IPSec Tunnel Mode Communication Method and Device for Multi-Link Dynamic Routing

By deploying IPSec nodes in the dynamic routing network and setting detection security policies, the problems of communication security and link backup in the dynamic routing environment are solved, and symmetric routing and link backup are realized, avoiding data interruption.

CN115865788BActive Publication Date: 2025-07-11WUHAN MARITIME COMMUNICATION RESEARCH INSTITUTE
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211481493.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-24
Publication Date
2025-07-11
Estimated Expiration
2042-11-24

AI Technical Summary

Technical Problem

The prior art cannot hide the true source, destination address and communication protocol of IP data in a dynamic routing network environment, resulting in low communication security and symmetric routing cannot be guaranteed, resulting in insufficient link backup and easy data interruption.

Method used

The IPSec tunnel mode communication method for multi-link dynamic routing is adopted. By deploying IPSec nodes at the center and remote ends, setting business security policies and probing security policies, using the probing security policies to prioritize higher than the service policies, path detection and switching are performed to ensure the consistency of the back and forth paths, and switching when the link is unavailable.

Benefits of technology

It realizes the real source, destination address and communication protocol for hiding IP data in the dynamic routing network, improves communication security, and avoids packet loss of firewalls through link backup and dynamic switching, ensuring the stability of symmetric routing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115865788B_ABST
    Figure CN115865788B_ABST
Patent Text Reader

Abstract

The present invention provides an IPSec tunnel mode communication method and apparatus for multi-link dynamic routing, including: setting N network links at the central end and deploying an IPSec node on each link, and deploying an IPSec node at each remote end; all the first IPSec nodes and the second IPSec nodes have an intercommunication relationship; dividing multiple service subnets at the central end into N first IPSec nodes, and each service selects the node with the shortest network path among the N first IPSec nodes as the primary first IPSec node, and the other N-1 nodes as the standby first IPSec nodes; separately configuring a service security policy SP for each service subnet, and when it is detected that the round-trip paths between the first IPSec node and the second IPSec node currently adopted by the service SP are inconsistent or unavailable, the service SP is switched to other first IPSec nodes where the round-trip paths detected by the second IPSec node are consistent and available. The present invention ensures symmetric routing and realizes link backup and dynamic routing adaptation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of communications, and more particularly, relates to an IPSec tunnel mode communication method and apparatus for multi-link dynamic routing. Background Art

[0002] Existing tunnel modes can hide the true source, destination addresses and communication protocols of IP data. By setting multiple Internet Protocol Security (IPSec) peer nodes in a Security Policy (SP), load balancing can be achieved through peer detection and switching. However, this solution can only select paths for the encrypted direction and cannot control the paths for the decrypted direction. If the data packet paths in the decrypted direction are inconsistent with those in the encrypted direction, firewall devices will block unpaired TCP packets, etc. In such a dynamic routing environment, asymmetric routing may occur probabilistically, that is, the round-trip paths are inconsistent, and link backup cannot be achieved, resulting in data interruption. At the same time, peer detection only detects the keep-alive status of peer nodes and does not detect the links from peer nodes to their protected subnets. In extreme cases, the internal network interface of a peer node may not be connected, but it is still judged that the peer is alive and no switching is performed, causing service interruption. Therefore, the application has high limitations.

[0003] In summary, the prior art has not provided a technical solution that can hide the true source, destination addresses and communication protocols of IP data in a dynamic routing network environment to improve communication security, ensure symmetric routing, achieve link backup, and avoid firewall packet loss. Summary of the Invention

[0004] Aiming at the deficiencies of the prior art, an object of the present invention is to provide an IPSec tunnel mode communication method and apparatus for multi-link dynamic routing, aiming to solve the problem that the prior art has not provided a technical solution that can hide the true source, destination addresses and communication protocols of IP data in a dynamic routing network environment to improve communication security, ensure symmetric routing, achieve link backup, and avoid firewall packet loss.

[0005] To achieve the above object, in a first aspect, the present invention provides an IPSec tunnel mode communication method for multi-link dynamic routing. The method is applicable to a communication network, the communication network includes a central end and a remote end, and the communication network uses a dynamic routing protocol. The method includes the following steps:

[0006] Set N network links at the central end, and deploy an IPSec node on each link, called the first IPSec node; deploy an IPSec node at each remote end, called the second IPSec node; all the first IPSec nodes and the second IPSec nodes have an interconnection relationship;

[0007] Divide multiple service subnets of the center into N first IPSec nodes, select the node with the shortest network path among the N first IPSec nodes as the main first IPSec node for each service subnet, and the other N-1 nodes as backup first IPSec nodes;

[0008] A service security policy SP is configured for each service subnet separately, and a corresponding detection SP is generated according to each service SP; the SP adopts a tunnel mode, and the priority of the detection SP is higher than that of the service SP;

[0009] Control N first IPSec nodes and second IPSec nodes to establish IPSec links for all service SPs and detection SPs; the service SPs preferentially use the primary first IPSec node for communication, and the detection SP is used to instruct the second IPSec node to perform path detection on the N first IPSec nodes;

[0010] When the second IPSec node detects that the round-trip path between the first IPSec node and the second IPSec node currently used by the service SP is inconsistent or unavailable, the service SP is switched to another first IPSec node whose round-trip path detected by the second IPSec node is consistent and available.

[0011] In an optional example, the detection SP is used to instruct the second IPSec node to perform path detection on N first IPSec nodes, specifically:

[0012] The second IPSec node initiates a probe to the first IPSec node using the TCP protocol and / or the UDP protocol; the probe includes a request packet and a response packet; the request packet is sent by the second IPSec node, and the response packet is responded by the first IPSec node;

[0013] The first IPSec node checks the path status to the protected subnet and its own status. If a fault occurs, it replies with a response packet containing an error code. When the second IPSec node receives an error response packet or does not receive a response packet within a specified time, it considers that an error packet is generated in the current probe request and continues to send a probe request packet to the first IPSec node.

[0014] When the second IPSec node receives a preset number of error packets cumulatively, it determines that the corresponding first IPSec node is invalid, and considers that the round-trip path between the second IPSec node and the corresponding first IPSec node is inconsistent or unavailable;

[0015] When the second IPSec node determines that the corresponding first IPSec node is invalid, it checks whether the corresponding first IPSec node is on a network link currently being used by a certain service SP. If so, the corresponding service SP is switched to another first IPSec node.

[0016] In an optional example, the method further includes the following steps:

[0017] A beacon device is set at the end of the route after each first IPSec node, each beacon device has a protection subnet with the same subnet position as it, and the service SP corresponding to the protection subnet is associated with the beacon device; the network protocol run by the beacon device is TCP protocol and / or UDP protocol;

[0018] The detection SP is used to instruct the second IPSec node to perform path detection on N first IPSec nodes, specifically:

[0019] The second IPSec node initiates a probe to the beacon device using the TCP protocol and / or the UDP protocol; the probe includes a request packet and a response packet; the request packet is sent by the second IPSec node, and the response packet is responded by the beacon device;

[0020] The beacon device checks its own network status. If a fault occurs, it replies with a response packet containing an error code. When the second IPSec node receives an error response packet or does not receive a response packet within a specified time, it considers that an error packet has been generated in the current probe request and continues to send a probe request to the beacon device.

[0021] When the second IPSec node receives a preset number of error packets cumulatively, it determines that the first IPSec node corresponding to the beacon device is invalid, and considers that the round-trip path between the second IPSec node and the corresponding first IPSec node is inconsistent or unavailable;

[0022] When the second IPSec node determines that the corresponding first IPSec node is invalid, it checks whether the corresponding first IPSec node is on a network link currently being used by a certain service SP. If so, the corresponding service SP is switched to another first IPSec node.

[0023] In an optional example, the switching of the service SP to another first IPSec node whose round-trip path detected by the second IPSec node is consistent and available is specifically:

[0024] The second IPSec node records the received decrypted traffic of the service SP of the path to be switched;

[0025] The second IPSec node determines the sender route of the service SP to which it belongs from the decrypted data according to the data format of the tunnel mode, and switches the service SP to the first IPSec node corresponding to the sender route;

[0026] Subsequently, once the second IPSec node determines that the primary first IPSec node of the service SP is valid, it restores the link of the service SP to the primary first IPSec node.

[0027] In an optional example, the switching of the service SP to another first IPSec node with consistent and available round-trip paths detected by the second IPSec node is specifically as follows:

[0028] Find the beacon device associated with the service SP, modify the detected SP to the beacon device, randomly select other first IPSec nodes except the failed first IPSec node as the peer of the detected SP, and then detect the beacon device until the detection reply is valid, and switch the link of the service SP to the first IPSec node with valid detection;

[0029] Subsequently, once the second IPSec node detects that the primary first IPSec node of the service SP is valid, it restores the link of the service SP to the primary first IPSec node.

[0030] In an optional example, if no beacon device is set, the detected SP is used to protect: the second IPSec node address and the first IPSec node address;

[0031] If a beacon device is set, the detected SP is used to protect: the second IPSec node address and the beacon device address.

[0032] In an optional example, the sending time interval of the detection request packet and the preset number of wrong packets are adjustable to control the sensitivity of route dynamic changes.

[0033] In an optional example, each service subnet selects 1 node from N first IPSec nodes as the primary first IPSec node, specifically as follows:

[0034] Each service subnet takes the node with the shortest network path required for processing its service among the N first IPSec nodes as the primary first IPSec node, and the N first IPSec nodes are mutually backup first IPSec nodes, sharing the network load with each other;

[0035] The priority of the primary first IPSec node is higher than that of the backup first IPSec node.

[0036] In an optional example, the method further includes the following steps:

[0037] If the primary first IPSec nodes of multiple service SPs are the same, then merge the multiple service SPs into one service SP.

[0038] In a second aspect, the present invention provides an IPSec tunnel mode communication device for multi-link dynamic routing, including: a memory and a processor;

[0039] The memory is used to store computer programs;

[0040] The processor is used to implement the method provided in the first aspect above when executing the computer program.

[0041] Generally speaking, compared with the prior art through the above technical solutions conceived by the present invention, the following beneficial effects are achieved:

[0042] The present invention provides an IPSec tunnel mode communication method and device for multi-link dynamic routing. For a dynamic routing network environment, the tunnel mode is selected to hide the real source and destination addresses and communication protocols of IP data, improving communication security. A method for planning service subnets is proposed, which corresponds to the central IPSec node and can merge service SPs, can perform overall switching, adapt to the changes of dynamic routing, and achieve the purpose of mutual backup.

[0043] The present invention provides an IPSec tunnel mode communication method and device for multi-link dynamic routing, and designs a dedicated SP for detection with the highest priority. The link is detected on this dedicated link, and the path change and asymmetric routing are fed back, and accordingly, the service link is switched to ensure the consistency of the round-trip path.

[0044] The present invention provides an IPSec tunnel mode communication method and device for multi-link dynamic routing, and designs a beacon device for responding to detection, which is arranged at the end of the routing after the central IPSec node. This device is any device or client running the TCP protocol or UDP protocol, and its function is to receive the detection request packet, construct a response packet using the sequence number of the request packet for reply, detect the actual path of the dynamic routing through the beacon device, and select multiple links according to the beacon detection result.

[0045] The present invention provides an IPSec tunnel mode communication method and device for multi-link dynamic routing, with configurable detection parameters, such as the packet sending interval of the request packet and the number of wrong packets, which can flexibly adjust the sensitivity and achieve a balance between fast switching and avoiding network oscillation. Description of the Drawings

[0046] Figure 1Simplified flowchart of the IPSec tunnel mode communication method for multi-link dynamic routing provided by the embodiments of the present invention;

[0047] Figure 2 Detailed flowchart of the IPSec tunnel mode communication method for multi-link dynamic routing provided by the embodiments of the present invention;

[0048] Figure 3 Schematic diagram of the differences between the tunnel mode and the transport mode provided by the embodiments of the present invention;

[0049] Figure 4 Schematic diagram of deploying multi-link central IPSec nodes in a dynamic routing environment provided by the embodiments of the present invention;

[0050] Figure 5 Schematic diagram of deploying multi-link central IPSec nodes in the case of having beacons provided by the embodiments of the present invention. Detailed implementation manners

[0051] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part rather than all of the embodiments of the present invention. The following description of at least one exemplary embodiment is actually illustrative only and in no way restricts the present invention and its application or use. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the scope of protection of the present invention.

[0052] It should be noted that the terms used herein are only for describing specific implementation manners and are not intended to limit the exemplary embodiments of the present invention. As used herein, unless otherwise clearly specified in the context, the singular form is also intended to include the plural form. In addition, it should be understood that when the terms "comprise" and / or "include" are used in this specification, they indicate the presence of features, steps, operations, devices, components and / or their combinations.

[0053] Unless otherwise specifically stated, the relative arrangement of components and steps, numerical expressions, and numerical values set forth in these embodiments do not limit the scope of the present invention. At the same time, it should be clear that, for the sake of convenience of description, the sizes of the various parts shown in the drawings are not drawn in actual proportional relationships. Technologies, methods, and devices known to those of ordinary skill in the relevant art may not be discussed in detail, but where appropriate, such technologies, methods, and devices should be regarded as part of the authorization specification. In all the examples shown and discussed here, any specific value should be interpreted as merely exemplary and not as a limitation. Therefore, other examples of the exemplary embodiments may have different values. It should be noted that like reference numerals and letters denote like items in the following drawings, and thus, once an item is defined in one drawing, it does not need to be further discussed in subsequent drawings.

[0054] In the description of the present invention, the meaning of "a number of" is more than one, the meaning of "a plurality of" is more than two, and understandings such as "greater than", "less than", "exceeding", etc. do not include the present number, and understandings such as "above", "below", "within", etc. include the present number. If there is a description of "first" and "second", it is only for the purpose of distinguishing technical features and cannot be understood as indicating or implying relative importance or implicitly indicating the quantity of the indicated technical features or implicitly indicating the sequence relationship of the indicated technical features.

[0055] In the description of the present invention, descriptions with reference to terms such as "an embodiment", "some embodiments", "schematic embodiments", "examples", "specific examples", or "some examples", etc. mean that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples.

[0056] In view of the deficiencies of the above-mentioned prior art, the present invention provides an IPSec tunnel mode communication method for multi-link dynamic routing, which can hide the true source, destination addresses, and communication protocols of IP data, improve communication security; automatically generate a probe SP for routing detection according to multiple peer security policies, automatically generate an SA (Security Association) associated with the probe SP, perform reachability and symmetry detection on the path on this dedicated IPSec link, and when the routing is asymmetric or unavailable, switch the routing to a symmetric and available link to ensure symmetric routing and achieve link backup and dynamic routing adaptation.

[0057] Figure 1 This is a simplified flowchart of the IPSec tunnel mode communication method for multi-link dynamic routing provided by the embodiments of the present invention; asFigure 1 As shown in the figure, it includes the following steps:

[0058] S11, Set N network links at the central end, and deploy an Internet Security Protocol (IPSec) node on each link, which is called the first IPSec node; deploy an IPSec node at each remote end, which is called the second IPSec node; all the first IPSec nodes and the second IPSec nodes have a communication relationship with each other.

[0059] S12, Divide multiple service subnets at the central end into N first IPSec nodes. For each service subnet, select the node with the shortest network path among the N first IPSec nodes as the primary first IPSec node, and the other N-1 nodes as the standby first IPSec nodes.

[0060] S13, Configure the service security policy (SP) for each service subnet separately, and generate the corresponding detection SP according to each service SP; the SP uses the tunnel mode, and the priority of the detection SP is higher than that of the service SP.

[0061] S14, Control the N first IPSec nodes and the second IPSec nodes to establish IPSec links for all service SPs and detection SPs; the service SP preferentially uses the primary first IPSec node for communication, and the detection SP is used to instruct the second IPSec node to perform path detection on the N first IPSec nodes.

[0062] S15, When the second IPSec node detects that the round-trip path between the first IPSec node currently used by the service SP and the second IPSec node is inconsistent or unavailable, switch the service SP to other first IPSec nodes where the round-trip path detected by the second IPSec node is consistent and available.

[0063] Specifically, the detailed process of the IPSec tunnel mode communication method for multi-link dynamic routing provided by the embodiments of the present invention is as Figure 2 shown, including the following steps:

[0064] (1) Step S101, Pre-set the network to use the dynamic routing protocol, set N network links at the central end, and deploy an IPSec node on each network link at the central end, that is, there are N central end IPSec nodes (N≥2).

[0065] (2) Step S102, Optionally, a beacon device for detection can be set at the end of the route after each central end IPSec node in step S11. This device is any device or client running the TCP protocol or UDP protocol, and its function is to receive the detection request packet and construct a response packet using the sequence number of the request packet for reply.

[0066] (3) In step S103, multiple service subnets at the central end are divided among N central - end IPSec nodes. The division rule is: the central - end IPSec node with the shortest network path to a specific service subnet is set as the primary central node of this subnet, and the remaining central - end IPSec nodes are the backup central nodes of this subnet. For different central - end service subnets, each service subnet has 1 primary central IPSec node and N - 1 backup central nodes. All central - end IPSec nodes are backup to each other and share the load.

[0067] (4) In step S104, on the remote - end IPSec nodes, an SP is configured separately for each central service subnet. The peer nodes are the N IPSec nodes at the central end. The primary central node of this central service subnet is set as the highest priority, and the other N - 1 IPSec nodes are set as the same lower priority. All SPs use the tunnel mode.

[0068] (5) In step S105, optionally, the service SPs in step S104 can be merged. If the primary central peer nodes in the service SPs are the same, then these multiple service SPs can be merged into one service SP, and this service SP protects multiple subnets.

[0069] (6) In step S106, the remote - end IPSec nodes automatically generate a probing SP for detection according to the SP. The priority of the probing SP is higher than that of the SP protecting the service subnet.

[0070] (7) In step S107, optionally, if the beacon in step S102 is not set, then the probing SP of the remote - end IPSec node in step S106 protects: the remote - end IPSec node address and the central - end IPSec node address.

[0071] (8) In step S108, optionally, if the beacon in step S102 is set, then the probing SP of the remote - end IPSec node in step S106 protects: the remote - end IPSec node address and the beacon address after the central - end IPSec node.

[0072] (9) In step S109, all IPSec nodes establish IPSec links for the service SP and the probing SP, and regardless of whether the link is valid, the link is not torn down to ensure fast switching.

[0073] (10) Step S110: All service SPs preferentially use the central IPSec nodes with the highest priority for communication. Each remote IPSec node uses a probing SP to perform path probing on all central IPSec nodes respectively. Since the probing SP has a higher priority than the service SP, the probing is not affected by other links. The probing uses the TCP and / or UDP protocol, with request packets and response packets, and the sequence numbers of the request packets and response packets should correspond. The responder of the probing packet needs to check the current network or its own status. If a fault occurs, an error code is returned. Since the TCP and / or UDP protocol is used, asymmetric routing can be feedback. Receiving an error response packet or not receiving a response packet within a specified time is considered that a wrong packet occurs for the current probing. When the number of wrong packets accumulates to a certain number, it is determined that the central IPSec node fails, and it is considered that the link is not established, disconnected, or the round-trip path is inconsistent. When it is determined that the node fails, check whether the central IPSec node is the central IPSec node of a certain service SP: If so, the service SP switches to the remaining central IPSec nodes.

[0074] (11) Step S111: The probing in step S110 is based on two parameters: the packet sending interval and the number of wrong packet determinations. The packet sending interval refers to the time interval between each probing packet; the number of wrong packet determinations refers to determining that the link fails when a specified number of wrong packets or no response packets occur. Shortening the packet sending interval or reducing the number of wrong packet determinations can improve the sensitivity of the IPSec node to network dynamic changes and enhance the switching rate; lengthening the packet sending interval or increasing the number of wrong packet determinations can reduce the sensitivity of the IPSec node to network dynamic changes and avoid frequent back-and-forth switching caused by frequent network changes.

[0075] (12) Step S112: If there is no beacon device deployed in the network, the optional switching scheme in step S110 is: The remote IPSec node records the incoming decrypted traffic. Through the new IP header and SA index number in the tunnel mode, it can know which central IPSec node it comes from, and correspondingly switches to that central IPSec node. Subsequently, link switching can be performed again according to the peer of the incoming decrypted traffic. If the probing route to the main central node resumes effectiveness, the link of the service SP is restored to the main central node.

[0076] It should be noted that the main central IPSec nodes of each service SP are different from each other to allocate different network services, and clear division of labor is achieved between different network links. The routing switching method given in the present invention switches its routing when one or some links are occasionally faulty (routing asymmetry or unavailable) to achieve routing backup and avoid data loss. When its main central IPSec node resumes availability, the service SP is immediately switched back to avoid frequent changes in network division of labor and ensure the stable operation of network services.

[0077] As Figure 3 shown, in the tunnel mode, a new IP header is added before the original IP header. The source and destination IP addresses of the new IP header are the two corresponding IPSec nodes respectively. The tunnel mode can encrypt the original IP header to make it invisible to untrusted networks and use the external IP header for routing. Since it hides the true source, destination addresses and communication protocols of the IP data, its security is higher than that of the transport mode.

[0078] (13) Step S113, if a beacon device is deployed in the network, the optional switching scheme in step S110 is: the remote IPSec node does not record the incoming decrypted traffic, modifies the detection SP of the beacon device corresponding to the main central IPSec node, randomly uses the standby central IPSec node as the peer and then conducts detection until the detection returns valid. Since the beacon device is deployed at the end of the routing network, if the return is valid, it indicates that the two-way path is consistent, and the service link is switched to the standby central IPSec node determined to be valid. Subsequent link switching can be performed according to the detection results of the beacon device.

[0079] As Figure 4 shown, in the first embodiment, the central network deploys N mutually backup and load-balanced links. Uneven numbers of subnets are deployed behind each central link. An IPSec node and a firewall are deployed on each central link, where the firewall is not necessary. The routing device of the central network enables dynamic routing protocols such as OSPF and RIP, and the entire network can also use dynamic routing protocols for route selection. The central network can connect multiple remote IPSec nodes through an untrusted network. Figure 4 Only one remote path is drawn in the figure. It is necessary to protect the link between the remote IPSec node and the central IPSec node. In the first embodiment, the Encapsulating Security Payload (ESP) and the tunnel mode are selected.

[0080] Combined with Figure 4 , the specific implementation process and steps of the IPSec tunnel mode communication method for multi-link dynamic routing in the first embodiment of the present invention are as follows:

[0081] Step S201, divide the multiple service subnets protected by the central network among N central IPSec nodes. Figure 4 Among them, the network path from subnet A to central IPSec node 1 is the shortest. Set IPSec node 1 as the main central node of subnet A, and the remaining IPSec nodes as the standby nodes of subnet A. And so on, the main central nodes of subnet B and subnet C are IPSec node 2, and the main central node of subnet D is IPSec node N.

[0082] In step S202, after the master central node is partitioned, it is necessary to configure the SP on all IPSec nodes. Taking Figure 4 as an example, the remote IPSec node itself protects subnet E. N SPs are configured to the central network. Each SP has N peers. For the SP to subnet A, the central IPSec1 at the central end is set as the highest priority, and the other central-end IPSec nodes are set as the same lower priority. The master central nodes of subnets B and C are the same, so they can be combined. And so on to complete the SP configuration of all nodes. The specific configuration is shown in Table 1:

[0083] Table 1

[0084]

[0085] In step S203, the remote IPSec node automatically generates a probing SP for detection according to its own SP. There is at most one probing SP for both ends of the IPSec nodes. The priority of the probing SP is higher than that of the SP protecting the service subnet. The probing SP protects the remote IPSec node address and the central-end IPSec node address.

[0086] In step S204, all IPSec nodes establish IPSec links for the service SP and the probing SP, and no matter whether the link is valid or not, the link is not torn down to ensure fast switching.

[0087] In step S205, all service SPs prefer to use the central-end IPSec node with the highest priority for communication. The remote IPSec node uses the probing SP to perform path detection on all central-end IPSec nodes. Since the probing SP has a higher priority than the service SP, the detection is not affected by other links. The probing packet in this embodiment uses the TCP protocol. The request packet contains a sequence number and is protected by encryption through a dedicated link. After receiving the request packet, the central-end IPSec node constructs a response packet using the sequence number in the request packet. At the same time, the central-end IPSec node also fills in a status value in the response packet. If the route to all the next hops is reachable and its own device is working properly, the status value is 0; otherwise, a non-zero value is filled in, and the error code corresponding to the specific error is filled in. Since the TCP protocol is used, it can feedback asymmetric routes. If the remote IPSec node receives an incorrect response packet or does not receive a response packet within a specified time, it is considered that a wrong packet is generated for the current detection. When the wrong packets accumulate to a certain number, it is determined that the central-end IPSec node fails, and it is considered that the link is not established, disconnected, or the round-trip path is inconsistent. When it is determined that the failure occurs, check whether the central-end IPSec node is the central-end IPSec node on the link being used by a certain service SP: If so, switch the corresponding service SP to other central-end IPSec nodes.

[0088] Step S206: In Embodiment 1, the detected packet sending interval can be set to 1 second, and the number of mispacket judgments can be set to 3. After verification, this setting can ensure second-level switching and avoid network oscillations. When it is determined that a primary node fails and needs to be switched, since the previously established service links are not torn down, the dynamic routing protocol will automatically select another path to send data. The remote IPSec node parses the incoming decrypted traffic. If it is the service SP that needs to be switched, the central IPSec node of the actual path is obtained based on the new IP header and SA index number in the tunnel mode after the incoming decrypted traffic. Then, the link of the service SP is switched to this central IPSec node. Subsequently, the link can be switched again according to the peer of the incoming decrypted traffic.

[0089] Step S207: If the detection of the primary central node becomes effective again, the link of the service SP is restored to the primary central node.

[0090] As Figure 5 shown, in Embodiment 2 of the present invention, a beacon device for detection is set at the end of the routing after each central IPSec node. This device is an independent device running the TCP protocol, which receives detection request packets and constructs response packets using the sequence numbers of the request packets for reply. Only the processes and steps different from those in Example 1 are described here:

[0091] Step S301: The difference between this embodiment and Step S203 in Embodiment 1 is that the detection SP automatically generated by the remote IPSec node protects the address of the remote IPSec node and the address of the beacon device.

[0092] Step S302: The difference between this embodiment and Step S205 in Embodiment 1 is that the central IPSec node no longer listens for and receives request packets, but instead the beacon device receives them. The beacon device constructs a response packet using the sequence number in the request packet. At the same time, the beacon device also fills in a status value in the response packet. If all the next-hop routes from itself are reachable, the status value is 0; otherwise, a non-zero value is filled in, and the error code corresponding to the specific error is filled in. Since the beacon device is at the end of the dynamic routing network and uses the TCP protocol, it can feedback the routing path situation.

[0093] Step S303: The remote IPSec node no longer needs to parse the incoming decrypted traffic. When it is determined that a central IPSec node fails and needs to be switched, the remote IPSec node modifies the detection SP to the beacon device corresponding to the central IPSec node, randomly selects another central IPSec node as the peer end, establishes a dedicated connection, and then conducts detection until a valid detection report is obtained. Since the beacon device is deployed at the end of the routing network, due to the existence of the firewall, the firewall will only release traffic when the routing paths in both directions are the same. Therefore, there will be only one available central IPSec node. After switching the service link to the determined valid central IPSec node, subsequent link switching can be performed based on the detection results of the beacon device.

[0094] In addition, an embodiment of the present invention provides a communication device, which includes: a memory and a processor;

[0095] The memory is used to store computer programs;

[0096] The processor is used to implement the method in the above embodiment when executing the computer program.

[0097] Furthermore, the present invention also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the method in the above embodiment is implemented.

[0098] Based on the method in the above embodiment, an embodiment of the present invention provides a computer program product. When the computer program product runs on a processor, the processor is caused to execute the method in the above embodiment.

[0099] Based on the method in the above embodiment, an embodiment of the present invention further provides a chip, which includes one or more processors and an interface circuit. Optionally, the chip may further include a bus. Wherein: The processor may be an integrated circuit chip with signal processing capabilities. During implementation, the steps of the above method can be completed through the integrated logic circuit in the hardware of the processor or instructions in software form. The above processor may be a general-purpose processor, a digital communicator (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods and steps disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0100] The interface circuit can be used for sending or receiving data, instructions, or information. The processor can utilize the data, instructions, or other information received by the interface circuit for processing, and can send the processed information through the interface circuit.

[0101] Optionally, the chip further includes a memory, which may include a read-only memory and a random access memory, and provides operation instructions and data to the processor. A part of the memory may also include a non-volatile random access memory (NVRAM).

[0102] Optionally, the memory stores executable software modules or data structures, and the processor can execute corresponding operations by calling the operation instructions stored in the memory (the operation instructions can be stored in the operating system).

[0103] Optionally, the interface circuit can be used to output the execution result of the processor.

[0104] It should be noted that the functions corresponding to the processor and the interface circuit can be implemented through hardware design, software design, or a combination of hardware and software, and there is no limitation here.

[0105] It should be understood that the steps of the above method embodiments can be completed by the logic circuit in hardware form or the instructions in software form in the processor. It can be understood that the sequence numbers of the steps in the above embodiments do not mean the order of execution. The execution order of each process should be determined according to its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application. In addition, in some possible implementation manners, the steps in the above embodiments can be selectively executed according to the actual situation, can be partially executed, or can be fully executed, and there is no limitation here.

[0106] It can be understood that the processor in the embodiments of the present application can be a central processing unit (CPU), and can also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor can be a microprocessor or any conventional processor.

[0107] The method steps in the embodiments of the present application can be implemented in a hardware manner or by a processor executing software instructions. The software instructions can be composed of corresponding software modules, and the software modules can be stored in a random access memory (RAM), flash memory, read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), register, hard disk, removable hard disk, CD-ROM, or any other form of storage medium well-known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and the storage medium can be located in an ASIC.

[0108] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted through the computer-readable storage medium. The computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired manner (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or a wireless manner (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that the computer can access or a data storage device such as a server, data center, etc. that includes one or more integrated available media. The available medium can be a magnetic medium (for example, floppy disk, hard disk, magnetic tape), an optical medium (for example, DVD), or a semiconductor medium (for example, solid state disk (SSD)), etc.

[0109] Those skilled in the art can easily understand that the above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, and improvements made within the spirit and principles of the present invention should be included in the protection scope of the present invention.

Claims

1. An IPSec tunnel mode communication method for multi-link dynamic routing, which is applicable to a communication network. The communication network includes a central end and a remote end, and the communication network adopts a dynamic routing protocol; characterized in that, The method comprises the following steps: N network links are set up at the central end and an Internet Security Protocol IPSec node is deployed on each link, which is called the first IPSec node; an IPSec node is deployed on each remote end, which is called the second IPSec node; All first IPSec nodes have an intercommunication relationship with second IPSec nodes; Divide multiple service subnets of the center into N first IPSec nodes, select the node with the shortest network path among the N first IPSec nodes as the main first IPSec node for each service subnet, and the other N-1 nodes as backup first IPSec nodes; Configure a service security policy SP for each service subnet separately, and generate a corresponding detection SP based on each service SP; The SP adopts the tunnel mode, and the detection SP has a higher priority than the service SP; Control N first IPSec nodes and second IPSec nodes to establish IPSec links for all service SPs and detection SPs; the service SPs preferentially use the primary first IPSec node for communication, and the detection SP is used to instruct the second IPSec node to perform path detection on the N first IPSec nodes; When the second IPSec node detects that the round-trip path between the first IPSec node and the second IPSec node currently used by the service SP is inconsistent or unavailable, the service SP is switched to another first IPSec node whose round-trip path detected by the second IPSec node is consistent and available.

2. The method according to claim 1, wherein The detection SP is used to instruct the second IPSec node to perform path detection on N first IPSec nodes, specifically: The second IPSec node initiates a probe to the first IPSec node using the TCP protocol and / or the UDP protocol; the probe includes a request packet and a response packet; the request packet is sent by the second IPSec node, and the response packet is responded by the first IPSec node; The first IPSec node checks the path status to the protection subnet and its own status. If a fault occurs, it replies with a response packet containing an error code. When the second IPSec node receives an erroneous response packet or does not receive a response packet within a specified time, it considers that an error packet is generated in the current probe request and continues to send a probe request packet to the first IPSec node. A beacon device is set at the end of the route behind each first IPSec node. Each beacon device has a protection subnet with the same subnet location as it, and the service SP corresponding to the protection subnet is associated with the beacon device. When the second IPSec node receives a preset number of error packets cumulatively, it determines that the corresponding first IPSec node is invalid, and considers that the round-trip path between the second IPSec node and the corresponding first IPSec node is inconsistent or unavailable; When the second IPSec node determines that the corresponding first IPSec node is invalid, it checks whether the corresponding first IPSec node is on a network link currently being used by a certain service SP. If so, the corresponding service SP is switched to another first IPSec node.

3. The method according to claim 1, wherein The following steps are also included: A beacon device is set at the end of the route after each first IPSec node, each beacon device has a protection subnet with the same subnet position as it, and the service SP corresponding to the protection subnet is associated with the beacon device; the network protocol run by the beacon device is TCP protocol and / or UDP protocol; The detection SP is used to instruct the second IPSec node to perform path detection on N first IPSec nodes, specifically: The second IPSec node initiates a probe to the beacon device using the TCP protocol and / or the UDP protocol; the probe includes a request packet and a response packet; the request packet is sent by the second IPSec node, and the response packet is responded by the beacon device; The beacon device checks its own network status. If a fault occurs, it replies with a response packet containing an error code. When the second IPSec node receives an error response packet or does not receive a response packet within a specified time, it considers that an error packet has been generated in the current probe request and continues to send a probe request to the beacon device. When the second IPSec node receives a preset number of error packets cumulatively, it determines that the first IPSec node corresponding to the beacon device is invalid, and considers that the round-trip path between the second IPSec node and the corresponding first IPSec node is inconsistent or unavailable; When the second IPSec node determines that the corresponding first IPSec node is invalid, it checks whether the corresponding first IPSec node is on a network link currently being used by a certain service SP. If so, the corresponding service SP is switched to another first IPSec node.

4. According to the method of claim 2, the switching of the service SP to other first IPSec nodes whose round-trip paths detected by the second IPSec node are consistent and available is specifically: The second IPSec node records the received decrypted traffic of the service SP of the path to be switched; The second IPSec node determines the sender route of the service SP to which it belongs from the decrypted data according to the data format of the tunnel mode, and switches the service SP to the first IPSec node corresponding to the sender route; Once the subsequent second IPSec node determines that the primary first IPSec node of the service SP is valid, it restores the link of the service SP to the primary first IPSec node.

5. The method according to claim 3, wherein The switching of the service SP to other first IPSec nodes detected by the second IPSec node with consistent round-trip paths and available is specifically: Find the beacon device associated with the service SP, modify the detection SP of the beacon device, randomly select other first IPSec nodes except the failed first IPSec node as the peer of the detection SP, and then detect the beacon device until the detection reply is valid, and switch the link of the service SP to the first IPSec node with valid detection; Once the subsequent second IPSec node detects that the primary first IPSec node of the service SP is valid, it restores the link of the service SP to the primary first IPSec node.

6. The method according to claim 2 or 3, characterized in that, If the beacon device is not set, the detection SP is used to protect: the second IPSec node address and the first IPSec node address; If the beacon device is set, the detection SP is used to protect: the second IPSec node address and the beacon device address.

7. The method according to claim 2 or 3, characterized in that, The transmission time interval of the detection request packet and the preset number of wrong packets are adjustable to control the sensitivity of the routing dynamic change.

8. The method according to claim 1, characterized in that Each service subnet selects 1 node from the N first IPSec nodes as the primary first IPSec node, specifically: Each service subnet takes the node with the shortest network path required for its service among the N first IPSec nodes as the primary first IPSec node, and the N first IPSec nodes are mutually backup first IPSec nodes to share the network load with each other; The priority of the primary first IPSec node is higher than that of the backup first IPSec node.

9. The method according to claim 1, wherein It further includes the following steps: If the primary first IPSec nodes of multiple service SPs are the same, the multiple service SPs are merged into one service SP.

10. An IPSec tunnel mode communication device for multi-link dynamic routing, characterized in that, It includes: A memory and a processor; The memory is used to store computer programs; The processor is used to implement the method according to any one of claims 1-9 when executing the computer program.

Citation Information

Patent Citations

  • Internet protocol security link protection method and device

    CN101931610A

  • Tunnel selecting method, device and system

    CN104601430A