030] If the CheckSum calculation content contains a variable part, after updating the variable part, recalculating a third CheckSum according to the CheckSum calculation method indicated by the CheckSumId, and updating the first CheckSum in the message with the third CheckSum.

[0031] In implementation, further comprising:

[0032] An algorithm for updating CheckSum at preset time.

[0033] A first network node, comprising:

[0034] A processor, configured to read a program in a memory and execute the following process:

[0035] receiving a packet, the packet will be detected and processed by a hop-by-hop network node in a packet forwarding path;

[0036] carrying a control plane identification on an extension header of the packet, the control plane identification is used to indicate that the packet is carried on a control plane or a forwarding plane processing packet;

[0037] sending the packet;

[0038] a transceiver, configured to receive and send data under control of the processor.

[0039] In an implementation, the packet is an IPv6 packet.

[0040] In an implementation, the packet extension header is an IPv6 packet extension header Hop-by-Hop Options Header.

[0041] In an implementation, further comprising:

[0042] carrying a CheckSum on the packet extension header.

[0043] In an implementation, further comprising:

[0044] carrying a CheckSumId on the packet extension header, the CheckSumId is used to indicate an algorithm used by the CheckSum.

[0045] In an implementation, further comprising:

[0046] updating the CheckSum according to a preset time.

[0047] A first network node, comprising:

[0048] a first node receiving module, configured to receive a packet, the packet will be detected and processed by a hop-by-hop network node in a packet forwarding path;

[0049] a first node identification module, configured to carry a control plane identification on an extension header of the packet, the control plane identification is used to indicate that the packet is carried on a control plane or a forwarding plane processing packet;

[0050] a first node sending module, configured to send the packet.

[0051] In an implementation, the packet is an IPv6 packet.

[0052] In an implementation, the packet extension header is an IPv6 packet extension header Hop-by-Hop Options Header.

[0053] In an implementation, the first node identification module is further configured to carry a CheckSum in the packet extension header.

[0054] In an implementation, the first node identification module is further configured to carry a CheckSumId in the packet extension header, which indicates an algorithm used by the CheckSum.

[0055] In an implementation, the first node identification module is further configured to update the algorithm of the CheckSum at a preset time.

[0056] A second network node, comprising:

[0057] a processor configured to read a program in a memory and perform the following processes:

[0058] receiving a packet, wherein the packet extension header carries a control plane identification for sending up, and the control plane identification indicates that the packet is processed in a control plane or a forwarding plane;

[0059] processing the packet in the control plane or the forwarding plane according to the control plane identification for sending up;

[0060] a transceiver configured to receive and send data under the control of the processor.

[0061] In an implementation, the packet is an IPv6 packet.

[0062] In an implementation, the packet extension header is an IPv6 packet extension header Hop-by-Hop Options Header.

[0063] In an implementation, further comprising:

[0064] carrying a first CheckSum in the packet extension header.

[0065] In an implementation, further comprising:

[0066] carrying a CheckSumId in the packet extension header, which indicates an algorithm used by the CheckSum.

[0067] In an implementation, further comprising:

[0068] comparing a second CheckSum calculated according to the algorithm indicated by the CheckSumId with the first CheckSum carried by the packet to determine whether the packet is a legal packet.

[0069] In an implementation, further comprising:

[0070] If the CheckSum calculation content contains variable parts, update the variable parts, and according to the CheckSum calculation method indicated by the CheckSumId, re-calculate a third CheckSum, and update the first CheckSum in the message with the third CheckSum.

[0071] In implementation, further comprising:

[0072] updating the CheckSum algorithm according to the preset time.

[0073] A second network node, comprising:

[0074] a second node receiving module, configured to receive a message, wherein the message carries a control plane identification on an extended header, and the control plane identification is used to indicate information carried on the message in the control plane or in the forwarding plane;

[0075] a second node sending module, configured to process the message in the control plane or the forwarding plane according to the control plane identification.

[0076] In implementation, the message is an IPv6 message.

[0077] In implementation, the message extended header is an IPv6 message extended header Hop-by-Hop Options Header.

[0078] In implementation, the second node receiving module is further configured to receive a message carrying a first CheckSum on the message extended header.

[0079] In implementation, the second node receiving module is further configured to receive a message carrying a CheckSumId on the message extended header, wherein the CheckSumId is used to indicate a CheckSum algorithm.

[0080] In implementation, the second node receiving module is further configured to compare a second CheckSum calculated according to the algorithm indicated by the CheckSumId with the first CheckSum carried by the message, and determine whether the message is a legal message.

[0081] In implementation, the second node receiving module is further configured to, if the CheckSum calculation content contains variable parts, update the variable parts, and according to the CheckSum calculation method indicated by the CheckSumId, re-calculate a third CheckSum, and update the first CheckSum in the message with the third CheckSum.

[0082] In implementation, the second node receiving module is further configured to update the CheckSum algorithm according to the preset time.

[0083] A computer readable storage medium, the computer readable storage medium stores a computer program for executing the packet sending method.

[0084] The present application has the following advantages:

[0085] In the technical solution provided by the embodiments of the present application, the upper-layer control plane identifier is carried on the packet extension header, and the upper-layer control plane identifier is used to indicate that the packet is carried on the control plane or the forwarding plane. Since the network nodes in the forwarding path must detect and process the information carried by the extension header, and according to the upper-layer control plane identifier carried by the extension header, it is determined whether the information carried by the extension header is processed on the control plane or the forwarding plane, therefore, on the basis of supporting the existing hop-by-hop processing function, the ability of processing packet information hop by hop on the forwarding plane can also be supported, and the function can better meet the needs of new technologies such as slicing and in-situ flow information telemetry.

[0086] Further, a CheckSum calculation scheme is further provided, which can verify the integrity of the packet and identify whether the content is changed in the forwarding process, and on the other hand, can verify the identity legitimacy of the packet sender. The flexible and variable CheckSum calculation method can meet the existing CheckSum guarantee of the integrity of the packet, and at the same time, can newly support the verification of the identity legitimacy of the packet sender. The illegal packet forged by hackers can be effectively identified, and the upper-layer control plane identifier can be effectively prevented from being tampered with or used by hackers to attack the network node. BRIEF DESCRIPTION OF DRAWINGS

[0087] The accompanying drawings, which are included to provide a further understanding of the application and are incorporated in and constitute a part of this application, illustrate embodiments of the application and together with the description serve to explain the application. In the drawings:

[0088] Figure 1 It is a schematic diagram of slicing forwarding in the background art;

[0089] Figure 2 It is a schematic diagram of the implementation process of the packet sending method one in the embodiments of the present application;

[0090] Figure 3 It is a schematic diagram of the implementation process of the packet sending method two in the embodiments of the present application;

[0091] Figure 4 It is a schematic diagram of the bit jump process in the packet forwarding process in the embodiments of the present application;

[0092] Figure 5 It is a schematic diagram of the process in which the illegal network device sends a large number of fake upper-layer control plane identifier packets to attack the network device in the embodiments of the present application;

[0093] Figure 6A Hop-by-Hop Options Header message format schematic diagram in an embodiment of the present application;

[0094] Figure 7 A processing flow implementation schematic diagram of an IPv6 message in an embodiment of the present application;

[0095] Figure 8 A first network node structure schematic diagram in an embodiment of the present application;

[0096] Figure 9 A second network node structure schematic diagram in an embodiment of the present application. DETAILED DESCRIPTION

[0097] The inventor noticed during the invention process that:

[0098] The information carried by the IPv6 (Internet Protocol Version 6) extension header Hop-by-Hop Options Header defined in the prior art must be detected and processed by network nodes in the message forwarding path. If the slice information and the flow detection information are carried through the extension header, the nodes on the forwarding path will detect and process the carried information.

[0099] Since the slice and flow detection technology is a new technology that is not yet mature, there is currently no solution to determine what way to carry the related information. However, carrying through the IPv6 Hop-by-Hop Options Header belongs to one of the most possible existing technologies to be used.

[0100] However, carrying the slice and flow detection information through the Hop-by-Hop Options Header at least has one of the following technical problems:

[0101] Currently, when a network node receives the Hop-by-Hop Options Header, it needs to be sent to the control panel for processing. When the service message carries the slice information, since the number of messages is large, sending all to the control panel for processing will cause excessive pressure on the control panel, and the device cannot be processed, which may cause the device to be paralyzed. In addition, the service message has a requirement on the forwarding delay. If the hop-by-hop node sends the message to the main control panel for processing, it will undoubtedly seriously affect the forwarding delay of the message. Therefore, it is basically not feasible to carry the slice and flow detection information through the existing Hop-by-Hop Options Header.

[0102] In addition, there are proposals to mention the status of Hop-by-Hop Options Header:

[0103] Some node configurations ignore the Hop-by-Hop Options Header extension header;

[0104] Some node configurations discard packets carrying Hop-by-Hop Options Header;

[0105] Some nodes will configure the rate limiting of packets carrying Hop-by-Hop Options Header, or put them into a slow queue for processing.

[0106] The specific content is as follows: New hop-by-hop options are not recommended because nodesmay be configured to ignore the Hop-by-Hop Options header,drop packetscontaining a Hop-by-Hop Options header,or assign packets containing a Hop-by-Hop Options header to a slow processing path.(Not recommended to use new hop-by-hop options, because nodes may be configured to ignore the Hop-by-Hop Options header, drop packets containing a Hop-by-Hop Options header, or assign packets containing a Hop-by-Hop Options header to a slow processing path)

[0107] In summary, the existing Hop-by-Hop Options Header is not suitable for carrying slice and flow detection information due to the above problems. New technologies such as slicing and flow detection require a solution that nodes on the forwarding path will detect and process information carried. In addition, these information need to be processed on the forwarding plane, without affecting the forwarding delay of the packet, and without increasing the overhead of the control plane of the forwarding node.

[0108] Based on this, an improved scheme for the extension header of packets that need hop-by-hop processing is proposed in the embodiments of the present application. This scheme not only implements the existing hop-by-hop processing function, but also meets the needs of new technologies such as slicing and flow detection for hop-by-hop detection and processing of information on the forwarding plane.

[0109] The specific embodiments of the present application will be described below with reference to the accompanying drawings.

[0110] In the description, the implementation from each node side will be described respectively, and then examples of their cooperation implementation will be given to better understand the implementation of the scheme given in the embodiments of the present application. Such description manner does not mean that they must be cooperated or must be implemented separately. In fact, when they are implemented separately, they each solve the problem on their own side, and when they are used in combination, better technical effects can be obtained.

[0111] Figure 2 An implementation flowchart of the packet sending method is shown in the figure, which can include:

[0112] Step 201, receiving a packet, which will be detected and processed by a hop-by-hop network node in a packet forwarding path;

[0113] Step 202, carrying a control plane identification for uploading on an extension header of the packet, which is used to indicate that the packet is carried on the information processed by the control plane or the forwarding plane;

[0114] Step 203, sending the packet.

[0115] Figure 3 An implementation flowchart of the packet sending method is shown in the figure, which can include:

[0116] Step 301, receiving a packet, which carries a control plane identification for uploading on an extension header of the packet, which is used to indicate that the packet is carried on the information processed by the control plane or the forwarding plane;

[0117] Step 302, according to the control plane identification for uploading, handing over the packet to the control plane or the forwarding plane for processing.

[0118] In the implementation, the packet is an IPv6 packet.

[0119] In the specific implementation, the packet extension header is an IPv6 packet extension header Hop-by-Hop Options Header.

[0120] In implementation, IPv6 packet and Hop-by-Hop Options Header can be taken as an example, because IPv6 packet is widely used and representative, and Hop-by-Hop Options Header has the characteristic that each hop network node in the packet forwarding path will detect and process, so it is taken as an example; but other packets and extension headers can also be used, as long as the packet has the characteristic that each hop network node in the packet forwarding path will detect and process, IPv6 packet and Hop-by-Hop Options Header are only used to teach those skilled in the art how to implement the present application, but do not mean that they can only be used in IPv6 packet and Hop-by-Hop Options Header, and the corresponding packet and extension header can be determined according to the actual needs in the implementation process.

[0121] The specific scheme can be that an IPv6 packet is received, a control plane identifier is carried on the Hop-by-Hop Options Header of the IPv6 packet, the control plane identifier is used to indicate that the packet carries information on the Hop-by-Hop Options Header in the control plane or in the forwarding plane, and the IPv6 packet is sent.

[0122] And the receiving end receives an IPv6 packet, the Hop-by-Hop Options Header of the IPv6 packet carries a control plane identifier, the control plane identifier is used to indicate that the packet carries information on the Hop-by-Hop Options Header in the control plane or in the forwarding plane, and the IPv6 packet is processed in the control plane or the forwarding plane according to the control plane identifier.

[0123] In the scheme, a new IPv6 extension header Hop-by-Hop Options Header is defined. The extension header carries a control plane identifier to indicate whether the information carried on the Hop-by-Hop Options Header is processed in the control plane or in the forwarding plane.

[0124] In implementation, the node receiving the packet can further include:

[0125] The CheckSum is carried on the packet extension header.

[0126] Specifically, the CheckSum is carried on the Hop-by-Hop Options Header of the IPv6 packet.

[0127] Correspondingly, the node receiving the packet has a first CheckSum carried on an IPv6 packet extension header Hop-by-Hop Options Header.

[0128] Figure 4 For a bit transition process diagram in the packet forwarding process, in the packet forwarding process, there can be problems as shown in Figure 4 Router A forwards the packet of user H to router B, and bit transition is caused due to some reasons, which causes the control plane label to be incorrectly set, and the packet that should be processed by the forwarding plane is incorrectly sent to the control plane. If there are many such packets, the control plane is under great pressure, and thus the network node router B is crashed.

[0129] Figure 5 For a process diagram of attacking a network device with a large number of packets carrying illegal control plane processing identification sent by an illegal network device, if a hacker actively attacks a network node, there can be problems as shown in Figure 5 Illegal AP_A sends a large number of packets carrying illegal control plane processing identification to router C, and router C sends all the packets to the control plane for processing, which causes router C to be paralyzed, and thus the legal packet forwarding of user H accessing service S is affected, and the service is damaged.

[0130] In this way, by carrying CheckSum in the packet, the above two problems can be avoided. On the one hand, the integrity of the packet can be verified, and whether there is a change in the forwarding process can be checked; on the other hand, the identity of the packet sender can be verified.

[0131] Correspondingly, in implementation, the node receiving the packet further has:

[0132] CheckSumId is carried on the packet extension header, and is used to indicate the algorithm used by CheckSum.

[0133] The node receiving the packet has CheckSumId carried on the packet extension header, and CheckSumId is used to indicate the algorithm used by CheckSum.

[0134] Specifically, CheckSumId is carried on an IPv6 packet extension header Hop-by-Hop Options Header, and CheckSumId is used to indicate the algorithm used by CheckSum.

[0135] The node receiving the packet has CheckSumId carried on an IPv6 packet extension header Hop-by-Hop Options Header, and CheckSumId is used to indicate the algorithm used by CheckSum.

[0136] In a specific implementation, further comprising:

[0137] According to the second CheckSum calculated by the algorithm indicated by CheckSumId, the first CheckSum carried by the packet is compared to determine whether the packet is a legal packet.

[0138] The following is described by examples.

[0139] First, the implementation of the packet format is described.

[0140] Figure 6 The Hop-by-Hop Options Header packet format is shown in the figure, which includes:

[0141] Next Header: Hop-by-Hop Options Header extension header type behind.

[0142] Hdr Ext Len: extension header length.

[0143] Flag: indicates whether it needs to be sent to the control plane processing. For example, if it is set to 1, the packet is processed in the control plane; if it is set to 0, the packet is processed in the forwarding plane.

[0144] CheckSumId (CheckSum identifier): index value of CheckSum calculation method.

[0145] CheckSum: according to the method indicated by CheckSumId, the CheckSum is calculated.

[0146] Options: carry any Option (option). The definition of Option can at least refer to Section 4.2 of [RFC8200] (Section 4.2 of RFC8200; RFC: Request For Comments; RFC is a series of memorandums published by Internet Engineering Task Force (IETF)).

[0147] The implementation of CheckSum calculation is described below.

[0148] The network device is pre-configured with a CheckSumId corresponding to a CheckSum calculation method, including a CheckSum algorithm, CheckSum calculation content, etc. For example, the CheckSum algorithm can be set as: parity check, LRC (Longitudinal Redundancy Check), etc. The CheckSum calculation content can be set as: calculating the Hop-by-Hop Options Header part, excluding the variable part; calculating the entire IPv6 packet header, excluding the variable part; calculating the Hop-by-Hop Options Header part, including the variable part, etc.

[0149] In the implementation, the method can further include:

[0150] updating the CheckSum algorithm according to a preset time.

[0151] Specifically, the network device can support configuring multiple CheckSumIds corresponding to multiple different CheckSum calculation methods, and the network device periodically changes the CheckSumId. Even if a hacker eavesdrops on network packets, the hacker cannot obtain the algorithm corresponding to the CheckSumId and the CheckSum calculation content, so it is difficult for the hacker to forge a legitimate packet; at the same time, the periodic change of the CheckSumId by the network device further increases the difficulty of hacking the CheckSumId content.

[0152] The implementation of the packet processing is described below.

[0153] Figure 7 An implementation schematic diagram of the processing flow of the IPv6 packet is shown in the figure, and can include:

[0154] 1. Node A receives a packet of user H, encapsulates the Hop-by-Hop Options Header, carries the hop-by-hop detection and processing information, and if the information needs to be sent to the control plane for processing, sets the Flag to 1, otherwise sets the Flag to 0.

[0155] 2. Node A matches the CheckSumId corresponding to the packet of user H according to the locally configured CheckSum information, calculates the CheckSum according to the method indicated by the CheckSumId, and carries the CheckSumId and CheckSum information into the Hop-by-Hop Options Header.

[0156] 3. Node B receives the message of user H forwarded by node A, and acquires the local CheckSum calculation method according to CheckSumId in the Hop-by-Hop Options Header, and calculates CheckSum' of the message. CheckSum' is compared with CheckSum carried in the message:

[0157] If they are the same, the message is a legal message, and is processed according to the indication of Flag in the control plane or the forwarding plane; otherwise, the message is illegal, and is processed according to the configuration of the administrator, such as discarding the message.

[0158] For example, if illegal node D sends a fake message, it cannot calculate the legal CheckSum because it does not know the CheckSum calculation method. Node B receives the illegal message, calculates CheckSum', and finds that CheckSum' is inconsistent with CheckSum carried in the message, and discards the illegal message, thereby avoiding hacker attacks.

[0159] 5. If the CheckSum calculation content contains variable parts, node B updates the variable parts, recalculates CheckSum2 according to the CheckSum calculation method indicated by CheckSumId, and updates CheckSum in the message with CheckSum2. That is, in the implementation, the method can further include:

[0160] If the CheckSum calculation content contains variable parts, the variable parts are updated, a third CheckSum is recalculated according to the CheckSum calculation method indicated by CheckSumId, and the first CheckSum in the message is updated with the third CheckSum.

[0161] 6. Node C receives the message of user H, and the message processing procedure is the same as that of node B.

[0162] Based on the same inventive concept, the embodiments of the present application further provide a network node and a computer readable storage medium. Since the principles of the devices for solving problems are similar to the message sending method, the implementation of the devices can be referred to the implementation of the method, and the repeated parts will not be described herein.

[0163] In the implementation of the technical solutions provided by the embodiments of the present application, the following implementation modes can be used.

[0164] Figure 8 A structure diagram of the first network node is shown in the figure, and the node includes:

[0165] The processor 800 is used to read the program in the memory 820, and execute the following processes:

[0166] receiving a packet, the packet will be detected and processed by a hop-by-hop network node in a packet forwarding path;

[0167] carrying a reporting control plane identifier on an extension header of the packet, the reporting control plane identifier is used to indicate that the packet is processed on a control plane or a forwarding plane;

[0168] sending the packet;

[0169] a transceiver 810, configured to receive and send data under control of the processor 800.

[0170] In an implementation, the packet is an IPv6 packet.

[0171] In an implementation, the packet extension header is an IPv6 packet extension header Hop-by-Hop Options Header.

[0172] In an implementation, further comprising:

[0173] carrying a CheckSum on the packet extension header.

[0174] In an implementation, further comprising:

[0175] carrying a CheckSumId on the packet extension header, the CheckSumId is used to indicate an algorithm used by the CheckSum.

[0176] In an implementation, further comprising:

[0177] updating the CheckSum according to a preset time.

[0178] In an implementation, the processor 800 is further configured to: Figure 8 In an implementation, the bus architecture can include any number of interconnecting buses and bridges, depending on the specific application of the processor 800 and the memory 820 represented by the various circuitry linking the processor 800 and the memory 820. The bus architecture can also link various other circuitry, such as peripheral devices, voltage regulators, and power management circuitry, all of which are well known in the art, and therefore, will not be described further. The bus interface provides an interface to the bus architecture. The transceiver 810 can be a plurality of elements, including a transmitter and a receiver, providing a means for communicating with various other apparatus over a transmission medium. The processor 800 is responsible for managing the bus architecture and general processing, and the memory 820 can store data used by the processor 800 in executing operations.

[0179] The embodiment of the present application also provides a first network node, comprising:

[0180] a first node receiving module, configured to receive a packet, the packet will be detected and processed by a hop-by-hop network node in a packet forwarding path;

[0181] The first node identification module is configured to carry a control plane upload identification on the extension header of the packet, and the control plane upload identification is used to indicate information carried on the packet processed by the control plane or the forwarding plane.

[0182] The first node sending module is configured to send the packet.

[0183] In an implementation, the packet is an IPv6 packet.

[0184] In an implementation, the packet extension header is an IPv6 packet extension header Hop-by-Hop Options Header.

[0185] In an implementation, the first node identification module is further configured to carry a CheckSum on the packet extension header.

[0186] In an implementation, the first node identification module is further configured to carry a CheckSumId on the packet extension header, which is used to indicate an algorithm used by the CheckSum.

[0187] In an implementation, the first node identification module is further configured to update the algorithm of the CheckSum at a preset time.

[0188] For the convenience of description, each part of the above-described apparatus is described as various modules or units in terms of functions. Of course, the functions of each module or unit can be implemented in the same or multiple software or hardware when the present application is implemented.

[0189] Figure 9 The second network node structure is shown in the figure, and the node includes:

[0190] The processor 900 is configured to read a program in the memory 920 and execute the following process:

[0191] The processor 900 is configured to read a program in the memory 920 and execute the following process:

[0192] The processor 900 is configured to read a program in the memory 920 and execute the following process:

[0193] The transceiver 910 is configured to receive and send data under the control of the processor 900.

[0194] In an implementation, the packet is an IPv6 packet.

[0195] In an implementation, the packet extension header is an IPv6 packet extension header Hop-by-Hop Options Header.

[0196] During implementation, it further includes:

[0197] The first CheckSum is carried in the message extension header.

[0198] During implementation, it further includes:

[0199] The message extension header carries a CheckSumId, which indicates the algorithm used by CheckSum.

[0200] During implementation, it further includes:

[0201] The second CheckSum, calculated by the algorithm indicated by CheckSumId, is compared with the first CheckSum carried in the message to determine whether the message is a legitimate message.

[0202] During implementation, it further includes:

[0203] If the calculated CheckSum contains a variable portion, after updating the variable portion, the third CheckSum is recalculated according to the CheckSum calculation method indicated by CheckSumId, and the first CheckSum in the message is updated with the third CheckSum.

[0204] During implementation, it further includes:

[0205] The algorithm updates CheckSum at preset intervals.

[0206] Among them, Figure 9 In this context, the bus architecture can include any number of interconnected buses and bridges, specifically linking various circuits together, represented by one or more processors (processor 900) and memory (memory 920). The bus architecture can also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides an interface. The transceiver 910 can be multiple elements, including transmitters and receivers, providing a unit for communicating with various other devices over a transmission medium. The processor 900 is responsible for managing the bus architecture and general processing, and the memory 920 can store data used by the processor 900 during operation.

[0207] This invention also provides a second network node, comprising:

[0208] The second node receiving module is used to receive messages. The message extension header carries an uplink control plane identifier, which is used to indicate whether the message is processed in the control plane or the forwarding plane.

[0209] The second node sending module is configured to send the packet to the control plane or the forwarding plane for processing according to the control plane identifier.

[0210] In an implementation, the packet is an IPv6 packet.

[0211] In an implementation, the packet extension header is an IPv6 packet extension header Hop-by-Hop Options Header.

[0212] In an implementation, the second node receiving module is further configured to receive the packet carrying the first CheckSum in the packet extension header.

[0213] In an implementation, the second node receiving module is further configured to receive the packet carrying the CheckSumId in the packet extension header, where the CheckSumId is used to indicate an algorithm used by the CheckSum.

[0214] In an implementation, the second node receiving module is further configured to compare the second CheckSum calculated according to the algorithm indicated by the CheckSumId with the first CheckSum carried by the packet, and determine whether the packet is a legal packet.

[0215] In an implementation, the second node receiving module is further configured to, if the CheckSum calculation content contains a variable part, update the variable part, recalculate a third CheckSum according to the CheckSum calculation method indicated by the CheckSumId, and update the first CheckSum in the packet with the third CheckSum.

[0216] In an implementation, the second node receiving module is further configured to update the CheckSum algorithm at a preset time.

[0217] For the convenience of description, the above-described parts of the apparatus are described as various modules or units in function respectively. Of course, the functions of the modules or units can be implemented in one or more software or hardware in implementing the present application.

[0218] The present application also provides a computer readable storage medium storing a computer program for executing the above packet sending method.

[0219] The specific implementation can refer to the implementation of the packet sending method on each node.

[0220] In summary, the technical solution provided by the embodiments of the present application proposes a new packet extension header, and network nodes in a forwarding path must detect and process information carried by the extension header, and decide whether to process the information carried by the extension header in the control plane or the forwarding plane according to the control plane identifier carried by the extension header.

[0221] Compared with the prior art Hop-by-Hop Options Header, the capability of processing packet information hop by hop at a forwarding plane is newly added on the basis of supporting the functions of the prior Hop-by-Hop Options Header, and the functions can better meet the requirements of new technologies such as slicing and in-stream detection. The prior Hop-by-Hop Options Header cannot meet the requirements of new technologies such as slicing and in-stream detection.

[0222] Further, a CheckSum calculation method is further proposed, which can verify the integrity of a packet and identify whether the content is changed in a forwarding process, and can verify the identity legitimacy of a packet sender. Periodic replacement of CheckSumId further increases the difficulty of hacker attacks.

[0223] The flexible and variable CheckSum calculation method meets the requirement of the prior CheckSum for guaranteeing the integrity of a packet, and newly supports verification of the identity legitimacy of a packet sender. The method can effectively identify illegal packets forged by hackers. The CheckSum calculation method used in the application proposal can effectively prevent the identification sent to a control plane from being tampered with or used by hackers to attack network nodes.

[0224] Those skilled in the art should understand that embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can adopt a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can adopt a computer program product in the form of being implemented on one or more computer usable storage media (including but not limited to disk storage and optical storage, etc.) containing computer usable program codes.

[0225] The present application is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a means for implementing the functions specified in the flowcharts and / or block diagrams. Figure 1 The means for implementing each flow or multiple flows and / or blocks Figure 1 The means for implementing each flow or multiple flows and / or blocks

[0226] These computer program instructions can also be stored in a computer- readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instructions which implement the Figure 1 function specified in the flow or flows and / or blocks Figure 1 of the block or blocks.

[0227] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions that are executed on the computer or other programmable apparatus provide steps for implementing the Figure 1 function specified in the flow or flows and / or blocks Figure 1 of the block or blocks.

[0228] Obviously, numerous modifications and variations of the present application are possible in light of the above teachings. It is therefore to be understood that within the scope of the appended claims and their equivalents, the application can be practiced otherwise than as specifically described.

Claims

1. A message sending method characterized by, comprising: receiving a packet, the packet to be detected and processed by hop-by-hop network nodes in a packet forwarding path; carrying a control plane reporting identifier on an extension header of the packet, the control plane reporting identifier indicating whether the packet is processed on a control plane or a forwarding plane; sending the packet; carrying a CheckSum on the extension header of the packet; the method further comprising: carrying a CheckSumId on the extension header of the packet, the CheckSumId indicating an algorithm used by the CheckSum.

2. The method of claim 1, wherein, the packet is an Internet Protocol version 6 (IPv6) packet.

3. The method of claim 2, wherein, the extension header is an IPv6 Hop-by-Hop Options Header.

4. The method of claim 1, wherein, further comprising: updating the algorithm of the CheckSum at a preset time.

5. A message sending method characterized by, comprising: receiving a packet, the packet carrying a control plane reporting identifier on an extension header of the packet, the control plane reporting identifier indicating whether the packet is processed on a control plane or a forwarding plane; processing the packet on the control plane or the forwarding plane according to the control plane reporting identifier; carrying a first CheckSum on the extension header of the packet; the method further comprising: carrying a CheckSumId on the extension header of the packet, the CheckSumId indicating an algorithm used by the CheckSum.

6. The method of claim 5, wherein, the packet is an IPv6 packet.

7. The method of claim 6, wherein, the extension header is an IPv6 Hop-by-Hop Options Header.

8. The method of claim 5, wherein, further comprising: comparing a second CheckSum calculated according to the algorithm indicated by the CheckSumId with the first CheckSum carried by the packet to determine whether the packet is a legal packet.

9. The method of claim 8, wherein, further comprising: if the CheckSum calculation content contains a variable part, updating the variable part, recalculating a third CheckSum according to the CheckSum calculation method indicated by the CheckSumId, and updating the first CheckSum in the packet with the third CheckSum.

10. The method of claim 5, wherein, further comprising: updating the algorithm of the CheckSum at a preset time.

11. A first network node, characterized by: comprising: a processor configured to read a program in a memory and perform the following processes: receiving a packet, the packet to be detected and processed by hop-by-hop network nodes in a packet forwarding path; carrying a control plane reporting identifier on an extension header of the packet, the control plane reporting identifier indicating whether the packet is processed on a control plane or a forwarding plane; sending the packet; carrying a CheckSum on the extension header of the packet; carrying a CheckSumId on the extension header of the packet, the CheckSumId indicating an algorithm used by the CheckSum. a transceiver configured to receive and send data under control of the processor.

12. A first network node, characterized by: comprising: a first node receiving module configured to receive a packet, the packet to be detected and processed by hop-by-hop network nodes in a packet forwarding path; The first node identification module is configured to carry an upper-layer control plane identifier in the extension header of the packet, and the upper-layer control plane identifier is used to indicate information carried in the packet in a control plane or a forwarding plane; The first node sending module is configured to send the packet; The first node identification module is further configured to carry a CheckSum in the extension header of the packet; The first node identification module is further configured to carry a CheckSumId in the extension header of the packet, which is used to indicate an algorithm used by the CheckSum.

13. A second network node, characterized by: The processor is configured to read a program in the memory and perform the following processes: receiving a packet, wherein an upper-layer control plane identifier is carried in an extension header of the packet, and the upper-layer control plane identifier is used to indicate information carried in the packet in a control plane or a forwarding plane; processing the packet in the control plane or the forwarding plane according to the upper-layer control plane identifier; carrying a first CheckSum in the extension header of the packet; carrying a CheckSumId in the extension header of the packet, which is used to indicate an algorithm used by the CheckSum; The transceiver is configured to receive and send data under control of the processor. The processor is configured to read a program in the memory and perform the following processes:

14. A second network node, characterized by: The second node receiving module is configured to receive a packet, wherein an upper-layer control plane identifier is carried in an extension header of the packet, and the upper-layer control plane identifier is used to indicate information carried in the packet in a control plane or a forwarding plane; The second node sending module is configured to process the packet in the control plane or the forwarding plane according to the upper-layer control plane identifier; The second node receiving module is further configured to receive a packet carrying a first CheckSum in an extension header of the packet; The second node receiving module is further configured to receive a packet carrying a CheckSumId in an extension header of the packet, which is used to indicate an algorithm used by the CheckSum. The computer readable storage medium stores a computer program for performing the method of any one of claims 1 to 10.

15. A computer-readable storage medium, characterized in that, ​

Citation Information

Patent Citations

  • Processing method, equipment and system for Internet protocol version 6 (IPv6) message

    CN102088391A

  • Ipv6 packet processing method and apparatus

    WO2021047310A1