A message transmission method, a network virtualization edge device and a storage medium

By introducing VSID and key version fields into the NVGRE header to indicate encryption requirements, encryption is only applied to service packets that meet the length threshold, thus solving the problems of insufficient transmission security and high network overhead in NVGRE tunnels and achieving efficient encrypted transmission and flow control.

CN117201639BActive Publication Date: 2026-05-15CHINA MOBILEHANGZHOUINFORMATION TECH CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA MOBILEHANGZHOUINFORMATION TECH CO LTD
Filing Date
2022-05-31
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

The existing NVGRE tunnels have insufficient security for service packet transmission, and the encapsulation process results in high network overhead, making it impossible to effectively perform load balancing and flow control.

Method used

By introducing VSID and key version fields into the NVGRE header to indicate encryption requirements, only business messages that meet the length threshold are encrypted. The existing NVGRE header flag field is used to indicate whether encryption is required, avoiding additional encapsulation. A symmetric encryption algorithm is used for encryption.

Benefits of technology

It reduces the number of layers in the encapsulated message, lowers network resource overhead, ensures transmission security, and improves the identification efficiency and flow control capabilities of the NVGRE network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117201639B_ABST
    Figure CN117201639B_ABST
Patent Text Reader

Abstract

The application discloses a message transmission method, which comprises the following steps: receiving a service message sent by any one of a plurality of subnets connected with a first network virtual edge device, and assembling an NVGRE header for the service message; in the case that a VSID in a VSID field and a key version number in a key version field jointly indicate that the service message needs to be encrypted, obtaining the service message satisfying a length threshold, and encrypting the service message satisfying the length threshold to obtain an encrypted service message; and sending the encrypted service message to a second network virtual edge device. The application also discloses a message transmission device, a first network virtual edge device, a second network virtual edge device and a computer readable storage medium.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to, but is not limited to, the field of computers, and particularly to a message transmission method, a first network virtualization edge device, a second network virtualization edge device, and a computer-readable storage medium. Background Technology

[0002] Network Virtualization using Generic Routing Encapsulation (NVGRE) is a Layer 2 Virtual Private Network (VPN) technology that uses Media Access Control Addresses (MACs) in GRE encapsulation. Using the NVGRE protocol, two local area networks (LANs) located in different geographical locations can be connected into a single virtual Layer 2 LAN. Network virtualization edge devices (NVEs) are the edge devices of an NVGRE network, responsible for encapsulating or decapsulating service packets transmitted within the NVGRE tunnel; the NVGRE protocol itself does not possess security capabilities.

[0003] In related technologies, to ensure the security of service message transmission within the NVGRE tunnel, Internet Protocol Security (IPsec) technology is used to encapsulate the service message data before transmission. For example, an additional Encapsulating Security Payload (ESP) header, an Internet Protocol (IP) header, and an ESP trailer are added. As a result, the encapsulated message has multiple layers, which leads to a large network overhead during transmission. Summary of the Invention

[0004] This application provides a message transmission method, a first network virtual edge device, a second network virtual edge device, and a computer-readable storage medium.

[0005] Firstly, a message transmission method is provided, including:

[0006] Receive service packets sent from any one of the multiple subnets connected to the first network virtual edge device, and assemble a network virtualization NVGRE header using general routing encapsulation for the service packets, wherein the NVGRE header includes a virtual subnet identifier (VSID) field and a key version field;

[0007] When the VSID in the VSID field and the key version number in the key version field jointly indicate that the service message needs to be encrypted, a service message that meets the length threshold is obtained, and the service message that meets the length threshold is encrypted to obtain an encrypted service message.

[0008] The encrypted service message is sent to the second network virtual edge device.

[0009] Secondly, a message transmission method is provided, including:

[0010] Receive service packets sent by a first network virtualization edge device; wherein the service packets have an NVGRE header, and the NVGRE header is assembled by the first network virtualization edge device for any service packets sent by any subnet received;

[0011] If the value of the second bit of the flag field in the NVGRE header is 1, it is determined that the service message is obtained by the first network virtualization edge device encrypting the service message that meets the length threshold, where the VSID in the VSID field and the key version number in the key version field of the NVGRE header jointly indicate that the service message needs to be encrypted.

[0012] Thirdly, a first network virtualization edge device is provided, the first network virtualization edge device comprising:

[0013] The first receiving module is configured to receive service packets sent by any one of the multiple subnets connected to the first network virtual edge device.

[0014] The first processing module is used to assemble a Network Virtualization (NVGRE) header using general routing encapsulation for the service message, wherein the NVGRE header includes a Virtual Subnet Identifier (VSID) field and a key version field;

[0015] The first processing module is further configured to, when the VSID in the VSID field and the key version number in the key version field jointly indicate that the service message needs to be encrypted, obtain a service message that meets the length threshold, and encrypt the service message that meets the length threshold to obtain an encrypted service message.

[0016] The first sending module is used to send the encrypted service message to the second network virtual edge device.

[0017] Fourthly, a second network virtualization edge device is provided, the second network virtualization edge device comprising:

[0018] The second receiving module is used to receive service packets sent by the first network virtualization edge device, wherein the service packets have an NVGRE header, and the NVGRE header is assembled by the first network virtualization edge device for any service packets sent by any subnet received;

[0019] The second processing module is used to encrypt a service message that meets the length threshold if the value of the second bit of the flag field in the NVGRE header is 1, indicating that the service message needs to be encrypted as jointly indicated by the VSID in the VSID field and the key version number in the key version field of the NVGRE header.

[0020] Fifthly, a first network virtualization edge device is provided, the first network virtualization edge device comprising: a first processor and a first memory, the first memory being used to store computer programs, and the first processor being used to call and run the computer programs stored in the first memory to execute the above-described message transmission method.

[0021] In a sixth aspect, a second network virtualization edge device is provided, the second network virtualization edge device comprising: a second processor and a second memory, the second memory being used to store computer programs, and the second processor being used to call and run the computer programs stored in the second memory to execute the above-described message transmission method.

[0022] In a seventh aspect, a computer-readable storage medium is provided for storing a computer program that causes a computer to perform the above-described message transmission method.

[0023] This application provides a message transmission method, a first network virtualization edge device, a second network virtualization edge device, and a computer-readable storage medium. The method involves receiving service messages from any subnet among multiple subnets connected to the first network virtualization edge device, and assembling a Network Virtualization (NVGRE) header using general routing encapsulation for the service message. The NVGRE header includes a Virtual Subnet Identifier (VSID) field and a key version field. If the VSID in the VSID field and the key version number in the key version field jointly indicate that the service message requires encryption, a service message meeting a length threshold is obtained and encrypted. The encrypted service message is then sent to the second network virtualization edge device. In other words, when the first network virtualization edge device receives a service message and encryption is required, it only encrypts the service message meeting the length threshold, without adding an extra layer or multiple layers of message headers or trailers. This reduces the number of layers in the encapsulated message and lowers network resource overhead during transmission, achieving encrypted transmission between the first and second network virtualization edge devices. Attached Figure Description

[0024] Figure 1 A schematic diagram of the network architecture for implementing the message transmission method provided in this application embodiment;

[0025] Figure 2 This is a schematic diagram of the NVGRE message encapsulation format in related technologies;

[0026] Figure 3 This is a schematic diagram illustrating the packet encapsulation format of NVGRE using the ESP tunnel mode encapsulation method with only encryption and no HMAC authentication in related technologies.

[0027] Figure 4 A schematic diagram of an implementation flow of the message transmission method provided in the embodiments of this application. Figure 1 ;

[0028] Figure 5 A schematic diagram of an implementation flow of the message transmission method provided in the embodiments of this application. Figure 2 ;

[0029] Figure 6 A schematic diagram of the NVGRE message encapsulation format provided in the embodiments of this application;

[0030] Figure 7 Schematic diagram of the structure of the first network virtualization edge device provided in the embodiments of this application Figure 1 ;

[0031] Figure 8 Schematic diagram of the structure of the first network virtualization edge device provided in the embodiments of this application Figure 2;

[0032] Figure 9 Schematic diagram of the structure of the second network virtualization edge device provided in the embodiments of this application Figure 1 ;

[0033] Figure 10 Schematic diagram of the structure of the second network virtualization edge device provided in the embodiments of this application Figure 2 . Detailed Implementation

[0034] The technical solutions of the embodiments of this application will now be described with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.

[0035] See Figure 1 , Figure 1 This is a schematic diagram of the network architecture for implementing the message transmission method provided in this application. The network architecture includes at least a first network virtualization edge device 100, a second network virtualization edge device 200, and a network 300; wherein the first network virtualization edge device 100 and the second network virtualization edge device 200 are connected through the network 300. The network virtualization edge device is a network entity that implements network virtualization functions, capable of identifying the NVGRE network to which an Ethernet data frame belongs, performing Layer 2 forwarding of the data frame based on NVGRE, and encapsulating / decapsulating messages. When encapsulating service messages, the network virtualization edge device adds an 8-byte NVGRE header, an IP header, and a data link layer header to the service message. Figure 2 This is a schematic diagram of the NV GRE message encapsulation format in related technologies. For example... Figure 2As shown, the NVGRE header includes a flag field, a reserved field, a version field, a protocol type field, a Virtual Subnet Identifier (VSID) field, and a Flow ID field. The flag field occupies 4 bits: the first bit is the Checksum Present bit, always 0, indicating the GRE header does not carry a GRE checksum; the second bit is undefined; the third bit is the KeyPresent bit, always 1, indicating the GRE header carries a VSID; and the fourth bit is the SequenceNumber Present bit, always 0, indicating the GRE header does not carry a sequence number. The reserved field occupies 9 bits. The version field occupies 3 bits and represents the GRE protocol version number. The protocol type field occupies 16 bits and represents the protocol type of the payload data encapsulated within the GRE header, always 0x6558, indicating transparent Ethernet bridging, i.e., Layer 2 Ethernet data frames are encapsulated within the GRE header. The VSID field occupies 24 bits and is used to identify an NVGRE subnet. The Flow ID field occupies 8 bits and is used to identify a flow.

[0036] Network virtualization edge devices are distributed throughout the entire network's 300 coverage area and can be stationary or mobile. Network virtualization edge devices include, but are not limited to, smartphones, tablets, laptops, PDAs, personal digital assistants (PDAs), navigation devices, user equipment (UEs), single servers or server clusters consisting of multiple servers, and cloud computing centers. Network 300 can be a wireless communication network using any communication standard or protocol, including but not limited to Global System for Mobile Communications (GSM), General Packet Radio Service (GPRS), Code Division Multiple Access 2000 (CDMA2000), Wideband Code Division Multiple Access (WCDMA), Time Division-Synchronous Code Division Multiple Access (TD-SCDMA), Long Term Evolution (LTE), the 4th Generation Mobile Communication Technology (4G), and the 5th Generation Mobile Communication Technology (5G).

[0037] In related technologies, to ensure the secure transmission of service packets within an NVGRE tunnel, IPsec technology is used to encapsulate the service packet data before transmission. This utilizes NVGRE over IPSec to ensure secure data communication between virtual Layer 2 tunnels. Taking the encapsulation method of the ESP tunnel mode, which uses only encryption and no key-related hash-based Message Authentication Code (HMAC) authentication in IPSec as an example... Figure 3 This is a schematic diagram illustrating the NVGRE message encapsulation format using the ESP tunnel mode encapsulation method with only encryption and no HMAC authentication in related technologies, such as... Figure 3As shown, after the NVGRE tunnel encapsulation is complete (i.e., after the outer IP header of the NVGRE encapsulation), an ESP header and another IP header are encapsulated on the outside, and an ESP trailer is encapsulated at the end. Therefore, to ensure the NVGRE tunnel has secure transmission characteristics, at least one additional ESP header, one IP header, and one ESP trailer are required during encryption encapsulation. This results in multiple layers of packet encapsulation, a long processing flow, and high network overhead. Furthermore, the NVGRE over IPSec encapsulation method also encrypts the NVGRE header. Since IPSec tunnels are point-to-point encrypted tunnels, forwarding devices cannot know the IPSec key. Therefore, load balancers, firewalls, routers, and other forwarding devices during transmission cannot extract the NVGRE tunnel's VSID because they do not know the NVGRE's IPSec key. Consequently, they cannot participate in NVGRE network routing optimization and cannot effectively control the flow of NVGRE services. Furthermore, when an NVE device needs to extract the VSID, it can only extract it after decrypting the entire IPSec packet. It cannot quickly extract it from the packet as soon as it arrives, resulting in low efficiency of NVGRE network identification.

[0038] See Figure 4 , Figure 4 This is a schematic diagram illustrating an implementation flow of the message transmission method provided in this application embodiment. This message transmission method can be applied to... Figure 1 The network architecture shown; the message transmission method includes the following steps:

[0039] Step 401: The first network virtualization edge device receives a service message sent by any one of the multiple subnets connected to the first network virtual edge device.

[0040] In this embodiment, devices connected to Layer 2 or Layer 3 switch ports are logically segmented, i.e., divided into different subnets. The first network virtual edge device receives service packets sent by devices in any of the multiple subnets connected to it. Here, the service packet is also referred to as the service payload or the original Layer 2 data frame.

[0041] Step 402: The first network virtualization edge device assembles the NVGRE header for the service packet.

[0042] The NVGRE header includes a VSID field and a key version field.

[0043] In this embodiment, after receiving a service packet, the first network virtualization edge device queries the MAC table to identify the subnet to which the service packet belongs and records the VSID of the subnet. Further, the first network virtualization edge device sends the service packet into the NVGRE encapsulation process. The NVGRE encapsulation module assembles the NVGRE header for the service packet.

[0044] Step 403: When the VSID in the VSID field and the key version number in the key version field jointly indicate that the service message needs to be encrypted, the first network virtualization edge device obtains the service message that meets the length threshold.

[0045] In this embodiment of the application, the VSID indicating that the service message needs to be encrypted can be achieved by indexing the key information of the subnet to which the service message belongs through the VSID; that is, this application reuses the VSID, which can both indicate the subnet to which the service message belongs and index the key information of the subnet to which the service message belongs.

[0046] In other embodiments of this application, when the service message needs to be encrypted, the NVGRE encapsulation module assembles an NVGRE header for the service message, including at least a flag bit field, a key version field, a version field, a protocol type field, a VSID field, and a stream ID field; wherein, the second bit in the flag bit field is used to indicate whether the message has been encrypted.

[0047] In some embodiments, when the VSID in the VSID field is not associated with the corresponding key information, the encapsulation module assembles an NVGRE header for the service message, including a flag bit field, a reserved field, a version field, a protocol type field, a VSID field, and a stream ID field; wherein, the second bit in the flag bit field is set to 0.

[0048] In this embodiment of the application, the service message that meets the length threshold includes the original message of the service message sent by any subnet when the length threshold is met, or the service message sent by any subnet when the length threshold is not met, the original message is padded to obtain the service message that meets the length threshold.

[0049] In this embodiment, step 402 can be executed before step 403, that is, the first network virtualization edge device can first encapsulate an NVGRE header for the service packet, and then adjust the NVGRE header when the service packet needs to be encrypted; of course, step 402 can be executed after step 403, that is, the NVGRE header is assembled for the service packet when the service packet needs to be encrypted; this application does not specifically limit this.

[0050] Step 404: The first network virtualization edge device encrypts the service packets that meet the length threshold to obtain the encrypted service packets.

[0051] In this embodiment, the first network virtualization edge device uses an encryption algorithm to encrypt service packets that meet the length threshold, obtaining encrypted service packets. Here, the encryption algorithm includes symmetric encryption algorithms and asymmetric encryption algorithms.

[0052] In some embodiments, when the second bit in the identifier field of the NVGRE header is 1, the service message is encrypted and encapsulated using encryption technology.

[0053] Step 405: The first network virtualization edge device sends the encrypted service message to the second network virtual edge device.

[0054] In this embodiment of the application, after the service message is encrypted, the first network virtualization edge device encapsulates the encrypted service message with an outer IP header and an outer Layer 2 header, and then sends the encapsulated message to the second network virtualization edge device.

[0055] In some embodiments, if the VSID in the VSID field is not associated with the corresponding key information, the first network virtualization edge device sends the service message in plaintext, or blocks and waits for the key information to arrive, or directly discards the service message.

[0056] Step 406: The second network virtual edge device receives the service message sent by the first network virtualization edge device.

[0057] The service message has an NVGRE header, which is assembled by the first network virtualization edge device for any service message sent by any subnet.

[0058] Step 407: If the value of the second bit of the flag field in the NVGRE header is 1, and the second network virtual edge device determines that the service message is required to be encrypted as indicated by the VSID in the VSID field and the key version number in the key version field of the NVGRE header, the first network virtualization edge device encrypts the service message that meets the length threshold.

[0059] In this embodiment, after receiving a service packet, the second network virtual edge device verifies the service packet. Upon successful verification, the decapsulation module strips the outer Layer 2 header and outer IP header. Furthermore, the second network virtual edge device verifies the NVGRE tunnel. After successful NVGRE tunnel verification, the decapsulation module strips fields from the NVGRE header, such as the flag field, version field, VSID field, and protocol type field.

[0060] In this embodiment, the NVGRE tunnel is a point-to-point logical tunnel between two NVEs. After encapsulating the data frame with an NVGRE header and an IP header, the NVE transparently forwards the encapsulated message to the remote NVE through the NVGRE tunnel, where the remote NVE decapsulates it.

[0061] Here, if the value of the second bit of the flag field is 1, the service message is an encrypted service message; if the value of the second bit of the flag field is 0, the service message is an unencrypted service message. This application utilizes the undefined second bit in the NVGRE header flag field of related technologies, using the value of the second bit to indicate whether the service message is encrypted. In other words, this application uses the existing NVGRE header to notify the second network virtual edge device whether the service message is encrypted, without introducing additional overhead.

[0062] This application provides a message transmission method that receives service messages from any subnet among multiple subnets connected to a first network virtual edge device, and assembles a Network Virtualization (NVGRE) header using general routing encapsulation for the service message. The NVGRE header includes a Virtual Subnet Identifier (VSID) field and a key version field. If the VSID in the VSID field and the key version number in the key version field both indicate that the service message needs encryption, a service message meeting a length threshold is obtained, and this length-threshold-compliant service message is encrypted to obtain an encrypted service message. The encrypted service message is then sent to a second network virtual edge device. In other words, when the first network virtual edge device receives a service message, if encryption is required, it only encrypts service messages meeting the length threshold, without adding an extra layer or layer of message headers or trailers. This reduces the number of layers in the encapsulated message, lowering network resource overhead during transmission. It achieves encrypted transmission between the first and second network virtual edge devices, ensuring that data exchanged between the internal networks corresponding to the network virtual edge devices is not exposed in plaintext on the public network, thus guaranteeing security during transmission. Furthermore, the encryption method in this application does not encrypt and encapsulate the NVGRE header. Thus, load balancers, firewalls, routers, and other forwarding devices during transmission can extract the VSID from the NVGRE header, enabling them to participate in NVGRE network routing optimization and perform effective flow control for NVGRE services. Moreover, when an NVGRE device needs to extract the VSID, it does not need to decrypt the entire packet; the VSID can be quickly extracted immediately upon packet arrival, resulting in high NVGRE network identification efficiency.

[0063] See Figure 5 , Figure 5 This is a schematic diagram illustrating an implementation flow of the message transmission method provided in this application embodiment. This message transmission method can be applied to... Figure 1 The network architecture shown; the message transmission method includes the following steps:

[0064] Step 501: The first network virtualization edge device receives a service message sent by any one of the multiple subnets connected to the first network virtual edge device.

[0065] Step 502: The first network virtualization edge device assembles the NVGRE header for the service packet.

[0066] The NVGRE header includes the Virtual Subnet Identifier (VSID) field and the Key Version field.

[0067] Step 503: When the VSID in the VSID field and the key version number in the key version field jointly indicate that the service message needs to be encrypted, the first network virtualization edge device determines the key information of the service message indexed by the VSID.

[0068] The key information includes the block length of the encryption algorithm.

[0069] In this embodiment, the key information used for encrypting and decrypting service messages (i.e., the key information used by the encryption algorithm to encrypt and decrypt the service messages) is marked by a VSID, which is also reused as the ID of the index key. The same key information is used within the same NVGRE subnet (i.e., NVGRE networks with the same VSID). The key is direction-insensitive; all NVE encryption keys and decryption keys within the same NVGRE subnet are identical.

[0070] In this embodiment of the application, VSID is used not only to identify an NVGRE subnet, but also to index the key information used by this NVGRE subnet.

[0071] In this embodiment, the encapsulation module in the first network virtualization edge device uses the VSID to index the key information of the subnet to which the service packet belongs. In other words, this application reuses the VSID, which can both indicate the subnet to which the service packet belongs and index the key information of that subnet.

[0072] In this embodiment, the key information of each network virtual edge device is distributed centrally. This distribution can be done statically or dynamically through a key management platform. All network virtual edge devices receive identical key information. However, the key version numbers used in different rounds of key distribution need to be differentiated.

[0073] Step 504: The first network virtualization edge device obtains service packets that meet the length threshold based on the block length.

[0074] In this embodiment, when the service message needs to be encrypted, the encapsulation module extracts the specific symmetric encryption algorithm and the block length of the symmetric encryption algorithm from the key information. Further, based on the block length, a service message that meets the length threshold is obtained.

[0075] It should be noted that the encapsulation module can also extract the key version number, whether it is in Cipher Block Chaining (CBC) mode, Counter mode (CounTeR, CTR) mode, Output-Feedback (OFB) mode, or Cipher Feedback (CFB) mode from the key information.

[0076] For example, if the length of the original service message sent by any subnet is an integer multiple of the block length, then the service message that meets the length threshold is the original service message sent by any subnet; if the length of the original service message sent by any subnet is not an integer multiple of the block length, then the service message that meets the length threshold is the service message obtained by padding the original service message. In other words, the length of the service message that meets the length threshold is greater than or equal to the length of the original service message sent by any subnet.

[0077] For example, if the length of the original service message sent by any subnet is equal to the block length, then the service message that meets the length threshold is the original service message sent by any subnet; if the length of the original service message sent by any subnet is not equal to the block length, then the service message that meets the length threshold is the service message obtained by padding the original service message.

[0078] In this embodiment of the application, step 504, based on the block length, obtains service packets that meet the length threshold, which can be achieved through the following steps:

[0079] Step A1: Obtain the first length of the service message.

[0080] Step A2: If the first remainder obtained by dividing the first length by the block length is not 0, obtain the fill data length value and the fill data.

[0081] In this embodiment, if the first remainder obtained by dividing the first length by the block length is not 1, the padding data length value and padding data are obtained; that is, if the original service message sent by any subnet is not an integer multiple of the block length, then the original service message sent by any subnet is not a service message that meets the length threshold, and the padding data length value and padding data need to be obtained. The padding data is then filled into the original service message sent by any subnet to obtain a service message that meets the length threshold. If the first remainder obtained by dividing the first length by the block length is 0, no padding data needs to be obtained; that is, if the original service message sent by any subnet is an integer multiple of the block length, then the original service message sent by any subnet is a service message that meets the length threshold.

[0082] In some embodiments, Figure 6 This is a schematic diagram of the NVGRE message encapsulation format in this application. For example... Figure 6 As shown, the NVGRE header includes a padding data length field and a padding data field. The padding data length field and the padding data field are combined to pad the length of the service message, ensuring that the length of the encrypted / decrypted service message is an integer multiple of the block length of the encryption algorithm. The padding data length field occupies one byte and has a value from 0x0 to 0xF. The padding data field is a variable-length field. When the service message needs encryption, and the first remainder obtained by dividing the first length by the block length is not zero, data is padded to the padding data field, and the data length value is padded to the padding data length field. The length of the data padded to the padding data field is the same as the length indicated by the padding data length field. Here, the padding data consists of the padding data in the padding data field and the length data in the padding data length field.

[0083] It should be noted that, Figure 6 The padding data field is optional. If the first remainder obtained by dividing the first length by the block length is 0, the padding data field does not exist, and the padding data length field takes the value 0x0.

[0084] In this embodiment of the application, the NVGRE header includes a padding field. Obtaining the padding data in step A2 can be achieved through the following steps:

[0085] Step B1: Determine the length indication information and the starting position indication information.

[0086] Among them, the length indicator information is used to indicate the length of the padding data in the business message; the start position indicator information is used to indicate the starting position of the padding data in the padding field.

[0087] It should be noted that the length indication information includes the length in the padding data length field plus the padding data length value.

[0088] Step B2: Obtain the fill data from the fill field based on the length indicator information and the start position indicator information.

[0089] In this embodiment, after determining the length indication information and the start position indication information, the first network virtualization edge device obtains the fill data from the fill field using the start position indicated by the start position indication information and the length indicated by the length indication information. Here, the fill data in the fill field can be pre-filled. As long as the fill field is pre-filled with data greater than the block length, the first network virtualization edge device can obtain the required fill data from the fill field.

[0090] In some embodiments, the padding field includes a padding data length field and a padding data field; the padding data length value is used to indicate the length of the data in the padding data field.

[0091] Step A3: Fill the data into the service message to obtain a service message that meets the length threshold.

[0092] It should be noted that, as Figure 6 As shown, a business message that meets the length threshold is the data obtained by filling the data in the fill data field and the length data in the fill data length field into the business message.

[0093] Step 505: The first network virtualization edge device uses a key to encrypt the service message that meets the length threshold, and obtains the encrypted service message.

[0094] In this embodiment, the key includes an encryption key and a decryption key. Here, the first network virtualization edge device uses the encryption key to encrypt service packets that meet the length threshold, obtaining encrypted service packets.

[0095] In this embodiment of the application, the key information also includes the block mode of the encryption algorithm. Step 505 uses the key to encrypt the service message that meets the length threshold to obtain the encrypted service message, which can be achieved through the following steps:

[0096] Step C1: If the grouping mode is the first type of grouping mode, obtain the IV data from the NVGRE header, including the initialization vector IV field.

[0097] In this application embodiment, the encryption algorithms for the first type of block mode include, but are not limited to, CBC, CTR, OFB, and CFB.

[0098] In this embodiment of the application, if the grouping mode is a first type of grouping mode, such as CBC / CTR / OFB / CFB mode, the encapsulation module fills the IV field in the NVGRE header.

[0099] like Figure 6As shown, the NVGRE header includes an IV field, used to store the IV required by symmetric encryption algorithms using Block I mode. Its length is equal to the block size of the encryption algorithm. The IV field is optional; it should be included when the encryption algorithm uses Block I mode. When the encryption algorithm uses Block II mode, this field is not included, meaning the encapsulation module does not need to fill the IV field in the NVGRE header. Block II mode encryption algorithms include, but are not limited to, Electronic Codebook (ECB).

[0100] In this embodiment of the application, IV data is used to assist the encryption algorithm of the first type of block mode in encryption; that is, the encryption algorithm of the first type of block mode needs to obtain IV data to encrypt the message. If there is no IV data, the message cannot be encrypted.

[0101] Step C2: Based on the IV data and the key, perform encryption operations on each block of data in the service message that meets the length threshold to obtain the encrypted service message.

[0102] Step 506: The first network virtualization edge device defines the second bit in the tag field of the NVGRE header as the encryption tag bit.

[0103] When the encryption flag is set to 1, it indicates that the service message has been encrypted; when the encryption flag is set to 0, it indicates that the service message has not been encrypted.

[0104] In the embodiments of this application, such as Figure 6 As shown, the first network virtualization edge device defines the second bit 601 in the tag field of the NVGRE header as the encryption tag bit.

[0105] In some embodiments, step 506 can be performed before step 503, i.e., when assembling the NVGRE header for the service packet in step 502, by directly setting the value of the second bit in the flag field of the NVGRE header to 1. In this case, the first network virtualization edge device directly uses encryption technology to encrypt and encapsulate the service packet, without needing to use a VSID to indicate whether the service packet needs encryption. During encryption, the key information indexed by the VSID is directly used to process the service packet.

[0106] Step 507: The first network virtualization edge device adds a key version number to the NVGRE header, including the key version field.

[0107] like Figure 6As shown, the NVGRE header of this application includes a key version field. It should be noted that the key version field reuses a reserved field from the NVGRE header in related technologies. This application utilizes the 9 reserved bits (bits 5 to 13) of the NVGRE header in related technologies, naming it the key version field, to identify the key version of the same NVGRE subnet (i.e., NVGRE networks with the same VSID). The key has an expiration date; when the NVGRE subnet changes its key, the key version also changes. The key version field is used to resolve key alignment issues during key changes.

[0108] It should be noted that the key version number changes with each round of key information distribution. Within the same round of distribution, each NVE receives the same key version number.

[0109] In this embodiment, when the service message needs to be encrypted, and the first remainder obtained by dividing the first length of the service message by the block length is not 0, and the block mode of the encryption algorithm is the first type of block mode, the NVGRE header of the service message includes a flag bit field, a key version field, a version field, a protocol type field, a VSID field, a stream ID field, an IV field, a padding data length field, and a padding data field; wherein, the second bit of the flag bit field is used to indicate whether the service message is encrypted; when the service message needs to be encrypted, and the first remainder obtained by dividing the first length of the service message by the block length is not 0, the service... The NVGRE header of the message includes a flag field, a key version field, a version field, a protocol type field, a VSID field, a stream ID field, a padding data length field, and a padding data field. The second bit of the flag field indicates whether the service message is encrypted. Alternatively, if the first remainder obtained by dividing the first length of the service message by the block length is 0, the NVGRE header of the service message includes the flag field, key version field, version field, protocol type field, VSID field, stream ID field, and padding data length field; the second bit of the flag field indicates whether the service message is encrypted. In other words, this application extends the NVGRE header.

[0110] In this embodiment, when the VSID in the VSID field is not associated with corresponding key information, the NVGRE header of the service message includes a flag field, a reserved field, a version field, a protocol type field, a VSID field, and a flow ID field. Clearly, the modified NVGRE protocol proposed in this application is compatible with the standard NVGRE protocol and can communicate with the standard NVGRE NVE. When communicating with the standard NVGRE NVE, the second flag bit in the NVGRE header is not set, the key version field is not set, the IV field is not encapsulated, the padding data length field is not encapsulated, the padding data field is not encapsulated, and the service payload is not encrypted or encapsulated.

[0111] Step 508: The first network virtualization edge device sends the encrypted service message to the second network virtual edge device.

[0112] Step 509: The second network virtual edge device receives the service message sent by the first network virtualization edge device.

[0113] The service message has an NVGRE header, which is assembled by the first network virtualization edge device for any service message sent by any subnet.

[0114] Step 510: If the value of the second bit of the flag field in the NVGRE header is 1, and the second network virtual edge device determines that the service message is required to be encrypted as indicated by the VSID in the VSID field and the key version number in the key version field of the NVGRE header, the first network virtualization edge device encrypts the service message that meets the length threshold.

[0115] In this embodiment, the second network virtual edge device decapsulation module checks whether the value of the second bit of the second identifier in the NVGRE header is 1; if it is not set to 1, that is, it is not an encrypted value, then the service message is sent directly to the service terminal in the backend intranet as needed in the manner of accepting plaintext service messages, or the service message is discarded.

[0116] Step 511: The second network virtual edge device obtains the key version number from the key version field in the NVGRE header.

[0117] Step 512: The second network virtual edge device determines the key information of the service message based on the VSID and key version number.

[0118] In this embodiment, the second network virtual edge device decapsulation module uses VSID and key version number to jointly index the key information corresponding to the subnet to which the service message belongs.

[0119] Step 513: The second network virtual edge device decrypts the service message based on the key information to obtain the decrypted service message.

[0120] In this embodiment, the second network virtual edge device decapsulation module obtains from the key information the specific symmetric encryption algorithm, block length, and whether it is a CBC / CTR / OFB / CFB mode used by the first network virtualization edge device when encrypting service packets.

[0121] In this embodiment, the decapsulation module of the second network virtual edge device decrypts the service packet based on the key information and removes the padding data. After decryption, the second network virtual edge device obtains the original service packet sent by the peer first network virtual edge device. The second network virtual edge device forwards the decapsulated original service packet to the service terminal in the backend intranet.

[0122] In this embodiment, the key information includes the block mode, key, block length, and IV data of the encryption algorithm used by the first network virtualization edge device when encrypting the service message; step 513, based on the key information, decrypts the service message to obtain the decrypted service message, which can be achieved through the following steps:

[0123] Based on the block mode, key, block length, and IV data, the service message is decrypted to obtain the decrypted service message.

[0124] In this embodiment of the application, when the value of the second bit in the field marked in the NVGRE header is 1, and the encryption algorithm used is the first mode, the NVGRE header contains an IV field.

[0125] In this embodiment of the application, when the value of the second bit in the field marked in the NVGRE header is 1, the NVGRE header contains a padding data length field.

[0126] In this embodiment of the application, when the value of the second bit in the field marked in the NVGRE header is 1, and the length of the service message is less than an integer multiple of the block length or the value of the padding data length field is not 0, the NVGRE header contains a padding data field.

[0127] It should be noted that the descriptions of the same steps and contents as in other embodiments in this embodiment can be found in the descriptions in other embodiments, and will not be repeated here.

[0128] Embodiments of this application provide a first network virtual edge device, which can be used to implement... Figures 4 to 5 The corresponding implementation provides a message transmission method, referring to... Figure 7 As shown, the first network virtual edge device 100 includes:

[0129] The first receiving module 701 is used to receive service messages sent by any one of the multiple subnets connected to the first network virtual edge device;

[0130] The first processing module 702 is used to assemble a network virtualization NVGRE header using general routing encapsulation for service packets. The NVGRE header includes a virtual subnet identifier (VSID) field and a key version field.

[0131] The first processing module 702 is also used to obtain a service message that meets the length threshold when the VSID in the VSID field and the key version number in the key version field jointly indicate that the service message needs to be encrypted, and to encrypt the service message that meets the length threshold to obtain the encrypted service message.

[0132] The first sending module 703 is used to send the encrypted service message to the second network virtual edge device.

[0133] In other embodiments of this application, the first processing module 702 is used to determine the key information of the service message indexed by the VSID; the key information includes the block length of the encryption algorithm; and based on the block length, obtain the service message that meets the length threshold.

[0134] In other embodiments of this application, the first processing module 702 is used to obtain the first length of the service message; if the first remainder obtained by dividing the first length by the block length is not 1, the first length length and the first length remainder are obtained; the length of the padding data and the padding data are filled into the service message to obtain a service message that meets the length threshold.

[0135] In other embodiments of this application, the first processing module 702 is used to encrypt a service message that meets a length threshold using a key to obtain an encrypted service message; the key information includes a key.

[0136] In other embodiments of this application, the first processing module 702 is used to determine length indication information and start position indication information; the length indication information is used to indicate the length of the padding data to be filled into the service message; the start position indication information is used to indicate the start position of the padding data in the padding field; and the padding data is obtained from the padding field in the NVGRE header according to the length indication information and the start position indication information.

[0137] In other embodiments of this application, the first processing module 702 is configured to, if the grouping mode is a first type of grouping mode, obtain IV data from the NVGRE header including the initialization vector IV field; wherein, the key information also includes the grouping mode of the encryption algorithm; and based on the IV data and the key, perform encryption operation on each block of data in the service message that meets the length threshold to obtain the encrypted service message.

[0138] In other embodiments of this application, the first processing module 702 is used to define the second bit in the flag field of the NVGRE header as an encryption flag bit; wherein, when the encryption flag bit is 1, it indicates that the service message has been encrypted, and when the encryption flag bit is 0, it indicates that the service message has not been encrypted.

[0139] In other embodiments of this application, the first processing module 702 is used to add a key version number to the key version field so that when the second network virtualization edge device decrypts the encrypted service message, it can determine the block mode, key, block length and IV data of the encryption algorithm used by the first network virtualization edge device when encrypting the service message based on the key version number and the VSID corresponding to the encrypted service message.

[0140] The descriptions of the above device embodiments are similar to those of the above method embodiments, and have similar beneficial effects. For technical details not disclosed in the device embodiments of this application, please refer to the descriptions of the method embodiments of this application for understanding.

[0141] It should be noted that, in the embodiments of this application, if the above-described test data generation method is implemented as a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiments of this application, or the part that contributes to the related technology, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a terminal device to execute all or part of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, mobile hard drives, read-only memory (ROM), magnetic disks, or optical disks. Thus, the embodiments of this application are not limited to any specific hardware and software combination.

[0142] Embodiments of this application provide a first network virtual edge device, which can be applied to... Figures 4 to 5 In a corresponding embodiment of the message transmission method, referring to Figure 8 As shown, the first network virtual edge device 100 includes: a first processor 801, a first memory 802 and a first communication bus 803, wherein: the first communication bus 803 is used to realize the communication connection between the first processor 801 and the first memory 802.

[0143] The first processor 801 is used to execute the unlocking program stored in the first memory 802, so as to achieve the following: Figures 4 to 5 A corresponding embodiment provides a message transmission method.

[0144] Embodiments of this application provide a second network virtual edge device, which can be used to implement... Figures 4 to 5 The corresponding implementation provides a message transmission method, referring to... Figure 9 As shown, the second network virtual edge device 200 includes:

[0145] The second receiving module 901 is used to receive service packets sent by the first network virtualization edge device, wherein the service packets have an NVGRE header, and the NVGRE header is assembled by the first network virtualization edge device for any service packets sent by any subnet received;

[0146] The second processing module 902 is used to encrypt a service message that meets the length threshold if the value of the second bit of the flag field in the NVGRE header is 1, indicating that the service message needs to be encrypted as jointly indicated by the VSID in the VSID field and the key version number in the key version field included in the NVGRE header.

[0147] In other embodiments of this application, the second processing module 902 is used to obtain the key version number in the key version field of the NVGRE header;

[0148] The second processing module 902 is also used to determine the key information of the service message based on the VSID and the key version number;

[0149] The second processing module 902 is also used to decrypt the service message based on the key information to obtain the decrypted service message.

[0150] In other embodiments of this application, the key information includes the block mode, key, block length, and IV data of the encryption algorithm used by the first network virtualization edge device when encrypting service messages.

[0151] In other embodiments of this application, the second processing module 902 is used to decrypt the service message based on the grouping mode, key, block length and IV data to obtain the decrypted service message.

[0152] The descriptions of the above device embodiments are similar to those of the above method embodiments, and have similar beneficial effects. For technical details not disclosed in the device embodiments of this application, please refer to the descriptions of the method embodiments of this application for understanding.

[0153] It should be noted that, in the embodiments of this application, if the above-described test data generation method is implemented as a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiments of this application, or the part that contributes to the related technology, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a terminal device to execute all or part of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, mobile hard drives, ROMs, magnetic disks, or optical disks. Thus, the embodiments of this application are not limited to any specific hardware and software combination.

[0154] Embodiments of this application provide a second network virtual edge device, which can be applied to... Figures 4 to 5 In a corresponding embodiment of the message transmission method, referring to Figure 10 As shown, the second network virtual edge device 200 includes: a second processor 1001, a second memory 1002, and a second communication bus 1003, wherein: the second communication bus 1003 is used to realize the communication connection between the second processor 1001 and the second memory 1002.

[0155] The second processor 1001 is used to execute the unlocking program stored in the second memory 1002, so as to achieve the following: Figures 4 to 5 A corresponding embodiment provides a message transmission method.

[0156] This application provides a computer-readable storage medium storing a computer program that can be executed by one or more processors to perform, as follows: Figures 4 to 5 The corresponding implementation provides a message transmission method.

[0157] It should be noted that the descriptions of the storage medium and device embodiments above are similar to the descriptions of the method embodiments above, and have similar beneficial effects. For technical details not disclosed in the storage medium and device embodiments of this application, please refer to the descriptions of the method embodiments of this application for understanding.

[0158] The aforementioned computer-readable storage media may be ROM, Programmable Read-Only Memory (PROM), Erasable Programmable Read-Only Memory (EPROM), Electrically Erasable Programmable Read-Only Memory (EEPROM), Ferromagnetic Random Access Memory (FRAM), Flash Memory, Magnetic Surface Memory, Optical Disc, or Compact Disc Read-Only Memory (CD-ROM), etc.; or may be various electronic devices including one or any combination of the above-mentioned memories, such as mobile phones, computers, tablet devices, personal digital assistants, etc.

[0159] It should be understood that the terms "an embodiment," "an embodiment," "an embodiment of this application," "the foregoing embodiment," "some embodiments," or "some implementations" mentioned throughout the specification mean that a specific feature, structure, or characteristic related to the embodiment is included in at least one embodiment of this application. Therefore, the phrases "an embodiment," "an embodiment," "an embodiment of this application," "the foregoing embodiment," "some embodiments," or "some implementations" appearing throughout the specification do not necessarily refer to the same embodiment. Furthermore, these specific features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. It should be understood that in the various embodiments of this application, the sequence numbers of the above processes do not imply a sequential order of execution; the execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application. The sequence numbers of the above embodiments of this application are merely descriptive and do not represent the superiority or inferiority of the embodiments.

[0160] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0161] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of this application.

[0162] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer application products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer application instructions. These computer application instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0163] These computer application instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0164] These computer application instructions can also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0165] The above are merely preferred embodiments of this application and do not limit the patent scope of this application. Any equivalent structural or procedural transformations made using the content of this application's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of this application.

Claims

1. A message transmission method, characterized in that, Applied to a first network virtualization edge device, the method includes: Receive service packets sent from any one of the multiple subnets connected to the first network virtual edge device, and assemble a network virtualization NVGRE header using general routing encapsulation for the service packets, wherein the NVGRE header includes a virtual subnet identifier (VSID) field and a key version field; When the VSID in the VSID field and the key version number in the key version field jointly indicate that the service message needs to be encrypted, a service message that meets the length threshold is obtained, and the service message that meets the length threshold is encrypted to obtain an encrypted service message. The encrypted service message is sent to the second network virtual edge device.

2. The method according to claim 1, characterized in that, The service message that meets the length threshold includes: Determine the key information of the service message indexed by the VSID; the key information includes the block length of the encryption algorithm; Based on the block length, service messages that meet the length threshold are obtained.

3. The method according to claim 2, characterized in that, The process of obtaining service messages that meet the length threshold based on the block length includes: Obtain the first length of the service message; If the first remainder obtained by dividing the first length by the block length is not 0, the fill data length value and the fill data are obtained. The padding data is filled into the service message to obtain the service message that meets the length threshold.

4. The method according to claim 2 or 3, characterized in that, The key information includes a key, and the encryption of the service message that meets the length threshold to obtain the encrypted service message includes: The service message that meets the length threshold is encrypted using the key to obtain the encrypted service message.

5. The method according to claim 3, characterized in that, The NVGRE header also includes a padding field, and obtaining the padding data includes: Determine length indication information and start position indication information; the length indication information is used to indicate the length of the padding data inserted into the service message; the start position indication information is used to indicate the start position of the padding data in the padding field; The fill data is obtained from the fill field based on the length indication information and the start position indication information.

6. The method according to claim 4, characterized in that, The key information also includes the block mode of the encryption algorithm. The step of encrypting the service message that meets the length threshold using the key to obtain the encrypted service message includes: If the grouping mode is the first type of grouping mode, obtain the IV data from the NVGRE header, including the initialization vector IV field; Based on the IV data and the key, each block of data in the service message that meets the length threshold is encrypted to obtain an encrypted service message.

7. The method according to any one of claims 1 to 3 or 5 to 6, characterized in that, The NVGRE header also includes a flag field. After encrypting the service message that meets the length threshold to obtain the encrypted service message, the method further includes: Define the second bit in the flag field of the NVGRE header as the encryption flag bit; Wherein, when the encryption flag bit is set to 1, it indicates that the service message has been encrypted; when the encryption flag bit is set to 0, it indicates that the service message has not been encrypted.

8. The method according to any one of claims 2 to 3 or 5 to 6, characterized in that, The key information includes a key version number, and the method further includes: The key version number is added to the key version field so that when the second network virtualization edge device decrypts the encrypted service message, it can determine the block mode, key, block length, and IV data of the encryption algorithm used by the first network virtualization edge device when encrypting the service message based on the key version number and the VSID corresponding to the encrypted service message.

9. A message transmission method, characterized in that, Applied to a second network virtualization edge device, the method includes: Receive service packets sent by a first network virtualization edge device; wherein the service packets have an NVGRE header, and the NVGRE header is assembled by the first network virtualization edge device for any service packets sent by any subnet received; If the value of the second bit of the flag field in the NVGRE header is 1, it is determined that the service message is obtained by the first network virtualization edge device encrypting the service message that meets the length threshold, where the VSID in the VSID field and the key version number in the key version field of the NVGRE header jointly indicate that the service message needs to be encrypted.

10. The method according to claim 9, characterized in that, The method further includes: Obtain the key version number from the key version field in the NVGRE header; Based on the VSID and the key version number, determine the key information of the service message; Based on the key information, the service message is decrypted to obtain the decrypted service message.

11. The method according to claim 10, characterized in that, The key information includes the block mode, key, block length, and IV data of the encryption algorithm used by the first network virtualization edge device when encrypting the service packet; obtaining the decrypted service packet based on the key information includes: Based on the grouping mode, the key, the block length, and the IV data, the service message is decrypted to obtain the decrypted service message.