Topology hiding method, topology restoration method, device, medium and plmn
By encrypting the network topology information and combining it with key identification, the problems of topology information leakage and inter-device compatibility in existing technologies are solved. This achieves secure hiding and correct restoration of topology information, ensuring the stability and security of communication.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA UNITED NETWORK COMM GRP CO LTD
- Filing Date
- 2023-05-31
- Publication Date
- 2026-04-28
AI Technical Summary
In existing technologies, when SEPP devices implement topology hiding, the mapping table is easily leaked or the key is leaked, leading to the leakage of the real topology information of the network. Furthermore, when load sharing and disaster recovery are carried out among multiple SEPP devices, the topology hiding and restoration methods lack universality, resulting in communication failures.
The actual topology information of this network is encrypted using an encryption algorithm. After encryption, the topology information and key identifier are combined to form hidden topology information. The topology information is securely hidden within this network and correctly restored to other networks by using a preset key, ensuring that the key is not obtained by other networks.
It achieves secure hiding of the network topology information, prevents leakage of real topology information, and realizes universal topology hiding and restoration among multiple SEPP devices, avoiding communication failures and enhancing the networking stability of 5G SA network sharing and international roaming architecture.
Smart Images

Figure CN116633792B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of communication technology, and in particular to a topology hiding method, a topology restoration method, a topology hiding device, a topology restoration device, a computer-readable storage medium, and a Public Land Mobile Network (PLMN). Background Technology
[0002] Section 5.9.3.3 of 3GPP TS33.501 requires that SEPP perform topology hiding by limiting the internal topology information visible to external parties. This standard is implemented in 5G SA network sharing and international roaming architectures.
[0003] However, current standards and technologies do not specify a concrete implementation scheme for SEPP topology hiding.
[0004] Currently, the implementation solutions for topology hiding by various SEPP equipment manufacturers mainly involve pre-establishing a mapping table between the actual topology information and the hidden topology information of the network. Alternatively, topology hiding may be achieved through encryption algorithms. The mapping table is relatively fixed. If the mapping table is missing or leaked, it may lead to the leakage of the actual topology information of the network. Similarly, if the corresponding key for the encryption algorithm is leaked, it may also lead to the leakage of the actual topology information of the network. Summary of the Invention
[0005] The technical problem to be solved by the present invention is to address the above-mentioned shortcomings of the prior art by providing a topology hiding method, a topology restoration method, a topology hiding device, a topology restoration device, a computer-readable storage medium, and a Public Land Mobile Network (PLMN) to solve the problem that the prior art may lead to the leakage of the network's true topology information.
[0006] In a first aspect, the present invention provides a topology hiding method applied to the first Security Edge Protection Proxy (SEPP) network element of this network, and includes:
[0007] Obtain the actual topology information of this network from the first signaling message to be sent from this network to another network;
[0008] The real topology information of this network is encrypted using a preset first key to obtain the encrypted topology information of this network.
[0009] Combine the encrypted topology information of this network with the first key identifier SKID to obtain the hidden topology information of this network;
[0010] The hidden topology information of this network is used to replace the real topology information of this network in the first signaling to obtain the second signaling;
[0011] Send a second signaling message to a different network.
[0012] Optionally, obtain the actual topology information of this network from the first signaling message to be sent from this network to another network, specifically including:
[0013] Receive the first signaling message from the first network function NF element of this network to be sent to the NF element of another network, and obtain the real topology information of this network from the first signaling message.
[0014] Optionally, a second signaling message may be sent to a different network, specifically including:
[0015] The second signaling is sent to the SEPP network element of the other network, so that the SEPP network element of the other network sends the second signaling to the NF network element of the other network.
[0016] Optionally, before encrypting the actual network topology information using a preset first key, the method further includes:
[0017] Multiple identical keys and SKIDs are pre-configured on multiple SEPP network elements within the local network to enable disaster recovery or load sharing among multiple SEPP network elements.
[0018] Optionally, the actual network topology information is encrypted using a preset first key to obtain encrypted network topology information, specifically including:
[0019] Select the topology information to be hidden based on the actual topology information of this network;
[0020] Select a pre-configured first key;
[0021] The first key is used to encrypt the hidden topology information in order to obtain the encrypted topology information of this network.
[0022] Optionally, the topology information to be hidden can be selected based on the actual topology information of this network, specifically including:
[0023] If the format of the actual topology information of this website is a fully qualified domain name (FQDN), then the information in the actual topology information of this website other than the domain name of this website shall be used as the topology information to be hidden.
[0024] If the format of the actual network topology information is Internet Protocol (IP) address, the IP address, IP address and port number, IP address plus a second prefix, or IP address and port number plus a second prefix in the actual network topology information shall be used as the topology information to be hidden.
[0025] Optionally, the topology information to be hidden is encrypted using a first key to obtain the encrypted topology information of this network, specifically including:
[0026] Generate the initialization vector (IV) value for the encryption algorithm;
[0027] The hidden topology information is encrypted using a first key and IV value based on an encryption algorithm to obtain the encrypted topology information of this network in binary ciphertext form.
[0028] Optionally, the encrypted topology information of this network and the first key identifier SKID are combined to obtain the hidden topology information of this network, specifically including:
[0029] Convert the encrypted topology information of this network into a ciphertext string, and convert the IV value into an IV value string;
[0030] Obtain the first prefix, the first SKID, and the domain name of this website, respectively;
[0031] Combine the first prefix, the ciphertext string, the first SKID, the IV value string, and the domain name of this network to hide the network topology information.
[0032] Optionally, the first prefix, the ciphertext string, the first SKID, the IV value string, and the local domain name are combined to hide the network topology information, specifically including:
[0033] Combine the first prefix, the ciphertext string, the first SKID, the IV value string, and the local domain name, and separate each part using a domain name separator to form the local hidden topology information in FQDN format.
[0034] Secondly, the present invention provides a topology restoration method, applied to the Security Edge Protection Proxy (SEPP) network element of this network, and includes:
[0035] Receive a fourth signaling message from another network, wherein the fourth signaling message is sent by the other network after receiving the second signaling message sent by the first SEPP network element of this network according to the topology hiding method described above;
[0036] Obtain the encrypted topology information and the first SKID of the local network from the hidden topology information of the local network in the fourth signaling;
[0037] Obtain the preset first key based on the first SKID, and use the first key to decrypt the encrypted topology information of this network to obtain the real topology information of this network.
[0038] The hidden topology information of this network in the fourth signaling is replaced with the actual topology information of this network to obtain the fifth signaling;
[0039] Send the fifth signaling message on this network.
[0040] Optionally, receiving fourth signaling from another network, specifically including:
[0041] Receive the fourth signaling from the SEPP network element of the other network, wherein the fourth signaling is sent by the SEPP network element of the other network according to the third signaling from the NF network element of the other network, and the third signaling is sent by the NF network element of the other network according to the second signaling.
[0042] Optionally, a fifth signaling message may be sent on this network, specifically including:
[0043] The fifth signaling is sent to the second NF network element of this network, which is pointed to by the actual topology information of this network.
[0044] Optionally, the encrypted topology information and the first SKID of the local network are obtained from the local network hidden topology information of the fourth signaling, specifically including:
[0045] The hidden topology information of this network is obtained from the entire string between the first prefix and the domain name of this network obtained from the fourth signaling.
[0046] Based on the domain name separator, obtain the first prefix, ciphertext string, first SKID, IV value string, and domain name of this network from the hidden topology information of this network;
[0047] The ciphertext string is converted to ciphertext to obtain the encrypted topology information of this network, and the IV value string is converted to IV value.
[0048] Optionally, a preset first key is obtained based on the first SKID, and the first key is used to decrypt the encrypted topology information of this network to obtain the real topology information of this network, specifically including:
[0049] Query its own pre-set first key based on the first SKID;
[0050] The encrypted topology information of this network is decrypted using the first key and IV value based on the encryption algorithm to obtain the restored topology information.
[0051] The actual topology information of this network is obtained based on the restored topology information.
[0052] Thirdly, the present invention provides a topology hiding device, comprising:
[0053] The first acquisition module is used to acquire the actual topology information of the local network in the first signaling message to be sent from the local network to the other network.
[0054] The first encryption module is connected to the first acquisition module and is used to encrypt the real topology information of the network using a preset first key in order to obtain the encrypted topology information of the network.
[0055] The first combination module, connected to the first encryption module, is used to combine the encrypted topology information of this network and the first key identifier SKID to obtain the hidden topology information of this network.
[0056] The first replacement module, connected to the first combination module, is used to replace the real topology information of the local network in the first signaling with the hidden topology information of the local network to obtain the second signaling;
[0057] The first sending module, connected to the first replacement module, is used to send the second signaling to the other network.
[0058] Fourthly, the present invention provides a topology restoration apparatus, comprising:
[0059] The second receiving module is used to receive the fourth signaling from the other network, wherein the fourth signaling is sent by the other network according to the second signaling after receiving the second signaling sent by the first SEPP network element of this network according to the topology hiding method described above;
[0060] The second acquisition module, connected to the second receiving module, is used to acquire the encrypted topology information of the local network and the first SKID from the local network hidden topology information of the fourth signaling.
[0061] The second decryption module is connected to the second acquisition module and is used to obtain a preset first key based on the first SKID and use the first key to decrypt the encrypted topology information of this network in order to obtain the real topology information of this network.
[0062] The second replacement module, connected to the second decryption module, is used to replace the hidden topology information of the network in the fourth signaling with the real topology information of the network to obtain the fifth signaling.
[0063] The second sending module, connected to the second replacement module, is used to send the fifth signaling within this network.
[0064] Fifthly, the present invention provides a computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor, it implements the topology hiding method and / or the topology restoration method as described above.
[0065] In a sixth aspect, the present invention provides a Public Land Mobile Network (PLMN), including a Security Edge Protection Proxy (SEPP) network element, and connecting to other networks through the SEPP network element;
[0066] The SEPP network element of this network includes the first SEPP network element of this network, and the topology hiding method described above is implemented by the first SEPP network element of this network.
[0067] Optionally, the topology restoration method described above can be implemented by the first SEPP network element of this network; or,
[0068] The SEPP network element of this network also includes a second SEPP network element, which implements the topology restoration method described above.
[0069] This invention provides a topology hiding method, topology hiding device, computer-readable storage medium, and Public Land Mobile Network (PLMN). By using a preset key to encrypt the real topology information of the local network, and by adding a preset identifier corresponding to the encryption key to the hidden topology information of the local network, the signaling sent to other networks will not expose the real topology information of the local network, and the key information cannot be obtained by other networks. Thus, other networks cannot parse the real topology information of the local network, ensuring the security of the real topology information of the local network.
[0070] The present invention provides a topology restoration method, a topology restoration device, a computer-readable storage medium, and a Public Land Mobile Network (PLMN). By parsing the aforementioned hidden topology information, the true topology information of the original network can be correctly restored, thereby ensuring the implementation of subsequent communication processes with responses. Attached Figure Description
[0071] Figure 1 This is a diagram illustrating the location of SEPP in a network;
[0072] Figure 2 This is a schematic diagram of the topology hiding and restoration process;
[0073] Figure 3 This is a schematic diagram of a SEPP disaster recovery network;
[0074] Figure 4 This is a flowchart of a topology hiding method according to an embodiment of the present invention;
[0075] Figure 5 This is a flowchart of a topology restoration method according to an embodiment of the present invention;
[0076] Figure 6 This is a schematic diagram of the structure of a topology hiding device according to an embodiment of the present invention;
[0077] Figure 7 This is a schematic diagram of the structure of a topology reduction device according to an embodiment of the present invention. Detailed Implementation
[0078] To enable those skilled in the art to better understand the technical solution of the present invention, the embodiments of the present invention will be further described in detail below with reference to the accompanying drawings.
[0079] It is understood that the specific embodiments and accompanying drawings described herein are merely for explaining the invention and are not intended to limit the invention.
[0080] It is understood that, without conflict, the various embodiments and features in the embodiments of the present invention can be combined with each other.
[0081] It is understood that, for ease of description, only the parts related to the present invention are shown in the accompanying drawings, while the parts unrelated to the present invention are not shown in the drawings.
[0082] It is understood that each unit or module involved in the embodiments of the present invention may correspond to only one entity structure, or may be composed of multiple entity structures, or multiple units or modules may be integrated into one entity structure.
[0083] It is understood that, without conflict, the functions and steps marked in the flowcharts and block diagrams of this invention may occur in a different order than that marked in the accompanying drawings.
[0084] It is understood that the flowcharts and block diagrams of this invention illustrate the possible architecture, functions, and operations of systems, apparatuses, devices, and methods according to various embodiments of this invention. Each block in the flowchart or block diagram may represent a unit, module, program segment, or code, containing executable instructions for implementing the specified function. Furthermore, each block or combination of blocks in the block diagram and flowchart can be implemented using a hardware-based system to achieve the specified function, or using a combination of hardware and computer instructions.
[0085] It is understood that the units and modules involved in the embodiments of the present invention can be implemented by software or by hardware. For example, the units and modules can be located in a processor.
[0086] To facilitate understanding of this invention, the SEPP and topology hiding and restoration of this application will be introduced first.
[0087] In the 5G (5th Generation Mobile Communication Technology) SA (Standalone) network sharing and international roaming architecture, the position of SEPP (Security Edge Protection Proxy) in the network is as follows: Figure 1As shown, hPLMN (HomePLMN) represents the home network, and vPLMN (Visited PLMN) represents the visited network. Each PLMN (Public Land Mobile Network) has its own SEPP (Secure and Restore Programmable Provider) to hide and restore the topology information of its own NFs (Network Functions). Specifically, hSEPP in hPLMN hides and restores the topology information of hNFs, and vSEPP in vPLMN hides and restores the topology information of vNFs. It should be noted that while hiding topology information is usually performed by the SEPP, restoring the hidden information can be done outside the SEPP, by the NFs themselves according to other principles. This restoration method is not the technical solution discussed in this application, but it illustrates that the SEPP can separate the hiding and restoration actions. Another scenario is that within the same operator's network, if multiple SEPPs are used for disaster recovery and load sharing, the SEPPs that perform topology information hiding and restoration may not be the same. This is one of the technical contents to be discussed in this application and will be elaborated in detail later.
[0088] The hiding and restoration of topology information occurs during NF communication across PLMNs, such as... Figure 2 As shown, when a local NF (Network Function) interacts with another PLMN (Plane Network Name) via SEPP (Search Engine Provider Protocol), SEPP performs topology hiding on outgoing signaling and topology restoration on returning signaling. Specifically, to prevent the peer PLMN from obtaining the local NF's topology information based on FQDN (Fully Qualified Domain Name) information or other important network information (such as IP (Internet Protocol) addresses and port information), SEPP needs to perform topology hiding on the local NF's FQDN or other important network information in all messages sent to the other PLMN. All local NFs' FQDN information or other important network information is replaced with the hidden FQDN based on SEPP's local configuration when passing through SEPP, preventing the peer PLMN from obtaining the local PLMN's topology information based on the FQDN or other important network information. Simultaneously, when a message returns, the hidden FQDN needs to be replaced back with the original FQDN or other important network information.
[0089] If the structure is as follows Figure 3The disaster recovery network shown refers to a single PLMN including multiple local SEPPs for disaster recovery or load sharing. Especially when multiple local SEPPs use equipment from different vendors, the implementation schemes for SEPP topology hiding differ significantly between vendors. The topology hiding of a message within the PLMN NF depends on which SEPP performed the topology hiding, and the message must be restored by the same (vendor's) SEPP upon return. This lack of universality in topology hiding and restoration methods increases the network burden on operators in scenarios such as 5G SA network sharing and international roaming architectures. Specifically, as shown... Figure 3 In the hPLMN, two SEPPs are used: one from vendor A and the other from vendor B. The hPLMN operator sets up two nodes (nodes 1 and 2), each deploying its own SEPP. These SEPPs are cross-node for disaster recovery and interconnection. The vPLMN can also be deployed in the same way. For example, with hPLMN as the local network and vPLMN as the external network, when the AMF (Access and Mobility Management Function) of node 2 in vPLMN discovers the UDM (Unified Data Management) of node 2 in hPLMN based on proximity, it uses the forwarding services of the SEPPs of node 2 in vPLMN and node 2 in hPLMN to find the UDM (Unified Data Management) of node 2 in hPLMN. In the management (unified data management function) process, the address of the UDM of node 2 in hPLMN is hidden by the SEPP of node 2 in hPLMN. If the SEPP of node 2 in hPLMN fails, when the AMF of node 2 in vPLMN subsequently sends a message to the UDM of node 2 in hPLMN, the SEPP of node 2 in vPLMN forwards the message to the SEPP of node 1 in hPLMN. At this time, the SEPP of node 1 in hPLMN needs to restore the topology hiding of the UDM. However, due to the different SEPP vendors, the topology hiding cannot be restored, and therefore signaling cannot be routed, leading to communication failure. A similar problem exists when subscribing to notifications between different nodes, since the paths of subscription messages and notification messages are generally different.
[0090] To address the shortcomings of existing technologies and the aforementioned hypothetical problem scenarios, this invention provides a topology hiding method, a topology restoration method, a topology hiding device, a topology restoration device, a computer-readable storage medium, and a Public Land Mobile Network (PLMN). SEPP employs an encryption algorithm to encrypt sensitive inter-network information. After encryption, it combines topology information and key identification information to further hide and protect the information of the local network. This ensures that signaling sent to other networks will not expose the true topology information of the local network, and the key cannot be obtained by other networks, thus preventing other networks from parsing the true topology information of the local network and ensuring the security of the true topology information of the local network. The encryption algorithm is a symmetric encryption algorithm, and the restoration... The correct network topology information can be obtained by using the reverse steps of the hiding process. This addresses the issue that when multiple SEPP devices are sharing load and performing disaster recovery, the device used for encryption and hiding may not be the same as the device used for decryption and recovery. Existing technologies may lead to the inability to restore the hidden topology information. The hidden topology information includes FQDN topology information, IP address, and port information. The paper provides specific methods for encrypting and hiding FQDN topology information, IP address, and port number information, as well as optimization schemes for the parameters involved in the encryption algorithm. More specific technical solutions will be described in detail in Examples 1-6.
[0091] Furthermore, in this application, both NF and SEPP are network elements, and NF includes Figure 3 Other network elements besides SEPP include NRF (NF Register Function), AMF, SMF (Session Management Function), UDM, etc.
[0092] Example 1:
[0093] like Figure 4 As shown, Embodiment 1 of the present invention provides a topology hiding method, applied to the first Security Edge Protection Proxy (SEPP) network element of this network, and includes:
[0094] S11. Obtain the actual topology information of this network from the first signaling message to be sent from this network to another network;
[0095] S12. Use the preset first key to encrypt the real topology information of this network to obtain the encrypted topology information of this network.
[0096] S13. Combine the encrypted topology information of this network with the first key identifier SKID to obtain the hidden topology information of this network;
[0097] S14. Replace the real topology information of the local network in the first signaling with the hidden topology information of the local network to obtain the second signaling;
[0098] S15. Send a second signaling message to an external network.
[0099] Specifically, in this embodiment, when a communication requirement arises between the local network and an external network, the communication signaling needs to be submitted to SEPP for topology hiding. Before sending a message to the external network, the local network's SEPP should convert, modify, or replace the FQDN information or other important network information, such as number ranges and IP addresses, in the signaling through topology hiding to avoid exposure to other operators. The specific approach in this embodiment is to encrypt the true topology information of the local network using an encryption algorithm. Simultaneously, an identifier for the encryption key is added to further hide and protect the encrypted topology information. The topology hiding information of the local network carries the key information, and prevents network elements not designated by the local network from obtaining the key. This ensures that the signaling sent to the external network does not expose the true topology information of the local network, and the key cannot be obtained by the external network. Consequently, the external network cannot obtain the true topology information of the local network through parsing, ensuring the security of the true topology information of the local network. The first signaling described in this embodiment can be signaling in which existing technologies hide topology information in certain scenarios, such as service discovery signaling during roaming. Existing technologies may use the method of maintaining a one-to-many mapping relationship locally in SEPP to achieve topology hiding. This may lead to an increase in the configuration of the mapping relationship as the number of NFs / FQDNs increases in the future, resulting in misconfiguration / underconfiguration, etc., causing the topology hiding or subsequent restoration to fail, and thus causing problems such as information leakage and / or communication failure. The present invention avoids these problems. The first signaling can also be signaling in which existing technologies do not propose topology hiding technology through SEPP. The present invention is not limited to this.
[0100] Optionally, obtain the actual topology information of this network from the first signaling message to be sent from this network to another network, specifically including:
[0101] Receive the first signaling message from the first network function NF element of this network to be sent to the NF element of another network, and obtain the real topology information of this network from the first signaling message.
[0102] Specifically, in this embodiment, the first signaling is generated by the first NF network element of this network. When the first NF network element of this network is preparing to send signaling to an NF network element of another network, it submits the signaling to the SEPP of this network for topology hiding. The first NF network element of this network can point to the second NF network element of this network through the real topology information of this network when generating the first signaling. The first NF network element and the second NF network element of this network mentioned here can be, for example,... Figure 2 As shown, AMF, SMF, UDM, NRF, etc., and the NF network element of the other network can be the peer AMF, SMF, UDM, NRF, etc. that the first signaling type will point to.
[0103] Optionally, a second signaling message may be sent to a different network, specifically including:
[0104] The second signaling is sent to the SEPP network element of the other network, so that the SEPP network element of the other network sends the second signaling to the NF network element of the other network.
[0105] Specifically, in this embodiment, the local network SEPP and the external network SEPP are connected. All signaling interactions between the local network and the external network are forwarded through the SEPP. However, this application does not exclude direct signaling interaction between local network NF elements and external network NF elements. But for the security of local network topology information, even if local network NF elements and external network NF elements directly interact with each other, it is still required to hide the local network topology information.
[0106] Optionally, before encrypting the actual network topology information using a preset first key, the method further includes:
[0107] Multiple identical keys and SKIDs are pre-configured on multiple SEPP network elements within the local network to enable disaster recovery or load sharing among multiple SEPP network elements.
[0108] Specifically, in this embodiment, a key identifier is carried in the hidden topology information to facilitate subsequent decryption. To enable topology hiding and restoration between different SEPPs within the same network, the operator's internal SEPPs need to uniformly configure keys and SKIDs. That is, multiple identical sets of keys and corresponding SKIDs are pre-set on multiple SEPPs within the same network. During encryption, a different key and corresponding SKID can be selected for different signaling to obtain different encryption results each time. The SKID length is a minimum of 1 character and a maximum recommended length of no more than 10 characters. The key length is a minimum of 8 characters and a maximum of 64 characters, and must contain at least two of the following four categories: uppercase English letters, lowercase English letters, numbers, and special characters. The proposed topology hiding and restoration method can be used by all operators. However, since each operator sets its own key and SKID, SEPPs can only parse the hidden topology information of their own network and cannot parse the hidden topology information of other networks. This ensures that the method is universal within the network while guaranteeing information security between different networks.
[0109] Optionally, the actual network topology information is encrypted using a preset first key to obtain encrypted network topology information, specifically including:
[0110] Select the topology information to be hidden based on the actual topology information of this network;
[0111] Select a pre-configured first key;
[0112] The first key is used to encrypt the hidden topology information in order to obtain the encrypted topology information of this network.
[0113] Specifically, in this embodiment, all the real topology information of the local network can be encrypted, or only a portion of the real topology information of the local network can be encrypted according to a pre-set selection rule. Of course, information can also be added to all or part of the real topology information of the local network according to a pre-set rule, and then encrypted. That is, the encrypted topology information to be hidden is not completely equivalent to the original real topology information of the local network in the first signaling, but it can definitely be restored to the original real topology information of the local network.
[0114] Optionally, the topology information to be hidden can be selected based on the actual topology information of this network, specifically including:
[0115] If the format of the actual topology information of this website is a fully qualified domain name (FQDN), then the information in the actual topology information of this website other than the domain name of this website shall be used as the topology information to be hidden.
[0116] If the format of the actual network topology information is Internet Protocol (IP) address, the IP address, IP address and port number, IP address plus a second prefix, or IP address and port number plus a second prefix in the actual network topology information shall be used as the topology information to be hidden.
[0117] Specifically, in this embodiment, the actual network topology information in FQDN format or IP address + port number format can be hidden. The network domain name contained in FQDN format does not need to be hidden. In order to distinguish between the two formats, a fixed prefix can be added to the actual topology information to be hidden before hiding. After subsequent restoration, the original actual topology information format can be determined by the fixed prefix to check the restoration result.
[0118] Optionally, the topology information to be hidden is encrypted using a first key to obtain the encrypted topology information of this network, specifically including:
[0119] Generate the initialization vector (IV) value for the encryption algorithm;
[0120] The hidden topology information is encrypted using a first key and IV value based on an encryption algorithm to obtain the encrypted topology information of this network in binary ciphertext form.
[0121] Optionally, the encryption algorithm is specifically the symmetric encryption algorithm AES_256_GCM.
[0122] Specifically, in this embodiment, the encryption algorithm used is AES_256_GCM. AES (Advanced Encryption Standard) was published by the National Institute of Standards and Technology (NIST) in 2000. It is a symmetric encryption algorithm. The GCM (Galois / Counter Mode) mode of AES is essentially a combination of AES CTR mode (counter mode) and GMAC (Galois Message Authentication Code) for hash calculation. GCM can provide encryption and integrity verification of messages. In addition, it can also provide integrity verification of additional messages. The AES_256_GCM encryption algorithm can prevent brute-force attacks and defend against quantum-level attacks. Because the encryption result is different each time, it is impossible to statistically analyze the information of existing network devices by repeatedly trying.
[0123] Optionally, the encrypted topology information of this network and the first key identifier SKID are combined to obtain the hidden topology information of this network, specifically including:
[0124] Convert the encrypted topology information of this network into a ciphertext string, and convert the IV value into an IV value string;
[0125] Obtain the first prefix, the first SKID, and the domain name of this website, respectively;
[0126] Combine the first prefix, the ciphertext string, the first SKID, the IV value string, and the domain name of this network to hide the network topology information.
[0127] Specifically, in this embodiment, after obtaining the IV value and binary ciphertext through AES_256_GCM, they are converted into strings for use in combining hidden topology information. The IV value of AES_GCM is 96 bits, which is 24 characters in hexadecimal. If the encrypted ciphertext exceeds 63 bytes, it needs to be segmented into multiple tags and then encoded into strings using BASE32. If the length after encoding is insufficient, the character 9 can be used to pad the length. The hidden topology information consists of a first prefix, a ciphertext string, SKID, an IV value string, and the local network domain name. The first prefix is a fixed value and can mark the starting position of the hidden topology information. The local network domain name marks the ending position and can also be used to identify whether the information belongs to the same network as SEPP. The string in the middle is used to decrypt the real topology information of the local network. The hidden topology information can be all or part of the real topology information, as long as it ensures that the internal topology structure information of the local network is not leaked after hiding.
[0128] Optionally, the first prefix, the ciphertext string, the first SKID, the IV value string, and the local domain name are combined to hide the network topology information, specifically including:
[0129] Combine the first prefix, the ciphertext string, the first SKID, the IV value string, and the local domain name, and separate each part using a domain name separator to form the local hidden topology information in FQDN format.
[0130] Specifically, in this embodiment, the hidden topology information is presented in FQDN format. Since operators cannot communicate with each other via IP, and IP addresses of different operators are planned separately, their address spaces may overlap. Communication between different networks via the topology-hidden FQDN meets security requirements and will not cause subsequent service request failures. To facilitate subsequent topology reconstruction, the first prefix, ciphertext string, SKID, IV value string, and local domain name are obtained respectively, with each part separated by "." in the FQDN.
[0131] To more clearly demonstrate the method of this embodiment, the encryption process will be explained below using an FQDN example and an IP address example respectively:
[0132] (I) Examples of specific methods for topology hiding in FQDN
[0133] (1) SEPP extracts the topology information A1 to be hidden from the FQDN and records the PLMN domain name of the FQDN, for example, the following FQDN:
[0134] APP-XJCHJxjINRF001BHW-01BHW012.chj.xj.node.5gc.mnc000.mcc460.3gppnetwork.org
[0135] A1=APP-XJCHJxjINRF001BHW-01BHW012.chj.xj.node.
[0136] (2) SEPP uses AES_256_GCM to encrypt the topology information to be hidden, and uses the encryption key corresponding to the pre-configured SKID to convert the topology information to be hidden into binary ciphertext A2. This ciphertext is in non-string format and is unreadable.
[0137] A2=AES_256_GCM(A1)=AES_256_GCM(APP-XJCHJxjINRF 001BHW-01BHW012.chj.xj.node)
[0138] (3) SEPP converts the binary ciphertext of (2) into a visible string A3 using BASE32 encoding. FQDN is case-insensitive, so BASE32 conversion is used:
[0139] A3=BASE32(A2)=BASE32(AES_256_GCM(APP-XJCHJxjINR F001BHW-01BHW012.chj.xj.node))=IFIFALKYJJBUQSTYNJEU4USGGAYDCQSIK4WTAMKCJBLTAMJSFZRWQ2ROPBVC43TP MRSS4
[0140] (4) To facilitate the recovery and parsing of subsequent business requests by SEPP (including disaster recovery SEPP) through topology hiding, the SKID and AES_256_GCM IV (Initialization Vector) values are also placed in the encrypted and hidden FQDN. Other SEPPs can obtain the real key by querying the local configuration. The prefix CP is added to the beginning of the string A3, and the SKID (skid), IV value, and the PLMN domain name suffix of the unencrypted part of the original FQDN are added to the end to form the hidden FQDN, as follows:
[0141] CP.IFIFALKYJJBUQSTYNJEU4USGGAYDCQSIK4WTAMK CJBLTAMJSFZRWQ2ROPBVC43TPMRSS4.skid1.ivF1E33E079831DF424A00D264.5gc.mnc000.mcc460.3gppnetwork.org
[0142] (II) Examples of specific methods for IP address topology hiding
[0143] (1) SEPP extracts the IP address or IP address + port B1 that needs to be hidden from the signaling, for example:
[0144] The IP address is: 2001:db8:85a3:8d3:1319:8a2e:370:7348
[0145] The port is: 443
[0146] (2) SEPP uses AES_256_GCM to encrypt the IP address information B1 that needs to be hidden, obtaining B2. When the information to be encrypted is an IP address, a fixed prefix (e.g., EP=") can be added before the information B1 to distinguish it from the FQDN encryption, making the subsequent decryption process simpler and clearer, such as:
[0147] B2=AES_256_GCM([2001:db8:85a3:8d3:1319:8a2e:370:7348]:443)
[0148] B2=AES_256_GCM(EP=[2001:db8:85a3:8d3:1319:8a2e:370:7348]:443)
[0149] (3) SEPP converts B2 to string B3 using BASE32:
[0150] B3=BASE32(B2)=BASE32(AES_256_GCM([2001:db8:85a3:8d3:1319:8a2e:370:7348]:443))=LMZDAMBRHJSGEOB2HA2WCMZ 2HBSDGORGMYTSORYMEZGKORTG4YDUNZTGQ4F2ORUG QZQ
[0151] (4) SEPP combines the encrypted content B3 with the pre-configured PLMN domain name (e.g., 5gc.mnc000.mcc460.3gppnetwork.org), adds CP, SKID, and IV, and hides the IP address in FQDN format, for example:
[0152] CP.LMZDAMBRHJSGEOB2HA2WCMZ2HBSDGORRGMYT SORYMEZGKORTG4YDUNZTGQ4F2ORUGQZQ.skid1.ivF1E33E079831DF424A00D264.5gc.mnc000.mcc460.3gppnetwork.org
[0153] Example 2:
[0154] like Figure 5 As shown, Embodiment 2 of the present invention provides a topology restoration method, applied to the Security Edge Protection Proxy (SEPP) network element of this network, and includes:
[0155] S21. Receive a fourth signaling message from another network, wherein the fourth signaling message is sent by the other network according to the second signaling message after receiving the second signaling message sent by the first SEPP network element of this network according to the topology hiding method described in Embodiment 1;
[0156] S22. Obtain the encrypted topology information and the first SKID of the local network from the hidden topology information of the local network in the fourth signaling;
[0157] S23. Obtain the preset first key according to the first SKID, and use the first key to decrypt the encrypted topology information of this network to obtain the real topology information of this network.
[0158] S24. Replace the hidden topology information of the local network in the fourth signaling with the real topology information of the local network to obtain the fifth signaling;
[0159] S25. Send the fifth signaling message on this network.
[0160] Specifically, in this embodiment, based on embodiment 1, the local network will also receive a fourth signaling returned by an external network according to the second signaling. This fourth signaling can be returned by the same SEPP that sent the second signaling, or by different SEPPs of the local network. Since the fourth signaling is the external network's response to the second signaling, the second signaling received by the external network only contains the hidden topology information of the network that sent the second signaling. According to existing response rules, the fourth signaling will carry the hidden topology information obtained from the second signaling. The local network's SEPP can obtain a key based on the identifier carried in the hidden topology information of the local network carried in the returned fourth signaling. The key is used to restore the real topology information of the local network, enabling the correct forwarding of signaling in the local network. This allows the local network's SEPPs to mutually achieve topology hiding and restoration, enhancing the universality of the topology hiding and restoration method and reducing the networking burden in scenarios such as 5G SA network sharing and international roaming architecture for operators.
[0161] Optionally, receiving fourth signaling from another network, specifically including:
[0162] Receive the fourth signaling from the SEPP network element of the other network, wherein the fourth signaling is sent by the SEPP network element of the other network according to the third signaling from the NF network element of the other network, and the third signaling is sent by the NF network element of the other network according to the second signaling.
[0163] Specifically, in this embodiment, the local network SEPP and the external network SEPP are connected. All signaling interactions between the local network and the external network are implemented between the two SEPPs. However, this application does not exclude direct signaling interaction between local network NF elements and external network NF elements. The NF element that generates the signaling and the target NF element to which the signaling is sent are determined by the nature and parameters of the signaling itself.
[0164] Optionally, a fifth signaling message may be sent on this network, specifically including:
[0165] The fifth signaling is sent to the second NF network element of this network, which is pointed to by the actual topology information of this network.
[0166] Specifically, in this embodiment, during the topology restoration process, the SEPP of this network sends the fifth signaling to the second NF network element of this network. The first NF network element of this network that generates the first signaling is not necessarily the second NF network element of this network that receives the fifth signaling. Instead, when the first NF network element generates the first signaling, it points to the second NF network element of this network through the real topology information of this network. When returning the fourth signaling, it restores the real topology information of the original network. The fifth signaling will be sent to the second NF network element of this network according to the predetermined design. The inter-network interaction process between the two networks is as follows: The first NF element of this network generates a first signaling message based on communication requirements. This first signaling message indicates that the target is a certain NF element in the other network, and specifies that the target for processing the returned response is the second NF element of this network. The first signaling message is processed into a second signaling message by the first SEPP of this network and then sent to the SEPP of the other network. The SEPP of the other network forwards the second signaling message to a certain NF element in the other network. The certain NF element in the other network processes the second signaling message and responds by generating a third signaling message. The third signaling message carries the hidden topology information from the second signaling message, and also carries the actual topology information pointing to a certain NF element in its own network, to specify the target. The response is then returned to the processing object. The third signaling is processed by the external network SEPP to hide the true topology information of the external network itself, resulting in the fourth signaling (at this time, the perspectives of the local network and the external network can be interchanged. The external network SEPP that processes the third signaling is equivalent to the local network's first SEPP in Example 1, the third signaling is equivalent to the first signaling in Example 1, and the fourth signaling is equivalent to the second signaling in Example 1). The fourth signaling is sent to the local network SEPP. The local network SEPP restores the hidden topology information of the local network in the fourth signaling and forwards the restored fifth signaling in the local network according to the restoration result. A sixth signaling may also be generated afterward, and the above process continues.
[0167] Optionally, the encrypted topology information and the first SKID of the local network are obtained from the local network hidden topology information of the fourth signaling, specifically including:
[0168] The hidden topology information of this network is obtained from the entire string between the first prefix and the domain name of this network obtained from the fourth signaling.
[0169] Based on the domain name separator, obtain the first prefix, ciphertext string, first SKID, IV value string, and domain name of this network from the hidden topology information of this network;
[0170] The ciphertext string is converted to ciphertext to obtain the encrypted topology information of this network, and the IV value string is converted to IV value.
[0171] Specifically, in this embodiment, during topology restoration, SEPP pre-stores the domain name of this network, and the first prefix is also fixed. Therefore, it can easily obtain the hidden topology information of this network. Each part of the hidden topology information of this network can be obtained by removing the dot, and the first prefix, ciphertext string, SKID, IV value string and domain name of this network can be obtained. SEPP can obtain the encrypted topology information of this network in binary ciphertext form by decoding the ciphertext string through BASE32. At the same time, it is also necessary to convert the IV value string into IV value.
[0172] Optionally, a preset first key is obtained based on the first SKID, and the first key is used to decrypt the encrypted topology information of this network to obtain the real topology information of this network, specifically including:
[0173] Retrieve its own pre-set first key based on the first SKID;
[0174] The encrypted topology information of this network is decrypted using the first key and IV value based on the encryption algorithm to obtain the restored topology information.
[0175] The actual topology information of this network is obtained based on the restored topology information.
[0176] Specifically, in this embodiment, given the known method of hiding the network topology, the topology restoration process is relatively simple and clear. SEPP queries its own pre-set key corresponding to the SKID based on the SKID, and uses AES_256_GCM to decode the binary ciphertext to restore the hidden topology information. The restored topology information corresponds to the topology information to be hidden in Embodiment 1. According to the hiding rules, if only part of the topology information is hidden, the restored topology information (hidden part) and the unhidden part are combined to obtain the complete real topology information of the network. If all the topology information is hidden, the restored topology information is directly used as the real topology information of the network. If information such as a second prefix is added, the second prefix is removed from the restored topology information.
[0177] Example 3:
[0178] like Figure 6 As shown, Embodiment 3 of the present invention provides a topology hiding device, comprising:
[0179] The first acquisition module 11 is used to acquire the real topology information of the local network in the first signaling to be sent to the other network from the local network;
[0180] The first encryption module 12 is connected to the first acquisition module 11 and is used to encrypt the real topology information of the network using a preset first key in order to obtain the encrypted topology information of the network.
[0181] The first combination module 13 is connected to the first encryption module 12 and is used to combine the encrypted topology information of this network and the first key identifier SKID to obtain the hidden topology information of this network.
[0182] The first replacement module 14 is connected to the first combination module 13 and is used to replace the real topology information of the local network in the first signaling with the hidden topology information of the local network to obtain the second signaling.
[0183] The first sending module 15, connected to the first replacement module 14, is used to send the second signaling to the other network.
[0184] Optionally, the first acquisition module 11 specifically includes:
[0185] The first receiving unit is used to receive the first signaling from the first network function NF network element of this network to be sent to the NF network element of another network.
[0186] The first acquisition unit, connected to the first receiving unit, is used to acquire the actual network topology information in the first signaling.
[0187] Optionally, the first transmitting module 15 is specifically used for:
[0188] The second signaling is sent to the SEPP network element of the other network, so that the SEPP network element of the other network sends the second signaling to the NF network element of the other network.
[0189] Optionally, the topology hiding device further includes:
[0190] The first pre-configured module, connected to the first encryption module 12, is used to pre-configure multiple sets of identical keys and SKIDs on multiple local SEPP network elements to achieve disaster recovery or load sharing among multiple local SEPP network elements.
[0191] Optionally, the first encryption module 12 specifically includes:
[0192] The first selection unit is used to select the topology information to be hidden based on the actual topology information of this network.
[0193] The first selection unit is used to select a first key that is preset by itself;
[0194] The first encryption unit, connected to the first selection unit and the first selection unit, is used to encrypt the topology information to be hidden using the first key to obtain the encrypted topology information of this network.
[0195] Optionally, the first selection unit is specifically used for:
[0196] If the format of the actual topology information of this website is a fully qualified domain name (FQDN), then the information in the actual topology information of this website other than the domain name of this website shall be used as the topology information to be hidden.
[0197] If the format of the actual network topology information is Internet Protocol (IP) address, the IP address, IP address and port number, IP address plus a second prefix, or IP address and port number plus a second prefix in the actual network topology information shall be used as the topology information to be hidden.
[0198] Optionally, the first encryption unit is specifically used for:
[0199] Generate the initialization vector (IV) value for the encryption algorithm;
[0200] The hidden topology information is encrypted using a first key and IV value based on an encryption algorithm to obtain the encrypted topology information of this network in binary ciphertext form.
[0201] Optionally, the first combination module 13 specifically includes:
[0202] The first conversion unit is used to convert the encrypted topology information of this network into a ciphertext string and the IV value into an IV value string;
[0203] The second acquisition unit is used to acquire the first prefix, the first SKID, and the domain name of this network, respectively.
[0204] The first combination unit, connected to the first conversion unit and the first acquisition unit, is used to combine the first prefix, the ciphertext string, the first SKID, the IV value string and the local domain name to form hidden topology information of the local network.
[0205] Optionally, the first combination unit is specifically used for:
[0206] Combine the first prefix, the ciphertext string, the first SKID, the IV value string, and the local domain name, and separate each part using a domain name separator to form the local hidden topology information in FQDN format.
[0207] Example 4:
[0208] like Figure 7 As shown, Embodiment 4 of the present invention provides a topology restoration device, comprising:
[0209] The second receiving module 21 is used to receive the fourth signaling from the other network, wherein the fourth signaling is sent by the other network according to the second signaling after receiving the second signaling sent by the first SEPP network element of this network according to the topology hiding method described above;
[0210] The second acquisition module 22 is connected to the second receiving module 21 and is used to acquire the encrypted topology information of the local network and the first SKID from the local network hidden topology information of the fourth signaling.
[0211] The second decryption module 23 is connected to the second acquisition module 22 and is used to obtain a preset first key according to the first SKID and use the first key to decrypt the encrypted topology information of this network to obtain the real topology information of this network.
[0212] The second replacement module 24 is connected to the second decryption module 23 and is used to replace the hidden topology information of the network in the fourth signaling with the real topology information of the network to obtain the fifth signaling.
[0213] The second sending module 25, connected to the second replacement module 24, is used to send the fifth signaling on this network.
[0214] Optionally, the second receiving module 21 is specifically used for:
[0215] Receive the fourth signaling from the SEPP network element of the other network, wherein the fourth signaling is sent by the SEPP network element of the other network according to the third signaling from the NF network element of the other network, and the third signaling is sent by the NF network element of the other network according to the second signaling.
[0216] Optionally, the second transmitting module 25 is specifically used for:
[0217] The fifth signaling is sent to the second NF network element of this network, which is pointed to by the actual topology information of this network.
[0218] Optionally, the second acquisition module 22 specifically includes:
[0219] The third acquisition unit is used to obtain the entire string from the first prefix to the domain name of this network as the hidden topology information of this network from the fourth signaling;
[0220] The fourth acquisition unit, connected to the third acquisition unit, is used to acquire the first prefix, ciphertext string, first SKID, IV value string and the domain name of this network from the hidden topology information of this network according to the domain name separator.
[0221] The second conversion unit, connected to the fourth acquisition unit, is used to convert the ciphertext string into ciphertext to obtain the encrypted topology information of the local network, and to convert the IV value string into an IV value.
[0222] Optionally, the second decryption module 23 specifically includes:
[0223] The second query unit is used to query its own preset first key based on the first SKID;
[0224] The second decryption unit, connected to the second query unit, is used to decrypt the encrypted topology information of this network using the first key and IV value based on the encryption algorithm to obtain the restored topology information.
[0225] The second obtaining unit, connected to the second decryption unit, is used to obtain the true topology information of the network based on the restored topology information.
[0226] Example 5:
[0227] Embodiment 5 of the present invention provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the topology hiding method as described in Embodiment 1 and / or the topology restoration method as described in Embodiment 2.
[0228] Specifically, in this embodiment, the topology hiding method and / or the topology restoration method can be run on the Security Edge Protection Agent (SEPP) network element to hide and restore the local network topology information in inter-network communication signaling. The computer-readable storage medium includes volatile or non-volatile, removable or non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, computer program modules, or other data). Computer-readable storage media include, but are not limited to, RAM (Random Access Memory), ROM (Read-Only Memory), EEPROM (Electrically Erasable Programmable Read-Only Memory), flash memory or other memory technologies, CD-ROM (CompactDisc Read-Only Memory), DVD or other optical disc storage, magnetic cartridges, magnetic tapes, disk storage or other magnetic storage devices, or any other medium that can be used to store desired information and is accessible by a computer.
[0229] In addition, the present invention may also provide a computer device, the device including a memory and a processor, wherein the memory stores a computer program, and when the processor runs the computer program stored in the memory, the processor executes the topology hiding method as described in Embodiment 1 and / or the topology restoration method as described in Embodiment 2.
[0230] The memory is connected to the processor. The memory can be flash memory, read-only memory or other types of memory. The processor can be a central processing unit or a microcontroller.
[0231] Example 6:
[0232] Embodiment 6 of the present invention provides a Public Land Mobile Network (PLMN), including a Security Edge Protection Proxy (SEPP) network element, and connecting to other networks through the SEPP network element;
[0233] The SEPP network element of this network includes the first SEPP network element of this network, and the topology hiding method as described in Example 1 is implemented by the first SEPP network element of this network.
[0234] Optionally, the topology restoration method described in Example 2 is implemented by the first SEPP network element of this network; or,
[0235] The SEPP network element of this network also includes a second SEPP network element of this network, which implements the topology restoration method as described in Example 2.
[0236] Specifically, in this embodiment, the structure of the PLMN can be as follows: Figure 1-3 As shown, with Figure 3 Taking hPLMN as an example, the SEPP of node 2 is equivalent to the first SEPP of the network, and the SEPP of node 1 is equivalent to the second SEPP of the network. The SEPP of node 2 first hides the real topology information of the network in the signaling that interacts with vPLMN. The response information returned by vPLMN can be received and restored by the SEPP of node 2 or by the SEPP of node 1.
[0237] The present invention provides a topology hiding method, topology hiding device, computer-readable storage medium, and Public Land Mobile Network (PLMN) in embodiments 1, 3, 5, and 6. By using a preset key to encrypt the real topology information of the local network, and by adding a preset identifier corresponding to the encryption key to the hidden topology information of the local network, the signaling sent to other networks will not expose the real topology information of the local network, and the key information cannot be obtained by other networks. Thus, other networks cannot parse the real topology information of the local network, ensuring the security of the real topology information of the local network.
[0238] The topology restoration method, topology restoration device, computer-readable storage medium, and Public Land Mobile Network (PLMN) provided in embodiments 2, 4, 5, and 6 of this invention can correctly restore the original network's true topology information by parsing the aforementioned hidden topology information, thereby ensuring the implementation of subsequent communication processes with responses.
[0239] It is understood that the above embodiments are merely exemplary implementations used to illustrate the principles of the present invention, and the present invention is not limited thereto. For those skilled in the art, various modifications and improvements can be made without departing from the spirit and essence of the present invention, and these modifications and improvements are also considered to be within the scope of protection of the present invention.
Claims
1. A method for topology hiding and restoration, characterized in that, Applied to the Security Edge Protection Agent (SEPP) network element of this network, and includes: Obtain the actual topology information of this network from the first signaling message to be sent to another network. The network's real topology information is encrypted using a pre-set first key to obtain the network's encrypted topology information. By combining the encrypted topology information of this network with the first key identifier SKID, the hidden topology information of this network can be obtained. The hidden topology information of this network is used to replace the real topology information of this network in the first signaling to obtain the second signaling. Send a second signaling message to a different network; Receive a fourth signaling message from another network, wherein the fourth signaling message is sent by the other network in response to the second signaling message sent by the SEPP network element of this network. Obtain the encrypted topology information and the first SKID of the local network from the hidden topology information of the local network in the fourth signaling. The first key is obtained based on the first SKID, and then used to decrypt the encrypted topology information of this network to obtain the true topology information of this network. The hidden topology information of this network is replaced in the fourth signaling message with the actual topology information of this network to obtain the fifth signaling message. Send the fifth signaling message on this network; The first key is not obtained by other networks.
2. The topology hiding and restoration method according to claim 1, characterized in that, Obtain the actual topology information of this network from the first signaling message to be sent to another network, specifically including: Receive the first signaling message from the first network function NF element of this network to be sent to the NF element of another network, and obtain the real topology information of this network from the first signaling message.
3. The topology hiding and restoration method according to claim 2, characterized in that, Sending a second signaling message to a different network, specifically including: The second signaling is sent to the SEPP network element of the other network, so that the SEPP network element of the other network sends the second signaling to the NF network element of the other network.
4. The topology hiding and restoration method according to claim 1, characterized in that, Before encrypting the actual network topology information using a preset first key, the method further includes: Multiple identical keys and SKIDs are pre-configured on multiple SEPP network elements within the local network to enable disaster recovery or load sharing among multiple SEPP network elements.
5. The topology hiding and restoration method according to any one of claims 1-4, characterized in that, The actual network topology information is encrypted using a pre-set first key to obtain the encrypted network topology information, specifically including: Select the topology information to be hidden based on the actual topology information of this network; Select a pre-configured first key; The first key is used to encrypt the hidden topology information in order to obtain the encrypted topology information of this network.
6. The topology hiding and restoration method according to claim 5, characterized in that, The topology information to be hidden is selected based on the actual topology information of this network, specifically including: If the format of the actual topology information of this website is a fully qualified domain name (FQDN), then the information in the actual topology information of this website other than the domain name of this website shall be used as the topology information to be hidden. If the format of the actual network topology information is Internet Protocol (IP) address, the IP address, IP address and port number, IP address plus a second prefix, or IP address and port number plus a second prefix in the actual network topology information shall be used as the topology information to be hidden.
7. The topology hiding and restoration method according to claim 5, characterized in that, The hidden topology information is encrypted using the first key to obtain the encrypted topology information of this network, specifically including: Generate the initialization vector (IV) value for the encryption algorithm; The hidden topology information is encrypted using a first key and IV value based on an encryption algorithm to obtain the encrypted topology information of this network in binary ciphertext form.
8. The topology hiding and restoration method according to claim 7, characterized in that, By combining the encrypted topology information of this network with the first key identifier SKID, the hidden topology information of this network can be obtained, specifically including: Convert the encrypted topology information of this network into a ciphertext string, and convert the IV value into an IV value string; Obtain the first prefix, the first SKID, and the domain name of this website, respectively; Combine the first prefix, the ciphertext string, the first SKID, the IV value string, and the domain name of this network to hide the network topology information.
9. The topology hiding and restoration method according to claim 8, characterized in that, The first prefix, ciphertext string, first SKID, IV value string, and this network's domain name are combined to hide the network's topology information, specifically including: Combine the first prefix, the ciphertext string, the first SKID, the IV value string, and the local domain name, and separate each part using a domain name separator to form the local hidden topology information in FQDN format.
10. The topology hiding and restoration method according to claim 1, characterized in that, Receiving fourth signaling from another network, specifically including: Receive the fourth signaling from the SEPP network element of the other network, wherein the fourth signaling is sent by the SEPP network element of the other network according to the third signaling from the NF network element of the other network, and the third signaling is sent by the NF network element of the other network according to the second signaling.
11. The topology hiding and restoration method according to claim 1, characterized in that, Sending the fifth signaling message on this network specifically includes: The fifth signaling is sent to the second NF network element of this network, which is pointed to by the actual topology information of this network.
12. The topology hiding and restoration method according to any one of claims 1, 10-11, characterized in that, The encrypted topology information and the first SKID of the local network are obtained from the hidden topology information of the local network in the fourth signaling, specifically including: The hidden topology information of this network is obtained from the entire string between the first prefix and the domain name of this network obtained from the fourth signaling. Based on the domain name separator, obtain the first prefix, ciphertext string, first SKID, IV value string, and domain name of this network from the hidden topology information of this network; The ciphertext string is converted to ciphertext to obtain the encrypted topology information of this network, and the IV value string is converted to IV value.
13. The topology hiding and restoration method according to claim 12, characterized in that, The first key is obtained based on the first SKID, and the first key is used to decrypt the encrypted topology information of this network to obtain the real topology information of this network, specifically including: Query its own pre-set first key based on the first SKID; The encrypted topology information of this network is decrypted using the first key and IV value based on the encryption algorithm to obtain the restored topology information. The actual topology information of this network is obtained based on the restored topology information.
14. A topology hiding and restoration device, characterized in that, include: The first acquisition module is used to acquire the actual topology information of the local network from the first signaling message to be sent to the other network. The first encryption module, connected to the first acquisition module, is used to encrypt the real topology information of the network using a preset first key to obtain the encrypted topology information of the network. The first combination module, connected to the first encryption module, is used to combine the encrypted topology information of this network with the first key identifier SKID to obtain the hidden topology information of this network. The first replacement module, connected to the first combination module, is used to replace the actual network topology information in the first signaling with hidden network topology information to obtain the second signaling. The first sending module, connected to the first replacement module, is used to send the second signaling to an external network; The second receiving module is used to receive the fourth signaling from the external network. This fourth signaling is sent by the external network in response to the second signaling sent by the SEPP network element of this network. The second acquisition module, connected to the second receiving module, is used to acquire the encrypted topology information of the local network and the first SKID from the local network hidden topology information in the fourth signaling. The second decryption module, connected to the second acquisition module, is used to obtain a preset first key based on the first SKID, and use the first key to decrypt the encrypted topology information of the network to obtain the true topology information of the network. The second replacement module, connected to the second decryption module, is used to replace the hidden topology information of the local network in the fourth signaling with the actual topology information of the local network, in order to obtain the fifth signaling. The second transmitting module, connected to the second replacement module, is used to transmit the fifth signaling within this network; The first key is not obtained by other networks.
15. A computer-readable storage medium, characterized in that, It stores a computer program, which, when executed by a processor, implements the topology hiding and restoration method as described in any one of claims 1-13.
16. A Public Land Mobile Network (PLMN), characterized in that, This includes the Security Edge Protection Agent (SEPP) network element of this network, and connects to other networks through the SEPP network element of this network; The SEPP network element of this network includes the first SEPP network element of this network, and the topology hiding and restoration method as described in any one of claims 1-13 is implemented by the first SEPP network element of this network; or, The SEPP network elements of this network include the first SEPP network element and the second SEPP network element of this network. The topology hiding and restoration method described in any one of claims 1-13 is implemented by the first SEPP network element and the second SEPP network element of this network.
Citation Information
Patent Citations
Network information hiding method and system
CN114844729A