An IPv6 Address Prefix Encoding Method, Device, Storage Medium and Electronic Device
By embedding the ciphertext of entity identifiers and timestamps or random numbers in the IPv6 address prefix, the IPv6 address prefix is generated, and the association problem between responsible entities and IPv6 addresses in the 5G network is solved, and the rapid traceability accountability is achieved, which is suitable for IPv6 address allocation in 5G networks.
Patent Information
- Application Number
- CN202211193796.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-28
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2042-09-28
AI Technical Summary
In 5G networks, it is difficult for the existing technology to effectively associate the responsible entity with the IPv6 address, resulting in difficulty in tracing the source of network attacks, especially in the SLAAC address allocation method, which cannot realize entity identification embedding.
By embedding the ciphertext of entity identifier, timestamp or random number in the IPv6 address prefix, the obfuscation algorithm is used to generate the sub-prefix, and combined with the auxiliary flag bits, the IPv6 address prefix is generated to realize the embedding and extraction of entity identifiers.
The traceability and accountability of responsible entities in 5G networks is realized, large-scale modifications to the existing network architecture are avoided, and rapid traceability accountability is supported.
Smart Images

Figure CN115941192B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of the Internet, and particularly relates to an IPv6 address prefix encoding method, device, storage medium, and electronic device. Background Art
[0002] IP address forgery has led to an increasingly prominent network security problem. Distributed denial of service attacks (DdoS) launched by means of forged source addresses are one of the important security threats to the current Internet, such as TCP SYN (Synchronize Sequence Numbers) flooding attacks, DNS (Domain Name System) reflection attacks, etc. To solve the problem of source address forgery, source address verification can be adopted, such as SAVA, etc. However, only using source address verification technology can only guarantee the authenticity of the address, and it is impossible to trace and hold accountable the responsible entity (i.e., the attacker), making it difficult to form a strong deterrent to network attacks. On the basis of the real source IP address, if the responsible entity can be associated with the IP address and a strong audit and accountability mechanism is implemented, a strong deterrent can be formed against attackers, so as to fundamentally alleviate network attacks.
[0003] The scale of 5G networks has shown leapfrog development, and it also faces the same problems. Since the above problems involve IP address allocation, the commonly used IPv6 address allocation methods in 5G networks are SLAAC (Stateless address autoconfiguration) and DHCPv6. The former is stateless address autoconfiguration, that is, the 5G network sends available prefixes to user terminals (UE, User Equipment), and the user terminals then select an available address under the prefix for their own use. The latter is stateful address autoconfiguration, that is, the 5G network directly allocates an available IPv6 address to the user terminal. Currently, the commonly used method by 5G operators is SLAAC, which usually allocates different IPv6 prefixes to different terminals, and each terminal can randomly select an IPv6 address from the obtained prefixes for use.
[0004] The existing methods for associating a responsible entity with an IPv6 address mainly include: (1) Recording the log of the correspondence between the IPv6 address and the responsible entity. However, this method requires searching in the network where the log is recorded, which is not convenient for quick traceability and accountability. (2) Embedding the responsible entity identifier in the interface identifier of the IPv6 address. However, this method is only applicable to DHCPv6, which does not conform to the current commonly used address allocation method in 5G networks (i.e., SLAAC).
[0005] Therefore, there is an urgent need in the art to solve the problem of associating and identifying responsible entities with IPv6 addresses under 5G networks. Summary of the Invention
[0006] The present invention provides an IPv6 address prefix encoding method, apparatus, storage medium, and electronic device, which realize embedding entity identifiers in the IPv6 addresses of specific entities under 5G networks, and associate the responsible entities in 5G networks with IPv6 addresses during IPv6 address prefix encoding, allocation, or entity identifier extraction. At the same time, large-scale modifications to the existing 5G network architecture and network elements of the core network are avoided, and the problem of associating and identifying responsible entities with IPv6 addresses under 5G networks is solved.
[0007] In a first aspect, an embodiment of the present invention provides an IPv6 address prefix encoding method, including:
[0008] Obtain a routing prefix;
[0009] Calculate a ciphertext including the entity identifier of the current entity, as well as a timestamp or a random number;
[0010] Generate a sub-prefix based on the ciphertext and an auxiliary flag bit for assisting in identifying the entity type;
[0011] Generate a prefix of the IPv6 address of the current entity based on the routing prefix and the sub-prefix.
[0012] In some implementation manners, a confusion algorithm or an encryption algorithm is used to calculate a ciphertext including the entity identifier of the current entity, as well as a timestamp or a random number.
[0013] In some implementation manners, using a confusion algorithm to calculate a ciphertext including the entity identifier of the current entity, as well as a timestamp or a random number, includes:
[0014] In the binary data of the entity identifier of the current entity, insert 1 bit of timestamp or random number every preset number of bits to obtain a ciphertext including the entity identifier of the current entity, as well as a timestamp or a random number, and the ciphertext is in binary form.
[0015] In some implementation manners, the generating a sub-prefix based on the ciphertext and an auxiliary flag bit for identifying the entity type includes:
[0016] Perform an exclusive OR operation on each bit of timestamp or random number in the ciphertext with the binary data of the entity identifier of the previous preset number of bits respectively to obtain an exclusive OR operation result;
[0017] Based on the total exclusive OR value of the exclusive OR operation result, set the auxiliary flag bit to identify that the entity type of the current entity is an entity identifier that has been embedded;
[0018] Generate a sub-prefix based on the XOR operation result and the auxiliary flag bit.
[0019] In a second aspect, an embodiment of the present invention provides an IPv6 address prefix allocation method, including:
[0020] In response to receiving an access request message of the current entity, perform secondary authentication according to the DNN configuration file;
[0021] When the secondary authentication is passed, query the entity identifier of the current entity;
[0022] Use the IPv6 address prefix encoding method described in the first aspect to generate the prefix of the IPv6 address of the current entity;
[0023] Encapsulate the prefix of the IPv6 address of the current entity in an access response message to allocate the prefix to the current entity.
[0024] In a third aspect, an embodiment of the present invention provides an entity identifier extraction method for an IPv6 address, including:
[0025] Extract the prefix of the IPv6 address of the current data packet, where the prefix of the IPv6 address is allocated based on the IPv6 address prefix allocation method described in the second aspect;
[0026] Determine the XOR result of the sub-prefix in the prefix, and send the entity type of the current entity of the current data packet based on the XOR result;
[0027] When it is determined that the entity type of the current entity is an entity identifier that has been embedded, restore the entity identifier of the current entity based on the sub-prefix.
[0028] In some implementation manners, the restoring the entity identifier of the current entity based on the sub-prefix includes:
[0029] Restore the entity identifier of the current entity by using the inverse process of the confusion algorithm or the decryption algorithm.
[0030] In some implementation manners, restoring the entity identifier of the current entity by using the inverse process of the confusion algorithm includes:
[0031] Extract the timestamp or random number inserted during encoding from the sub-prefix;
[0032] Perform XOR on each bit of the timestamp or random number with the numbers of the previous preset number of bits;
[0033] Remove the timestamp or random number to obtain the entity identifier of the current entity.
[0034] In a fourth aspect, an embodiment of the present invention provides an IPv6 address prefix encoding device, including:
[0035] An acquisition module, configured to acquire a routing prefix;
[0036] A calculation module, configured to calculate a ciphertext including an entity identifier of a current entity and a timestamp or a random number;
[0037] A first generation module, configured to generate a sub-prefix based on the ciphertext and an auxiliary flag bit for assisting in identifying an entity type;
[0038] A second generation module, configured to generate a prefix of an IPv6 address of a current entity based on the routing prefix and the sub-prefix.
[0039] In a fifth aspect, an embodiment of the present invention provides an IPv6 address prefix allocation device, including:
[0040] An authentication module, configured to perform secondary authentication according to a DNN configuration file in response to receiving an access request message of a current entity;
[0041] A query module, configured to query an entity identifier of a current entity when the secondary authentication is passed;
[0042] A generation module, configured to generate a prefix of an IPv6 address of a current entity by using the device described in the fourth aspect;
[0043] An allocation module, configured to encapsulate the prefix of the IPv6 address of the current entity in an access response message to allocate the prefix to the current entity.
[0044] In a sixth aspect, an embodiment of the present invention provides an entity identifier extraction device for an IPv6 address, including:
[0045] An extraction module, configured to extract a prefix of an IPv6 address of a current data packet, where the prefix of the IPv6 address is allocated by the IPv6 address prefix allocation device described in the fifth aspect;
[0046] A determination module, configured to determine an exclusive OR result of sub-prefixes in the prefix, and send an entity type of the current entity of the current data packet based on the exclusive OR result;
[0047] A restoration module, configured to restore an entity identifier of a current entity based on the sub-prefix when it is determined that the entity type of the current entity is an entity identifier that has been embedded.
[0048] In a seventh aspect, an embodiment of the present invention provides a computer storage medium, where a computer program is stored on the computer-readable storage medium, and when the computer program is executed by one or more processors, the method described in the first aspect, the second aspect, or the third aspect is implemented.
[0049] In an eighth aspect, an embodiment of the present invention provides a server, including a memory and one or more processors. A computer program is stored on the memory, and when the computer program is executed by the one or more processors, the method described in the first aspect, the second aspect, or the third aspect is implemented.
[0050] One or more embodiments of the present invention can at least bring the following beneficial effects:
[0051] When a current entity accesses a 5G network, first, a ciphertext containing an ID and a TS is calculated using an obfuscation algorithm to embed the entity identifier of the current entity; then, the ciphertext embedded with the entity identifier and a Flag field are combined to form a sub-prefix; finally, a routing prefix and the sub-prefix are synthesized into a prefix of an IPv6 address. The IPv6 address obtained based on the formed prefix can trace entity information due to the embedded entity identifier, realizing audit accountability. BRIEF DESCRIPTION OF THE DRAWINGS
[0052] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings required for use in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as limiting the scope.
[0053] Figure 1 is a flowchart of a method for encoding an IPv6 address prefix provided by an embodiment of the present invention;
[0054] Figure 2 is a schematic diagram of the composition of an IPv6 address provided by an embodiment of the present invention;
[0055] Figure 3 is an example of generating a sub-prefix provided by an embodiment of the present invention;
[0056] Figure 4 is a flowchart of a method for allocating an IPv6 address prefix provided by an embodiment of the present invention;
[0057] Figure 5 is a flowchart of implementing secondary authentication in the related art provided by an embodiment of the present invention;
[0058] Figure 6 is a flowchart of implementing secondary authentication provided by an embodiment of the present invention;
[0059] Figure 7 is a flowchart of a method for extracting an entity identifier of an IPv6 address provided by an embodiment of the present invention;
[0060] Figure 8 is an example of extracting an entity identifier provided by an embodiment of the present invention;
[0061] Figure 9It is a block diagram of an IPv6 address prefix encoding device provided by an embodiment of the present invention;
[0062] Figure 10 It is a block diagram of an IPv6 address prefix allocation device provided by an embodiment of the present invention;
[0063] Figure 11 It is a block diagram of an entity identifier extraction device for an IPv6 address provided by an embodiment of the present invention. Detailed implementation manners
[0064] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Usually, the components of the embodiments of the present invention described and illustrated herein can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely represents selected embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.
[0065] The secondary authentication technology in the 5G network allows the external AAA server to allocate a specified address for the UE through the SMF (Session Management function). The so-called secondary authentication means that in the 5G network architecture, when the UE performs the initialization registration process, an initial authentication is performed between the UE and the AUSF (Authentication Server Function). If the UE needs to access a private network, a secondary authentication will be performed before the session establishment process, where the private network can refer to a specific DNN (Data Network Name). The AAA server has authentication, authorization, and accounting functions. In the solution of the present invention, authentication can refer to identifying whether the access entity (such as a terminal) is an entity that needs to embed an identifier, and authorization can refer to allocating a prefix of an IPv6 address for embedding an entity identifier (such as an identifier of a terminal user, an identifier of an Internet of Things device, etc.). The DNN determines the access mode of the entity and the accessed network. The DNN selects the SMF and UPF (User Port Function) for the PDU (Protocol Data Unit) session and determines the policy applied to this PDU session.
[0066] Example 1
[0067] This embodiment provides an IPv6 address prefix encoding method, which can be applied to an AAA server, such asFigure 1 As shown in the figure, it includes:
[0068] Step S101: Obtain a routing prefix.
[0069] The IPv6 address is divided into three parts: a routing prefix, a sub-prefix, and an interface identifier. Among them, the routing prefix is used for routing; in this embodiment, the sub-prefix part is generated using an encoding method that embeds an entity identifier and is used for auditing and accountability; the interface identifier represents the address suffix used by an access entity (UE) under the prefix formed by the routing prefix and the sub-prefix.
[0070] Step S102: Calculate the ciphertext of the entity identifier including the current entity and a timestamp or a random number.
[0071] The composition of the IPv6 address in this embodiment is as Figure 2 shown, and the field descriptions for generating the sub-prefix are as follows:
[0072] ID: Entity identifier, that is, the identifier of the accessed entity, which is used to be embedded in the IPv6 address prefix. For example, the mapping from IMSI (International Mobile Subscriber Identity) or MSISDN (Mobile Subscriber's International ISDN Number) established and maintained by the 5G network to the ID can be used. The length of the ID determines the number of entities it identifies. If the length is short, the number of identified entities is limited.
[0073] TS: Timestamp or random number, which enables the prefix obtained by the entity each time it connects to the network to change dynamically.
[0074] Flag: Auxiliary flag bit, which is used to assist in identifying the entity type.
[0075] E(*): Confusion algorithm / encryption algorithm, which reversibly hides the ID in the sub-prefix.
[0076] In some implementation manners, a confusion algorithm or an encryption algorithm is used to calculate the ciphertext of the entity identifier including the current entity and a timestamp or a random number.
[0077] In some implementation manners, preferably, a confusion algorithm is used to calculate the ciphertext of the entity identifier including the current entity and a timestamp or a random number, including:
[0078] In the binary data of the entity identifier of the current entity, insert 1 bit of timestamp or random number every preset number of bits to obtain the ciphertext of the entity identifier including the current entity and a timestamp or a random number, and the ciphertext is in binary form.
[0079] Step S103: Generate a sub-prefix based on the ciphertext and the auxiliary flag bit used to identify the entity type.
[0080] In some implementations, generating a sub-prefix based on the ciphertext and an auxiliary flag bit for identifying the entity type includes:
[0081] Step S103a: Perform an exclusive OR operation on each bit of the timestamp or random number in the ciphertext and the binary data of the entity identifier with a previously preset number of bits respectively to obtain the result of the exclusive OR operation.
[0082] Step S103b: Based on the total exclusive OR value of the result of the exclusive OR operation, set the auxiliary flag bit to identify that the entity type of the current entity is an entity identifier that has been embedded.
[0083] Step S103c: Generate a sub-prefix based on the result of the exclusive OR operation and the auxiliary flag bit.
[0084] The following takes a 32-bit routing prefix + 32-bit sub-prefix as an example to illustrate the generation of the sub-prefix:
[0085] In the 32-bit sub-prefix, it contains 26 bits of ID and 5 bits of TS, and also contains 1 bit of Flag, which is used to assist in indicating whether the current entity needs to be identified in the IPv6 address prefix. After setting the Flag bit, perform an exclusive OR operation on each bit of the 32-bit sub-prefix to obtain the result of the exclusive OR operation. Based on the result of the exclusive OR operation, determine the set auxiliary flag bit. If the auxiliary flag bit makes the 32-bit exclusive OR result be 1, it means that the entity identifier is embedded in the prefix of the IPv6 address. If the auxiliary flag bit makes the 32-bit exclusive OR result be 0, it means that the entity identifier is not embedded in the prefix of the IPv6 address.
[0086] In this example, a simple obfuscation algorithm is used to generate the sub-prefix. As Figure 3 shown, the ID of a current entity accessing the 5G network is 0x2B26AA5, the TS is 11010, and the preset number of bits is 5. Therefore, insert 1 bit of TS every 5 bits of ID to obtain a 31-bit sequence. Then perform an exclusive OR operation on each bit of TS and the corresponding first 5 bits of ID respectively to obtain a 31-bit result. The exclusive OR value of this 31-bit result is 1, so set the Flag bit to 0 to make the total exclusive OR result be 1, which means that the entity identifier is embedded in the sub-prefix of the IPv6 address. Therefore, the sub-prefix is generated as follows: 55B6:AB92.
[0087] Step S104: Generate the prefix of the IPv6 address of the current entity based on the routing prefix and the sub-prefix.
[0088] Based on generating the prefix of the IPv6 address of the current entity based on the routing prefix and the sub-prefix, generate an IPv6 address based on the prefix and the interface identifier (64bit).
[0089] In this embodiment, when the current entity accesses the 5G network, first, a ciphertext containing the ID and TS is calculated using a confusion algorithm to embed the entity identifier of the current entity; then, the ciphertext embedded with the entity identifier and the Flag field form a sub-prefix; finally, the routing prefix and the sub-prefix are combined to form the prefix of the IPv6 address. The IPv6 address obtained based on the formed prefix can trace the entity information due to the embedded entity identifier, realizing audit accountability.
[0090] Example 2
[0091] The implementation process of secondary authentication in the related art is as Figure 5 shown:
[0092] First, the UE requests to establish a PDU session. The SMF returns a response, instructing the UE to perform secondary authentication and requiring the acquisition of the UE's identifier UE-ID.
[0093] Then, the UE sends a PDU Session Authentication Complete message to the SMF, which carries the UE-ID for the AAA server to query.
[0094] Then, the EAP process (EAP, Extensible Authentication Protocol) is performed.
[0095] Then, the Access accept message sent by the AAA server carries the IPv6 address prefix allocated to the UE.
[0096] After the secondary authentication is completed, the UE sends an RS message (RS Router Solicitation Message) to the SMF, and the SMF replies with an RA message (Router Advertisement), carrying the allocated IPv6 address prefix.
[0097] However, Figure 5 the EAP process (steps 7 - 10) in
[0098] This embodiment provides an IPv6 address prefix allocation method, which can be applied to the AAA server, as Figure 4 shown, including:
[0099] Step S201, in response to receiving the access request message of the current entity, perform secondary authentication according to the DNN configuration file.
[0100] The AMF in the 5G network obtains the subscribed DNN of the entity from the UDM (Unified Data Management) in advance and maps the entity to a dedicated DNN. The SMF sends an Access request message to the AAA server, and the AAA server performs secondary authentication according to the DNN configuration file.
[0101] Step S202: When the secondary authentication is passed, query the entity identifier of the current entity.
[0102] Step S203: Use the IPv6 address prefix encoding method of Embodiment 1 to generate the prefix of the IPv6 address of the current entity.
[0103] The AAA server queries the ID of the corresponding UE, uses the IPv6 address prefix encoding method of Embodiment 1 to generate an IPv6 address prefix. The IPv6 address prefix encoding method of Embodiment 1 is detailed in the foregoing embodiments and will not be elaborated in this embodiment.
[0104] Step S204: Enclose the prefix of the IPv6 address of the current entity in an access response message to allocate the prefix to the current entity.
[0105] The implementation process of the secondary authentication of the method in this embodiment is as Figure 6 shown. The simplified RADIUS protocol is used to skip the EAP process. The AMF in the 5G network obtains the subscribed DNN of the entity from the UDM (Unified Data Management) in advance and maps the entity to a dedicated DNN. In step 4, the SMF sends an Access request message to the AAA server, and the AAA server performs secondary authentication according to the DNN configuration file. The AAA server queries the ID of the corresponding UE, generates an IPv6 address prefix, and encapsulates it in an Access accept message and sends it to the SMF to allocate the IPv6 address prefix to the UE. In the method of this embodiment, the intermediate EAP process is skipped and the prefix is directly allocated, so as to be transparent to the user.
[0106] Example 3
[0107] This embodiment provides a method for extracting the entity identifier of an IPv6 address, which can be applied to the AAA server, as Figure 7 shown, including:
[0108] Step S301: Extract the prefix of the IPv6 address of the current data packet. The prefix of the IPv6 address is allocated based on the IPv6 address prefix allocation method of Embodiment 2.
[0109] In the case of data packet transmission based on a 5G network, the AAA server extracts the prefix of the IPv6 address of the current data packet. This prefix is allocated based on the IPv6 address prefix allocation method of Embodiment 2. For the IPv6 address prefix encoding method of Embodiment 2, please refer to the foregoing embodiments and will not be elaborated herein.
[0110] Step S302: Determine the exclusive OR result of the sub-prefixes in the prefix, and send the entity type of the current entity of the current data packet based on the exclusive OR result.
[0111] Calculate the exclusive OR result of the sub-prefixes. If the exclusive OR result is 1, it indicates that an entity identifier is embedded in the prefix of the IPv6 address. If the exclusive OR result is 0, it indicates that no entity identifier is embedded in the prefix of the IPv6 address. In this case, end the recognition process and release this data packet. If the exclusive OR result is 1, it indicates that an entity identifier is embedded in the prefix of the IPv6 address, and execute Step S303.
[0112] Step S303: When it is determined that the entity type of the current entity is an entity identifier that has been embedded, restore the entity identifier of the current entity based on the sub-prefix.
[0113] In some implementation manners, restoring the entity identifier of the current entity based on the sub-prefix includes:
[0114] Use the inverse process of the confusion algorithm or the decryption algorithm to restore the entity identifier of the current entity.
[0115] Further, using the inverse process of the confusion algorithm to restore the entity identifier of the current entity includes:
[0116] Step S303a: Extract the timestamp or random number inserted during encoding from the sub-prefix;
[0117] Step S303b: Exclusive OR each digit of the timestamp or random number with the numbers of the previous preset number of digits;
[0118] Step S303c: Remove the timestamp or random number to obtain the entity identifier of the current entity.
[0119] Take Figure 3 the sub-prefix generated in Figure 8 as an example to illustrate the extraction of the entity identifier. As Figure 3 shown, after extracting the sub-prefix 55B6:AB92 generated in
[0120] Example 4
[0121] Corresponding to the first embodiment, this embodiment provides an IPv6 address prefix encoding device, as Figure 9 shown, including:
[0122] An obtaining module 401, configured to obtain a routing prefix;
[0123] A calculating module 402, configured to calculate a ciphertext including the entity identifier of the current entity, and a timestamp or a random number;
[0124] A first generating module 403, configured to generate a sub-prefix based on the ciphertext and an auxiliary flag bit for identifying the entity type;
[0125] A second generating module 404, configured to generate a prefix of the IPv6 address of the current entity by using the routing prefix and the sub-prefix.
[0126] In some implementation manners, a confusion algorithm or an encryption algorithm is used to calculate a ciphertext including the entity identifier of the current entity, and a timestamp or a random number.
[0127] In some implementation manners, preferably a confusion algorithm is used to calculate a ciphertext including the entity identifier of the current entity, and a timestamp or a random number, including:
[0128] In the binary data of the entity identifier of the current entity, insert 1 bit of timestamp or random number every preset number of bits to obtain a ciphertext including the entity identifier of the current entity, and a timestamp or a random number, and the ciphertext is in binary form.
[0129] In some implementation manners, generating a sub-prefix based on the ciphertext and an auxiliary flag bit for identifying the entity type includes:
[0130] Perform an exclusive OR operation on each bit of the timestamp or random number in the ciphertext and the binary data of the entity identifier of the previous preset number of bits respectively to obtain an exclusive OR operation result;
[0131] Based on the total exclusive OR value of the exclusive OR operation result, set the auxiliary flag bit to identify that the entity type of the current entity is an embedded entity identifier;
[0132] Generate a sub-prefix based on the exclusive OR operation result and the auxiliary flag bit.
[0133] In this embodiment, when the current entity accesses the 5G network, first, a ciphertext containing the ID and TS is calculated using a confusion algorithm to embed the entity identifier of the current entity; then, the ciphertext embedded with the entity identifier and the Flag field form a sub-prefix; finally, the routing prefix and the sub-prefix are combined to form the prefix of the IPv6 address. The IPv6 address obtained based on the formed prefix can trace the entity information due to the embedded entity identifier, realizing audit accountability.
[0134] Example 5
[0135] Corresponding to Embodiment 2, this embodiment provides an IPv6 address prefix allocation device, as Figure 10 shown, including:
[0136] The authentication module 501 is used to perform secondary authentication according to the DNN configuration file in response to receiving an access request message of the current entity;
[0137] The query module 502 is used to query the entity identifier of the current entity when the secondary authentication is passed;
[0138] The generation module 503 is used to generate the prefix of the IPv6 address of the current entity by using the device of Embodiment 4;
[0139] The allocation module 504 is used to encapsulate the prefix of the IPv6 address of the current entity in the access response message to allocate the prefix to the current entity.
[0140] Example 6
[0141] Corresponding to Embodiment 3, this embodiment provides an entity identifier extraction device for an IPv6 address, as Figure 11 shown, including:
[0142] The extraction module 601 is used to extract the prefix of the IPv6 address of the current data packet, and the prefix of the IPv6 address is obtained by allocation based on the IPv6 address prefix allocation device of Embodiment 5;
[0143] The determination module 602 is used to determine the exclusive OR result of the sub-prefix in the prefix and send the entity type of the current entity of the current data packet based on the exclusive OR result;
[0144] The restoration module 603 is used to restore the entity identifier of the current entity based on the sub-prefix when it is determined that the entity type of the current entity is an entity identifier that has been embedded.
[0145] In some implementation manners, restoring the entity identifier of the current entity based on the sub-prefix includes:
[0146] Restore the entity identifier of the current entity by using the reverse process of the obfuscation algorithm or the decryption algorithm.
[0147] Further, restoring the entity identifier of the current entity by using the reverse process of the obfuscation algorithm includes:
[0148] Extract the timestamp or random number inserted during encoding from the sub-prefix; perform exclusive OR on each bit of the timestamp or random number with the numbers in the previous preset number of bits; remove the timestamp or random number to obtain the entity identifier of the current entity.
[0149] Example 7
[0150] This embodiment provides a computer storage medium, on which a computer program is stored. When the computer program is executed by one or more processors, the methods in the foregoing embodiments are implemented.
[0151] Among them, the computer-readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (Static Random Access Memory, abbreviated as SRAM), electrically erasable programmable read-only memory (Electrically Erasable Programmable Read-Only Memory, abbreviated as EEPROM), erasable programmable read-only memory (Erasable Programmable Read-Only Memory, abbreviated as EPROM), programmable read-only memory (Programmable Read-Only Memory, abbreviated as PROM), read-only memory (Read-Only Memory, abbreviated as ROM), magnetic memory, flash memory, magnetic disk or optical disc
[0152] Example 8
[0153] This embodiment provides a server, including a memory and one or more processors. When a computer program stored on the memory is executed by the one or more processors, the methods in the foregoing embodiments are implemented.
[0154] In practical applications, the server can be an AAA server.
[0155] The processor may be implemented by an application specific integrated circuit (ASIC), a digital signal processor (DSP), a digital signal processing device (DSPD), a programmable logic device (PLD), a field programmable gate array (FPGA), a controller, a microcontroller unit (MCU), a microprocessor, or other electronic components, and is used to execute the method in the above embodiments.
[0156] The above embodiments of the present invention solve the problem of associating an entity with an IP address in a 5G network, and can achieve the association under the current IPv6 address allocation practice in a 5G network without modifying the address allocation method. Compared with the existing solutions, the transformation of the network is small. Only the following configurations need to be made to the SMF: add a specific DNN alias for the operator DNN (e.g., ADD APNDNN command); add a configuration file for the specific DNN (e.g., use the ADD AUTHRADIUSAPNMAP command) to select the authentication AAA server and the authentication policy; map the session with the entity to the DNN alias. In addition, some development needs to be done on the AAA server, which has little impact on the existing network.
[0157] In several embodiments provided by the embodiments of the present invention, it should be understood that the disclosed systems and methods can also be implemented in other ways. The system and method embodiments described above are only illustrative.
[0158] It should be noted that in this article, the terms "first", "second", etc. in the specification and claims of this application and the above drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. The term "including", "comprising" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of another identical element in the process, method, article or device including the element.
[0159] Although the embodiments disclosed in the present invention are as described above, the content described is only an embodiment adopted for the convenience of understanding the present invention and is not intended to limit the present invention. Any person skilled in the art within the technical field to which the present invention pertains may make any modifications and changes in the form of implementation and details without departing from the spirit and scope disclosed in the present invention. However, the scope of patent protection of the present invention shall still be subject to the scope defined by the appended claims.
Claims
1. An IPv6 address prefix encoding method, characterized in that, Comprising: Obtaining a routing prefix when a current entity accesses a 5G network; Inserting 1 timestamp or random number every preset number of bits in the binary data of the entity identifier of the current entity to obtain a ciphertext containing the entity identifier of the current entity and the timestamp or random number; Performing an exclusive OR operation on each timestamp or random number in the ciphertext with the binary data of the entity identifier of the previous preset number of bits respectively to obtain an exclusive OR operation result; Based on the total exclusive OR value of the exclusive OR operation result, setting an auxiliary flag bit to identify the entity type of the current entity as an entity identifier embedded; Generating a sub-prefix based on the exclusive OR operation result and the auxiliary flag bit; Generating a prefix of the IPv6 address of the current entity based on the routing prefix and the sub-prefix.
2. The IPv6 address prefix encoding method according to claim 1, characterized in that, The ciphertext is in binary form.
3. A method for allocating IPv6 address prefixes, characterized in that, Comprising: In response to receiving an access request message of a current entity, performing secondary authentication according to a DNN configuration file; Querying the entity identifier of the current entity in the case of successful secondary authentication; Using the IPv6 address prefix encoding method described in claim 1 or 2 to generate a prefix of the IPv6 address of the current entity; Encapsulating the prefix of the IPv6 address of the current entity in an access response message to allocate the prefix to the current entity.
4. A method for extracting entity identifiers of IPv6 addresses, characterized in that, Comprising: Extracting the prefix of the IPv6 address of a current data packet, where the prefix of the IPv6 address is allocated based on the IPv6 address prefix allocation method described in claim 3; Determining the exclusive OR result of the sub-prefix in the prefix, and sending the entity type of the current entity of the current data packet based on the exclusive OR result; In the case of determining that the entity type of the current entity is an entity identifier embedded, restoring the entity identifier of the current entity based on the sub-prefix.
5. The method for extracting the entity identifier of an IPv6 address according to claim 4, wherein, The restoring the entity identifier of the current entity based on the sub-prefix includes: Restoring the entity identifier of the current entity by using the inverse process of the confusion algorithm or the decryption algorithm.
6. The method for extracting entity identifiers of IPv6 addresses according to claim 4, characterized in that, Restoring the entity identifier of the current entity by using the inverse process of the confusion algorithm includes: Extracting the timestamp or random number inserted during encoding from the sub-prefix; Performing an exclusive OR on each timestamp or random number with the numbers of the previous preset number of bits; Removing the timestamp or random number to obtain the entity identifier of the current entity.
7. An IPv6 address prefix encoding device, characterized in that, Comprising: An obtaining module, configured to obtain a routing prefix when a current entity accesses a 5G network; A calculating module, configured to insert 1 timestamp or random number every preset number of bits in the binary data of the entity identifier of the current entity to obtain a ciphertext containing the entity identifier of the current entity and the timestamp or random number; A first generating module, configured to perform an exclusive OR operation on each timestamp or random number in the ciphertext with the binary data of the entity identifier of the previous preset number of bits respectively to obtain an exclusive OR operation result; Based on the total exclusive OR value of the exclusive OR operation result, setting an auxiliary flag bit to identify the entity type of the current entity as an entity identifier embedded; Generating a sub-prefix based on the exclusive OR operation result and the auxiliary flag bit; A second generating module, configured to generate a prefix of the IPv6 address of the current entity based on the routing prefix and the sub-prefix.
8. An IPv6 address prefix allocation device, characterized in that Comprising: An authentication module, configured to perform secondary authentication according to a DNN configuration file in response to receiving an access request message of a current entity; A query module, configured to query an entity identifier of the current entity when the secondary authentication is passed; A generation module, configured to generate a prefix of an IPv6 address of the current entity by using the device according to claim 7; An allocation module, configured to encapsulate the prefix of the IPv6 address of the current entity in an access response message to allocate the prefix to the current entity.
9. An apparatus for extracting entity identifiers of IPv6 addresses, characterized in that, Comprising: An extraction module, configured to extract a prefix of an IPv6 address of a current data packet, where the prefix of the IPv6 address is allocated based on the IPv6 address prefix allocation device according to claim 8; A determination module, configured to determine an exclusive OR result of sub-prefixes in the prefix, and send an entity type of the current entity of the current data packet based on the exclusive OR result; A restoration module, configured to restore the entity identifier of the current entity based on the sub-prefix when it is determined that the entity type of the current entity is an entity identifier embedded entity.
10. A computer storage medium, characterized in that, A computer program is stored on the computer-readable storage medium, and when the computer program is executed by one or more processors, the method according to any one of claims 1 to 6 is implemented.
11. A server, characterized in that, Comprising a memory and one or more processors, a computer program is stored on the memory, and when the computer program is executed by the one or more processors, the method according to any one of claims 1 to 6 is implemented.
Citation Information
Patent Citations
Data processing method and device
CN113497788A