Secure routing method and device based on link and node carrying capacity

By considering the bearing capacity and network security policies of links and nodes in the SDN routing algorithm, and dynamically selecting the best routing path, the problems of unbalanced network resource allocation and security strategies in the existing technology are solved, and the security and effective balance of network resources and the improvement of network security are achieved.

CN116132114BActive Publication Date: 2025-05-16BEIHANG UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211673046.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-26
Publication Date
2025-05-16
Estimated Expiration
2042-12-26

AI Technical Summary

Technical Problem

When load balancing and provisioning network resources, the existing SDN routing algorithm only focuses on the transmission rate and carrying capacity of the link, which leads to an increase in the probability of overloading of local network nodes, ignores the carrying capacity of hardware equipment nodes, which leads to a degradation of network performance, and does not consider network security policies, resulting in untrusted nodes in the data packet or fails to pass the specified equipment, reducing the security and reliability of the network.

Method used

A secure routing method based on link and node bearer capabilities is adopted. By using network topology information and preset network security policies, multiple routing paths passing through secure nodes are selected, and real-time status information of data plane is collected based on the SDN controller, the bearing capacity of links and nodes is evaluated, and the dynamic selection of path evaluation algorithms scores alternative paths and selects the current best path.

Benefits of technology

Effectively balance network resources, avoid the risk of denial of service or routing path corruption caused by overload nodes, and improve the security and reliability of the network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116132114B_ABST
    Figure CN116132114B_ABST
Patent Text Reader

Abstract

The present application relates to the field of information security technology, and in particular to a secure routing method and device based on link and node carrying capacity, wherein the method includes: based on network topology information and preset network security policies, using preset low-complexity algorithms to select multiple routing paths passing through secure nodes, collecting real-time status information of the data plane based on the SDN controller, and evaluating the carrying capacity of links and nodes in multiple dimensions, comparing the differences in carrying capacity between different facilities, dynamically selecting a path evaluation algorithm to score the candidate paths, and selecting the current best path. The embodiment of the present application can take into account network security requirements and network resource carrying capacity, and by simplifying the path construction and selection mechanism, it can balance network resources safely and effectively through routing in large-scale networks, thereby avoiding the risk of denial of service caused by overloaded nodes or routing paths destroying security policies, thereby ensuring the security and reliability of the network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of information security technology, and in particular to a secure routing method and device based on link and node carrying capacity. Background Art

[0002] With the rapid development of information technology, network architecture has gradually become more diverse. Software-Defined Networking (SDN) can solve the problems of traditional network systems that are difficult to deploy, monitor, and manage, and provides new room for improvement in routing calculation methods.

[0003] In the related technologies, there are a large number of security requirements and security risks related to routing in SDN systems. Routing solutions need to be designed to address the problems of transmitting through security devices in the network in a specified order and the problems of transmitting in a network with untrusted nodes to ensure network security.

[0004] However, in the relevant technology, the existing SDN routing algorithm only focuses on the transmission rate and carrying capacity of the link when performing load balancing to allocate network resources, which increases the probability of local network node overload and ignores the carrying capacity of hardware device nodes, causing network performance to degrade. In addition, the routing algorithm does not consider network security policies when making routing decisions, resulting in the presence of untrusted nodes in the output data packets and path packets or failure to pass through designated devices, reducing the security and reliability of the network, which needs to be solved urgently. Summary of the invention

[0005] The present application provides a secure routing method and device based on link and node carrying capacity, in order to solve the problems in the related art that the existing SDN routing algorithm only focuses on the transmission rate and carrying capacity of the link when performing load balancing to allocate network resources, resulting in an increased probability of local network node overload, ignoring the carrying capacity of hardware device nodes, causing network performance to degrade, and the routing algorithm does not consider network security policies when making routing decisions, resulting in the presence of untrusted nodes in the output data packets and path packets or failure to pass through the designated device, thereby reducing the security and reliability of the network.

[0006] The first aspect of the present application provides a secure routing method based on link and node carrying capacity, comprising the following steps: based on network topology information and preset network security policies, multiple routing paths passing through secure nodes are selected using a preset low-complexity algorithm that does not consider the real-time resource status of the network; for the multiple routing paths passing through the secure nodes, real-time status information of the data plane is collected based on an SDN controller, and the carrying capacity of the links and nodes is evaluated from multiple dimensions based on the possibility of network events being executed and current network performance indicators; the differences in carrying capacity between different facilities are compared to determine the network congestion situation, a path evaluation algorithm is dynamically selected to score the alternative paths, and the current best path is selected based on the evaluation results.

[0007] Among them, in one embodiment of the present application, based on the network topology information and the preset network security policy, a preset low-complexity algorithm that does not consider the real-time resource status of the network is used to select multiple routing paths passing through the security node, including: according to the isolation nodes required by the preset network security policy, the corresponding nodes are removed from the network topology; according to the necessary nodes or network middleboxes that must be passed in the target order according to the requirements of the preset network security policy, the routing requirements from the starting point to the end point are split into multiple sub-routing requirements with the middlebox as the end point or starting point; based on the sub-routing requirements, the KSP (k-shortest paths) algorithm is used to construct the multiple routing paths passing through the security node.

[0008] Among them, in one embodiment of the present application, the multiple routing paths passing through the security node collect real-time status information of the data plane based on the SDN controller, and evaluate the carrying capacity of the links and nodes from multiple dimensions according to the possibility of network events being executed and the current network performance indicators, including: evaluating the carrying capacity of the network nodes according to the current network performance indicators; evaluating the carrying capacity of the network links according to the current network performance indicators.

[0009] Among them, in one embodiment of the present application, the comparison of the difference in carrying capacity between different facilities, the determination of network congestion, the dynamic selection of a path evaluation algorithm to score the alternative paths, and the selection of the current optimal path according to the evaluation results include: for each dimension of the carrying capacity vector, the congestion situation is determined according to the difference between different facilities, and the metric parameter weight vector is calculated; the alternative paths are scored according to the carrying capacity vector and the weight vector, and a routing decision plan is output.

[0010] The second aspect of the present application provides a secure routing device based on link and node carrying capacity, including: a first selection module, which is used to select multiple routing paths passing through secure nodes based on network topology information and preset network security policies, using a preset low-complexity algorithm that does not consider the real-time resource status of the network; an evaluation module, which is used to collect real-time status information of the data plane for the multiple routing paths passing through the secure nodes based on the SDN controller, and evaluate the carrying capacity of the links and nodes from multiple dimensions according to the possibility of network events being executed and the current network performance indicators; a second selection module, which is used to compare the differences in carrying capacity between different facilities, determine the network congestion situation, dynamically select a path evaluation algorithm to score the alternative paths, and select the current best path according to the evaluation results.

[0011] Among them, in one embodiment of the present application, the first selection module includes: a removal unit, which is used to remove corresponding nodes from the network topology according to the isolation nodes required by the preset network security policy; a splitting unit, which is used to split the routing demand from the starting point to the end point into multiple sub-routing demands with the middlebox as the end point or starting point according to the necessary nodes or network middleboxes that must be passed in the target order as required by the preset network security policy; a construction unit, which is used to construct the multiple routing paths passing through the security nodes using the KSP algorithm based on the sub-routing demands.

[0012] Among them, in one embodiment of the present application, the evaluation module includes: a first evaluation unit, used to evaluate the carrying capacity of the network node according to the current network performance indicator; a second evaluation unit, used to evaluate the carrying capacity of the network link according to the current network performance indicator.

[0013] In one embodiment of the present application, the second selection module includes: a calculation unit, which is used to determine the congestion situation for each dimension of the carrying capacity vector according to the difference between different facilities, and calculate the metric parameter weight vector; an output unit, which is used to score the alternative paths according to the carrying capacity vector and the weight vector, and output a routing decision plan.

[0014] The third aspect of the present application provides an electronic device, comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the secure routing method based on link and node carrying capacity as described in the above embodiment.

[0015] The fourth aspect embodiment of the present application provides a computer-readable storage medium, which stores a computer program. When the program is executed by a processor, it implements the above-mentioned secure routing method based on link and node carrying capacity.

[0016] The embodiments of the present application can select multiple routing paths passing through security nodes based on network topology information and preset network security policies, using a preset low-complexity algorithm that does not consider the real-time resource status of the network. For the multiple routing paths passing through security nodes, the SDN controller can collect real-time status information of the data plane, and evaluate the carrying capacity of links and nodes from multiple dimensions based on the possibility of network events being executed and current network performance indicators. The difference in carrying capacity between different facilities is compared, the network congestion situation is determined, and a path evaluation algorithm is dynamically selected to score the alternative paths. The current best path is selected based on the evaluation results. By simplifying the path construction and selection mechanism, network resources can be safely and effectively balanced through routing in large-scale networks, thereby avoiding the risk of denial of service caused by overloaded nodes or routing paths destroying security policies, thereby ensuring the security and reliability of the network. This solves the problem in the related technology that the existing SDN routing algorithm only focuses on the transmission rate and carrying capacity of the link when performing load balancing to allocate network resources, which increases the probability of local network node overload and ignores the carrying capacity of hardware device nodes, causing network performance to degrade. In addition, the routing algorithm does not consider network security policies when making routing decisions, resulting in the presence of untrusted nodes in the output data packets and path packets or failure to pass through designated devices, thereby reducing the security and reliability of the network.

[0017] Additional aspects and advantages of the present application will be given in part in the description below, and in part will become apparent from the description below, or will be learned through the practice of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] The above and / or additional aspects and advantages of the present application will become apparent and easily understood from the following description of the embodiments in conjunction with the accompanying drawings, in which:

[0019] Figure 1 A flowchart of a secure routing method based on link and node carrying capacity provided according to an embodiment of the present application;

[0020] Figure 2 A schematic diagram of a congestion determination and path evaluation architecture according to an embodiment of the present application;

[0021] Figure 3 A schematic diagram of a secure routing solution architecture based on link and node carrying capacity according to an embodiment of the present application;

[0022] Figure 4 A schematic diagram of a network topology according to an embodiment of the present application;

[0023] Figure 5 A schematic diagram of the structure of a secure routing device based on link and node carrying capacity according to an embodiment of the present application;

[0024] Figure 6Schematic diagram of the structure of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION

[0025] Embodiments of the present application are described in detail below, and examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are intended to be used to explain the present application, and should not be construed as limiting the present application.

[0026] The following describes the secure routing method and device based on link and node carrying capacity of the embodiment of the present application with reference to the accompanying drawings. In view of the above-mentioned background technology center mentioned in the related technology, the existing SDN routing algorithm only focuses on the transmission rate and carrying capacity of the link when performing load balancing to allocate network resources, which increases the probability of local network node overload, ignores the carrying capacity of hardware device nodes, and reduces network performance. In addition, the routing algorithm does not consider network security policies when making routing decisions, resulting in the presence of untrusted nodes in the output data packets and path packets or failure to pass through designated devices, which reduces the security and reliability of the network. The present application provides a secure routing method based on link and node carrying capacity, which can be based on network topology information and preset network security policies, using a preset low-complexity algorithm that does not consider the real-time resource status of the network. , select multiple routing paths passing through security nodes, collect data plane real-time status information based on SDN controller for multiple routing paths passing through security nodes, and evaluate the carrying capacity of links and nodes from multiple dimensions according to the possibility of network events being executed and the current network performance indicators, compare the differences in carrying capacity between different facilities, determine the network congestion, dynamically select path evaluation algorithms to score alternative paths, select the current best path according to the evaluation results, and balance network resources safely and effectively through routing in large-scale networks by simplifying the path construction and selection mechanism, thereby avoiding the risk of denial of service caused by overloaded nodes or routing paths destroying security policies, thereby ensuring the security and reliability of the network. Therefore, the existing SDN routing algorithm in the relevant technology only focuses on the transmission rate and carrying capacity of the link when performing load balancing to allocate network resources, resulting in an increase in the probability of local network node overload, ignoring the carrying capacity of hardware device nodes, and reducing network performance. In addition, the routing algorithm does not consider network security policies when making routing decisions, resulting in the presence of untrusted nodes or failure to pass through designated devices in the output data packets and path packets, reducing the security and reliability of the network.

[0027] Specifically, Figure 1 A flowchart of a secure routing method based on link and node carrying capacity provided in an embodiment of the present application.

[0028] like Figure 1As shown, the secure routing method based on link and node carrying capacity includes the following steps:

[0029] In step S101, based on network topology information and preset network security policies, a plurality of routing paths passing through security nodes are selected using a preset low-complexity algorithm that does not consider the real-time resource status of the network.

[0030] It is understandable that the preset network security policy in the embodiment of the present application may be a relevant policy for network security prevention and protection, such as access control policy, intrusion detection system, etc. The preset low-complexity algorithm may be a low-complexity routing algorithm, thereby selecting a routing path passing through a secure node, the secure node corresponds to a dangerous node that is untrustworthy or controlled by an attacker, and the routing path passing through the secure node may be a routing path that does not contain a dangerous node.

[0031] It should be noted that the preset network security policy and the preset low-complexity algorithm are set by those skilled in the art according to actual conditions and are not specifically limited here.

[0032] In the actual execution process, k routing paths can be constructed. According to the network topology, the necessary network devices and the network devices that need to be isolated, a low-complexity routing algorithm is selected, and the reference factors of the real-time resource status of the network and the network performance indicators are eliminated to obtain K alternative paths passing through the security nodes.

[0033] The embodiment of the present application can select multiple routing paths passing through security nodes based on network topology information and preset network security policies, using a preset low-complexity algorithm that does not consider the real-time resource status of the network, thereby providing a basis for the alternative evaluation of the following steps and realizing the construction of alternative paths.

[0034] Among them, in one embodiment of the present application, based on network topology information and preset network security policies, a preset low-complexity algorithm that does not consider the real-time resource status of the network is used to select multiple routing paths passing through security nodes, including: according to the isolation nodes required by the preset network security policy, the corresponding nodes are removed from the network topology; according to the necessary nodes or network middleboxes that need to be passed in the target order as required by the preset network security policy, the routing requirements from the starting point to the end point are split into multiple sub-routing requirements with the middlebox as the end point or starting point; based on the sub-routing requirements, the KSP algorithm is used to construct multiple routing paths passing through security nodes.

[0035] It is understandable that in the embodiment of the present application, the corresponding nodes can be eliminated by eliminating related nodes that do not meet the preset network security policy requirements, such as nodes with faults, or nodes with black hole problems that cannot be processed for specific data flows. The sub-routing requirements can be split according to the traffic needs to pass through different necessary nodes or network middleboxes in a specified order. The middlebox can be a firewall, VPN gateway, proxy, and intrusion detection system.

[0036] In some embodiments, when a node fails or a node has a black hole problem that cannot be processed for a specific data stream, in order to avoid introducing the above nodes and causing network security problems, when building a route, a problem node set V output by the SDN controller security module is received. iso , when calculating the specified end-to-end data packet path, remove the problem nodes from the topology and receive the set of nodes that must be passed through V req , decompose the current route into multiple sub-path connections, where the sub-routes are connected by V req The middle node is the starting point or end point. For the decomposed sub-routing requirements, the Yen algorithm is used to calculate the shortest K paths between any two nodes in the network, where the K value can be adjusted according to the actual situation to efficiently solve the KSP problem without passing through repeated nodes. The basic process of the alternative path construction algorithm is as follows:

[0037]

[0038] When building a routing path, the number of hops can be used as the standard for calculating the path, and the weights of all links can be set to a uniform value. When the network topology is first established or changes occur, the algorithm for planning the path based on real-time network status information may not be able to output normally due to missing data, while the algorithm based on the number of hops can calculate the path normally, is robust, and omits the link weighting process, reduces information collection, weight calculation and other calculation processes, and does not require repeated calculations when the network topology is stable, reducing the calculation overhead and improving the operation efficiency.

[0039] The embodiments of the present application can remove corresponding nodes from the network topology according to the isolation nodes required by the preset network security policy, and split the routing requirements from the starting point to the end point into multiple sub-routing requirements with the middlebox as the end point or starting point according to the necessary nodes or network middleboxes that must be passed in the target order as required by the preset network security policy, and use the KSP algorithm to construct multiple routing paths passing through security nodes, thereby meeting the requirements of the network security policy and making the constructed routing paths more secure and reliable.

[0040] In step S102, for multiple routing paths passing through security nodes, the real-time status information of the data plane is collected based on the SDN controller, and the carrying capacity of the links and nodes is evaluated from multiple dimensions according to the possibility of network events being executed and the current network performance indicators.

[0041] It can be understood that the carrying capacity of links and nodes in the embodiments of the present application can be presented through dimensions such as node forwarding capability, node forwarding delay, link delay and link idle rate, which can facilitate the representation of the remaining carrying capacity of the link and its associated nodes, so as to evaluate the link and node carrying capacity through real-time status information on the data plane.

[0042] The embodiments of the present application can collect real-time status information of the data plane for multiple routing paths passing through security nodes based on the SDN controller, and evaluate the carrying capacity of links and nodes from multiple dimensions according to the possibility of network events being executed and current network performance indicators, thereby avoiding network performance degradation caused by local network node overload and ensuring network reliability.

[0043] Among them, in one embodiment of the present application, for multiple routing paths passing through security nodes, real-time status information of the data plane is collected based on the SDN controller, and the carrying capacity of the links and nodes is evaluated from multiple dimensions according to the possibility of network events being executed and the current network performance indicators, including: evaluating the carrying capacity of network nodes according to the current network performance indicators; evaluating the carrying capacity of network links according to the current network performance indicators.

[0044] In the actual implementation process, G = (V, E) can be used to represent the network topology of the SDN network data plane with x hardware nodes and y links, where the set of all hardware devices is V = (v 1 ,…,v x ), the set of all network links is E = (e 1 ,…,e y ).

[0045] The carrying capacity of network nodes and their links is comprehensively represented by a multidimensional vector, where each vector can represent the possible or current network performance index of a certain network event. i ∈V, let v i The link e between the node and its previous hop j , v i The carrying capacity is given by a four-dimensional vector U i express

[0046] U i =(u 1i ,…,u 4i ),

[0047] U i middle u 1i ,u 2i Vector and u 3i ,u 4i The vectors reflect the node v i and link ej carrying capacity.

[0048] Among them, u 1i For node v i The successful forwarding rate. In the statistical time window T window =T start -T end Within, record the node v i The number of received packets is N Rx , the number of packets sent is N Tx , according to the controller flow rule, the number of packets to be dropped is N Drop .u 1i By node v i The ratio of successfully forwarded data packets represents the probability that the node will successfully forward the data packet at the next moment. The calculation method is:

[0049] u 2i For node v i The processing delay of node v i The delay introduced by processing the data packet is u 2i The average processing delay of network nodes and node v i The processing delay ratio is expressed as:

[0050] u 3i Link e j The delay of link e j The delay is u 3i The average delay of the network link and the link e j The delay ratio is expressed as:

[0051] u 4i Link e j The link idle rate is j The current bandwidth is BW j , e j The maximum bandwidth is C j , is the link utilization, u 4i The calculation method is

[0052] The embodiments of the present application can evaluate the carrying capacity of network nodes according to current network performance indicators, and evaluate the carrying capacity of network links according to current network performance indicators, thereby realizing the evaluation of the carrying capacity of network facilities and reducing the security risks of the network.

[0053] In step S103, the differences in carrying capacity between different facilities are compared to determine the network congestion situation, a path evaluation algorithm is dynamically selected to score the candidate paths, and the current best path is selected based on the evaluation results.

[0054] It can be understood that in the embodiment of the present application, the network congestion situation can be determined by considering whether there are congested bottleneck links or nodes in the network, and then comparing the differences in carrying capacity between different facilities, thereby dynamically selecting a path evaluation algorithm to score the alternative paths, such as a traditional routing algorithm or a routing algorithm that can adjust the link / node load, to obtain an evaluation result.

[0055] In the actual implementation process, when the current network traffic does not exceed the network carrying capacity, the traditional routing algorithm can be used to reduce the computing intensity of the controller. When some network characteristics vary greatly among the hardware, it indicates that there is congestion in the network, and a routing algorithm that can adjust the link / node load can be used.

[0056] The embodiments of the present application can compare the differences in carrying capacity between different facilities, determine the network congestion situation, dynamically select a path evaluation algorithm to score the alternative paths, and select the current optimal path based on the evaluation results, thereby balancing the actual network traffic and the network hardware carrying capacity, effectively managing network resources and meeting transmission requirements, obtaining a path that complies with security policies and has the largest remaining carrying capacity of network facilities, and reducing computing intensity.

[0057] Among them, in one embodiment of the present application, the difference in carrying capacity between different facilities is compared, the network congestion situation is determined, the path evaluation algorithm is dynamically selected to score the alternative paths, and the current optimal path is selected according to the evaluation results, including: for each dimension of the carrying capacity vector, the congestion situation is determined according to the difference between different facilities, and the metric parameter weight vector is calculated; the alternative paths are scored according to the carrying capacity vector and the weight vector, and the routing decision plan is output.

[0058] For example, to determine network congestion, the following function can be used to measure the four-dimensional vector U in the entire network: i The difference between the vectors in

[0059]

[0060] Where x is the number of nodes, y is the number of links, and u m is the mth carrying capacity metric parameter of the node / link, for u m The average value, u mi is the mth carrying capacity measurement parameter of the ith node, u MJ is the Mth carrying capacity metric parameter of the Jth link. M with u mOne-to-one correspondence, and there is a corresponding threshold When , the network is considered to be smooth in this attribute, and the carrying capacity exceeds the actual traffic transmission demand; When , the network is considered to have link / node congestion on this attribute, and a routing algorithm that considers load balancing needs to be called.

[0061] like Figure 2 The figure is a schematic diagram of the congestion determination and path evaluation architecture of an embodiment of the present application. After determining the network congestion situation, use the corresponding evaluation algorithm to evaluate each path in kSPList. k Calculate the remaining carrying capacity R of the path at the current moment k , r k The path with the largest value is the selected path. k = {v 1 ,…, l}, where k∈(1,K),ath k ∈kspList,v i ∈V,path k The carrying capacity is represented by a four-dimensional vector A k Expressed as

[0062] A k =(a 1k ,…, 4k ) T ,

[0063] Among them, A k For path k The carrying capacity, a mk is the mth carrying capacity measurement parameter of the kth path, T represents the transposed matrix, m = 1, 2, 3, 4. k Each vector in and the node carrying capacity vector U i =(u 1i ,…, 4i ) corresponds to each other, and the carrying capacity of the path is displayed by evaluating the node forwarding capability, node forwarding delay, link delay and link idle rate of the path, which is represented by the cumulative multiplication of the corresponding vectors of each node constituting the path. The calculation method is:

[0064]

[0065] Among them, a mk is the mth carrying capacity metric parameter of the kth path, v l is the lth node on the path, u mi is the mth node carrying capacity vector of the i-th node. The carrying capacity matrix of K shortest paths is expressed as

[0066]

[0067] Among them, A is the carrying capacity matrix of K shortest paths, A k For path k The carrying capacity, a mk is the mth carrying capacity measurement parameter of the kth path, m = 1, 2, 3, 4. is the multiple attribute vectors of the aggregated path, and the measurement parameter importance vector IM is introduced. 1 ,…,m 4 ), the metric parameter weight vector W is calculated to be (w 1 ,…, 4 ), to indicate the importance and sensitivity of different carrying capacities in the routing selection process. When a certain attribute of a node / link is balanced in the entire network, the attribute vector does not participate in the routing decision. m The calculation method is

[0068]

[0069] Among them, w m is the mth metric parameter weight vector, im m is the mth metric parameter importance vector, im n is the importance vector of the nth metric parameter. k The overall residual carrying capacity r k The calculation method is

[0070]

[0071] Among them, r k For path path k The overall residual carrying capacity, w m is the mth metric parameter weight vector, a mk is the mth carrying capacity measurement parameter of the kth path. The overall residual carrying capacity evaluation result of the K paths in kspList is

[0072]

[0073] Where R is the overall remaining carrying capacity evaluation result of the K paths in kspList, W is the metric parameter weight vector, A is the carrying capacity matrix of the K shortest paths, and w m is the mth metric parameter weight vector, a mk is the mth carrying capacity metric parameter of the kth path, m=1,2,3,4. Select r from R j The largest path j As the final routing result.

[0074] The basic process of the algorithm is as follows:

[0075]

[0076]

[0077] The embodiment of the present application can determine the congestion situation for each dimension of the carrying capacity vector according to the difference between different facilities and calculate the metric parameter weight vector; score the alternative paths according to the carrying capacity vector and the weight vector, output the routing decision plan, and dynamically select the evaluation plan based on the actual network situation, thereby reducing the complexity of the overall routing algorithm and improving the scalability of the algorithm in complex network environments.

[0078] Combine the following Figure 3-4 , the working content of the embodiment of this application is described in detail with a specific embodiment.

[0079] in, Figure 3 This is a schematic diagram of a secure routing solution architecture based on link and node carrying capacity according to an embodiment of the present application. According to the architecture shown in the figure, a hybrid routing instance based on link and node carrying capacity is presented.

[0080] exist Figure 4 In the network topology shown, a hybrid routing algorithm based on link and node carrying capacity is used to plan the communication lines for hosts H1 and H2. After ignoring the lines connecting the hosts and switches, it is necessary to build a route between the source node S1 and the destination node S8.

[0081] As shown in the following table, Table 1 is the network node carrying capacity information, and Table 2 is the network link carrying capacity information. According to the above routing algorithm and the network status information collected by the controller, the carrying information of the network nodes and links in the current network topology is obtained, as given in Table 1-2. Then, the maximum remaining carrying capacity is selected by Algorithm 2 in the above steps. The parameters selected in this example are: K = 5, im m =1, where m=1,2,3,4.

[0082] Table 1

[0083]

[0084] Table 2

[0085]

[0086] In the case of conventional routing, it is assumed that all nodes in the network can transmit the current data packet. The network topology is input into the KSP algorithm to obtain 5 reference paths, and then the remaining carrying capacity of the above paths is evaluated.

[0087] Table 3 shows the evaluation results of the remaining carrying capacity of the conventional path, including the path number, node order and evaluation results. In the conventional routing that only considers the number of path hops, the result obtained by using the Dijkstra shortest path algorithm is path 1, i.e. (S1->S3->S6->S8), which passes through 4 data plane switches. Taking into account the carrying capacity of nodes and links in various aspects, path 5 with the highest remaining carrying capacity value, i.e. (S1->S3->S9->S7->S8), is selected as the transmission path between S1 and S8.

[0088] Table 3

[0089]

[0090] In the case of secure routing, it is considered that there are some nodes in the network that cannot transmit the current data packet, such as node failure, or the node has a black hole problem that cannot be processed for the current data flow, and the network middlebox nodes that must be passed. Therefore, it is necessary to first obtain the problem nodes that should be bypassed in the routing from the output of the controller and the detection tool in Chapter 3, remove the problem nodes from the topology, and then split the original routing requirements into several sub-routing requirements that pass through the middlebox. Finally, the path selection and evaluation plan are consistent with the conventional routing path selection.

[0091] As shown in Table 4, the evaluation results of the remaining carrying capacity of the security path are shown. After removing the node S3 with security risks from the network topology and adding the necessary node S2, the evaluation results of the routing algorithm on the five KSP paths can be referred to Table 4. In this case, the path No. 4 with the highest carrying capacity value, i.e. (S1->S2->S4->S5->S7->S8), is selected as the transmission path between S1 and S8.

[0092] Table 4

[0093]

[0094] According to the secure routing method based on link and node carrying capacity proposed in the embodiment of the present application, multiple routing paths passing through secure nodes can be selected based on network topology information and preset network security policies, using a preset low-complexity algorithm that does not consider the real-time resource status of the network. For multiple routing paths passing through secure nodes, the real-time status information of the data plane is collected based on the SDN controller, and the carrying capacity of the links and nodes is evaluated from multiple dimensions based on the possibility of network events being executed and the current network performance indicators. The differences in carrying capacity between different facilities are compared, the network congestion situation is determined, and a path evaluation algorithm is dynamically selected to score the alternative paths. The current best path is selected based on the evaluation results. By simplifying the path construction and selection mechanism, network resources can be safely and effectively balanced through routing in large-scale networks, thereby avoiding the risk of denial of service caused by overloaded nodes or routing paths destroying security policies, thereby ensuring the security and reliability of the network. This solves the problem in the related technology that the existing SDN routing algorithm only focuses on the transmission rate and carrying capacity of the link when performing load balancing to allocate network resources, which increases the probability of local network node overload and ignores the carrying capacity of hardware device nodes, causing network performance to degrade. In addition, the routing algorithm does not consider network security policies when making routing decisions, resulting in the presence of untrusted nodes in the output data packets and path packets or failure to pass through designated devices, thereby reducing the security and reliability of the network.

[0095] Next, a secure routing device based on link and node carrying capacity proposed in an embodiment of the present application is described with reference to the accompanying drawings.

[0096] Figure 5 It is a block diagram of a secure routing device based on link and node carrying capacity according to an embodiment of the present application.

[0097] like Figure 5 As shown, the secure routing device 10 based on link and node carrying capacity includes: a first selection module 100 , an evaluation module 200 and a second selection module 300 .

[0098] Among them, the first selection module 100 is used to select multiple routing paths passing through security nodes based on network topology information and preset network security policies, using a preset low-complexity algorithm that does not consider the real-time resource status of the network.

[0099] The evaluation module 200 is used to collect real-time status information of the data plane for multiple routing paths passing through security nodes based on the SDN controller, and evaluate the carrying capacity of links and nodes from multiple dimensions according to the possibility of network events being executed and current network performance indicators.

[0100] The second selection module 300 is used to compare the differences in carrying capacity between different facilities, determine the network congestion situation, dynamically select a path evaluation algorithm to score the candidate paths, and select the current best path based on the evaluation results.

[0101] In one embodiment of the present application, the first selection module 100 includes: a removal unit, a splitting unit and a construction unit.

[0102] The removal unit is used to remove corresponding nodes from the network topology according to the isolation nodes required by the preset network security policy.

[0103] The splitting unit is used to split the routing demand from the starting point to the end point into multiple sub-routing demands with the middlebox as the end point or the starting point according to the necessary nodes or network middleboxes that must be passed through in the target order according to the requirements of the preset network security policy.

[0104] The construction unit is used to construct multiple routing paths passing through security nodes using the KSP algorithm based on sub-routing requirements.

[0105] In one embodiment of the present application, the evaluation module 200 includes: a first evaluation unit and a second evaluation unit.

[0106] The first evaluation unit is used to evaluate the carrying capacity of the network node according to the current network performance index.

[0107] The second evaluation unit is used to evaluate the carrying capacity of the network link according to the current network performance index.

[0108] In one embodiment of the present application, the second selection module 300 includes: a calculation unit and an output unit.

[0109] The calculation unit is used to determine the congestion situation for each dimension of the carrying capacity vector according to the difference between different facilities and calculate the metric parameter weight vector.

[0110] The output unit is used to score the candidate paths according to the carrying capacity vector and the weight vector, and output the routing decision plan.

[0111] It should be noted that the aforementioned explanation of the embodiment of the secure routing method based on link and node carrying capacity is also applicable to the secure routing device based on link and node carrying capacity of this embodiment, which will not be repeated here.

[0112] According to the secure routing device based on link and node carrying capacity proposed in the embodiment of the present application, multiple routing paths passing through secure nodes can be selected based on network topology information and preset network security policies, using a preset low-complexity algorithm that does not consider the real-time resource status of the network. For multiple routing paths passing through secure nodes, real-time status information of the data plane is collected based on the SDN controller, and the carrying capacity of links and nodes is evaluated from multiple dimensions based on the possibility of network events being executed and current network performance indicators. The differences in carrying capacity between different facilities are compared, the network congestion situation is determined, and a path evaluation algorithm is dynamically selected to score alternative paths. The current best path is selected based on the evaluation results. By simplifying the path construction and selection mechanism, network resources are safely and effectively balanced through routing in large-scale networks, thereby avoiding the risk of denial of service caused by overloaded nodes or routing paths destroying security policies, thereby ensuring the security and reliability of the network. This solves the problem in the related technology that the existing SDN routing algorithm only focuses on the transmission rate and carrying capacity of the link when performing load balancing to allocate network resources, which increases the probability of local network node overload and ignores the carrying capacity of hardware device nodes, causing network performance to degrade. In addition, the routing algorithm does not consider network security policies when making routing decisions, resulting in the presence of untrusted nodes in the output data packets and path packets or failure to pass through designated devices, thereby reducing the security and reliability of the network.

[0113] Figure 6 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. The electronic device may include:

[0114] A memory 601 , a processor 602 , and a computer program stored in the memory 601 and executable on the processor 602 .

[0115] When the processor 602 executes the program, the secure routing method based on link and node carrying capacity provided in the above embodiment is implemented.

[0116] Furthermore, the electronic device further comprises:

[0117] The communication interface 603 is used for communication between the memory 601 and the processor 602 .

[0118] The memory 601 is used to store computer programs that can be executed on the processor 602 .

[0119] The memory 601 may include a high-speed RAM memory, and may also include a non-volatile memory (non-volatile memory), such as at least one disk memory.

[0120] If the memory 601, the processor 602 and the communication interface 603 are implemented independently, the communication interface 603, the memory 601 and the processor 602 can be connected to each other through a bus and communicate with each other. The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component (PCI) bus or an Extended Industry Standard Architecture (EISA) bus. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 6 Only one thick line is used in the diagram, but this does not mean that there is only one bus or only one type of bus.

[0121] Optionally, in a specific implementation, if the memory 601, the processor 602 and the communication interface 603 are integrated on a chip, the memory 601, the processor 602 and the communication interface 603 can communicate with each other through an internal interface.

[0122] The processor 602 may be a central processing unit (CPU), or an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application.

[0123] This embodiment also provides a computer-readable storage medium on which a computer program is stored. When the program is executed by a processor, the above-mentioned secure routing method based on link and node carrying capacity is implemented.

[0124] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" etc. means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present application. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or N embodiments or examples in a suitable manner. In addition, those skilled in the art may combine and combine the different embodiments or examples described in this specification and the features of the different embodiments or examples, without contradiction.

[0125] In addition, the terms "first" and "second" are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of technical features indicated. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include at least one of the features. In the description of this application, "N" means at least two, such as two, three, etc., unless otherwise clearly and specifically defined.

[0126] Any process or method description in a flowchart or otherwise described herein may be understood to represent a module, fragment or portion of code comprising one or N executable instructions for implementing the steps of a custom logical function or process, and the scope of the preferred embodiments of the present application includes alternative implementations in which functions may not be performed in the order shown or discussed, including performing functions in a substantially simultaneous manner or in reverse order depending on the functions involved, which should be understood by technicians in the technical field to which the embodiments of the present application belong.

[0127] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as an ordered list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by an instruction execution system, device or apparatus (such as a computer-based system, a system including a processor, or other system that can fetch instructions from an instruction execution system, device or apparatus and execute instructions), or in combination with these instruction execution systems, devices or apparatuses. For the purpose of this specification, "computer-readable medium" can be any device that can contain, store, communicate, propagate or transmit a program for use by an instruction execution system, device or apparatus, or in combination with these instruction execution systems, devices or apparatuses. More specific examples of computer-readable media (a non-exhaustive list) include the following: an electrical connection with one or N wirings (electronic devices), a portable computer disk box (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), a fiber optic device, and a portable compact disk read-only memory (CDROM). In addition, the computer-readable medium may even be paper or other suitable medium on which the program is printed, since the program may be obtained electronically by optically scanning the paper or other medium and then editing, interpreting or processing in other suitable ways as necessary and then storing it in a computer memory.

[0128] It should be understood that the various parts of the present application can be implemented by hardware, software, firmware or a combination thereof. In the above-mentioned embodiment, the N steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, it can be implemented by any one of the following technologies known in the art or their combination: a discrete logic circuit having a logic gate circuit for implementing a logic function for a data signal, a dedicated integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.

[0129] A person skilled in the art may understand that all or part of the steps in the method for implementing the above-mentioned embodiment may be completed by instructing related hardware through a program, and the program may be stored in a computer-readable storage medium, which, when executed, includes one or a combination of the steps of the method embodiment.

[0130] In addition, each functional unit in each embodiment of the present application may be integrated into a processing module, or each unit may exist physically separately, or two or more units may be integrated into one module. The above-mentioned integrated module may be implemented in the form of hardware or in the form of a software functional module. If the integrated module is implemented in the form of a software functional module and sold or used as an independent product, it may also be stored in a computer-readable storage medium.

[0131] The storage medium mentioned above may be a read-only memory, a magnetic disk or an optical disk, etc. Although the embodiments of the present application have been shown and described above, it can be understood that the above embodiments are exemplary and cannot be understood as limiting the present application. A person of ordinary skill in the art may change, modify, replace and modify the above embodiments within the scope of the present application.

Claims

1. A secure routing method based on link and node carrying capacity, characterized in that: The following steps are involved: Based on network topology information and preset network security policies, multiple routing paths passing through secure nodes are selected using a preset low-complexity algorithm that does not consider the real-time resource status of the network; For the multiple routing paths passing through the security nodes, the real-time status information of the data plane is collected based on the SDN controller, and the carrying capacity of the links and nodes is evaluated from multiple dimensions according to the possibility of the network events being executed and the current network performance indicators; as well as Compare the differences in carrying capacity between different facilities, determine the network congestion situation, dynamically select the path evaluation algorithm to score the alternative paths, and select the current best path based on the evaluation results.

2. The method according to claim 1, characterized in that: The method of selecting multiple routing paths passing through security nodes based on network topology information and preset network security policies using a preset low-complexity algorithm that does not consider the real-time resource status of the network includes: According to the isolation nodes required by the preset network security policy, the corresponding nodes are removed from the network topology; According to the preset network security policy requirements, the necessary nodes or network middleboxes to pass through in the target order are split into multiple sub-routing requirements with the middlebox as the end point or the starting point; Based on the sub-routing requirements, the KSP algorithm is used to construct the multiple routing paths passing through the security nodes.

3. The method according to claim 1, characterized in that: For the plurality of routing paths passing through the security nodes, the real-time status information of the data plane is collected based on the SDN controller, and the carrying capacity of the links and nodes is evaluated from multiple dimensions according to the possibility of the network event being executed and the current network performance indicators, including: Evaluate the carrying capacity of network nodes based on current network performance indicators; The carrying capacity of the network link is evaluated according to the current network performance indicator.

4. The method according to claim 1, characterized in that: The above comparison shows the difference in carrying capacity between different facilities. Determine network congestion, dynamically select a path evaluation algorithm to score candidate paths, and select the current best path based on the evaluation results, including: For each dimension of the carrying capacity vector, the congestion situation is determined according to its difference between different facilities, and the metric parameter weight vector is calculated; The candidate paths are scored according to the carrying capacity vector and the weight vector, and a routing decision solution is output.

5. A secure routing device based on link and node carrying capacity, characterized in that: include: A first selection module is used to select multiple routing paths passing through security nodes based on network topology information and preset network security policies, using a preset low-complexity algorithm that does not consider the real-time resource status of the network; An evaluation module, configured to collect data plane real-time status information for the plurality of routing paths passing through the security nodes based on the SDN controller, and evaluate the carrying capacity of the links and nodes from multiple dimensions according to the possibility of execution of network events and current network performance indicators; as well as The second selection module is used to compare the differences in carrying capacity between different facilities, determine the network congestion situation, dynamically select the path evaluation algorithm to score the alternative paths, and select the current best path based on the evaluation results.

6. The device according to claim 5, characterized in that The first selection module includes: A removal unit, configured to remove corresponding nodes from the network topology according to the isolation nodes required by the preset network security policy; A splitting unit, used to split the routing requirement from the starting point to the end point into multiple sub-routing requirements with the middlebox as the end point or the starting point according to the necessary nodes or network middleboxes passed in the target order according to the requirements of the preset network security policy; A construction unit is used to construct the plurality of routing paths passing through the security nodes by using a KSP algorithm based on the sub-routing requirements.

7. The device according to claim 5, characterized in that The evaluation module includes: A first evaluation unit, configured to evaluate the carrying capacity of a network node according to a current network performance indicator; The second evaluation unit is used to evaluate the carrying capacity of the network link according to the current network performance indicator.

8. The device according to claim 5, characterized in that The second selection module includes: A calculation unit, configured to determine the congestion situation for each dimension of the carrying capacity vector according to the difference between different facilities, and calculate a metric parameter weight vector; The output unit is used to score the candidate paths according to the carrying capacity vector and the weight vector, and output a routing decision solution.

9. An electronic device, characterized in that: include: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the secure routing method based on link and node carrying capacity as described in any one of claims 1 to 4.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: The program is executed by a processor to implement the secure routing method based on link and node carrying capacity as described in any one of claims 1 to 4.

Citation Information

Patent Citations

  • Router for realizing passage separation and transmitting method of passage separation thereof

    CN101753438A

  • Multi-domain ASON damage perception multicast routing method based on hypergraph model

    CN105357132A