A strategy message processing method, device and storage medium
By introducing CE and DE entities of DTPF, the policy messages are encrypted, decrypted, and verified in multiple layers, which solves the security problem of policy distribution in digital twin networks and ensures the security of the physical network and the accuracy of the policies.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA MOBILE COMM LTD RES INST
- Filing Date
- 2021-08-05
- Publication Date
- 2026-04-21
AI Technical Summary
The digital twin network framework does not comprehensively consider security issues during the policy distribution process from a security perspective, which may lead to the physical network being susceptible to misconfiguration and attacks.
The Digital Twin Protection Function (DTPF) is introduced, which uses two functional entities, CE and DE, to encrypt and decrypt policy messages, verify the source, verify the destination, and verify the integrity and stability of the policy messages, preventing routing loops and ensuring the security and integrity of policy messages.
This ensures the security and accuracy of policy distribution to the physical network, prevents misconfigurations and attacks, and improves the efficiency of policy distribution.
Smart Images

Figure CN115941214B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data security technology, and in particular to a policy message processing method, device and storage medium. Background Technology
[0002] Digital twins, real-time mirror images of physical entities in the digital world, are becoming a new focus of global information technology development and industrial digital transformation. In the future network, digital twin technology will be widely used in fields such as intelligent manufacturing, smart cities, and scientific research, leading society towards a "digital twin" world that combines the virtual and the real.
[0003] A Digital Twin Network (DTN) is a network system with a physical network entity and a virtual twin, capable of real-time interactive mapping between the two. Within this system, various network management and applications can leverage the virtual twin constructed using digital twin technology to efficiently analyze, diagnose, simulate, and control the physical network based on data and models. The network twin helps the physical network achieve low-cost trial and error, intelligent decision-making, high-efficiency innovation, and predictive maintenance. Using digital twin networks as a key enabling platform for future mobile communication networks can help them achieve the goal of distributed autonomy. Furthermore, through capability openness and twin copying, digital twin networks can help users clearly perceive network status, efficiently mine valuable network information, and explore innovative network applications with a more user-friendly and immersive interface.
[0004] Digital twin networks have been initiated and discussed at the ITU (International Telecommunication Union), and the framework design has been basically completed. However, its shortcomings lie in the fact that the framework does not comprehensively consider security issues in the policy deployment process from a security perspective. Summary of the Invention
[0005] This invention provides a policy message processing method, device, and storage medium to address the security issues in the policy distribution process where the digital twin network framework does not comprehensively consider security from a security perspective.
[0006] This invention provides the following technical solutions:
[0007] A strategy message processing method, comprising:
[0008] The CE receives policy messages sent by the PDE;
[0009] CE verifies the policy messages;
[0010] After successful verification, the CE sends the policy message to the DE deployed at the edge of the physical network.
[0011] The CE is an entity that sends policy messages to the DE deployed at the boundary of the physical network after verifying the policy messages sent by the PDE. The DE is an entity that extracts the instructions from the policy messages and sends them to the network element entity device.
[0012] In implementation, before CE verifies the policy message, it further includes:
[0013] The policy message is decrypted using the first key negotiated between the CE and PDE.
[0014] In practice, after verification, part of the policy message sent to the DE is encrypted by the PDE using a second key negotiated between the DE and the PDE.
[0015] In practice, TLS is used to transmit policy messages between CE and DE.
[0016] During implementation, policy messages are validated, including one or a combination of the following validations:
[0017] Source verification, target verification, and post-policy verification, including verification of policy integrity and stability.
[0018] In practice, stability verification includes one or a combination of the following verifications:
[0019] A dynamic baseline comparison is adopted, using historical data as input. When the adjustment range of the strategy exceeds the preset value, manual secondary confirmation is required.
[0020] Compare the policy intent of the target object with the actual function of the network element device to prevent the policy intent from being mistakenly applied to other network element devices;
[0021] The policy is filtered to prevent routing loops.
[0022] During implementation, policy messages are validated, including:
[0023] Upon receiving a policy message, verify the integrity of the policy message;
[0024] After successful verification, the policy content in the policy message will be extracted.
[0025] After the strategy content is extracted, it is hashed and compared with the stored original hash value;
[0026] After the hash value comparison is successful, the policy message verification is successful.
[0027] A strategy message processing method, comprising:
[0028] DE receives policy messages sent by CE;
[0029] DE extracts the instructions from the policy message and sends them to the network element physical device.
[0030] The CE is an entity that sends policy messages to the DE deployed at the boundary of the physical network after verifying the policy messages sent by the PDE. The DE is an entity that extracts the instructions from the policy messages and sends them to the network element entity device.
[0031] In implementation, after receiving the policy message sent by the CE, the process further includes:
[0032] The second key negotiated between the DE and PDE is used to decrypt part of the policy message.
[0033] A strategy message processing method, comprising:
[0034] PDE generates policy messages;
[0035] PDE sends a policy message to CE.
[0036] The CE is an entity that sends policy messages to the DE deployed at the boundary of the physical network after verifying the policy messages sent by the PDE. The DE is an entity that extracts the instructions from the policy messages and sends them to the network element entity device.
[0037] In implementation, before sending the policy message to the CE, the following further steps are taken:
[0038] The policy message is encrypted using the first key negotiated between the CE and PDE;
[0039] Part of the policy message is encrypted using a second key negotiated between the DE and PDE.
[0040] During implementation, after generating the policy message, it further includes:
[0041] The policy message is hashed and then the hash value is stored.
[0042] A CE, comprising:
[0043] The processor is used to read programs from memory and execute the following procedures:
[0044] Receive policy messages sent by PDE;
[0045] Validate the policy message;
[0046] After successful verification, the policy message is sent to the DE deployed at the edge of the physical network.
[0047] A transceiver is used to receive and send data under the control of a processor.
[0048] The CE is an entity that sends policy messages to the DE deployed at the boundary of the physical network after verifying the policy messages sent by the PDE. The DE is an entity that extracts the instructions from the policy messages and sends them to the network element entity device.
[0049] During implementation, before validating the policy message, the following further steps are taken:
[0050] The policy message is decrypted using the first key negotiated between the CE and PDE.
[0051] In practice, after verification, part of the policy message sent to the DE is encrypted by the PDE using a second key negotiated between the DE and the PDE.
[0052] In practice, TLS is used to transmit policy messages with the DE.
[0053] During implementation, policy messages are validated, including one or a combination of the following validations:
[0054] Source verification, target verification, and post-policy verification, including verification of policy integrity and stability.
[0055] In practice, stability verification includes one or a combination of the following verifications:
[0056] A dynamic baseline comparison is adopted, using historical data as input. When the adjustment range of the strategy exceeds the preset value, manual secondary confirmation is required.
[0057] Compare the policy intent of the target object with the actual function of the network element device to prevent the policy intent from being mistakenly applied to other network element devices;
[0058] The policy is filtered to prevent routing loops.
[0059] During implementation, policy messages are validated, including:
[0060] Upon receiving a policy message, verify the integrity of the policy message;
[0061] After successful verification, the policy content in the policy message will be extracted.
[0062] After the strategy content is extracted, it is hashed and compared with the stored original hash value;
[0063] After the hash value comparison is successful, the policy message verification is successful.
[0064] A CE, comprising:
[0065] The CE receiving module is used to receive policy messages sent by the PDE.
[0066] The CE verification module is used to verify policy messages;
[0067] The CE sending module is used to send policy messages to the DE deployed at the boundary of the physical network after successful verification.
[0068] The CE is an entity that sends policy messages to the DE deployed at the boundary of the physical network after verifying the policy messages sent by the PDE. The DE is an entity that extracts the instructions from the policy messages and sends them to the network element entity device.
[0069] During implementation, it further includes:
[0070] The CE decryption module is used to decrypt policy messages using the first key negotiated between the CE and PDE before the CE verifies the policy messages.
[0071] In practice, the CE sending module further uses a portion of the policy message sent to the DE after verification to be encrypted by the PDE using a second key negotiated between the DE and the PDE.
[0072] In implementation, the CE sending module is further used to transmit policy messages with the DE using TLS.
[0073] In implementation, the CE verification module is further used to verify policy messages, including one or a combination of the following verifications:
[0074] Source verification, target verification, and post-policy verification, including verification of policy integrity and stability.
[0075] In practice, the CE verification module further performs stability verification including one or a combination of the following verifications:
[0076] A dynamic baseline comparison is adopted, using historical data as input. When the adjustment range of the strategy exceeds the preset value, manual secondary confirmation is required.
[0077] Compare the policy intent of the target object with the actual function of the network element device to prevent the policy intent from being mistakenly applied to other network element devices;
[0078] The policy is filtered to prevent routing loops.
[0079] In implementation, the CE verification module is further used to verify policy messages, including:
[0080] Upon receiving a policy message, verify the integrity of the policy message;
[0081] After successful verification, the policy content in the policy message will be extracted.
[0082] After the strategy content is extracted, it is hashed and compared with the stored original hash value;
[0083] After the hash value comparison is successful, the policy message verification is successful.
[0084] A DE, comprising:
[0085] The processor is used to read programs from memory and execute the following procedures:
[0086] Receive policy messages sent by CE;
[0087] The instructions in the policy message are extracted and sent to the network element device.
[0088] A transceiver is used to receive and send data under the control of a processor.
[0089] The CE is an entity that sends policy messages to the DE deployed at the boundary of the physical network after verifying the policy messages sent by the PDE. The DE is an entity that extracts the instructions from the policy messages and sends them to the network element entity device.
[0090] In implementation, after receiving the policy message sent by the CE, the process further includes:
[0091] The second key negotiated between the DE and PDE is used to decrypt part of the policy message.
[0092] A DE, comprising:
[0093] The DE receiving module is used to receive policy messages sent by the CE.
[0094] The DE sending module is used to extract instructions from policy messages and send them to network element devices.
[0095] The CE is an entity that sends policy messages to the DE deployed at the boundary of the physical network after verifying the policy messages sent by the PDE. The DE is an entity that extracts the instructions from the policy messages and sends them to the network element entity device.
[0096] During implementation, it further includes:
[0097] The DE decryption module is used to decrypt part of the policy message after receiving it from the CE using the second key negotiated between the DE and the PDE.
[0098] A PDE, comprising:
[0099] The processor is used to read programs from memory and execute the following procedures:
[0100] Generate policy messages;
[0101] Send a policy message to the CE;
[0102] A transceiver is used to receive and send data under the control of a processor.
[0103] The CE is an entity that sends policy messages to the DE deployed at the boundary of the physical network after verifying the policy messages sent by the PDE. The DE is an entity that extracts the instructions from the policy messages and sends them to the network element entity device.
[0104] In implementation, before sending the policy message to the CE, the following further steps are taken:
[0105] The policy message is encrypted using the first key negotiated between the CE and PDE;
[0106] Part of the policy message is encrypted using a second key negotiated between the DE and PDE.
[0107] During implementation, after generating the policy message, it further includes:
[0108] The policy message is hashed and then the hash value is stored.
[0109] A PDE, comprising:
[0110] The PDE generation module is used to generate policy messages;
[0111] The PDE sending module is used to send policy messages to the CE.
[0112] The CE is an entity that sends policy messages to the DE deployed at the boundary of the physical network after verifying the policy messages sent by the PDE. The DE is an entity that extracts the instructions from the policy messages and sends them to the network element entity device.
[0113] During implementation, it further includes:
[0114] The PDE encryption module is used to encrypt the policy message with the first key negotiated between the CE and PDE before sending the policy message to the CE; and to encrypt part of the information in the policy message with the second key negotiated between the DE and PDE.
[0115] In practice, the PDE generation module is further used to generate policy messages, and then to perform hash processing on the policy messages and store the hash value.
[0116] A computer-readable storage medium, characterized in that the computer-readable storage medium stores a computer program that performs the above-described strategy message processing method.
[0117] The beneficial effects of this invention are as follows:
[0118] The technical solution provided in this invention addresses the security issue of policy distribution by introducing a DTPF containing CE and DE. When a policy is distributed to the CE, the CE can verify the integrity, reliability, and authenticity of the policy source. If the verification passes, the policy can be correctly distributed to various network elements in the physical world, thus ensuring the security of the distributed policy. This also solves the security problem of policies generated by digital twin networks directly affecting the physical network layer. Attached Figure Description
[0119] The accompanying drawings, which are included to provide a further understanding of the invention and form part of this invention, illustrate exemplary embodiments of the invention and are used to explain the invention, but do not constitute an undue limitation of the invention. In the drawings:
[0120] Figure 1 This is a schematic diagram of the digital twin network architecture in an embodiment of the present invention;
[0121] Figure 2 This is a schematic diagram of the implementation flow of the policy message processing method on the PDE side in an embodiment of the present invention;
[0122] Figure 3 This is a schematic diagram of the implementation flow of the policy message processing method on the CE side in an embodiment of the present invention;
[0123] Figure 4 This is a schematic diagram of the implementation flow of the strategy message processing method on the DE side in an embodiment of the present invention;
[0124] Figure 5 This is a schematic diagram of DTPF and its application environment in an embodiment of the present invention;
[0125] Figure 6 This is a schematic diagram of the DTPF structure in an embodiment of the present invention;
[0126] Figure 7 This is a schematic diagram of the interaction process between PDE, CE, and DE in an embodiment of the present invention;
[0127] Figure 8 This is a schematic diagram of the post-strategy verification process in an embodiment of the present invention;
[0128] Figure 9 This is a schematic diagram of the CE structure in an embodiment of the present invention;
[0129] Figure 10 This is a schematic diagram of the DE structure in an embodiment of the present invention;
[0130] Figure 11 This is a schematic diagram of the PDE structure in an embodiment of the present invention. Detailed Implementation
[0131] The inventor noticed the following during the invention process:
[0132] The framework does not take a comprehensive approach to security. Since the policies generated by the digital twin network will directly affect the physical network layer, which is completely different from traditional network control and configuration, it is crucial to solve the security problems in the policy distribution process. This will also be the last line of defense for the automated configuration and optimization of the physical network by the digital twin network.
[0133] Therefore, the problem with existing technologies is that existing standards and procedures do not cover the security aspect.
[0134] The technical problem to be solved by the technical solution provided in the embodiments of the present invention involves designing a strategy to distribute an interface security model to ensure interface security.
[0135] Based on the above security issues and requirements, the technical solution provided in this invention provides a method to protect the security of the policy distribution interface in a digital twin network. This is achieved by introducing a twin security center module to address the security issues of policy distribution. When a policy is distributed to the twin security center, the center can verify the integrity, reliability, and authenticity of the policy source. If the verification passes, the policy can be correctly distributed to various network elements in the physical world. The twin security center can perform differentiated security configurations for different security levels in the physical network, thereby improving the efficiency of policy distribution.
[0136] The specific embodiments of the present invention will now be described with reference to the accompanying drawings.
[0137] In this explanation, the implementation will be described from the perspectives of PDE and CE / DE respectively. Examples of their combined implementation will also be given to better understand the implementation of the solutions presented in the embodiments of this invention. This explanation does not imply that they must be implemented together or separately. In fact, when PDE is implemented separately from CE / DE, each solves its own problem, while combining them yields better technical results.
[0138] First, the environment and background for implementing the plan will be explained.
[0139] Figure 1 The diagram shows a digital twin network architecture. The digital twin network architecture mainly includes: a network application layer, a twin network layer, and a physical network layer. There are data acquisition and control distribution interfaces between the twin network layer and the physical network layer.
[0140] Digital twin networks are characterized by digitization, networking, and intelligence. Their application environment is more open, interconnected, and shared. As their application areas continue to expand, cybersecurity issues will gradually become more prominent. Digital twin networks and applications mainly face the following security risks and challenges:
[0141] 1. Data security risks: Digital twin networks need to generate and store massive amounts of device data, user data, interaction data, and management data during application. Ensuring the security of this data transmission and storage will pose a huge challenge to the network.
[0142] 2. Sensor Equipment Risks: Sensor equipment, the intelligent cells of a digital twin network, is the fundamental link for collecting network configuration information, network operation status, and user service data. These sensors are characterized by their large number, wide distribution, and centralized management. If security vulnerabilities in the hardware, software, and data interfaces are maliciously exploited, it will have a huge impact on the physical network.
[0143] 3. Digital twins threaten the physical world: Originally relatively closed physical networks, such as mobile communication wireless systems, may have multiple exposed interfaces. Due to the various unknown security vulnerabilities of virtual systems such as digital twins, they are susceptible to external attacks, leading to system disorder and issuing incorrect instructions to the real physical network.
[0144] 4. Network Application Security Risks: Network applications input requirements into the twin network and deploy services on the twin network through modeled instances. After thorough verification, the twin network layer sends control updates to the physical network. Improper network permission configuration may lead to unauthorized access, allowing attackers to send incorrect requirements, causing the twin network to generate incorrect configurations and ultimately affecting the physical network.
[0145] The security importance of the control distribution interface is particularly prominent, and to a certain extent it can be equated to the last line of defense of the physical network. The control information transmitted through the control distribution interface is critical network configuration information and needs to be known by the smallest possible scope. Therefore, security faces two issues:
[0146] 1. How to ensure the security of the interface channel;
[0147] 2. How to ensure that privacy is minimized during message transmission.
[0148] Based on this, the technical solution provided in the embodiments of the present invention will introduce DTPF (Digital Twin Protection Function) to solve the above two problems.
[0149] Figure 2 The diagram illustrates the implementation flow of the policy message processing method on the PDE side, and may include:
[0150] Step 201: PDE generates policy messages;
[0151] Step 202: PDE sends a policy message to CE.
[0152] The CE is an entity that sends policy messages to the DE deployed at the boundary of the physical network after verifying the policy messages sent by the PDE. The DE is an entity that extracts the instructions from the policy messages and sends them to the network element entity device.
[0153] Figure 3 The diagram illustrates the implementation flow of the policy message processing method on the CE side, and may include:
[0154] Step 301: The CE receives the policy message sent by the PDE;
[0155] Step 302: CE verifies the policy message;
[0156] Step 303: After the verification is successful, the CE sends the policy message to the DE deployed at the boundary of the physical network.
[0157] The CE is an entity that sends policy messages to the DE deployed at the boundary of the physical network after verifying the policy messages sent by the PDE. The DE is an entity that extracts the instructions from the policy messages and sends them to the network element entity device.
[0158] Figure 4 The diagram illustrates the implementation flow of the policy message processing method on the DE side, and may include:
[0159] Step 401: DE receives the policy message sent by CE;
[0160] Step 402: DE extracts the instructions from the policy message and sends them to the network element entity device.
[0161] Here, CE is the entity that sends policy messages to DE deployed at the boundary of the physical network after verifying the policy messages sent by PDE. DE is the entity that extracts the instructions from the policy messages and sends them to the network element entity device.
[0162] In practice, the CE sends the policy message to the DE entity deployed at the boundary of the physical network after the policy message sent by the PDE passes the verification. The DE is the entity that extracts the instructions in the policy message and sends them to the network element entity device. Considering that these entities may be virtualized network elements in the future of 5G, even if they are virtualized network elements, they still need to be carried on the entity. Therefore, the entity here can be understood as the entity that can realize the DE or CE function.
[0163] Figure 5The figure illustrates DTPF and its application environment. The technical solution provided in this embodiment of the invention addresses the security issues of policy distribution by introducing DTPF. DTPF consists of two functional entities: CE (Central Entity) and DE (Distributed Entity). CE is centrally deployed and can partially decrypt and verify policies. Furthermore, CE can provide fine-grained differentiated services to different network objects based on the varying security levels of the physical networks. DE is deployed at the boundaries of each physical network and can fully decrypt policies, extracting instructions from the policies and directly sending them to the network element devices.
[0164] CE's security functions include, but are not limited to, verifying the authenticity of the source, performing secondary comparison and verification of the issued policies, and verifying the matching between policy intent and network element entity functions.
[0165] The following section explains how to encrypt and decrypt policy messages.
[0166] In implementation, before sending the policy message to the CE on the PDE (Policy Distribution Entity) side, the following further steps are included:
[0167] The policy message is encrypted using the first key negotiated between the CE and PDE;
[0168] Part of the policy message is encrypted using a second key negotiated between the DE and PDE.
[0169] Accordingly, on the CE side, before the CE verifies the policy message, it further includes:
[0170] The policy message is decrypted using the first key negotiated between the CE and PDE.
[0171] In practice, after verification, part of the policy message sent to the DE is encrypted by the PDE using a second key negotiated between the DE and the PDE.
[0172] Correspondingly, on the DE side, after receiving the policy message sent by the CE, it further includes:
[0173] The second key negotiated between the DE and PDE is used to decrypt part of the policy message.
[0174] Figure 5 The objects A, B, and C in the diagram represent heterogeneous networks, which have different security levels.
[0175] The control distribution center (PDE), CE, and DE employ a multi-layered encryption method. PDE and CE use a first-layer encryption, while PDE and DE use a second-layer encryption. For example, the control distribution center (PDE) first uses the DE's key to encrypt part of the information, and then uses the CE's key to encrypt all payload information. The difference between the DTPF mechanism and traditional TLS (Transport Layer Security) is that TLS only involves two ends, while DTPF involves three entities. The secure channel implementation methods of DTPF include, but are not limited to, TLS. That is, in implementation, CE and DE use TLS to transmit policy messages.
[0176] During implementation, policy messages are validated, including one or a combination of the following validations:
[0177] Source verification, target verification, and post-policy verification, including verification of policy integrity and stability.
[0178] In practice, stability verification includes one or a combination of the following verifications:
[0179] A dynamic baseline comparison is adopted, using historical data as input. When the adjustment range of the strategy exceeds the preset value, manual secondary confirmation is required.
[0180] Compare the policy intent of the target object with the actual function of the network element device to prevent the policy intent from being mistakenly applied to other network element devices;
[0181] The policy is filtered to prevent routing loops.
[0182] Specifically, after receiving the policy, DTPF first uses the CE's key to decrypt the message and then performs three verifications on the decrypted content:
[0183] Source verification includes, but is not limited to, sending a message in reverse to add a pair of interactive information to verify the authenticity of the source.
[0184] Target verification includes, but is not limited to, CE caching the addresses of all network element physical devices, extracting the target address and comparing it with the address of the controlled network element to verify the target address.
[0185] Post-policy validation includes two main aspects: validating the policy's completeness and validating its stability. Policy stability can include the following aspects:
[0186] A dynamic baseline comparison is adopted, using historical data as input. If the adjustment range of the new strategy exceeds 5%, manual secondary confirmation is required.
[0187] Compare the policy intent of the target object with the actual function of the network element device to prevent the policy intent from being mistakenly applied to other network element devices;
[0188] The policy is filtered to prevent routing loops.
[0189] After the above aspects have been basically verified, the message with partial ciphertext will be sent to the DE. The DE will use its own key to decrypt the remaining ciphertext message, extract it to form the final control command, and send it to the designated network element device.
[0190] Figure 6 The diagram shows the structure of DTPF. DTPF includes two main functional modules, such as... Figure 6 As shown, logically, DTPF is a functional unit that mainly implements control and transmission functions. In actual deployment, CE and DE can be separated. CE has certain requirements for computing resources. CE can be deployed according to the network node location and device load. DE is deployed according to the principle of the nearest physical network element device.
[0191] CE primarily performs one or a combination of the following functions: message reception, decryption, policy verification, authentication, key update, and message sending.
[0192] DE primarily implements one or a combination of the following functions: message reception, authentication, key update, decryption, command extraction, and message sending.
[0193] Figure 7 The diagram illustrates the interaction flow between PDE, CE, and DE. The interaction flow between PDE, CE, and DE can be as follows:
[0194] After the PDE and CE perform two-way authentication, key negotiation is carried out.
[0195] After the PDE and DE perform two-way authentication, key negotiation is carried out.
[0196] PDE distributes policies;
[0197] CE performs partial decryption and policy verification;
[0198] Once verification is successful, the policy will be forwarded to the DE.
[0199] After DE is fully decrypted, policy extraction is performed.
[0200] DE will distribute the extracted configuration.
[0201] The implementation of the post-strategy verification process is explained below.
[0202] In implementation, for the PDE side, after generating the policy message, it further includes:
[0203] The policy message is hashed and then the hash value is stored.
[0204] Correspondingly, on the DE side, there is a process for validating policy messages, including:
[0205] Upon receiving a policy message, verify the integrity of the policy message;
[0206] After successful verification, the policy content in the policy message will be extracted.
[0207] After the strategy content is extracted, it is hashed and compared with the stored original hash value;
[0208] After the hash value comparison is successful, the policy message verification is successful.
[0209] Figure 8 The diagram illustrates the post-policy verification process, which mainly includes:
[0210] The policy distribution center (PDE) generates a policy, first hashes the policy and stores the value, and then sends the policy message.
[0211] After receiving the policy message, the Twin Security Center (CE) first verifies the integrity of the message. If the verification is successful, it means that the transmission process has not been tampered with. Then, the policy content in the message is extracted, hashed, and compared with the stored original hash value to ensure that it has not been attacked or tampered with at the source.
[0212] If all checks pass, the policy check is considered successful.
[0213] Based on the same inventive concept, this embodiment of the invention also provides a CE, DE, PDE, and a computer-readable storage medium. Since the principle of these devices in solving the problem is similar to that of the policy message processing method, the implementation of these devices can be referred to the implementation of the method, and repeated details will not be repeated.
[0214] When implementing the technical solutions provided in the embodiments of the present invention, they can be implemented in the following manner.
[0215] Figure 9 The diagram shows the structure of a CE (Ceiling Electrode). The CE includes:
[0216] Processor 900 is used to read the program from memory 920 and execute the following procedures:
[0217] The CE receives policy messages sent by the PDE. The CE sends the policy messages to the DE entity deployed at the boundary of the physical network after verifying the policy messages sent by the PDE. The DE is the entity that extracts the instructions from the policy messages and sends them to the network element entity device.
[0218] Validate the policy message;
[0219] After successful verification, the policy message is sent to the DE deployed at the edge of the physical network.
[0220] Transceiver 910 is used to receive and send data under the control of processor 900.
[0221] During implementation, before validating the policy message, the following further steps are taken:
[0222] The policy message is decrypted using the first key negotiated between the CE and PDE.
[0223] In practice, after verification, part of the policy message sent to the DE is encrypted by the PDE using a second key negotiated between the DE and the PDE.
[0224] In practice, TLS is used to transmit policy messages with the DE.
[0225] During implementation, policy messages are validated, including one or a combination of the following validations:
[0226] Source verification, target verification, and post-policy verification, including verification of policy integrity and stability.
[0227] In practice, stability verification includes one or a combination of the following verifications:
[0228] A dynamic baseline comparison is adopted, using historical data as input. When the adjustment range of the strategy exceeds the preset value, manual secondary confirmation is required.
[0229] Compare the policy intent of the target object with the actual function of the network element device to prevent the policy intent from being mistakenly applied to other network element devices;
[0230] The policy is filtered to prevent routing loops.
[0231] During implementation, policy messages are validated, including:
[0232] Upon receiving a policy message, verify the integrity of the policy message;
[0233] After successful verification, the policy content in the policy message will be extracted.
[0234] After the strategy content is extracted, it is hashed and compared with the stored original hash value;
[0235] After the hash value comparison is successful, the policy message verification is successful.
[0236] Among them, Figure 9 In this context, the bus architecture can include any number of interconnected buses and bridges, specifically linking various circuits together, represented by one or more processors (processor 900) and memory (memory 920). The bus architecture can also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides an interface. The transceiver 910 can be multiple elements, including transmitters and receivers, providing a unit for communicating with various other devices over a transmission medium. The processor 900 is responsible for managing the bus architecture and general processing, and the memory 920 can store data used by the processor 900 during operation.
[0237] This invention also provides a CE, comprising:
[0238] The CE receiving module is used to receive policy messages sent by the PDE. The CE is an entity that sends policy messages to the DE deployed at the boundary of the physical network after verifying the policy messages sent by the PDE. The DE is an entity that extracts the instructions in the policy messages and sends them to the network element entity device.
[0239] The CE verification module is used to verify policy messages;
[0240] The CE sending module is used to send policy messages to the DE deployed at the boundary of the physical network after successful verification.
[0241] During implementation, it further includes:
[0242] The CE decryption module is used to decrypt policy messages using the first key negotiated between the CE and PDE before the CE verifies the policy messages.
[0243] In practice, the CE sending module further uses a portion of the policy message sent to the DE after verification to be encrypted by the PDE using a second key negotiated between the DE and the PDE.
[0244] In implementation, the CE sending module is further used to transmit policy messages with the DE using TLS.
[0245] In implementation, the CE verification module is further used to verify policy messages, including one or a combination of the following verifications:
[0246] Source verification, target verification, and post-policy verification, including verification of policy integrity and stability.
[0247] In practice, the CE verification module further performs stability verification including one or a combination of the following verifications:
[0248] A dynamic baseline comparison is adopted, using historical data as input. When the adjustment range of the strategy exceeds the preset value, manual secondary confirmation is required.
[0249] Compare the policy intent of the target object with the actual function of the network element device to prevent the policy intent from being mistakenly applied to other network element devices;
[0250] The policy is filtered to prevent routing loops.
[0251] In implementation, the CE verification module is further used to verify policy messages, including:
[0252] Upon receiving a policy message, verify the integrity of the policy message;
[0253] After successful verification, the policy content in the policy message will be extracted.
[0254] After the strategy content is extracted, it is hashed and compared with the stored original hash value;
[0255] After the hash value comparison is successful, the policy message verification is successful.
[0256] For ease of description, the various parts of the device described above are divided into modules or units according to their functions. Of course, in implementing this invention, the functions of each module or unit can be implemented in one or more software or hardware components.
[0257] Figure 10 The diagram shows the DE structure. CE includes:
[0258] Processor 1000 is used to read the program from memory 1020 and execute the following procedures:
[0259] The system receives policy messages sent by the CE, which is an entity of the DE deployed at the boundary of the physical network after verifying the policy message sent by the PDE. The DE is an entity that extracts the instructions from the policy message and sends them to the network element entity device.
[0260] The instructions in the policy message are extracted and sent to the network element device.
[0261] Transceiver 1010 is used to receive and send data under the control of processor 1000.
[0262] In implementation, after receiving the policy message sent by the CE, the process further includes:
[0263] The second key negotiated between the DE and PDE is used to decrypt part of the policy message.
[0264] Among them, Figure 10 In this context, the bus architecture may include any number of interconnected buses and bridges, specifically linking various circuits together, represented by one or more processors (processor 1000) and memory (memory 1020). The bus architecture may also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides an interface. The transceiver 1010 may be multiple elements, including a transmitter and a receiver, providing a unit for communicating with various other devices over a transmission medium. The processor 1000 is responsible for managing the bus architecture and general processing, and the memory 1020 may store data used by the processor 1000 during operation.
[0265] This invention also provides a DE, comprising:
[0266] The DE receiving module is used to receive policy messages sent by the CE. The CE sends the policy message to the DE entity deployed at the boundary of the physical network after verifying the policy message sent by the PDE. The DE is the entity that extracts the instructions in the policy message and sends them to the network element entity device.
[0267] The DE sending module is used to extract instructions from policy messages and send them to network element devices.
[0268] During implementation, it further includes:
[0269] The DE decryption module is used to decrypt part of the policy message after receiving it from the CE using the second key negotiated between the DE and the PDE.
[0270] For ease of description, the various parts of the device described above are divided into modules or units according to their functions. Of course, in implementing this invention, the functions of each module or unit can be implemented in one or more software or hardware components.
[0271] Figure 11 The diagram shows the structure of the PDE. The CE includes:
[0272] Processor 1100 is used to read the program from memory 1120 and execute the following procedures:
[0273] Generate policy messages;
[0274] Sending a policy message to the CE, wherein the CE is an entity that sends the policy message to the DE deployed at the boundary of the physical network after verifying the policy message sent to the PDE, and the DE is an entity that extracts the instructions in the policy message and sends them to the network element entity device.
[0275] Transceiver 1110 is used to receive and send data under the control of processor 1100.
[0276] In implementation, before sending the policy message to the CE, the following further steps are taken:
[0277] The policy message is encrypted using the first key negotiated between the CE and PDE;
[0278] Part of the policy message is encrypted using a second key negotiated between the DE and PDE.
[0279] During implementation, after generating the policy message, it further includes:
[0280] The policy message is hashed and then the hash value is stored.
[0281] Among them, Figure 11 In this context, the bus architecture may include any number of interconnected buses and bridges, specifically linking various circuits together, represented by one or more processors (processor 1100) and memory (memory 1120). The bus architecture may also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides an interface. The transceiver 1110 may be multiple elements, including transmitters and receivers, providing a unit for communicating with various other devices over a transmission medium. The processor 1100 is responsible for managing the bus architecture and general processing, and the memory 1120 may store data used by the processor 1100 during operation.
[0282] This invention also provides a PDE, comprising:
[0283] The PDE generation module is used to generate policy messages;
[0284] The PDE sending module is used to send policy messages to the CE.
[0285] The CE is an entity that sends policy messages to the DE deployed at the boundary of the physical network after verifying the policy messages sent by the PDE. The DE is an entity that extracts the instructions from the policy messages and sends them to the network element entity device.
[0286] During implementation, it further includes:
[0287] The PDE encryption module is used to encrypt the policy message with the first key negotiated between the CE and PDE before sending the policy message to the CE; and to encrypt part of the information in the policy message with the second key negotiated between the DE and PDE.
[0288] In practice, the PDE generation module is further used to generate policy messages, and then to perform hash processing on the policy messages and store the hash value.
[0289] For ease of description, the various parts of the device described above are divided into modules or units according to their functions. Of course, in implementing this invention, the functions of each module or unit can be implemented in one or more software or hardware components.
[0290] This invention also provides a computer-readable storage medium, characterized in that the computer-readable storage medium stores a computer program that executes the above-described strategy message processing method.
[0291] For details, please refer to the implementation of the policy message processing methods on the CE, DE, and PDE sides.
[0292] In summary, the technical solution provided by the embodiments of the present invention adds a twin security center functional module to the policy distribution interface between the digital twin network layer and the physical network layer, including two major functional modules: CE and DE. The CE verifies the policy distributed by the PDE before distributing it to the DE, thereby improving security.
[0293] Furthermore, a multi-layered encryption method is adopted between PDE, CE, and DE;
[0294] Furthermore, DPTF mainly has functions such as source verification, post-policy verification, and destination verification;
[0295] Furthermore, a post-policy verification process is provided, including policy stability verification and policy integrity verification.
[0296] Furthermore, a security model for distributing digital twin network policies is also provided.
[0297] The solution addresses the security issues of policy delivery by introducing DTPF. When a policy is delivered to the CE (Cybernetic Edge), the CE can verify the policy's integrity, reliability, and the authenticity of its source. If the verification passes, the policy can be correctly delivered to various network elements in the physical world, thus ensuring the security of the delivered policy. For different security levels in the physical network, the twin security center can perform differentiated security configurations, thereby improving the efficiency of policy delivery.
[0298] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage and optical storage) containing computer-usable program code.
[0299] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0300] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0301] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0302] Obviously, those skilled in the art can make various modifications and variations to this invention without departing from its spirit and scope. Therefore, if these modifications and variations fall within the scope of the claims of this invention and their equivalents, this invention also intends to include these modifications and variations.
Claims
1. A method of processing a policy message, characterized by, include: The central entity (CE) receives policy messages sent by the policy sending entity (PDE). CE verifies the policy messages; After successful verification, the CE sends the policy message to the DE deployed at the edge of the physical network. Before CE verifies the policy message, it further includes: The policy message is decrypted using the first key negotiated between the CE and PDE. After successful verification, part of the policy message sent to the DE is encrypted by the PDE using a second key negotiated between the DE and the PDE.
2. The method of claim 1, wherein, The CE and DE use Transport Layer Security (TLS) to transmit policy messages.
3. The method of claim 1, wherein, The policy message is validated, including one or a combination of the following validations: Source verification, target verification, and post-policy verification, including verification of policy integrity and stability.
4. The method of claim 3, wherein, Stability verification includes one or a combination of the following verifications: A dynamic baseline comparison is adopted, using historical data as input. When the adjustment range of the strategy exceeds the preset value, manual secondary confirmation is required. Compare the policy intent of the target object with the actual function of the network element device to prevent the policy intent from being mistakenly applied to other network element devices; The policy is filtered to prevent routing loops.
5. The method of claim 1, wherein, The policy message is validated, including: Upon receiving a policy message, verify the integrity of the policy message; After successful verification, the policy content in the policy message will be extracted. After the strategy content is extracted, it is hashed and compared with the stored original hash value; After the hash value comparison is successful, the policy message verification is successful.
6. A method of processing a policy message, the method comprising: include: DE receives policy messages sent by CE; DE extracts the instructions from the policy message and sends them to the network element physical device; After receiving the policy message sent by the CE, the process further includes: The second key negotiated between the DE and PDE is used to decrypt part of the policy message.
7. A method of processing a policy message, the method comprising: include: PDE generates policy messages; PDE sends a policy message to CE; Before sending the policy message to the CE, the following further steps are included: The policy message is encrypted using the first key negotiated between the CE and PDE; Part of the policy message is encrypted using a second key negotiated between the DE and PDE.
8. The method of claim 7, wherein, After generating the policy message, it further includes: The policy message is hashed and then the hash value is stored.
9. A CE, characterized by, include: The processor is used to read programs from memory and execute the following procedures: Receive policy messages sent by PDE; Validate the policy message; After successful verification, the policy message is sent to the DE deployed at the edge of the physical network. Before CE verifies the policy message, it further includes: The policy message is decrypted using the first key negotiated between the CE and PDE. After successful verification, part of the policy message sent to the DE is encrypted by the PDE using a second key negotiated between the PDE and the DE. A transceiver is used to receive and send data under the control of a processor.
10. A CE, characterized by, include: The CE receiving module is used to receive policy messages sent by the PDE. The CE verification module is used to verify policy messages; The CE sending module is used to send policy messages to the DE deployed at the boundary of the physical network after successful verification. Further includes: The CE decryption module is used to decrypt policy messages using the first key negotiated between the CE and PDE. The CE sending module further uses a portion of the policy message sent to the DE after verification to be encrypted by the PDE using a second key negotiated between the DE and the PDE.
11. A DE, characterized in that, include: The processor is used to read programs from memory and execute the following procedures: Receive policy messages sent by CE; The instructions in the policy message are extracted and sent to the network element device. After receiving the policy message sent by the CE, the process further includes: Use the second key negotiated between the DE and PDE to decrypt part of the policy message; A transceiver is used to receive and send data under the control of a processor.
12. A DE, characterized in that, include: The DE receiving module is used to receive policy messages sent by the CE. The DE sending module is used to extract the instructions from the policy message and send them to the network element physical device. The DE decryption module is used to decrypt part of the policy message after receiving it from the CE using the second key negotiated between the DE and the PDE.
13. A PDE, comprising: include: The processor is used to read programs from memory and execute the following procedures: Generate policy messages; Send a policy message to the CE; Before sending the policy message to the CE, the following further steps are included: The policy message is encrypted using the first key negotiated between the CE and PDE; Part of the policy message is encrypted using the second key negotiated between the DE and PDE; A transceiver is used to receive and send data under the control of a processor.
14. A PDE according to claim 13, wherein the PDE is a PDE4. include: The PDE generation module is used to generate policy messages; The PDE sending module is used to send policy messages to the CE. The PDE encryption module is used to encrypt the policy message with the first key negotiated between the CE and PDE before sending the policy message to the CE; and to encrypt part of the information in the policy message with the second key negotiated between the DE and PDE.
15. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that performs the method of any one of claims 1 to 8.
Citation Information
Patent Citations
Intention-driven network universal architecture and intention-driven network translation method thereof
CN110278111A