Data processing method, device, equipment and storage medium

By carrying five-tuple data in the deregistration request for multi-layer verification, the risk of attacks in the 5G network element device sinking environment without the TLS transport layer encryption mechanism is resolved, the security of the deregistration process is strengthened, and network paralysis is prevented.

CN116347447BActive Publication Date: 2025-10-03CHINA MOBILE COMM LTD RES INST +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111592800.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-23
Publication Date
2025-10-03
Estimated Expiration
2041-12-23

AI Technical Summary

Technical Problem

In the environment where 5G mobile communication network element equipment is sunk, the security risk of network attacks increases, especially when the TLS transport layer encryption mechanism is not enabled. Attackers can act as middlemen to tamper with and forge registration requests, causing core network elements to be paralyzed.

Method used

By carrying five-tuple data in the deregistration request for verification, including the initiating network element's identity, random number and check value, etc., these data are used to perform multi-layer verification on the deregistering network element's identity to ensure the legitimacy of the request.

Benefits of technology

This effectively prevents attackers from tampering with or forging deregistration requests, improves the security of the network element deregistration process, avoids network paralysis, and does not add additional interaction steps.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116347447B_ABST
    Figure CN116347447B_ABST
Patent Text Reader

Abstract

The present invention discloses a data processing method, apparatus, device, and storage medium. The method includes: obtaining a deregistration request; the deregistration request carries an identifier of a deregistered network element and five-tuple data; using the five-tuple data, verifying the identifier of the deregistered network element carried in the deregistration request to obtain a verification result; and performing a deregistration operation when the verification result indicates that the identifier of the deregistered network element carried in the deregistration request passes the verification.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of wireless technology, and in particular to a data processing method, apparatus, device and storage medium. Background Art

[0002] Currently, the deployment of fifth-generation (5G) mobile communication network elements further down the network significantly increases the risk of network attacks, directly impacting the security of the entire core network. 5G also introduces a service-based architecture (SBA), defining network functions (NFs) as microservices, enabling signaling messages between NFs to be delivered in a service-based manner. Consequently, without enabling TLS (Transport Layer Security) authentication in the core network, attackers could potentially act as middlemen, obtain data sent from edge / downstream networks, and exploit service-based open interfaces to bypass the core network's deregistered business processes, forcing legitimate NFs offline and paralyzing the network. Summary of the Invention

[0003] In view of this, embodiments of the present invention are intended to provide a data processing method, apparatus, device, and storage medium.

[0004] The technical solution of the embodiment of the present invention is achieved as follows:

[0005] At least one embodiment of the present invention provides a data processing method, applied to a first network element, the method comprising:

[0006] Obtaining a deregistration request; the deregistration request carries an identifier of a deregistering network element and five-tuple data;

[0007] Using the quintuple data, verifying the identifier of the deregistering network element carried in the deregistration request to obtain a verification result;

[0008] When the verification result indicates that the identifier of the deregistering network element carried in the deregistration request passes the verification, the deregistration operation is performed.

[0009] Furthermore, according to at least one embodiment of the present invention, the five-tuple data includes:

[0010] The identifier of the second network element that initiates the deregistration request;

[0011] To register the network element's identifier;

[0012] Random numbers;

[0013] First check value;

[0014] Second check value;

[0015] Accordingly, the verifying the identifier of the deregistering network element carried in the deregistration request by using the quintuple data includes:

[0016] Comparing the identifier of the deregistering network element carried in the deregistration request with the identifier of the deregistering network element in the quintuple data to obtain a first comparison result;

[0017] Based on the first comparison result, the identifier of the deregistering network element carried in the deregistration request is verified.

[0018] Furthermore, according to at least one embodiment of the present invention, the verifying, based on the first comparison result, the identifier of the deregistering network element carried in the deregistration request includes:

[0019] When the first comparison result indicates that the identifier of the deregistration network element carried in the deregistration request is the same as the identifier of the deregistration network element in the quintuple data, generating first authentication data according to the identifier of the second network element that initiates the deregistration request and the identifier of the deregistration network element in the quintuple data;

[0020] Comparing the value corresponding to the first authentication data with the first check value in the quintuple data to obtain a second comparison result;

[0021] Based on the second comparison result, the identifier of the deregistering network element carried in the deregistration request is verified.

[0022] Furthermore, according to at least one embodiment of the present invention, the verifying, based on the second comparison result, the identifier of the deregistering network element carried in the deregistration request includes:

[0023] When the second comparison result indicates that the value corresponding to the first authentication data is the same as the first check value, generating second authentication data according to the random number in the quintuple data;

[0024] Comparing the value corresponding to the second authentication data with the second check value in the quintuple data to obtain a third comparison result;

[0025] Based on the third comparison result, the identifier of the deregistering network element carried in the deregistration request is verified.

[0026] At least one embodiment of the present invention provides a data processing method, applied to a second network element, the method comprising:

[0027] Sending a deregistration request; the deregistration request carries an identifier of the deregistering network element and five-tuple data;

[0028] Among them, the five-tuple data is used for the first network element that obtains the deregistration request to verify the identifier of the deregistration network element and obtain a verification result; when the verification result indicates that the identifier of the deregistration network element carried by the deregistration request passes the verification, the deregistration operation is performed.

[0029] Furthermore, according to at least one embodiment of the present invention, the method further comprises:

[0030] Determining an identifier of the second network element that initiated the deregistration request and an identifier of the deregistering network element;

[0031] Generate random numbers;

[0032] Encrypting the generated random number to obtain a first check value;

[0033] Encrypting the identifier of the second network element and the identifier of the deregistering network element to obtain a second verification value;

[0034] Based on the identifier of the second network element, the identifier of the deregistration network element, the random number, the first check value and the second check value, the five-tuple data carried by the deregistration request is obtained.

[0035] Furthermore, according to at least one embodiment of the present invention, the method further comprises:

[0036] Obtaining the five-tuple data carried in the deregistration request initiated by the third network element;

[0037] Modify the parameter values ​​in the obtained quintuple data;

[0038] Based on the modified parameter value, the five-tuple data carried in the deregistration request is obtained.

[0039] At least one embodiment of the present invention provides a data processing device, including:

[0040] An acquiring unit, configured to acquire a deregistration request, wherein the deregistration request carries an identifier of a deregistering network element and five-tuple data;

[0041] The processing unit is used to use the five-tuple data to verify the identifier of the deregistered network element carried by the deregistration request to obtain a verification result; when the verification result indicates that the identifier of the deregistered network element carried by the deregistration request passes the verification, perform the deregistration operation.

[0042] At least one embodiment of the present invention provides a data processing device, including:

[0043] A sending unit, configured to send a deregistration request; the deregistration request carries an identifier of a deregistering network element and five-tuple data;

[0044] Among them, the five-tuple data is used for the first network element that obtains the deregistration request to verify the identifier of the deregistration network element and obtain a verification result; when the verification result indicates that the identifier of the deregistration network element carried by the deregistration request passes the verification, the deregistration operation is performed.

[0045] At least one embodiment of the present invention provides a first network element, including:

[0046] The first communication interface is configured to obtain a deregistration request, wherein the deregistration request carries an identifier of a deregistering network element and five-tuple data;

[0047] The first processor is configured to verify the identifier of the deregistering network element carried in the deregistration request using the five-tuple data to obtain a verification result; when the verification result indicates that the identifier of the deregistering network element carried in the deregistration request passes the verification, perform a deregistration operation.

[0048] At least one embodiment of the present invention provides a second network element, including:

[0049] Second processor,

[0050] The second communication interface is used to send a deregistration request; the deregistration request carries an identifier of the deregistering network element and five-tuple data;

[0051] Among them, the five-tuple data is used for the first network element that obtains the deregistration request to verify the identifier of the deregistration network element and obtain a verification result; when the verification result indicates that the identifier of the deregistration network element carried by the deregistration request passes the verification, the deregistration operation is performed.

[0052] At least one embodiment of the present invention provides a first network element, comprising a first processor and a first memory for storing a computer program that can be run on the first processor.

[0053] The first processor is configured to execute the steps of any one of the above-mentioned methods on the first network element side when running the computer program.

[0054] At least one embodiment of the present invention provides a second network element, comprising a second processor and a second memory for storing a computer program that can be run on the second processor.

[0055] The second processor is configured to execute the steps of any one of the above-mentioned methods on the second network element side when running the computer program.

[0056] At least one embodiment of the present invention provides a storage medium having a computer program stored thereon, wherein the computer program implements the steps of any of the above methods when executed by a processor.

[0057] The data processing method, apparatus, device and storage medium provided by the embodiment of the present invention obtain a deregistration request; the deregistration request carries an identifier of a deregistered network element and five-tuple data; the identifier of the deregistered network element carried by the deregistration request is verified using the five-tuple data to obtain a verification result; when the verification result indicates that the identifier of the deregistered network element carried by the deregistration request passes the verification, the deregistration operation is performed. The technical solution provided by the embodiment of the present invention is adopted, and the five-tuple data carried by the deregistration request is used to verify the identifier of the deregistration network element carried by the deregistration request, thereby preventing attackers from tampering with or forging messages carried by deregistration requests initiated by legitimate network elements due to the core network not opening the TLS mechanism, thereby achieving security reinforcement and tamper-proofing of the deregistration process, and improving the security of the network element deregistration process. BRIEF DESCRIPTION OF THE DRAWINGS

[0058] Figure 1 This is a schematic diagram of the service process of deregistering a core network element in the related technology;

[0059] Figure 2 This is a schematic diagram of the format of the Uniform Resource Locator (URL) corresponding to the deregistration request initiated by the NF in the related art;

[0060] Figure 3 This is a schematic diagram of the implementation process of the deregistration process in the related technology;

[0061] Figure 4 This is a schematic diagram of the implementation process of the data processing method of the embodiment of the present invention Figure 1 ;

[0062] Figure 5 This is a schematic diagram of the implementation process of the data processing method of the embodiment of the present invention Figure 2 ;

[0063] Figure 6 This is a schematic diagram of the specific implementation process of the data processing method of the embodiment of the present invention. Figure 1 ;

[0064] Figure 7 The specific structure of the data processing device of the embodiment of the present invention is shown in FIG. Figure 2 ;

[0065] Figure 8 This is a schematic diagram of the structure of the data processing device according to an embodiment of the present invention. Figure 1 ;

[0066] Figure 9 This is a schematic diagram of the structure of the data processing device according to an embodiment of the present invention. Figure 2 ;

[0067] Figure 10is a schematic diagram of the composition structure of the first network element according to an embodiment of the present invention;

[0068] Figure 11 It is a schematic diagram of the composition structure of the second network element in an embodiment of the present invention. DETAILED DESCRIPTION

[0069] Before introducing the technical solutions of the embodiments of the present invention, the relevant technologies are first described.

[0070] In related technologies, the sinking of 5G network element equipment will greatly increase the security risk of network attacks and directly affect the security of the entire core network. For example: in edge computing scenarios, nodes will be sunk to the edge of the core network, and user plane function (UPF, UserPlane Function) equipment will be deployed on the user side; in vertical industry applications, some core network network element equipment will be sunk to the park and managed by the industry itself. This reduces the operator's ability to control the edge / sunk network and increases the possibility of illegal attacks.

[0071] Traditional network architectures are all based on reference interfaces, which are characterized by communication between network elements through fixed reference interfaces. When there are no reference interfaces between network elements, direct communication between network elements is impossible.

[0072] 5G introduces a service-based architecture (SBA), which defines network element functions as microservices. This allows signaling messages between network elements to be transmitted in a service-based manner. Therefore, if TLS authentication is not enabled in the core network, attackers could potentially act as middlemen, obtain data sent from edge / downstream networks, and exploit service-based open interfaces to bypass the registered business processes of core network elements, forcing legitimate core network elements offline and causing network paralysis.

[0073] Figure 1 This is a diagram of the business process of core network element registration in related technologies, such as Figure 1 As shown, the deregistration process may specifically include:

[0074] Step 1: The NF client (consumer) sends an Nnrf_NFManagement_NFDeregister request to the NF Repository Function (NRF), instructing the NRF to perform the deregistration operation.

[0075] Step 2: NRF marks the NF consumer as unavailable and deletes the NF’s data according to the corresponding policy;

[0076] Step 3: NRF returns the relevant information for NF consumer to register.

[0077] Figure 2 This is a schematic diagram of the URL format corresponding to the registration request initiated by NF in the related art, such as Figure 2 As shown in the figure, the URL for the NE to initiate a deregistration request is: http: / / {nrf_IP} / nnrf-nfm / v1 / nf-instances / {NF Instance ID}, where the Method is DELETE.

[0078] Figure 3 This is a schematic diagram of the implementation process of the deregistration process in related technologies, such as Figure 3 As shown in the figure, by analyzing the current deregistration process, we know that initiating a deregistration request requires two prerequisites: the Internet Protocol (IP) address of the NRF and the identifier of the network element to be deregistered, namely the Instance ID. If an attacker has access to the sunken campus / edge network or the transmission network between it and the core network, both prerequisites can be met. The attacker can then act as a middleman, disguised as a legitimate network element, and initiate a deregistration request to the NRF for any network element, causing network service anomalies.

[0079] The deregistration process in related technologies has technical flaws, including: First, when TLS is not enabled in the core network, data packets are transmitted in plaintext under the transport layer encryption mechanism. This allows attackers to act as man-in-the-middle (MITM) and capture and intercept data packets, parsing the information within to perform tampering and replay attacks. Second, the NRF lacks a validation mechanism and does not perform further validation or restrictions on sensitive operations such as DELETE and PUT, directly responding to requests without performing DELETE validation. Third, the current security mechanism of the 5G service-oriented architecture uses the OAuth 2.0 framework at the application layer to ensure that only authorized NFs have access to the NF providing services. However, attackers can capture valid tokens and forge request data. In other words, the existing OAuth 2.0 authorization mechanism cannot completely address MITM attacks. Fourth, if the transport layer uses the TLS protocol to authenticate and protect information transmitted between network elements, it will increase operational and management costs, increase service complexity, and reduce communication efficiency. Network service providers may choose not to enable and use TLS security mechanisms.

[0080] Based on this, in an embodiment of the present invention, a deregistration request is obtained; the deregistration request carries an identifier of the deregistering network element and five-tuple data; the identifier of the deregistration network element carried by the deregistration request is verified using the five-tuple data to obtain a verification result; when the verification result indicates that the identifier of the deregistration network element carried by the deregistration request passes the verification, the deregistration operation is performed.

[0081] Figure 4Schematic diagram of the implementation flow of the data processing method according to an embodiment of the present invention, which is applied to a first network element, such as Figure 4 As shown, the method includes steps 401 to 403:

[0082] Step 401: Obtain a deregistration request; the deregistration request carries an identifier of a deregistering network element and five-tuple data.

[0083] It can be understood that the network element that initiates the deregistration request may be the second network element.

[0084] That is, the first network element obtains the deregistration request sent by the second network element.

[0085] It is understandable that when the TLS transport layer encryption mechanism is not enabled in the core network, since the data packets are transmitted in plain text, the attacker can act as a middleman to capture and intercept the data packets, parse the information in the data packets, and modify the parsed information before initiating a deregistration request. In this way, in order to avoid the problem of network element paralysis caused by the failure to verify the deregistration request initiated by the attacker in the related technology, the deregistration request obtained by the first network element may carry not only the identifier of the deregistering network element, but also five-tuple data; the five-tuple data is used to verify the identifier of the deregistering network element.

[0086] It is understandable that the five-tuple data includes:

[0087] The identifier of the second network element that initiates the deregistration request;

[0088] To register the network element's identifier;

[0089] Random numbers;

[0090] First check value;

[0091] Second check value.

[0092] It should be noted that if the second network element that initiates the deregistration request is a legitimate network element, the process of the second network element generating the five-tuple data includes:

[0093] Determining an identifier of the second network element that initiated the deregistration request and an identifier of the deregistering network element;

[0094] generating the random number;

[0095] Encrypting the generated random number to obtain the first verification value;

[0096] encrypting the identifier of the second network element and the identifier of the deregistering network element to obtain the second verification value;

[0097] Based on the identifier of the second network element, the identifier of the deregistration network element, the random number, the first check value and the second check value, the five-tuple data carried by the deregistration request is obtained.

[0098] It should be noted that if the second network element initiating the deregistration request is an attacker, the process of the attacker generating the five-tuple data includes:

[0099] Obtaining the five-tuple data carried in the deregistration request initiated by the third network element;

[0100] Modify the parameter values ​​in the obtained quintuple data;

[0101] Based on the modified parameter value, the five-tuple data carried in the deregistration request is obtained.

[0102] Wherein, the third network element is a legal network element.

[0103] Step 402: Using the five-tuple data, verify the identifier of the deregistering network element carried in the deregistration request to obtain a verification result.

[0104] In the first case, based on the identifier of the deregistering network element carried in the deregistration request and the identifier of the deregistering network element in the quintuple data, it is detected whether the second network element that initiates the deregistration request is a legitimate network element.

[0105] In actual application, when the TLS transport layer encryption mechanism is not enabled in the core network, since the data packets are transmitted in plain text, an attacker can act as a middleman to capture and intercept the data packets sent by the legitimate network element, parse the information in the data packets, and modify the parsed information before initiating a deregistration request. Considering that the attacker may modify the identifier of the deregistering network element in the data packet while not modifying other information, it is possible to detect whether the second network element initiating the deregistration request is a legitimate network element based on the identifier of the deregistering network element carried in the deregistration request and the identifier of the deregistering network element in the five-tuple data.

[0106] Based on this, in one embodiment, the verifying the identifier of the deregistering network element carried in the deregistration request by using the quintuple data includes:

[0107] Comparing the identifier of the deregistering network element carried in the deregistration request with the identifier of the deregistering network element in the quintuple data to obtain a first comparison result;

[0108] Based on the first comparison result, the identifier of the deregistering network element carried in the deregistration request is verified.

[0109] It can be understood that when the first comparison result indicates that the identifier of the deregistration network element carried by the deregistration request is different from the identifier of the deregistration network element in the quintuple data, it indicates that the second network element that initiates the deregistration request is not a legitimate network element, and the second network element has modified one of the following:

[0110] The identifier of the deregistering network element carried in the intercepted deregistration request initiated by other legitimate network elements;

[0111] The identifier of the deregistering network element in the five-tuple data carried in the intercepted deregistration request initiated by other legitimate network elements.

[0112] In the second case, based on the identifier of the deregistration network element carried in the deregistration request, the identifier of the deregistration network element in the five-tuple data, the identifier of the second network element that initiates the deregistration request and the first verification value, it is detected whether the second network element that initiates the deregistration request is a legal network element.

[0113] In actual application, when the TLS transport layer encryption mechanism is not enabled in the core network, since the data packets are transmitted in plain text, an attacker can act as a middleman to capture and intercept the data packets sent by the legitimate network element, parse the information in the data packets, and modify the parsed information before initiating a deregistration request. Considering that the attacker may modify at least one of the identifier of the second network element that initiated the registration request and the first check value in the data packet, while not modifying other information, in this way, based on the identifier of the deregistration network element carried in the deregistration request, the identifier of the deregistration network element in the five-tuple data, the identifier of the second network element that initiated the deregistration request, and the first check value, it is possible to detect whether the second network element that initiated the deregistration request is a legitimate network element.

[0114] Based on this, in one embodiment, verifying the identifier of the deregistering network element carried in the deregistration request based on the first comparison result includes:

[0115] When the first comparison result indicates that the identifier of the deregistration network element carried in the deregistration request is the same as the identifier of the deregistration network element in the quintuple data, generating first authentication data according to the identifier of the second network element that initiates the deregistration request and the identifier of the deregistration network element in the quintuple data;

[0116] Comparing the value corresponding to the first authentication data with the first check value in the quintuple data to obtain a second comparison result;

[0117] Based on the second comparison result, the identifier of the deregistering network element carried in the deregistration request is verified.

[0118] It can be understood that when the second comparison result indicates that the numerical value corresponding to the first authentication data is different from the first check value in the quintuple data, it indicates that the second network element that initiates the deregistration request is not a legitimate network element, and the second network element modifies at least one of the following quintuple data carried in the deregistration request initiated by the intercepted legitimate network element:

[0119] The identifier of the second network element that initiates the deregistration request;

[0120] First check value.

[0121] In the third case, based on the identifier of the deregistration network element carried in the deregistration request, the identifier of the deregistration network element in the five-tuple data, the identifier of the second network element that initiates the deregistration request, the random number, the first verification value and the second verification value, it is detected whether the second network element that initiates the deregistration request is a legal network element.

[0122] In actual application, when the TLS transport layer encryption mechanism is not enabled in the core network, since the data packets are transmitted in plain text, an attacker can act as a middleman to capture and intercept the data packets sent by the legitimate network element, parse the information in the data packets, and modify the parsed information before initiating a deregistration request. Considering that the attacker may modify at least one of the identifier and the first check value of the second network element while not modifying other information, it is possible to detect whether the second network element initiating the deregistration request is a legitimate network element based on the identifier of the deregistration network element carried in the deregistration request, the identifier of the deregistration network element in the five-tuple data, the identifier of the second network element initiating the deregistration request, and the first check value.

[0123] Based on this, in one embodiment, verifying the identifier of the deregistering network element carried in the deregistration request based on the second comparison result includes:

[0124] When the second comparison result indicates that the value corresponding to the first authentication data is the same as the first check value, generating second authentication data according to the random number in the quintuple data;

[0125] Comparing the value corresponding to the second authentication data with the second check value in the quintuple data to obtain a third comparison result;

[0126] Based on the third comparison result, the identifier of the deregistering network element carried in the deregistration request is verified.

[0127] It can be understood that when the third comparison result indicates that the numerical value corresponding to the second authentication data is different from the second check value in the quintuple data, it indicates that the second network element that initiates the deregistration request is not a legitimate network element, and at least one of the following quintuple data carried in the deregistration request initiated by the legitimate network element intercepted by the second network element has been modified:

[0128] Random numbers;

[0129] Second check value.

[0130] It should be noted that when the identifier of the deregistering network element in the quintuple data is the same as the identifier of the deregistering network element carried in the deregistration request and the numerical value corresponding to the first authentication data is the same as the first verification value in the quintuple data and the numerical value corresponding to the second authentication data is the same as the second verification value in the quintuple data, it indicates that the second network element initiating the deregistration request is a legal network element.

[0131] Step 403: When the verification result indicates that the identifier of the deregistering network element carried in the deregistration request passes the verification, the deregistration operation is performed.

[0132] It can be understood that when it is determined that the second network element initiating the deregistration request is a legitimate network element, it is determined that the identifier of the deregistration network element carried by the deregistration request passes the verification; otherwise, it is determined that the identifier of the deregistration network element carried by the deregistration request fails the verification.

[0133] Furthermore, when the verification result indicates that the identifier of the deregistration network element carried in the deregistration request passes the verification, the deregistration operation is performed, and first information is returned to the second network element that initiated the deregistration request; the first information indicates that the deregistration operation is successfully executed.

[0134] When the verification result indicates that the identifier of the deregistration network element carried in the deregistration request fails the verification, the deregistration operation is not performed, and first information is returned to the second network element that initiated the deregistration request; the first information indicates that the deregistration operation failed.

[0135] In actual application, when the transport layer encryption mechanism is not enabled in the core network, since the data packets are transmitted in plain text, an attacker can act as a middleman to capture and intercept the data packets sent by the legitimate network element, parse the information in the data packets, and use the parsed information to initiate multiple deregistration requests in succession. In this way, in order to achieve anti-replay, when the verification result indicates that the identifier of the deregistration network element carried by the deregistration request fails the verification, it can be detected whether the information carried by the two adjacent deregistration requests is exactly the same. If it is detected that the information carried by the two adjacent deregistration requests is exactly the same, then no response can be given to the second deregistration request.

[0136] Based on this, in one embodiment, when the verification result indicates that the identifier of the deregistering network element carried in the deregistration request fails verification, the method further includes:

[0137] Get the deregistration request again;

[0138] Check whether the identifier of the deregistration network element and the five-tuple data carried in two consecutive deregistration requests are the same;

[0139] If the identifier of the deregistration network element and the five-tuple data carried in two consecutive deregistration requests are the same, the deregistration request obtained again will not be responded to.

[0140] In the embodiment of the present invention, obtaining a deregistration request carrying the identifier of the deregistering network element and quintuple data has the following advantages:

[0141] (1) The five-tuple data carried in the deregistration request is used to verify the identifier of the deregistering network element carried in the deregistration request, so as to prevent the attacker from tampering with or forging the message carried in the deregistration request initiated by the legitimate network element due to the core network not opening the TLS mechanism, thereby achieving security reinforcement and tamper-proofing of the deregistration process and improving the security of the network element deregistration process.

[0142] (2) Compared with the implementation steps of the network element deregistration service process in the related art, no additional interaction steps of the network element deregistration service process are required.

[0143] Figure 5 Schematic diagram of the implementation flow of the data processing method according to an embodiment of the present invention, which is applied to the second network element, such as Figure 5 As shown, the method includes step 501:

[0144] Step 501: Send a deregistration request; the deregistration request carries the identifier of the deregistering network element and five-tuple data;

[0145] Among them, the five-tuple data is used for the first network element that obtains the deregistration request to verify the identifier of the deregistration network element and obtain a verification result; when the verification result indicates that the identifier of the deregistration network element carried by the deregistration request passes the verification, the deregistration operation is performed.

[0146] It should be noted that if the second network element that initiates the deregistration request is a legitimate network element, the process of the second network element generating the five-tuple data includes:

[0147] Determining an identifier of the second network element that initiated the deregistration request and an identifier of the deregistering network element;

[0148] Generate random numbers;

[0149] Encrypting the generated random number to obtain a first check value;

[0150] Encrypting the identifier of the second network element and the identifier of the deregistering network element to obtain a second verification value;

[0151] Based on the identifier of the second network element, the identifier of the deregistration network element, the random number, the first check value and the second check value, the five-tuple data carried by the deregistration request is obtained.

[0152] It should be noted that if the second network element initiating the deregistration request is an attacker, the process of the attacker generating the five-tuple data includes:

[0153] Obtaining the five-tuple data carried in the deregistration request initiated by the third network element;

[0154] Modify the parameter values ​​in the obtained quintuple data;

[0155] Based on the modified parameter value, the five-tuple data carried in the deregistration request is obtained.

[0156] Among them, the third network element is a legal network element.

[0157] It can be understood that the modification of the parameter value in the acquired quintuple data may refer to the modification of at least one of the five parameter values ​​in the acquired quintuple data.

[0158] It should be noted that, if the second network element that initiates the deregistration request is not a legitimate network element, the second network element may also modify the identifier of the deregistration network element carried in the deregistration request initiated by the third network element.

[0159] In actual applications, when the transport layer encryption mechanism is not enabled in the core network, since the data packets are transmitted in plain text, an attacker can act as a middleman to capture and intercept data packets sent by legitimate network elements, parse the information in the data packets, and use the parsed information to continuously initiate multiple deregistration requests.

[0160] Based on this, in one embodiment, the method further includes:

[0161] Send a deregistration request again; the deregistration request carries the identifier of the deregistering network element and the five-tuple data.

[0162] In the embodiment of the present invention, sending a deregistration request carrying the identifier of the deregistering network element and quintuple data has the following advantages:

[0163] (1) For a network element that obtains a deregistration request, the five-tuple data carried in the deregistration request can be used to verify the identifier of the deregistration network element carried in the deregistration request, thereby preventing an attacker from tampering with or forging the message carried in the deregistration request initiated by a legitimate network element due to the core network not opening the TLS mechanism. This implements security reinforcement and tamper-proofing of the deregistration process, thereby improving the security of the network element deregistration process.

[0164] (2) Compared with the implementation steps of the network element deregistration service process in the related art, no additional interaction steps of the network element deregistration service process are required.

[0165] The implementation process of the data processing method according to the embodiment of the present invention will be described in detail below with reference to specific embodiments.

[0166] Figure 6 This is a schematic diagram of a specific implementation flow of the data processing method according to an embodiment of the present invention. Figure 6 As shown, NRF corresponds to the first network element; NF corresponds to the second network element; the method includes steps 601 to 607:

[0167] Step 601: NF generates quintuple data.

[0168] It is understandable that before the NF initiates a deregistration request to the NRF, it generates five-tuple data.

[0169] It should be noted that if the NF initiating the deregistration request is a legitimate NE, the process of the NF generating the five-tuple data includes:

[0170] Determine the NF identity and the identity of the deregistered network element;

[0171] Generate random numbers;

[0172] Encrypting the generated random number to obtain a first check value;

[0173] Encrypting the identifier of the second network element and the identifier of the deregistering network element to obtain a second verification value;

[0174] Based on the identifier of the second network element, the identifier of the deregistration network element, the random number, the first check value and the second check value, the five-tuple data carried in the deregistration request is obtained.

[0175] The format of the quintuple data is as follows:

[0176] <srcNFID,delNFID,random,xCheck,yCheck>

[0177] in,

[0178] srcNFID is the ID of the NF that actually initiates the deregistration request;

[0179] delNFID is the ID of the deregistered NE and is consistent with the ID of the deregistered NE in the URL corresponding to the deregistration request, namely, nfInstance ID;

[0180] Random is a random number generated by NF each time it initiates a deregistration request;

[0181] yCheck is the first check value obtained by encrypting srcNFID and delNFID;

[0182] xCheck is the second check value obtained by encrypting the random number.

[0183] It can be understood that first, srcNFID and delNFID are transformed by the fsrc(x) and fdel(x) functions respectively to obtain the transformation results; then, the obtained transformation results are respectively subjected to MD5 operation to obtain two operation results; finally, the two operation results are spliced ​​together and then symmetric encryption operation is performed by the fy(x) function to obtain the first check value, i.e. yCheck. As shown in formula (1):

[0184] yCheck=fy(md5(fsrc(srcNFID))+md5(fdel(delNFID))) (1)

[0185] in,

[0186] The fsrc(x) function is used to operate on the parameter x, specifically: fsrc(x) = x + 1;

[0187] The fdel(x) function is used to operate on the parameter x, specifically: fdel(x) = x-1;

[0188] The md5(x) function is used to perform an MD5 operation on the parameter x. MD5 is a public information digest algorithm that generates a 128-bit hash value through a cryptographic hash function to prevent data tampering.

[0189] The fy(x) function is used to perform a symmetric encryption operation on the parameter x using the Advanced Encryption Standard (AES) symmetric encryption algorithm with a preconfigured key to obtain ciphertext data.

[0190] It can be understood that the second check value xCheck is obtained by operating the random number random using the symmetric encryption function fx(x), as shown in formula (2):

[0191] xCheck=fx(random) (2)

[0192] The fx(x) function is used to perform symmetric encryption operation on the parameter x using the AES symmetric encryption algorithm to obtain ciphertext data.

[0193] It should be noted that if the NF initiating the deregistration request is not a valid NE, the process of the NF generating the five-tuple data includes:

[0194] Obtaining the five-tuple data carried in the deregistration request initiated by the third network element;

[0195] Modify the parameter values ​​in the obtained quintuple data;

[0196] Based on the modified parameter value, the five-tuple data carried in the deregistration request is obtained.

[0197] Among them, the third network element is a legal network element.

[0198] It can be understood that the modification of the parameter value in the acquired quintuple data may refer to the modification of at least one of the five parameter values ​​in the acquired quintuple data.

[0199] It should be noted that, if the NF initiating the deregistration request is not a legitimate network element, the NF may also modify the identifier of the deregistration network element carried in the deregistration request initiated by the third network element.

[0200] Step 602: The NF sends a deregistration request to the NRF; the deregistration request carries the identifier of the deregistered network element and five-tuple data.

[0201] It is understandable that the URL corresponding to the registration request is as follows:

[0202] http: / / [nrf_IP] / nnrf-nfm / v1 / nf-instances / [nfInstance ID],

[0203] Among them, the HYYP request contains the following four parts:

[0204] Uniform Resource Identifier: URI

[0205] Request method: Method is DELETE,

[0206] Request headers: Headers

[0207] Request body: The body carries five-tuple data.

[0208] Step 603: The NRF receives the deregistration request sent by the NF.

[0209] It is understandable that the NRF saves the identifier of the deregistered network element in the URL corresponding to the deregistration request, ie, the nfInstanceID parameter, and the five-tuple data.

[0210] Step 604: NRF verifies whether the identifier of the deregistered network element carried in the deregistration request is consistent with the identifier of the deregistered network element in the five-tuple data to complete the preliminary verification; if the identifier of the deregistered network element carried in the deregistration request is the same as the identifier of the deregistered network element in the five-tuple data, execute step 605; otherwise, do not perform the deregistration operation.

[0211] It can be understood that NRF can verify whether the quintuple data is compliant, that is, whether the quintuple data contains empty attribute values. If the quintuple data contains empty attribute values, the deregistration request is discarded; if the quintuple data does not contain empty attribute values, the quintuple data is verified to be compliant.

[0212] It is understandable that if the verification quintuple data is compliant, the NRF verifies whether the identifier of the deregistered network element carried in the deregistration request, ie, nfInstance ID, is consistent with the identifier of the deregistered network element in the quintuple data, ie, delNFID.

[0213] If the NRF verifies that the identifier of the deregistered NE carried in the deregistration request, i.e., nfInstance ID, is inconsistent with the identifier of the deregistered NE in the quintuple data, i.e., delNFID, it indicates that the NF initiating the deregistration request is not a valid NE and that the NF has modified one of the following:

[0214] The identifier of the deregistering network element carried in the intercepted deregistration request initiated by other legitimate network elements;

[0215] The identifier of the deregistering network element in the five-tuple data carried in the intercepted deregistration request initiated by other legitimate network elements is modified.

[0216] Step 605: NRF generates first authentication data and verifies whether the value corresponding to the first authentication data is consistent with the first verification value in the five-tuple data; if the value corresponding to the first authentication data is the same as the first verification value in the five-tuple data, execute step 606; otherwise, do not perform the deregistration operation.

[0217] It can be understood that, first, srcNFID and delNFID are transformed by fsrc(x) and fdel(x) functions respectively to obtain transformation results; then, MD5 operation is performed on the obtained transformation results respectively to obtain two operation results; finally, the two operation results are spliced ​​and then symmetric encryption operation is performed by fy(x) function to obtain the first authentication data, namely Checky, as shown in formula (3):

[0218] Checky=fy(md5(fsrc(srcNFID))+md5(fdel(delNFID))) (3)

[0219] When the NRF verifies that the value corresponding to the first authentication data is inconsistent with the first verification value in the five-tuple data, it indicates that the NF network element that initiated the deregistration request is not a legitimate network element, and the NF has modified at least one of the following in the five-tuple data carried in the deregistration request initiated by the legitimate network element:

[0220] The identifier of the NF that initiated the deregistration request;

[0221] First check value.

[0222] Step 606: The NRF generates second authentication data and verifies whether the value corresponding to the second authentication data is consistent with the second verification value in the five-tuple data; if the value corresponding to the second authentication data is the same as the second verification value in the five-tuple data, execute step 607; otherwise, do not perform the deregistration operation.

[0223] It is understandable that the second authentication data, Checkx, is generated based on the random number in the stored five-tuple data, namely random. Specifically, Checkx is obtained by operating random with the symmetric encryption function fx(x), as shown in formula (4):

[0224] Checkx=fx(random) (4)

[0225] When the NRF verifies that the value corresponding to the second authentication data is different from the second verification value in the five-tuple data, it indicates that the NF initiating the deregistration request is not a legitimate network element, and the NF has modified at least one of the following in the five-tuple data carried in the deregistration request initiated by the legitimate network element:

[0226] Random numbers;

[0227] Second check value.

[0228] It should be noted that when the identifier of the deregistering network element in the quintuple data is the same as the identifier of the deregistering network element carried by the deregistration request and the numerical value corresponding to the first authentication data is the same as the first verification value in the quintuple data and the numerical value corresponding to the second authentication data is the same as the second verification value in the quintuple data, it indicates that the NF initiating the deregistration request is a legitimate network element.

[0229] Step 607: After determining that the deregistration identifier carried in the deregistration request passes the verification, the NRF performs the deregistration operation and returns the first information to the NF.

[0230] It is understandable that after determining that the deregistration identifier carried in the deregistration request passes the verification, the NRF performs the deregistration operation and returns the first information to the NF; the first information may indicate that the NF deregistration operation is successfully executed.

[0231] It should be noted that, after determining that the deregistration identifier carried in the deregistration request fails to pass the verification, the NRF does not perform the deregistration operation and returns the first information to the NF; the first information may indicate that the NF deregistration operation has failed.

[0232] Figure 7 This is a schematic diagram of a specific implementation flow of the data processing method according to an embodiment of the present invention. Figure 7 As shown, NRF corresponds to the first network element; NF corresponds to the second network element; the method includes steps 701 to 706:

[0233] Step 701: The NRF receives a deregistration request sent by the NF; the deregistration request carries the identifier of the deregistered network element and five-tuple data;

[0234] Step 702: The NRF uses the five-tuple data to verify the identifier of the deregistering network element carried in the deregistration request to obtain a verification result.

[0235] Step 703: When the verification result indicates that the identifier of the deregistering network element carried in the deregistration request fails the verification, the deregistration operation is not performed.

[0236] Step 704: The NRF receives the deregistration request sent again by the NF.

[0237] Step 705: The NRF detects whether the identifier of the deregistration network element and the five-tuple data carried in the two adjacent deregistration requests are the same; if the identifier of the deregistration network element and the five-tuple data carried in the two adjacent deregistration requests are the same, execute step 706.

[0238] Step 706: Do not respond to the deregistration request received again.

[0239] In this example, checking whether the identifier of the deregistration network element and the five-tuple data carried in two consecutive deregistration requests are the same has the following advantages:

[0240] (1) In a scenario where multiple deregistration requests are initiated consecutively, the identifier of the deregistration network element carried in the deregistration request is verified using the five-tuple data carried in the deregistration request.

[0241] (2) In the scenario where multiple deregistration requests are initiated consecutively, if the identifier of the deregistration network element carried in the first deregistration request fails to pass the verification, the replayed deregistration request will no longer be responded to. This prevents attackers from replaying the messages carried in the deregistration requests initiated by legitimate network elements due to the core network not opening the TLS mechanism, thereby achieving security reinforcement and anti-replay of the deregistration process.

[0242] In order to implement the data processing method of the embodiment of the present invention, the embodiment of the present invention also provides a data processing device. Figure 8 FIG. 1 is a schematic diagram of the structure of a data processing device according to an embodiment of the present invention. Figure 8 As shown, the device includes:

[0243] The acquiring unit 81 is configured to acquire a deregistration request, wherein the deregistration request carries an identifier of a deregistering network element and five-tuple data;

[0244] The processing unit 82 is used to use the five-tuple data to verify the identifier of the deregistering network element carried by the deregistration request to obtain a verification result; when the verification result indicates that the identifier of the deregistering network element carried by the deregistration request passes the verification, perform the deregistration operation.

[0245] In one embodiment, the five-tuple data includes:

[0246] The identifier of the second network element that initiates the deregistration request;

[0247] To register the network element's identifier;

[0248] Random numbers;

[0249] First check value;

[0250] Second check value;

[0251] Accordingly, the processing unit 82 is specifically configured to:

[0252] Comparing the identifier of the deregistering network element carried in the deregistration request with the identifier of the deregistering network element in the quintuple data to obtain a first comparison result;

[0253] Based on the first comparison result, the identifier of the deregistering network element carried in the deregistration request is verified.

[0254] In one embodiment, the processing unit 82 is specifically configured to:

[0255] When the first comparison result indicates that the identifier of the deregistration network element carried in the deregistration request is the same as the identifier of the deregistration network element in the quintuple data, generating first authentication data according to the identifier of the second network element that initiates the deregistration request and the identifier of the deregistration network element in the quintuple data;

[0256] Comparing the value corresponding to the first authentication data with the first check value in the quintuple data to obtain a second comparison result;

[0257] Based on the second comparison result, the identifier of the deregistering network element carried in the deregistration request is verified.

[0258] In one embodiment, the processing unit 82 is specifically configured to:

[0259] When the second comparison result indicates that the value corresponding to the first authentication data is the same as the first check value, generating second authentication data according to the random number in the quintuple data;

[0260] Comparing the value corresponding to the second authentication data with the second check value in the quintuple data to obtain a third comparison result;

[0261] Based on the third comparison result, the identifier of the deregistering network element carried in the deregistration request is verified.

[0262] In actual application, the acquisition unit 81 can be implemented by a communication interface in a data processing device; the processing unit 82 can be implemented by a processor in the data processing device.

[0263] It should be noted that the data processing device provided in the above embodiments is illustrated only by the division of the aforementioned program modules when performing data processing. In actual applications, the aforementioned processing can be assigned to different program modules as needed, that is, the internal structure of the device can be divided into different program modules to complete all or part of the aforementioned processing. In addition, the data processing device provided in the above embodiments and the data processing method embodiment are based on the same concept. The specific implementation process is detailed in the method embodiment and will not be repeated here.

[0264] In order to implement the data processing method of the embodiment of the present invention, the embodiment of the present invention also provides a data processing device. Figure 9 FIG. 1 is a schematic diagram of the structure of a data processing device according to an embodiment of the present invention. Figure 9 As shown, the device includes:

[0265] The sending unit 91 is configured to send a deregistration request; the deregistration request carries an identifier of a deregistering network element and five-tuple data;

[0266] Among them, the five-tuple data is used for the first network element that obtains the deregistration request to verify the identifier of the deregistration network element and obtain a verification result; when the verification result indicates that the identifier of the deregistration network element carried by the deregistration request passes the verification, the deregistration operation is performed.

[0267] In one embodiment, the apparatus further comprises: a generating unit,

[0268] The generating unit is configured to:

[0269] Determining an identifier of the second network element that initiated the deregistration request and an identifier of the deregistering network element;

[0270] Generate random numbers;

[0271] Encrypting the generated random number to obtain a first check value;

[0272] Encrypting the identifier of the second network element and the identifier of the deregistering network element to obtain a second verification value;

[0273] Based on the identifier of the second network element, the identifier of the deregistration network element, the random number, the first check value and the second check value, the five-tuple data carried by the deregistration request is obtained.

[0274] In one embodiment, the generating unit is further configured to:

[0275] Obtaining the five-tuple data carried in the deregistration request initiated by the third network element;

[0276] Modify the parameter values ​​in the obtained quintuple data;

[0277] Based on the modified parameter value, the five-tuple data carried in the deregistration request is obtained.

[0278] In actual application, the generating unit 91 can be implemented by a communication interface in a data processing device; the generating unit can be implemented by a processor in a data processing device.

[0279] It should be noted that the data processing device provided in the above embodiments is illustrated only by the division of the aforementioned program modules when performing data processing. In actual applications, the aforementioned processing can be assigned to different program modules as needed, that is, the internal structure of the device can be divided into different program modules to complete all or part of the aforementioned processing. In addition, the data processing device provided in the above embodiments and the data processing method embodiment are based on the same concept. The specific implementation process is detailed in the method embodiment and will not be repeated here.

[0280] The embodiment of the present invention further provides a first network element, such as Figure 10 Shown, including:

[0281] The first communication interface 101 is capable of exchanging information with other devices;

[0282] The first processor 103 is connected to the first communication interface 101 and is configured to execute the method provided by one or more technical solutions of the second network element side when running a computer program. The computer program is stored in the first memory 103 .

[0283] It should be noted that the specific processing procedures of the first processor 103 and the first communication interface 101 are detailed in the method embodiment and will not be repeated here.

[0284] Of course, in actual application, the various components in the first network element 100 are coupled together through the bus system 104. It can be understood that the bus system 104 is used to realize the connection and communication between these components. In addition to the data bus, the bus system 104 also includes a power bus, a control bus, and a status signal bus. However, for the sake of clarity, Figure 10 Various buses are labeled as bus system 104 .

[0285] The first memory 103 in the embodiment of the present application is used to store various types of data to support the operation of the first network element 100. Examples of such data include: any computer program used to operate on the first network element 100.

[0286] The methods disclosed in the above embodiments of the present application can be applied to the first processor 103 or implemented by the first processor 103. The first processor 103 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by hardware integrated logic circuits or software instructions in the first processor 103. The above first processor 103 may be a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The first processor 103 can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of the present application can be directly implemented as being executed by a hardware decoding processor, or can be executed by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium located in the first memory 103. The first processor 103 reads the information in the first memory 103 and completes the steps of the above method in combination with its hardware.

[0287] The embodiment of the present invention further provides a second network element, such as Figure 11 Shown, including:

[0288] The second communication interface 111 is capable of exchanging information with other devices;

[0289] The second processor 112 is connected to the second communication interface 111 and is configured to execute the method provided by one or more technical solutions of the first network element side when running a computer program. The computer program is stored in the second memory 113.

[0290] It should be noted that the specific processing procedures of the second processor 112 and the second communication interface 111 are detailed in the method embodiment and will not be repeated here.

[0291] Of course, in actual application, the various components in the second network element 110 are coupled together through the bus system 114. It can be understood that the bus system 114 is used to realize the connection and communication between these components. In addition to the data bus, the bus system 114 also includes a power bus, a control bus, and a status signal bus. However, for the sake of clarity, Figure 11 Various buses are labeled as bus system 114 .

[0292] The second memory 113 in the embodiment of the present application is used to store various types of data to support the operation of the second network element 110. Examples of such data include: any computer program used to operate on the second network element 110.

[0293] The methods disclosed in the above embodiments of the present application can be applied to the second processor 112 or implemented by the second processor 112. The second processor 112 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by the hardware integrated logic circuit or software instructions in the second processor 112. The above second processor 112 may be a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The second processor 112 can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of the present application can be directly implemented as being executed by a hardware decoding processor, or can be executed by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium located in the second memory 113. The second processor 112 reads the information in the second memory 113 and completes the steps of the above method in combination with its hardware.

[0294] In an exemplary embodiment, the first network element 100 and the second network element 110 can be implemented by one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), general-purpose processors, controllers, microcontrollers (MCUs), microprocessors, or other electronic components to execute the aforementioned method.

[0295] It can be understood that the memory (first memory 103, second memory 113) of the embodiment of the present application can be a volatile memory or a non-volatile memory, and can also include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a magnetic random access memory (FRAM), a flash memory, a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM); the magnetic surface memory can be a magnetic disk memory or a tape memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static random access memory (SRAM), synchronous static random access memory (SSRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct rambus random access memory (DRRAM).The memories described in the embodiments of this application are intended to include, but are not limited to, these and any other suitable types of memories.

[0296] In an exemplary embodiment, the present invention further provides a storage medium, namely, a computer storage medium, specifically, a computer-readable storage medium, such as a memory storing a computer program. The computer program can be executed by the first processor 103 of the first network element 100 to complete the steps of the aforementioned first network element-side method. The computer-readable storage medium can be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface storage, optical disk, or CD-ROM.

[0297] It should be noted that: "first", "second", etc. are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.

[0298] In addition, the technical solutions described in the embodiments of the present invention can be arbitrarily combined without conflict.

[0299] The above description is merely a preferred embodiment of the present invention and is not intended to limit the scope of protection of the present invention.

Claims

1. A data processing method, characterized in that: Applied to a first network element, the method includes: Obtaining a deregistration request; the deregistration request carries an identifier of the deregistering network element and five-tuple data; wherein the five-tuple data includes: an identifier of the second network element initiating the deregistration request; an identifier of the deregistering network element; a random number; a first check value; and a second check value; Utilize the five-tuple data to verify the identifier of the deregistration network element carried by the deregistration request to obtain a verification result; wherein, the identifier of the deregistration network element carried by the deregistration request is compared with the identifier of the deregistration network element in the five-tuple data to obtain a first comparison result; when the first comparison result indicates that the identifier of the deregistration network element carried by the deregistration request is the same as the identifier of the deregistration network element in the five-tuple data, generate first authentication data according to the identifier of the second network element that initiates the deregistration request and the identifier of the deregistration network element in the five-tuple data; compare the numerical value corresponding to the first authentication data with the first verification value in the five-tuple data to obtain a second comparison result; when the second comparison result indicates that the numerical value corresponding to the first authentication data is the same as the first verification value, generate a random number according to the five-tuple data. into second authentication data; compare the value corresponding to the second authentication data with the second check value in the five-tuple data to obtain a third comparison result; based on the third comparison result, verify the identifier of the deregistration network element carried by the deregistration request; wherein, when it is determined that the second network element initiating the deregistration request is a legitimate network element, it is determined that the identifier of the deregistration network element carried by the deregistration request passes the verification; otherwise, it is determined that the identifier of the deregistration network element carried by the deregistration request fails the verification; when the identifier of the deregistration network element in the five-tuple data is the same as the identifier of the deregistration network element carried by the deregistration request and the value corresponding to the first authentication data is the same as the first check value in the five-tuple data and the value corresponding to the second authentication data is the same as the second check value in the five-tuple data, the second network element initiating the deregistration request is characterized as a legitimate network element; When the verification result indicates that the identifier of the deregistering network element carried in the deregistration request passes the verification, the deregistration operation is performed.

2. A data processing method, characterized in that: Applied to a second network element, the method includes: Sending a deregistration request; the deregistration request carries an identifier of the deregistering network element and five-tuple data; The five-tuple data is used for the first network element that obtains the deregistration request to verify the identifier of the deregistration network element to obtain a verification result; when the verification result indicates that the identifier of the deregistration network element carried by the deregistration request passes the verification, the deregistration operation is performed; The five-tuple data includes: the identifier of the second network element that initiates the deregistration request; the identifier of the deregistering network element; a random number; a first check value; a second check value; the five-tuple data is used for the first network element that obtains the deregistration request to verify the identifier of the deregistering network element, and when the verification result is obtained, the first network element compares the identifier of the deregistering network element carried by the deregistration request with the identifier of the deregistering network element in the five-tuple data to obtain a first comparison result; when the first comparison result indicates that the identifier of the deregistering network element carried by the deregistration request is the same as the identifier of the deregistering network element in the five-tuple data, the five-tuple data is used by the first network element to generate first authentication data according to the identifier of the second network element that initiates the deregistration request and the identifier of the deregistering network element in the five-tuple data; compare the numerical value corresponding to the first authentication data with the first check value in the five-tuple data to obtain a second comparison result; when the second comparison result indicates that the numerical value corresponding to the first authentication data is the same as the first check value When the numerical value is the same as the first verification value, the quintuple data is used by the first network element to generate second authentication data according to the random number in the quintuple data; the numerical value corresponding to the second authentication data is compared with the second verification value in the quintuple data to obtain a third comparison result; based on the third comparison result, the identifier of the deregistration network element carried by the deregistration request is verified; wherein, when it is determined that the second network element initiating the deregistration request is a legal network element, it is determined that the identifier of the deregistration network element carried by the deregistration request passes the verification; otherwise, it is determined that the identifier of the deregistration network element carried by the deregistration request fails the verification; when the identifier of the deregistration network element in the quintuple data is the same as the identifier of the deregistration network element carried by the deregistration request and the numerical value corresponding to the first authentication data is the same as the first verification value in the quintuple data and the numerical value corresponding to the second authentication data is the same as the second verification value in the quintuple data, the second network element initiating the deregistration request is characterized as a legal network element.

3. The method according to claim 2, characterized in that The method further comprises: Determining an identifier of the second network element that initiated the deregistration request and an identifier of the deregistering network element; Generate random numbers; Encrypting the generated random number to obtain a first check value; Encrypting the identifier of the second network element and the identifier of the deregistering network element to obtain a second verification value; Based on the identifier of the second network element, the identifier of the deregistration network element, the random number, the first check value and the second check value, the five-tuple data carried by the deregistration request is obtained.

4. The method according to claim 2, characterized in that The method further comprises: Obtaining the five-tuple data carried in the deregistration request initiated by the third network element; Modify the parameter values ​​in the obtained quintuple data; Based on the modified parameter value, the five-tuple data carried in the deregistration request is obtained.

5. A data processing device, characterized in that: include: An acquiring unit, used for acquiring a deregistration request; The deregistration request carries an identifier of the deregistering network element and five-tuple data; wherein the five-tuple data includes: an identifier of the second network element that initiates the deregistration request; an identifier of the deregistering network element; a random number; a first check value; and a second check value; A processing unit is used to use the five-tuple data to verify the identifier of the deregistration network element carried by the deregistration request to obtain a verification result; when the verification result indicates that the identifier of the deregistration network element carried by the deregistration request passes the verification, perform a deregistration operation; wherein, the processing unit uses the five-tuple data to verify the identifier of the deregistration network element carried by the deregistration request, including: comparing the identifier of the deregistration network element carried by the deregistration request with the identifier of the deregistration network element in the five-tuple data to obtain a first comparison result; when the first comparison result indicates that the identifier of the deregistration network element carried by the deregistration request is the same as the identifier of the deregistration network element in the five-tuple data, generate first authentication data according to the identifier of the second network element that initiates the deregistration request and the identifier of the deregistration network element in the five-tuple data; compare the numerical value corresponding to the first authentication data with the first verification value in the five-tuple data to obtain a second comparison result; when the second comparison result indicates that the identifier of the deregistration network element carried by the deregistration request is the same as the identifier of the deregistration network element in the five-tuple data, generate first authentication data according to the identifier of the second network element that initiates the deregistration request and the identifier of the deregistration network element When the result indicates that the numerical value corresponding to the first authentication data is the same as the first verification value, second authentication data is generated according to the random number in the quintuple data; the numerical value corresponding to the second authentication data is compared with the second verification value in the quintuple data to obtain a third comparison result; based on the third comparison result, the identifier of the deregistration network element carried by the deregistration request is verified; wherein, when it is determined that the second network element initiating the deregistration request is a legal network element, it is determined that the identifier of the deregistration network element carried by the deregistration request passes the verification; otherwise, it is determined that the identifier of the deregistration network element carried by the deregistration request fails the verification; when the identifier of the deregistration network element in the quintuple data is the same as the identifier of the deregistration network element carried by the deregistration request and the numerical value corresponding to the first authentication data is the same as the first verification value in the quintuple data and the numerical value corresponding to the second authentication data is the same as the second verification value in the quintuple data, the second network element initiating the deregistration request is characterized as a legal network element.

6. A data processing device, characterized in that: include: a sending unit, configured to send a deregistration request; The deregistration request carries the identifier of the deregistering network element and quintuple data; The five-tuple data is used for the first network element that obtains the deregistration request to verify the identifier of the deregistration network element to obtain a verification result; when the verification result indicates that the identifier of the deregistration network element carried by the deregistration request passes the verification, the deregistration operation is performed; The five-tuple data includes: the identifier of the second network element that initiates the deregistration request; the identifier of the deregistering network element; a random number; a first check value; a second check value; the five-tuple data is used for the first network element that obtains the deregistration request to verify the identifier of the deregistering network element, and when the verification result is obtained, the first network element compares the identifier of the deregistering network element carried by the deregistration request with the identifier of the deregistering network element in the five-tuple data to obtain a first comparison result; when the first comparison result indicates that the identifier of the deregistering network element carried by the deregistration request is the same as the identifier of the deregistering network element in the five-tuple data, the five-tuple data is used by the first network element to generate first authentication data according to the identifier of the second network element that initiates the deregistration request and the identifier of the deregistering network element in the five-tuple data; compare the numerical value corresponding to the first authentication data with the first check value in the five-tuple data to obtain a second comparison result; when the second comparison result indicates that the numerical value corresponding to the first authentication data is the same as the first check value When the numerical value is the same as the first verification value, the quintuple data is used by the first network element to generate second authentication data according to the random number in the quintuple data; the numerical value corresponding to the second authentication data is compared with the second verification value in the quintuple data to obtain a third comparison result; based on the third comparison result, the identifier of the deregistration network element carried by the deregistration request is verified; wherein, when it is determined that the second network element initiating the deregistration request is a legal network element, it is determined that the identifier of the deregistration network element carried by the deregistration request passes the verification; otherwise, it is determined that the identifier of the deregistration network element carried by the deregistration request fails the verification; when the identifier of the deregistration network element in the quintuple data is the same as the identifier of the deregistration network element carried by the deregistration request and the numerical value corresponding to the first authentication data is the same as the first verification value in the quintuple data and the numerical value corresponding to the second authentication data is the same as the second verification value in the quintuple data, the second network element initiating the deregistration request is characterized as a legal network element.

7. A first network element, characterized in that: include: A first communication interface, used to obtain a deregistration request; The deregistration request carries an identifier of the deregistering network element and five-tuple data; wherein the five-tuple data includes: an identifier of the second network element that initiates the deregistration request; an identifier of the deregistering network element; a random number; a first check value; and a second check value; The first processor is configured to use the five-tuple data to verify the identifier of the deregistration network element carried by the deregistration request to obtain a verification result; when the verification result indicates that the identifier of the deregistration network element carried by the deregistration request passes the verification, perform a deregistration operation; wherein, the first processor uses the five-tuple data to verify the identifier of the deregistration network element carried by the deregistration request, including: comparing the identifier of the deregistration network element carried by the deregistration request with the identifier of the deregistration network element in the five-tuple data to obtain a first comparison result; when the first comparison result indicates that the identifier of the deregistration network element carried by the deregistration request is the same as the identifier of the deregistration network element in the five-tuple data, generate first authentication data according to the identifier of the second network element that initiates the deregistration request and the identifier of the deregistration network element in the five-tuple data; compare the value corresponding to the first authentication data with the first verification value in the five-tuple data to obtain a second comparison result; when the second comparison result indicates that the identifier of the deregistration network element carried by the deregistration request is the same as the identifier of the deregistration network element in the five-tuple data, generate first authentication data; compare the value corresponding to the first authentication data with the first verification value in the five-tuple data to obtain a second comparison result; When the comparison result indicates that the numerical value corresponding to the first authentication data is the same as the first verification value, second authentication data is generated according to the random number in the quintuple data; the numerical value corresponding to the second authentication data is compared with the second verification value in the quintuple data to obtain a third comparison result; based on the third comparison result, the identifier of the deregistration network element carried by the deregistration request is verified; wherein, when it is determined that the second network element initiating the deregistration request is a legal network element, it is determined that the identifier of the deregistration network element carried by the deregistration request passes the verification; otherwise, it is determined that the identifier of the deregistration network element carried by the deregistration request fails the verification; when the identifier of the deregistration network element in the quintuple data is the same as the identifier of the deregistration network element carried by the deregistration request and the numerical value corresponding to the first authentication data is the same as the first verification value in the quintuple data and the numerical value corresponding to the second authentication data is the same as the second verification value in the quintuple data, the second network element initiating the deregistration request is characterized as a legal network element.

8. A second network element, characterized in that: include: Second processor, A second communication interface, used to send a deregistration request; The deregistration request carries the identifier of the deregistering network element and quintuple data; The five-tuple data is used for the first network element that obtains the deregistration request to verify the identifier of the deregistration network element to obtain a verification result; when the verification result indicates that the identifier of the deregistration network element carried by the deregistration request passes the verification, the deregistration operation is performed; The five-tuple data includes: the identifier of the second network element that initiates the deregistration request; the identifier of the deregistering network element; a random number; a first check value; a second check value; the five-tuple data is used for the first network element that obtains the deregistration request to verify the identifier of the deregistering network element, and when the verification result is obtained, the first network element compares the identifier of the deregistering network element carried by the deregistration request with the identifier of the deregistering network element in the five-tuple data to obtain a first comparison result; when the first comparison result indicates that the identifier of the deregistering network element carried by the deregistration request is the same as the identifier of the deregistering network element in the five-tuple data, the five-tuple data is used by the first network element to generate first authentication data according to the identifier of the second network element that initiates the deregistration request and the identifier of the deregistering network element in the five-tuple data; compare the numerical value corresponding to the first authentication data with the first check value in the five-tuple data to obtain a second comparison result; when the second comparison result indicates that the numerical value corresponding to the first authentication data is the same as the first check value When the numerical value is the same as the first verification value, the quintuple data is used by the first network element to generate second authentication data according to the random number in the quintuple data; the numerical value corresponding to the second authentication data is compared with the second verification value in the quintuple data to obtain a third comparison result; based on the third comparison result, the identifier of the deregistration network element carried by the deregistration request is verified; wherein, when it is determined that the second network element initiating the deregistration request is a legal network element, it is determined that the identifier of the deregistration network element carried by the deregistration request passes the verification; otherwise, it is determined that the identifier of the deregistration network element carried by the deregistration request fails the verification; when the identifier of the deregistration network element in the quintuple data is the same as the identifier of the deregistration network element carried by the deregistration request and the numerical value corresponding to the first authentication data is the same as the first verification value in the quintuple data and the numerical value corresponding to the second authentication data is the same as the second verification value in the quintuple data, the second network element initiating the deregistration request is characterized as a legal network element.

9. A first network element, characterized in that: comprising a first processor and a first memory for storing a computer program capable of being executed on the first processor, Wherein, when the first processor is used to run the computer program, it executes the steps of the method according to claim 1.

10. A second network element, characterized in that: comprising a second processor and a second memory for storing a computer program capable of being executed on the second processor, Wherein, when the second processor is used to run the computer program, it executes the steps of the method according to any one of claims 2 to 4.

11. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to claim 1 are implemented, or the steps of the method according to any one of claims 2 to 4 are implemented.

Citation Information

Patent Citations

  • A service unregistration method based on IP access

    CN101166134A

  • Verification method, data synchronization method and device, network element and medium

    CN112584380A