Method and system for traffic control to protect out-of-band network management channel
By deploying policies to intercept and verify traffic in security protection devices, allowing only authenticated and encrypted tunnel traffic to pass through, the security risk of attacks on the core network management plane by sinking network elements is resolved, and secure data transmission between network elements and the management plane is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA TELECOM CORP LTD
- Filing Date
- 2022-03-22
- Publication Date
- 2026-07-31
AI Technical Summary
In communication technology, when sinking network elements are deployed in enterprise parks in untrusted areas, the edge management plane and the core network management plane share the same channel, which leads to security risks. Hackers can use the edge management plane to attack the core network management plane and other network elements.
By deploying a primary security policy in security protection devices, traffic is intercepted and verified, allowing only authenticated traffic and encrypted tunnel traffic to pass through, establishing encrypted tunnels for secure transmission, and ensuring the trustworthiness of network element identities.
It improves the security of the target management plane, prevents unauthorized intrusion, ensures the security of data transmission between network elements and the management plane, and solves the problems of network element identity trust and data transmission security.
Smart Images

Figure CN116828465B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of communication technology, and in particular to a flow control method and system for protecting out-of-band network management channels. Background Technology
[0002] Currently, network management systems (such as management planes) improved by operators typically employ out-of-band management to monitor, manage, and maintain network elements. Out-of-band management utilizes dedicated management channels to manage the network, separating management data from service data. This establishes an independent channel for management data, ensuring the secure and reliable transmission of critical data within the network, improving management efficiency and reliability, and enhancing the security of management data.
[0003] However, with the commercial development of communication technologies (such as 5G (5th Generation Mobile Communication Technology)), in order to meet the needs of new services, operators have chosen to deploy some network elements to enterprise campuses (such as lightweight UPF (User Plane Function) and MEC (Mobile Edge Computing)) to provide high-quality private network services for industry customers. For ease of management, the edge network management system (such as the edge management plane) corresponding to these deployed network elements (also known as edge network elements) is usually deployed in the provincial / regional resource pool, and out-of-band network management is still used to configure network resources and monitor the status of the deployed edge network elements.
[0004] These substation network elements deployed in enterprise parks are located in untrusted areas for operators. However, since their corresponding edge management planes share the same channel with the core network management plane, and the security protection capabilities of enterprise parks vary, there is a security risk that hackers may use substation network elements as a breakthrough point to attack the core network management plane and other network elements by using the edge management plane channel.
[0005] It should be noted that the information disclosed in the background section above is only used to enhance the understanding of the background of this disclosure. Summary of the Invention
[0006] The purpose of this disclosure is to provide a method and system for protecting out-of-band network management channels, which can improve the security of traffic received by the target management plane, thereby providing security for the target management plane, preventing the target management plane and the network elements it manages from being illegally intruded, and thus improving the security of the traffic control system for protecting out-of-band network management channels.
[0007] Other features and advantages of this disclosure will become apparent from the following detailed description, or may be learned in part from practice of this disclosure.
[0008] This disclosure provides a traffic control method for protecting out-of-band network management channels, comprising: a security protection device intercepting first traffic sent by a first network element to a target management plane according to a first security policy; after determining that the first traffic is neither traffic from a target encrypted tunnel nor authentication traffic, the security protection device discarding the first traffic according to the first security policy; after determining that the first traffic is traffic from a target encrypted tunnel or authentication traffic, the security protection device allowing the first traffic to pass according to the first security policy, so that the target management plane can receive and process the first traffic; wherein, the target encrypted tunnel is an encrypted tunnel established between the first network element and the security protection device after passing security authentication, and the authentication traffic is traffic used for security authentication.
[0009] In some embodiments, after the security protection device intercepts the first traffic sent by the first network element to the target management plane according to the first security policy, the method further includes: the security protection device defaulting to the first traffic being untrusted according to the first security policy; and the security protection device performing security verification on the first traffic according to the first security policy to determine whether the first traffic is traffic from the target encrypted tunnel or whether it is authenticated traffic.
[0010] In some embodiments, the first security policy defaults to all traffic intercepted by the security protection device as untrusted traffic, and instructs the security protection device to verify all intercepted traffic in sequence, and allows verified traffic or traffic from the encrypted tunnel to pass through, while discarding traffic that is neither verified traffic nor from the encrypted tunnel.
[0011] In some embodiments, the first traffic is authentication traffic; wherein, the target management plane receives and processes the first traffic, including: the target management plane receiving the first traffic from the security protection device; after determining that the first traffic is authentication traffic, the target management plane performs security authentication processing on the first traffic; after the first traffic passes security authentication, the target management plane dynamically issues a second security policy to the security protection device to notify the security protection device to establish a target encrypted tunnel with the first network element, so that the first network element and the security protection device can transmit traffic through the target encrypted tunnel.
[0012] In some embodiments, the method further includes: after the first traffic fails to pass security authentication, the target management sends a third policy to the security protection device to notify the security protection device not to establish a target encrypted tunnel with the first network element.
[0013] In some embodiments, the target management plane includes security authentication information of multiple security network elements. The security authentication information of the multiple security network elements is synchronized to the target management plane before the multiple security network elements are deployed online. The first traffic carries the security authentication information of the first network element. The target management plane performs security authentication processing on the first traffic, including: the target management plane matches the security authentication information of the first network element with the security authentication information of the multiple security network elements; if the match is successful, it is determined that the first traffic has passed security authentication.
[0014] In some embodiments, the target management plane is an edge management plane in a traffic control system that protects the out-of-band network management channel. The traffic control system that protects the out-of-band network management channel also includes a core network management plane. The first traffic is traffic from the target encrypted tunnel. The target management plane receives and processes the first traffic, including: the edge management plane receiving the first traffic from the security protection device; and the edge management plane sending the first traffic to the core network management plane through the out-of-band network management channel so that the core network management plane can process the first traffic.
[0015] In some embodiments, the first traffic is encrypted traffic from the target encrypted tunnel; wherein, the security protection device allows the first traffic to pass through, including: the security protection device obtaining the public key of the first network element; the security protection device decrypting the first traffic using the public key; and the security protection device allowing the decrypted first traffic to pass through.
[0016] In some embodiments, the first traffic is authentication traffic. A trusted security component is deployed in the first network element, and a security management component is deployed in the target management plane. The trusted security component is used to generate the first traffic based on the network element information of the first network element, so as to initiate security authentication to the target management plane through the first traffic. The trusted security component is also used to perform security monitoring on the first network element and periodically report the operating environment status of the first network element to the target management plane. The security management component is used to perform security authentication on the first traffic and, after the security authentication of the first traffic is passed, issue a security policy to the security protection device to enable the security protection device to establish a target encrypted tunnel with the first network element.
[0017] This disclosure provides a traffic control system for protecting out-of-band network management channels. The traffic control system includes a target management plane and a first network element. The first network element is managed by the target management plane. A security protection device is deployed at the entry point of the target management plane, and a first security policy is deployed in the security protection device. The security protection device is used to intercept first traffic sent from the first network element to the target management plane according to the first security policy. The security protection device is also used to discard the first traffic after determining, according to the first security policy, that the first traffic is neither traffic from a target encrypted tunnel nor authentication traffic. Furthermore, the security protection device is used to allow the first traffic to pass through after determining, according to the first security policy, that the first traffic is traffic from a target encrypted tunnel or authentication traffic, so that the target management plane can receive and process the first traffic. The target encrypted tunnel is an encrypted tunnel established between the first network element and the security protection device after security authentication, and the authentication traffic is traffic used for security authentication.
[0018] In some embodiments, the security protection device is further configured to, after intercepting the first traffic sent by the first network element to the target management plane, default the first traffic to be untrusted according to the first security policy, and perform security verification on the first traffic according to the first security policy to determine whether the first traffic is traffic from the target encrypted tunnel or whether it is authenticated traffic.
[0019] This disclosure provides an electronic device comprising: one or more processors; and a storage device for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the flow control method for protecting out-of-band network management channels as described above.
[0020] This disclosure provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements a flow control method for protecting out-of-band network management channels as described above.
[0021] This disclosure provides a computer program product or computer program that includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the aforementioned flow control method for protecting out-of-band network management channels.
[0022] The flow control method, apparatus, electronic device, and computer-readable storage medium for protecting out-of-band network management channels provided in this disclosure, on the one hand, intercept all traffic destined for the target management plane, preventing malicious traffic from flowing to the target management plane and improving the security of the target management plane; on the other hand, the protection device allows authentication traffic and traffic from encrypted tunnels to pass through, both by allowing authentication traffic to provide each network element with the opportunity to authenticate to the target management plane, and by intercepting traffic from unencrypted tunnels, ensuring the security of traffic flowing to the target management plane; in addition, after the target management plane performs security verification on a network element, this application allows the network element to establish an encrypted tunnel with the protection device, so that the network element can transmit encrypted traffic to the protection device through the encrypted tunnel, improving the security of traffic transmission. In summary, this not only solves the problem of network element identity trustworthiness and the problem of attacking the target management plane and other network elements through sinking network elements, but also solves the problem of data transmission security between network elements and the target management plane.
[0023] It should be understood that the above general description and the following detailed description are merely exemplary and do not limit this disclosure. Attached Figure Description
[0024] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of this disclosure. It is obvious that the drawings described below are merely some embodiments of this disclosure, and those skilled in the art can obtain other drawings based on these drawings without any inventive effort.
[0025] Figure 1 This is a flowchart illustrating a flow control method for protecting out-of-band network management channels according to an exemplary embodiment.
[0026] Figure 2 This is a flowchart illustrating a flow control method for protecting out-of-band network management channels according to an exemplary embodiment.
[0027] Figure 3 This is a flowchart illustrating a flow control method for protecting out-of-band network management channels according to an exemplary embodiment.
[0028] Figure 4 This is a flowchart illustrating a flow control method for protecting out-of-band network management channels according to an exemplary embodiment.
[0029] Figure 5 A flow control system for protecting out-of-band network management channels is provided.
[0030] Figure 6 This is a timing diagram illustrating a flow control method for protecting out-of-band network management channels according to an exemplary embodiment. Detailed Implementation
[0031] Exemplary embodiments will now be described more fully with reference to the accompanying drawings. However, these exemplary embodiments can be implemented in many forms and should not be construed as limited to the embodiments set forth herein; rather, they are provided so that this disclosure will be thorough and complete, and will fully convey the concept of the exemplary embodiments to those skilled in the art. The same reference numerals in the drawings denote the same or similar parts, and therefore repeated descriptions of them will be omitted.
[0032] The features, structures, or characteristics described in this disclosure can be combined in any suitable manner in one or more embodiments. Numerous specific details are provided in the following description to give a thorough understanding of embodiments of this disclosure. However, those skilled in the art will recognize that the technical solutions of this disclosure can be practiced with one or more specific details omitted, or other methods, components, apparatuses, steps, etc., can be employed. In other instances, well-known methods, apparatuses, implementations, or operations are not shown or described in detail to avoid obscuring various aspects of this disclosure.
[0033] The accompanying drawings are merely illustrative of this disclosure, and the same reference numerals in the drawings denote the same or similar parts, thus omitting repeated descriptions of them. Some block diagrams shown in the drawings do not necessarily correspond to physically or logically independent entities. These functional entities may be implemented in software, in one or more hardware modules or integrated circuits, or in different network and / or processor devices and / or microcontroller devices.
[0034] The flowchart shown in the accompanying drawings is merely illustrative and does not necessarily include all content and steps, nor does it require execution in the described order. For example, some steps may be broken down, while others may be combined or partially combined; therefore, the actual execution order may change depending on the specific circumstances.
[0035] In this specification, the terms “a,” “an,” “the,” “the,” and “at least one” are used to indicate the presence of one or more elements / components / etc.; the terms “comprising,” “including,” and “having” are used to indicate an open-ended inclusion and to mean that there may be other elements / components / etc. in addition to the listed elements / components / etc.; the terms “first,” “second,” and “third,” etc., are used only as markings and are not a limitation on the number of objects.
[0036] To better understand the above-mentioned objectives, features and advantages of the present invention, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be noted that, unless otherwise specified, the embodiments and features in the embodiments of this application can be combined with each other.
[0037] The exemplary embodiments of this disclosure will now be described in detail with reference to the accompanying drawings.
[0038] Figure 1 This is a flowchart illustrating a flow control method for protecting out-of-band network management channels according to an exemplary embodiment.
[0039] The traffic control method for protecting out-of-band network management channels provided in this disclosure involves a traffic control system for protecting out-of-band network management channels. This traffic control system can be a network system (e.g., a 5G network system). The traffic control system can include a target management plane and a first network element. The first network element can be managed by the target management plane. A security protection device can be deployed at the entry point of the target management plane, and a first security policy can be deployed in the security protection device.
[0040] The first network element can be an edge network element residing in an untrusted area or a network element located in a trusted area; this disclosure does not impose any restrictions on this. A network element can refer to a functional network element in the network system (such as an MEC functional network element, a UPF functional network element, etc.; this disclosure does not impose any restrictions on this).
[0041] Untrusted areas can refer to areas where security is uncontrollable, such as business parks, shopping malls, subways, and other places accessible to the public and non-operator personnel. Trusted areas can refer to areas with high security and controllability, such as resource pools deployed by operators in provinces / regions and data centers set up by operators.
[0042] The target management plane can be an edge management plane within a traffic control system that protects out-of-band network management channels and can be controlled by the core network management plane (e.g., a network management system for a 5G core network), or it can be the core network management plane itself; this disclosure does not impose any restrictions on this. The edge management plane can refer to a network management system used to manage some edge network elements.
[0043] It is understood that the core network in a traffic control system protecting out-of-band network management channels can manage multiple edge management surfaces, and each edge management surface can manage at least one network element (e.g., an edge network element deployed in an untrusted area). This disclosure does not impose any limitations on this. Here, edge network elements can refer to network elements that are located near the user (e.g., in enterprise parks, shopping malls, or subways).
[0044] In some embodiments, if the target management plane is an edge management plane in a flow control system that protects out-of-band network management channels, then the edge management plane can be deployed near an edge network element (such as the first network element) or near a core network management plane (such as in a resource pool where the core network is located). This disclosure does not impose any restrictions on this.
[0045] In addition, the aforementioned security protection equipment may refer to firewalls deployed at the entry and exit points of the target management plane.
[0046] Reference Figure 1 The flow control method for protecting out-of-band network management channels provided in this disclosure may include the following steps.
[0047] In step S102, the security protection device intercepts the first traffic sent by the first network element to the target management plane according to the first security policy.
[0048] In some embodiments, a first security policy may be pre-deployed in the security protection device, which can be used to instruct the security protection device to intercept and perform security verification on each traffic passing through the security protection device.
[0049] In step S104, after determining that the first traffic is neither traffic from the target encrypted tunnel nor authentication traffic, the security protection device discards the first traffic according to the first security policy.
[0050] The target encrypted tunnel is an encrypted tunnel established between the first network element and the security protection device after the first network element has passed security authentication. The authentication traffic is the traffic used for security authentication. It can be understood that if the first network element can send traffic to the security protection device through the encrypted tunnel, then the first network element has already completed security authentication in advance.
[0051] In some embodiments, the security protection device may determine the traffic type of the first traffic to determine whether the first traffic is authentication traffic or traffic from an encrypted tunnel.
[0052] In some embodiments, the security protection device can perform security verification on each intercepted traffic. In some embodiments, security verification can be performed based on identity information, or based on the network element token carried by the traffic (which can be used multiple times once obtained). This disclosure does not limit the security verification method.
[0053] In this context, authentication traffic can refer to traffic sent by a network element to the target management plane to request identity authentication. This authentication traffic may carry authentication information of the network element, such as identity information, device information (such as device ID (Identity document), MAC (Media Access Control Address), IP (Internet Protocol Address), location information, etc. built into the first network element device), etc. This disclosure does not impose any restrictions on this.
[0054] An encrypted tunnel can refer to a dedicated tunnel in which all traffic transmitted is encrypted. This disclosure does not limit the encryption method used for traffic in an encrypted tunnel.
[0055] In step S106, after determining that the first traffic is traffic from the target encrypted tunnel or authentication traffic, the security protection device allows the first traffic to pass through according to the first security policy so that the target management plane can receive and process the first traffic.
[0056] In some embodiments, if the first traffic is encrypted traffic from the target encrypted tunnel, the security protection device can decrypt the first traffic before sending it to the target management plane, or it can directly forward it to the target management plane and decrypt the first traffic through the target management plane. This disclosure does not limit this.
[0057] In some embodiments, the traffic in the target encrypted tunnel can be traffic encrypted by the first network element using its private key. When the security protection device receives the first traffic, it can obtain the public key of the first network element, then decrypt the first traffic using the public key of the first network element, and finally forward the decrypted first traffic to the target management plane.
[0058] The traffic control method for protecting out-of-band network management channels provided in this embodiment has two main aspects. First, the security protection device intercepts all traffic destined for the target management plane, preventing malicious traffic from flowing to the target management plane and improving its security. Second, the protection device allows authentication traffic and traffic from encrypted tunnels to pass through. This provides each network element with the opportunity to authenticate to the target management plane by allowing authentication traffic, while blocking traffic from unencrypted tunnels (distrusting all traffic), ensuring the security of traffic flowing to the target management plane. Furthermore, after the target management plane performs security verification on a network element, it allows the network element to establish an encrypted tunnel with the protection device, enabling encrypted traffic transmission between the network element and the protection device, thus improving the security of traffic transmission. In summary, this embodiment not only solves the problem of network element identity trust and prevents unauthorized attackers from attacking the target management plane and other network elements by sinking network elements, but also improves the security of data transmission between network elements and the target management plane.
[0059] In some embodiments, the first traffic can be authentication traffic, a trusted security component can be deployed in the first network element, and a security management component can be deployed in the target management plane. The trusted security component can generate the first traffic based on the network element information of the first network element, and initiate security authentication to the target management plane through the first traffic. The trusted security component can also perform security monitoring on the first network element and periodically report the operating environment status of the first network element to the target management plane. The security management component can perform security authentication on the first traffic, and after successful security authentication, issue security policies to the security protection device to enable the security protection device to establish a target encrypted tunnel with the first network element.
[0060] Figure 2 This is a flowchart illustrating a flow control method for protecting out-of-band network management channels according to an exemplary embodiment.
[0061] Reference Figure 2 The flow control method for protecting out-of-band network management channels provided in this disclosure may include the following steps.
[0062] In step S202, the security protection device intercepts the first traffic sent by the first network element to the target management plane according to the first security policy.
[0063] The first security policy can default to treating all traffic intercepted by the security protection device as untrusted traffic, instruct the security protection device to verify all intercepted traffic, and allow verified traffic or traffic from the encrypted tunnel to pass through, while discarding traffic that is neither verified nor from the encrypted tunnel.
[0064] In step S204, the security protection device defaults to not trusting the first traffic flow according to the first security policy.
[0065] In this embodiment, the security protection device does not trust any traffic by default and blocks all traffic from passing through in order to avoid attacks from illegal traffic.
[0066] In step S206, the security protection device performs security verification on the first traffic according to the first security policy to determine whether the first traffic is traffic from the target encrypted tunnel or whether it is authentication traffic.
[0067] In some embodiments, the target management plane may include security authentication information for multiple security network elements. This security authentication information may be synchronized to the target management plane before the multiple security network elements are deployed online. The security network element may refer to a network element that is known in advance to be secure and reliable.
[0068] In some embodiments, if the first traffic carries the security authentication information of the first network element, the security authentication process of the first traffic can be implemented by the following method: the target management plane matches the security authentication information of the first network element with the security authentication information of multiple security network elements; if the matching is successful, it is determined that the first traffic has passed the security authentication.
[0069] The security authentication information may include: identity information, device information (such as device ID, MAC, IP, location information, etc. built into the first network element device), etc., and this disclosure does not impose any restrictions on it.
[0070] In step S208, after determining that the first traffic is neither traffic from the target encrypted tunnel nor authentication traffic, the security protection device discards the first traffic according to the first security policy.
[0071] In step S210, after determining that the first traffic is traffic from the target encrypted tunnel or authentication traffic, the security protection device allows the first traffic to pass through according to the first security policy so that the target management plane can receive and process the first traffic.
[0072] The technical solution provided in this embodiment involves a security protection device that intercepts all traffic destined for a target and assumes that all traffic passing through the security protection device is insecure and untrusted. Upon interception, the security protection device performs security authentication on the traffic. Only after the security authentication determines that the traffic is either authenticated traffic or traffic originating from an encrypted tunnel will the traffic be allowed to pass. This embodiment, by assuming all traffic is insecure and performing security authentication on all traffic flowing through the security protection device (even if the network element sending the traffic has previously passed security authentication, the security protection device will still consider the traffic sent by the network element insecure and require security verification), provides a zero-trust traffic control method, improving the security of traffic flowing to the target management plane and preventing attacks on the target management plane.
[0073] Figure 3 This is a flowchart illustrating a flow control method for protecting out-of-band network management channels according to an exemplary embodiment.
[0074] In some embodiments, the first traffic may be authentication traffic.
[0075] Reference Figure 3 The flow control method for protecting out-of-band network management channels provided in this disclosure may include the following steps.
[0076] In step S302, the security protection device intercepts the first traffic sent by the first network element to the target management plane according to the first security policy.
[0077] Step S304: If it is determined that the first traffic is neither traffic from the target encrypted tunnel nor authentication traffic, the security protection device discards the first traffic according to the first security policy.
[0078] Step S306: If it is determined that the first traffic is authentication traffic, the security protection device allows the first traffic to pass through according to the first security policy.
[0079] Step S308: The target management plane receives the first traffic from the security protection device;
[0080] Step S310: After determining that the first traffic is authentication traffic, the target management performs security authentication processing on the first traffic.
[0081] In some embodiments, the security authentication process for the first traffic can be implemented by the following method: the target management plane matches the security authentication information of the first network element with the security authentication information of multiple security network elements; if the match is successful, the first traffic is determined to have passed security authentication. The security authentication information may include: identity information, device information (such as the device ID, MAC address, IP address, location information, etc. built into the first network element device), etc., and this disclosure does not impose any limitations on this.
[0082] Step S312: After the first traffic passes security authentication, the target management dynamically issues a second security policy to the security protection device to notify the security protection device to establish a target encrypted tunnel with the first network element, so that the first network element and the security protection device can transmit traffic through the target encrypted tunnel.
[0083] The second security strategy carries the device information of the first network element, so that the security protection device can establish a target encrypted tunnel with the first network element based on the device information, and the first network element can send traffic to the security protection device through the target encrypted tunnel.
[0084] Step S314: After the first traffic fails to pass security authentication, the target management sends a third policy to the security protection device to notify the security protection device not to establish a target encrypted tunnel with the first network element.
[0085] The technical solution provided in this embodiment allows the security protection device to pass through after determining that the first traffic is authentication traffic, so that the target management surface can authenticate the authentication traffic. Once the first traffic is successfully authenticated, the target management surface considers the first network element to be secure and reliable, and can then authorize the security protection device to establish an encrypted tunnel with the first network element through a second security policy, so that the first network element can subsequently transmit traffic with the security protection device through the encrypted tunnel.
[0086] Figure 4 This is a flowchart illustrating a flow control method for protecting out-of-band network management channels according to an exemplary embodiment.
[0087] In some embodiments, the target management plane is the edge management plane in the traffic control system for protecting the out-of-band network management channel, and the traffic control system for protecting the out-of-band network management channel also includes the core network management plane, and the first traffic is traffic from the target encrypted tunnel.
[0088] Reference Figure 4 The flow control method for protecting out-of-band network management channels provided in this disclosure may include the following steps.
[0089] In step S402, the security protection device intercepts the first traffic sent by the first network element to the target management plane according to the first security policy.
[0090] In step S404, after determining that the first traffic is neither traffic from the target encrypted tunnel nor authentication traffic, the security protection device discards the first traffic according to the first security policy.
[0091] Step S406: After determining that the first traffic is authentication traffic, the security protection device allows the first traffic to pass through according to the first security policy.
[0092] In step S408, the edge management surface receives the first traffic from the security protection device.
[0093] In step S410, the edge management plane sends the first traffic to the core network management plane through the out-of-band network management channel so that the core network management plane can process the first traffic.
[0094] In other embodiments, the first traffic flow may carry management control information for controlling other network elements within the core network management plane. Upon receiving the first traffic flow, the core network management plane can then control and manage other network elements in the traffic control system protecting the out-of-band network management channel based on the control information contained within it.
[0095] The technical solution provided in the above embodiments, by defaulting all traffic to untrusted by the security protection device and performing security verification on each untrusted traffic, ensures that every force received by the target management plane is safe and reliable, thereby preventing the first network element from attacking the target management plane or the network element controlled by the target management plane through the first traffic and improving the security of traffic transmission in the out-of-band network management channel.
[0096] This disclosure provides a flow control system for protecting out-of-band network management channels. The flow control system for protecting out-of-band network management channels may include a target management plane and a first network element. The first network element is managed by the target management plane. A security protection device is deployed at the entrance of the target management plane, and a first security policy is deployed in the security protection device.
[0097] The security protection device can be used to intercept the first traffic sent by the first network element to the target management plane according to the first security policy; the security protection device can also be used to discard the first traffic after determining that the first traffic is neither traffic from the target encrypted tunnel nor authentication traffic according to the first security policy; the security protection device can also be used to allow the first traffic to pass through after determining that the first traffic is traffic from the target encrypted tunnel or authentication traffic according to the first security policy, so that the target management plane can receive and process the first traffic; wherein, the target encrypted tunnel is an encrypted tunnel established between the first network element and the security protection device after passing security authentication, and the authentication traffic is traffic used for security authentication.
[0098] The security protection device is also used to, after intercepting the first traffic sent by the first network element to the target management plane, default the first traffic to be untrusted according to the first security policy, and perform security verification on the first traffic according to the first security policy to determine whether the first traffic is traffic from the target encrypted tunnel or whether it is authenticated traffic.
[0099] In some embodiments, the target management plane, security protection equipment and the first network element in the related technologies can be modified by hardware to implement the system or method provided in the above embodiments. Alternatively, the following components can be used to implement the system or method provided in the above embodiments: deploy a trusted security component on the first network element and deploy a security management component in the target management plane.
[0100] The trusted security component can include modules such as authentication management, encryption / decryption, security monitoring, and status reporting. Its main functions are as follows: generating authentication traffic carrying digital signatures based on the device ID, MAC, IP, and location information built into the sinking network element device, and sending authentication requests carrying this authentication traffic to the security management component; establishing an encrypted tunnel between the sinking network element and the access / aggregation firewall; encrypting / decrypting the traffic sent / received by the management interface corresponding to the network element; and performing real-time security monitoring of the network element's operating environment and periodically reporting the operating environment status to the edge management plane / core management plane.
[0101] The security management component can run on the target management plane and may include modules such as user identity management, authentication and authorization management, and policy management. Its main functions are as follows: authenticating and authorizing authentication requests issued by network element devices; issuing security control policies to security protection devices (such as firewalls), by default treating all traffic intercepted by the security protection device as untrusted traffic, and instructing the security protection device to verify all intercepted traffic in sequence, allowing authenticated traffic or traffic from encrypted tunnels to pass through, and discarding traffic that is neither authenticated nor from encrypted tunnels; and controlling the management channels (such as out-of-band network management channels) between security protection device network elements, allowing only authenticated network elements to establish encrypted tunnels with the security protection device.
[0102] In addition, a security upgrade is required for the integrated security protection system. The upgraded security protection device can open a management interface to the security management component, accept the security policies issued by it, configure security policies to allow only authenticated traffic and encrypted tunnel traffic to pass through, process and forward encrypted tunnel traffic, and discard traffic that is neither authenticated traffic nor from the encrypted tunnel.
[0103] The following will describe, with reference to specific embodiments, how to implement the system or method provided in the above embodiments using the above components.
[0104] Figure 5 A flow control system for protecting out-of-band network managed channels is provided. For example... Figure 5 As shown, the traffic control system for the protection band out-of-band network management channel may include a 5G core network management plane, an edge management plane, and a sinking network element (an example of the first network element, which may be, for example, an MEC function network element, a UPF function network element, or an NEVI function network element) that sinks to an untrusted area (e.g., an enterprise campus).
[0105] Among them, the 5G core network management plane can control and manage functional network elements such as UDM (Unified Data Management), AUSF (Authentication Server Function), PCF (Policy Control Function), UPF, AMF (Authentication Management Function), and SMF (Session Management Function).
[0106] Before the aforementioned subdivided network elements go online, a trusted security component with a built-in device ID is deployed and enabled within these subdivided network elements. This security management component can perform network element identity management, authentication management, authorization management, and policy management.
[0107] In addition, a security management component can be deployed on the aforementioned edge management plane, and relevant information about the sinking network element can be entered, including device ID, MAC address, IP address, and network element location. The firewalls deployed at the edge management plane resource pool ingress / egress points (one type of security protection is merging) are upgraded to open management interfaces to the security management component, accepting security policies issued by it. Simultaneously, the following security policies are configured: allow authentication traffic from the sinking network element to the edge management plane to pass through; allow traffic from the encrypted tunnel to be processed and passed locally (encrypted tunnels can choose IPSec (IP security protocol), TLS (Transport Layer Security protocol), etc.); and discard traffic that is neither authentication traffic nor originating from the encrypted tunnel.
[0108] Figure 6 This is a timing diagram illustrating a flow control method for protecting out-of-band network management channels according to an exemplary embodiment.
[0109] Combination Figure 6 Can be Figure 5 The flow control method for the outer protection zone network channel corresponding to the flow control system shown is explained.
[0110] refer to Figure 6 The above-mentioned method for controlling the flow of the protected external network channel may include the following steps.
[0111] 1. The trusted security component in the sinking network element generates a digital signature based on the device ID, key parameters, MAC address, IP address, location information, and other information built into the sinking network element device, and sends an authentication request (carrying authentication traffic) to the security management component.
[0112] 2. A firewall (a type of security protection device) treats all traffic as untrusted by default. It then determines whether traffic coming from the untrusted zone is authenticated or encrypted tunnel traffic. If it is authenticated traffic, the firewall allows it to pass; otherwise, it blocks it. This solves the problem of hackers using the untrusted zone as a springboard to laterally penetrate the core network management plane.
[0113] 3. The firewall allows authentication requests carrying authentication traffic to pass through;
[0114] 4. The security management component in the edge management plane parses the authentication request sent by the sinking network element, uses the public key of the sinking network element to decrypt the digital signature, and compares it with the information entered before the sinking network element went online (device ID, MAC, IP, network element location, etc.) to confirm whether the information carried in the authentication request is correct.
[0115] 5. If authentication is successful, the security management component authorizes the communication of the sinking network element, issues security policies to it through the firewall's management interface, allows the firewall to establish an encrypted tunnel with the network element, and sends relevant information about the network element to the firewall.
[0116] 6. If authentication fails, the security management component notifies the firewall that it cannot establish an encrypted tunnel with the network element.
[0117] 7. If authentication is successful, the firewall will send the authentication success information to the downstream network element.
[0118] 8. The trusted security component uses the key parameters from the authentication phase to establish an encrypted tunnel with the firewall.
[0119] 9. The firewall determines whether the end that initiates the tunnel establishment request is an authenticated network element.
[0120] 10. If the tunnel establishment request is initiated by an authenticated network element, then agree to establish an encrypted tunnel.
[0121] 11. If the tunnel establishment request is not initiated by an authenticated network element, the establishment of an encrypted tunnel with it will be rejected.
[0122] 12. Once the encrypted tunnel is successfully established, the sinking network element transmits management information such as alarms, performance, resource configuration, version, and logs to the edge management plane through the encrypted tunnel.
[0123] 13. The firewall determines whether traffic sent from an untrusted area is authenticated traffic or encrypted tunnel traffic.
[0124] 14. The firewall identifies the traffic as encrypted tunnel traffic, decrypts the encrypted tunnel traffic, and allows the decrypted traffic to pass.
[0125] 15. The sinking network element regularly reports its security status information to the edge management plane through an encrypted tunnel, monitors the security status of the sinking network element, and sends an alarm to the administrator if an anomaly is detected, thereby ensuring the security of the sinking network element.
[0126] The technical solution provided in this embodiment has the following technical effects: it can effectively confirm the identity and credibility of the sinking network element; it can prevent the sinking network element from attacking the edge management plane (or core network management plane) and other network elements; it can improve the security of data transmission between the sinking network element and the edge management plane; in addition, this embodiment only requires software upgrades to the management interface of the sinking network element and its management plane system, and the deployment of security policies on the resource pool ingress / egress firewalls. No hardware modification is required, there are no special hardware requirements, it is simple to implement, and there is no need to add existing network hardware equipment, resulting in low cost, minimal modification, and easy implementation.
[0127] In summary, this application organically combines authentication, encryption, and whitelisting mechanisms to provide a completely new security protection mechanism for subsurface network elements and management channels. It eliminates the security risks arising from subsurface network elements being located in untrusted areas and untrusted and trusted management traffic sharing channels, rendering attacks such as attacks on subsurface network elements, attacks impersonating subsurface network elements, and man-in-the-middle attacks ineffective.
[0128] Furthermore, this disclosure separates control (security management components) and security policy enforcement (firewalls) for flexible deployment. Control can be deployed centrally, while the security policy enforcement unit can be deployed in a segmented manner. Regardless of where the untrusted network element is deployed, as long as its management plane can access the corresponding security policy enforcement unit through the network, the security of the management plane of the untrusted network element can be ensured, meeting the deployment requirements of untrusted network elements in various business scenarios.
[0129] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0130] Furthermore, the above figures are merely illustrative of the processes included in the method according to exemplary embodiments of this disclosure and are not intended to be limiting. It is readily understood that the processes shown in the above figures do not indicate or limit the temporal order of these processes. Additionally, it is readily understood that these processes may be executed synchronously or asynchronously, for example, in multiple modules.
[0131] Through the above description of the embodiments, those skilled in the art will readily understand that the exemplary embodiments described herein can be implemented by software or by combining software with necessary hardware.
[0132] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not claimed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this disclosure are indicated by the claims.
[0133] It should be understood that this disclosure is not limited to the detailed structures, drawing arrangements or implementations shown herein; rather, this disclosure is intended to cover various modifications and equivalent arrangements contained within the spirit and scope of the appended claims.
Claims
1. A traffic control method for protecting an out-of-band network management channel, characterized by, The traffic control system for protecting out-of-band network management channels includes a target management plane and a first network element. The first network element is managed by the target management plane. A security protection device is deployed at the entrance of the target management plane, and a first security policy is deployed in the security protection device. The traffic control system is a network management system used by operators to manage communication networks, including a core network management plane, an edge management plane, and a subdivided network element that extends to an untrusted area. The target management plane is the edge management plane, and the first network element is the subdivided network element. The method includes: The security protection device intercepts all first traffic sent from the first network element to the target management plane according to the first security policy, and defaults all first traffic as untrusted traffic; The security protection device performs security verification on the first traffic to determine whether the first traffic is traffic from the target encrypted tunnel or whether it is authentication traffic; After determining that the first traffic is neither traffic from the target encrypted tunnel nor authentication traffic, the security protection device discards the first traffic according to the first security policy; After determining that the first traffic is traffic from the target encrypted tunnel or authentication traffic, the security protection device allows the first traffic to pass through according to the first security policy, so that the target management plane can receive and process the first traffic; The target encrypted tunnel is an encrypted tunnel established between the first network element and the security protection device after the first network element passes security authentication, and the authentication traffic is traffic used for security authentication. When the first traffic is authentication traffic, the target management plane receives the first traffic from the security protection device; after determining that the first traffic is authentication traffic, the target management plane performs security authentication processing on the first traffic; after the first traffic passes security authentication, the target management plane dynamically issues a second security policy to the security protection device to notify the security protection device to establish the target encrypted tunnel with the first network element, so that the first network element and the security protection device can transmit traffic through the target encrypted tunnel; after the first traffic fails security authentication, the target management plane issues a third policy to the security protection device to notify the security protection device not to establish the target encrypted tunnel with the first network element.
2. The method of claim 1, wherein, The first security policy assumes that all traffic intercepted by the security protection device is untrusted traffic, and instructs the security protection device to verify all intercepted traffic in sequence, allowing verified traffic or traffic from the encrypted tunnel to pass through, and discarding traffic that is neither verified nor from the encrypted tunnel.
3. The method of claim 1, wherein, The target management plane includes security authentication information for multiple security network elements. This security authentication information is synchronized to the target management plane by the multiple security network elements before deployment. The first traffic carries the security authentication information of the first network element. The target management plane performs security authentication processing on the first traffic, including: The target management plane matches the security authentication information of the first network element with the security authentication information of the plurality of security network elements; If the match is successful, it is determined that the first traffic has passed security authentication.
4. The method of claim 1, wherein, The target management plane is the edge management plane in the traffic control system of the out-of-band network management channel. The traffic control system of the out-of-band network management channel also includes a core network management plane. The first traffic is traffic from the target encrypted tunnel. The target management plane receives and processes the first traffic, including: The edge management surface receives the first traffic from the security protection device; The edge management plane sends the first traffic to the core network management plane through an out-of-band network management channel, so that the core network management plane can process the first traffic.
5. The method of claim 1, wherein, The first traffic is encrypted traffic from the target encrypted tunnel; wherein, the security protection device allows the first traffic to pass through, including: The security protection device obtains the public key of the first network element; The security device decrypts the first traffic using the public key; The security protection device allows the first traffic after decryption to pass through.
6. The method of claim 1, wherein, The first traffic is authentication traffic; a trusted security component is deployed in the first network element; and a security management component is deployed in the target management plane. The trusted security component is used to generate the first traffic based on the network element information of the first network element, so as to initiate security authentication to the target management plane through the first traffic; The trusted security component is also used to perform security monitoring on the first network element and periodically report the operating environment status of the first network element to the target management plane; The security management component is used to perform security authentication on the first traffic, and after the first traffic passes the security authentication, it issues a security policy to the security protection device to enable the security protection device to establish the target encrypted tunnel with the first network element.
7. A flow control system for protecting out-of-band network channels, characterized in that, The traffic control system for the protected out-of-band network management channel includes a target management plane and a first network element. The first network element is managed by the target management plane. A security protection device is deployed at the entrance of the target management plane, and a first security policy is deployed in the security protection device. The traffic control system is a network management system for operators to manage communication networks, including a core network management plane, an edge management plane, and a substation network element that extends to an untrusted area. The target management plane is the edge management plane, and the first network element is the substation network element. The security protection device is used to intercept all first traffic sent by the first network element to the target management plane according to the first security policy, and to default all first traffic as untrusted traffic; to perform security verification on the first traffic to determine whether the first traffic is traffic from the target encrypted tunnel or whether it is authenticated traffic; The security protection device is also used to discard the first traffic after determining, according to the first security policy, that the first traffic is neither traffic from the target encrypted tunnel nor authentication traffic; The security protection device is further configured to allow the first traffic to pass through after determining, according to the first security policy, whether the first traffic is traffic from the target encrypted tunnel or authentication traffic, so that the target management plane can receive and process the first traffic; wherein, the target encrypted tunnel is an encrypted tunnel established between the first network element and the security protection device after passing security authentication, and the authentication traffic is traffic used for security authentication; Wherein, when the first traffic is authentication traffic, the target management plane is further configured to receive the first traffic from the security protection device; after determining that the first traffic is authentication traffic, the target management plane performs security authentication processing on the first traffic; after the first traffic passes security authentication, the target management plane dynamically issues a second security policy to the security protection device to notify the security protection device to establish the target encrypted tunnel with the first network element, so that the first network element and the security protection device can transmit traffic through the target encrypted tunnel; after the first traffic fails security authentication, the target management plane issues a third policy to the security protection device to notify the security protection device not to establish the target encrypted tunnel with the first network element.