Data Object Synchronization Verification Method, Apparatus and RP

By building prior knowledge and assigning synchronization and verification tasks to different threads, the RPKI synchronization verification process is optimized, and the problem of insufficient utilization of thread resources is solved, which improves the efficiency of synchronization verification and the convergence speed of inter-domain routing.

CN117278571BActive Publication Date: 2025-07-18COMP NETWORK INFORMATION CENT CHINESE ACADEMY OF SCI
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310551764.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-05-16
Publication Date
2025-07-18
Estimated Expiration
2043-05-16

AI Technical Summary

Technical Problem

During the existing RPKI synchronous verification process, thread resources are insufficiently utilized, resulting in inefficient synchronization verification and extending the inter-domain routing convergence time.

Method used

By building prior knowledge, using prior knowledge to optimize the synchronization verification process, allocating synchronization and verification tasks to different threads, improving hardware resource utilization, reducing thread idleness, and using scheduler and multi-threaded model for synchronization and verification tasks distribution.

Benefits of technology

It improves the efficiency of RPKI synchronization verification, reduces synchronization time and improves the convergence speed between domain routing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117278571B_ABST
    Figure CN117278571B_ABST
Patent Text Reader

Abstract

Data object synchronization verification method, device and RP. The method includes: when the RP starts to perform RPKI data object synchronization verification for the current round, obtaining at least one publishing point involved in the RPKI data object synchronization verification of the RP in the previous round of the current round; synchronizing the RPKI data objects in the at least one publishing point; verifying the legality of the RPKI data objects synchronized from the at least one publishing point, and sending the RPKI data objects that pass the legality verification to the router.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of Internet technologies, as well as to the fields of inter-domain routing security technologies and Internet number resource public key infrastructure (Resource Public Key Infrastructure, RPKI) technologies; in particular, it relates to a data object synchronization verification method, device and RP. Background Art

[0002] The Border Gateway Protocol (BGP) is the de facto inter-domain routing standard for the Internet. It connects tens of thousands of autonomous systems (AS) in the Internet and provides routing. However, it did not provide an in-band security mechanism at the beginning of its design, that is, the BGP protocol itself does not stipulate a security mechanism. Since in the BGP protocol, the trust relationship between ASes is natural, it is very difficult for the BGP system to cope with misconfigurations or malicious attacks. Events of large-scale network unavailability or direct economic losses caused by BGP security problems occur from time to time.

[0003] Given the importance of BGP security issues, both the industrial community and the academic community are concerned about BGP security issues. The current mainstream solution is the Internet number resource public key infrastructure (Resource Public Key Infrastructure, RPKI) proposed by the Internet Engineering Task Force (IETF). Since its proposal, the deployment rate of RPKI has been increasing year by year. The proportion of IP prefixes protected by RPKI in the total IP prefixes of the Internet exceeds 40%. It can be said that RPKI has become an important cornerstone of inter-domain routing security.

[0004] RPKI completes the binding of public keys, Internet number resources and resource owners by extending X.509 public key certificates. RPKI performs resource authorization by issuing resource certificates level by level from top to bottom through a Certification Authority (CA). Each layer of resource holders issues a Route Origin Authorization (ROA) to complete the binding of IP prefixes to specific ASes.

[0005] The RPKI system mainly consists of three components: multi-level certification authorities, relying parties (RPs), and RPKI publication points. Among them, each holder of Internet Number Resources (INRs) incorporated into the RPKI certification system is a CA. The CA is responsible for issuing resource certificates, further distributing the ownership of the resources it holds to subordinate CAs, and is also responsible for issuing RPKI data objects such as ROAs to authenticate the right to use INRs for the protection of the BGP routing system. The CA places all the data objects it issues in the publication point, which can be maintained by the CA itself or outsourced. All publication points together constitute the global distributed RPKI repository. Considering that the resources of routers are relatively precious, in the RPKI system, BGP routers are not required to synchronize and verify the RPKI repository. Instead, an RP is added as an agent for the BGP router. The RP synchronizes data from the global RPKI repository at a certain frequency and conducts legality verification, and distributes the data that passes the legality verification to the BGP router according to the RTR protocol for judging the legality of the received BGP routes.

[0006] The RPKI certificate authentication system is consistent with the existing Internet number resource allocation system. The top-level CAs are the five Regional Internet Registries (RIRs), and the subordinate CAs include National Internet Registries (NIRs), Local Internet Registries (LIRs), Internet Service Providers (ISPs), and other INR holding institutions. Any INR holder authenticated in RPKI is a CA, responsible for the issuance and maintenance of BGP routes for resource certificates and ROAs, etc.

[0007] Each of the five RIRs serves as a trust anchor (TA), and as a special CA, becomes the root node of the RPKI resource certificate forest. Their resource certificates are self-signed certificates that contain all INR resources. The RP software configures the trust anchor locator (TAL) it trusts as the starting point for trust origin and synchronization verification.

[0008] Although the deployment of RPKI enhances the security of inter-domain routing, RPKI also brings problems to the convergence speed of inter-domain routing. A BGP router that performs route origin verification through RPKI data may determine a route as illegal when it does not receive a newly issued ROA corresponding to a certain route and will not continue to propagate it until it receives the ROA corresponding to that route. The article "RPKI Time-of-Flight: Tracking Delays in the Management, Control, and Data Planes" published in PAM-2023 measured the time-to-live of ROA on the data plane in the live network for a long time. The results show that the adoption of RPKI has increased the BGP route convergence process that should have been completed in 1-2 minutes to dozens or even hundreds of minutes, and the main time is spent on RP synchronization verification.

[0009] Among them, the main bottleneck in the process of RP synchronization verification lies in synchronization, which occupies 84% of the total time of synchronization verification. How to accelerate synchronization through multi-threading is the main problem in enhancing the efficiency of RP synchronization verification. Summary of the Invention

[0010] The present invention comprehensively analyzes 7 publicly available RP software shared globally. Their concurrent models can be divided into two types. One is to verify while synchronizing, and the other is to synchronize first and then verify. Regardless of which type, their synchronization starts from the trust anchor, traverses the content of a publication point after synchronizing a publication point, and then adds the publication point corresponding to the resource certificate in the synchronized publication point as a task to the task queue. The problem with this is that the thread has little prior knowledge of which publication points need to be synchronized. At the beginning, there are only tasks corresponding to a few trust anchor points configured by the user. As the synchronization verification process progresses, new tasks will be added to the task queue for synchronization. This results in some threads being idle during the synchronization verification process, leading to low synchronization verification efficiency. Moreover, in current RP software, the thread simultaneously undertakes the tasks of synchronization and verification. However, the synchronization process is I / O-intensive, and the verification process is CPU-intensive. The thread undertaking these two tasks simultaneously requires the number of threads to be set according to the CPU-intensive nature. However, most of the time, it is doing I / O-intensive work, which is not conducive to the full utilization of hardware resources.

[0011] The unreasonable concurrent model of RP software will damage the synchronization verification efficiency of RP, and further increase the time for inter-domain routing convergence. Therefore, the present invention proposes a synchronization verification scheme using prior knowledge, which can make full use of threads and improve the utilization rate of hardware resources. Moreover, in the scheme of the present invention, synchronization and verification can be parallelized to improve the synchronization verification efficiency of RP.

[0012] The solution of the present invention is as follows.

[0013] In a first aspect, a method for synchronously verifying data objects is provided. This method is applied to a relying party (RP) in the Resource Public Key Infrastructure (RPKI) for Internet numbering resources. The RP is used to synchronize and verify RPKI data objects in the RPKI's publication points and send the verified RPKI data objects to one or more Border Gateway Protocol (BGP) routers between autonomous systems in the Internet. The method includes the following steps:

[0014] When the RP starts the synchronous verification of RPKI data objects in the current round, it obtains at least one publication point involved in the synchronous verification of RPKI data objects in the previous round of the current round by the RP.

[0015] Synchronize the RPKI data objects in the at least one publication point.

[0016] Verify the legality of the RPKI data objects synchronized from the at least one publication point and send the RPKI data objects that pass the legality verification to the router.

[0017] In some embodiments, the Resource Public Key Infrastructure for Internet numbering resources further includes a first publication point. Among them, the RPKI data objects in the first publication point depend on the RPKI data objects in a second publication point among the at least one publication point. The method further includes: after the RPKI data objects in the at least one publication point pass the legality verification, synchronize the RPKI data objects in the first publication point; verify the legality of the RPKI data objects synchronized from the first publication point.

[0018] In some embodiments, the RP has a preset publication point, and the method further includes: the step of synchronizing the RPKI data objects in the at least one publication point includes: synchronizing the RPKI data objects in the at least one publication point and the RPKI data objects in the preset publication point simultaneously; the step of verifying the legality of the RPKI data objects synchronized from the at least one publication point: verifying the legality of the RPKI data objects in the at least one publication point and the RPKI data objects in the preset publication point simultaneously.

[0019] In some embodiments, the at least one publishing point includes a plurality of publishing points, and the RP includes a scheduler and a plurality of synchronization threads for synchronizing RPKI data objects from the publishing points; wherein, synchronizing the RPKI data objects in the at least one publishing point includes: the scheduler takes the plurality of publishing points as a plurality of synchronization tasks and adds them to a synchronization task queue, where one publishing point is taken as one synchronization task; each of the plurality of synchronization threads obtains one synchronization task from the synchronization task queue and executes the obtained synchronization task to synchronize the RPKI data objects from the publishing point corresponding to the synchronization task.

[0020] In an example of this embodiment, the method further includes: before the synchronization thread executes the obtained synchronization task, determining whether the publishing point corresponding to the synchronization task obtained by the synchronization thread is in a synchronization-in-progress state or a synchronization-completed state; when it is confirmed that the publishing point corresponding to the synchronization task obtained by the synchronization thread is not in a synchronization-in-progress state and a synchronization-completed state, executing the synchronization task obtained by the synchronization thread.

[0021] In another example of this embodiment, the RP further includes: at least one verification thread for verifying the legality of RPKI data objects; verifying the legality of the RPKI data objects synchronized from the at least one publishing point includes: the scheduler takes the RPKI data objects synchronized by the synchronization thread as verification tasks and adds them to a verification task queue; each of the at least one verification threads obtains one verification task from the verification task queue and executes the obtained verification task.

[0022] In an example of this embodiment, the RP includes a scheduler, a verification thread, and a synchronization thread; a plurality of synchronization threads need to acquire a mutex when reading and writing the same RPKI data object; wherein, the scheduler, the verification thread, and the plurality of synchronization threads are connected through a verification task queue, a prior synchronization task queue, a synchronization task queue, a verification result queue, a first HashSet for accommodating the publishing points being synchronized, a second HashSet for accommodating the publishing points with synchronization completed, and an int variable for representing the number of verification threads executing verification tasks; the scheduler is used to put tasks into the task queue, the verification thread is used to take tasks from the verification task queue and execute the taken tasks, and the synchronization thread is used to take tasks from the thread task queue and execute the taken tasks;

[0023] The method includes:

[0024] Set the number of threads according to the user configuration; among them, the default number of synchronization threads is 2×(the number of CPU cores - 1), and the default number of verification threads is 1; the verification task queue is initialized as an empty queue; the verification result queue is initialized as an empty queue; the prior synchronization task queue is initialized as an empty queue; the synchronization task queue is initialized as a queue containing the publication points corresponding to the trust anchors configured by the user; the first HashSet is initialized as an empty HashSet; the second HashSet is initialized as an empty HashSet; the value of the int variable is initialized to 0;

[0025] The verification thread executes steps 11 - 13;

[0026] The synchronization thread executes steps 21 - 25;

[0027] The scheduler executes steps 31 - 36;

[0028] Among them,

[0029] Step 11 includes: The verification thread attempts to obtain a verification task from the task queue. If successful, it enters step 12; if failed, it continues step 11;

[0030] Step 12 includes: Increment the value of the int variable by one, perform a verification operation on the RPKI data object signed by the RPKI data object indicated by the verification task, and enter step 13;

[0031] Step 13 includes: Package the verification result as a publication point verification result and put it into the verification result queue, and decrement the value of the int variable by one;

[0032] After step 13, the verification thread executes step 11 again;

[0033] Step 21 includes: Attempt to obtain a synchronization task from the synchronization task queue. If successful, it enters step 23; if failed, it enters step 22;

[0034] Step 22 includes: Attempt to obtain a synchronization task from the prior synchronization task queue. If successful, it enters step 23; if failed, it enters step 21;

[0035] Step 23 includes: Obtain the mutex lock, check whether the publication point corresponding to the synchronization task is in the first HashSet or the second HashSet. If it is in the first HashSet or the second HashSet, discard the task, release the mutex lock, and enter step 21. If it is not in the first HashSet or the second HashSet, add the publication point corresponding to this task to the first HashSet, release the mutex lock, and enter step 24;

[0036] Step 24 includes: synchronizing RPKI data objects from the publishing points in the first HashSet;

[0037] Step 25 includes: adding the publishing points for which the synchronization of RPKI data objects is completed to the second HashSet and removing them from the first HashSet;

[0038] After step 25, the synchronization thread executes step 21 again;

[0039] Step 31 includes: removing the RPKI resource certificates that have been synchronized from the RPKI resource certificate queue of the publishing points that currently need to be synchronized and adding them to the verification task queue;

[0040] Step 32 includes: checking the newly emerged verification records in the verification result queue, marking them as passing the legality verification; and adding the RPKI resource certificates that pass the legality verification to the RPKI resource certificate queue of the publishing points that currently need to be synchronized, and adding the publishing points corresponding to the newly added resource certificates in the RPKI resource certificate queue of the publishing points that currently need to be synchronized to the synchronization task queue;

[0041] Step 33 includes: checking whether both the synchronization task queue and the prior synchronization task queue are empty. If they are empty, go to step 34; if not, go to step 35;

[0042] Step 34 includes: retrieving prior knowledge, attempting to select publishing points that depend on the publishing points in the first HashSet or the second HashSet and that do not appear in these two sets and are equivalent to the number of synchronization threads, and adding them to the prior synchronization task queue, then go to step 35;

[0043] Step 35 includes: judging whether the value of the int variable is 0, whether the verification task queue is empty, whether the RPKI resource certificate queue of the publishing points that currently need to be synchronized is empty, and whether there are no unprocessed verification records in the verification result queue. If all are yes, go to step (6);

[0044] Step 36 includes: closing the verification thread and the synchronization thread, constructing the valid route origin statements and the dependency relationships between the publishing points in this synchronization verification process through the verification result queue, and persisting them locally for subsequent use;

[0045] Among them, prior knowledge refers to the dependency relationships between the publishing points constructed through the previous synchronization verification process.

[0046] Second aspect, a data object synchronization verification apparatus is provided. The apparatus is applied to a relying party (RP) in a Resource Public Key Infrastructure (RPKI) for Internet number resources. The RP is used to synchronize and verify RPKI data objects in a publication point of the RPKI, and send the verified RPKI data objects to one or more routers between autonomous systems in the Internet. The apparatus includes:

[0047] An obtaining unit, configured to obtain at least one publication point involved in the RPKI data object synchronization verification in a previous round when starting the RPKI data object synchronization verification in the current round;

[0048] A synchronization unit, configured to synchronize the RPKI data objects in the at least one publication point;

[0049] A verification unit, configured to perform a legality verification on the RPKI data objects synchronized from the at least one publication point, and send the RPKI data objects passing the legality verification to the router.

[0050] Third aspect, an RP is provided, including a processor and a memory. The processor is configured to execute instructions stored in the memory to perform the method described in the first aspect.

[0051] Fourth aspect, a computer-readable storage medium includes computer program instructions. When the computer program instructions are executed by a computing device, the computing device executes the method described in the first aspect.

[0052] The data object synchronization verification method, apparatus and RP provided by the embodiments of the present invention construct prior knowledge through the previous synchronization verification process. By using the prior knowledge, the publication points that may need to be synchronized and verified can be obtained, so that the synchronization thread can perform synchronization in time, reducing the idle time of the synchronization thread, thereby reducing the synchronization time-consuming and improving the efficiency of synchronization verification. BRIEF DESCRIPTION OF THE DRAWINGS

[0053] Figure 1 is a flowchart of a data object synchronization verification method provided by an embodiment of the present invention;

[0054] Figure 2 is a schematic structural diagram of a data object synchronization verification apparatus provided by an embodiment of the present invention;

[0055] Figure 3 is a schematic structural diagram of an RP provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0056] Next, the solution of the present invention will be introduced in conjunction with the accompanying drawings.

[0057] The present invention mainly optimizes the concurrent model of the software implementation of RP to improve the efficiency of the RP software synchronization verification in RPKI, so as to reduce the impact of RPKI on the inter-domain routing convergence speed.

[0058] Currently, RP has no prior knowledge of the publication points to be synchronized, which causes some threads to be idle during the synchronization verification process; the threads undertake the work of synchronization and verification, making the hardware resources not fully utilized. The combination of these two factors leads to low efficiency of RP synchronization verification. This solution distributes the synchronization process and the verification process to different threads, so that the number of synchronization threads can be set relatively large, increasing the utilization of hardware resources; through the previous synchronization process, the synchronization dependency relationships of the publication points (if the resource certificate X is included in the publication point A, and the storage location of the RPKI data object signed by the resource certificate X is the publication point B, then it is said that the publication point B depends on the publication point A, and so on) are constructed as prior knowledge, and the method of early synchronization is adopted, that is, when there is an idle synchronization thread, let it synchronize the subsequent publication points that may be used, that is, the publication points synchronized in the previous round. The scheduler distributes the synchronization tasks to multiple synchronization threads and the verification tasks to multiple verification threads. The resource certificates passed by the publication point verification are fed back to the scheduler to prevent new publication points from being synchronized.

[0059] Among them, the resource certificate X signs the RPKI data object Y, and it can also be said that the RPKI data object Y depends on the resource certificate X.

[0060] In the embodiment of the present invention, the resource certificate includes at least one IP prefix and at least one AS number. The resource certificate and the route origin statement can be collectively referred to as RPKI data objects.

[0061] In the data object synchronization verification scheme provided by the embodiment of the present invention, the utilization rate of hardware resources is increased by distributing the synchronization process and the verification process to different threads, and the idle time of the threads is reduced by constructing prior knowledge through the previous synchronization verification process, improving the efficiency compared with the previous concurrent model.

[0062] Next, the data object synchronization verification scheme provided by the embodiment of the present invention will be specifically described.

[0063] This solution mainly includes a scheduler, a verification thread, and a synchronization thread. The three parts communicate through four queues, two HashSets, and an int variable. A HashSet is a data structure that can be used to hold other data. Multiple threads need to acquire a mutex lock when reading and writing the same object, and the mutex lock is used to ensure that a data object is processed by one thread at a time. The above four queues are: the verification task queue, the prior synchronization task queue, the synchronization task queue, and the verification result queue. The two HashSets are: HashSet A1 for holding the publishing points being synchronized, and HashSet A2 for holding the publishing points that have been synchronized. The value of an int variable is used to represent the number of verification processes currently executing verification tasks. The scheduler puts tasks into the three task queues. The verification thread fetches and executes tasks from the verification task queue. The synchronization thread fetches and executes tasks from the prior synchronization task queue and the synchronization task queue. It is worth mentioning that the synchronization task queue has a higher priority because the publishing points in the synchronization task queue are confirmed to be valid by the resource certificate, and synchronizing such tasks will not cause waste, and the content after synchronization can be handed over to the verification thread for verification faster. In addition, the verification result queue is maintained by the verification, and the publishing points being synchronized and the publishing points that have been synchronized are maintained by the synchronization process. Among them, verification can refer to legality verification.

[0064] In the following different embodiments, the initialization process, the functions of the scheduler, the verification thread, the synchronization thread, or the behaviors are specifically introduced.

[0065] Embodiment 1, Initialization

[0066] Initialization mainly involves the initialization of threads, the initialization of data structures such as the queues and HashSets mentioned above, and the initialization of other data structures required by the scheduler. The number of threads is configured by the user. The default number of synchronization threads is 2*(number of CPU cores - 1), and the default number of verification threads is 1. Among them, the CPU is the CPU of the RP, the CPU is a multi-core processor, and the number of CPU cores is the number of computing cores in the multi-core processor. The verification task queue is denoted as validation_queue and is initialized as an empty queue.

[0067] The verification result queue is denoted as validation_record_queue and is initialized as an empty queue.

[0068] The prior synchronization task queue is denoted as p_sync_queue and is initialized as an empty queue.

[0069] The synchronization task queue is denoted as sync_queue and is initialized as a queue containing the publishing points corresponding to several trust anchors configured by the user.

[0070] The publishing points being synchronized are denoted as running_pubpoint and initialized as an empty HashSet A1; the publishing points with synchronization completed are denoted as done_pubpoint and initialized as an empty HashSet A2.

[0071] The number of verification tasks executed by the verification thread is denoted as v_num and initialized to 0. That is, an int variable is denoted as v_num and initialized to 0.

[0072] The initialization of prior knowledge is denoted as p_map, which refers to the dependency relationship between publishing points constructed through the previous synchronization verification process and is persisted in a local file after each synchronization verification process. If it is the first synchronization verification, it is initialized as an empty HashMap; otherwise, it reads the local file and is initialized as a HashMap containing the dependency relationship of publishing points in the previous synchronization verification process, where the key is the information of the dependent publishing point and the value is an array containing all the publishing points that depend on the publishing point referred to by the key.

[0073] The RPKI resource certificate queue of the publishing points that need to be synchronized currently is denoted as sync_cert_queue and initialized as a queue of RPKI resource certificates corresponding to the trust anchors configured by the user.

[0074] Example 2, the function or behavior of the verification thread

[0075] The behavior of the verification thread is relatively simple, and its main workflow is as follows:

[0076] (1) Try to obtain a verification task from the validation_queue (i.e., the verification task queue). If successful, go to step (2); if failed, continue with step (1).

[0077] (2) Increment the value of v_num (i.e., the int variable), perform a verification operation on the RPKI data signed by the resource certificate indicated by the verification task, and go to step (3).

[0078] (3) Package the verification result as a publishing point verification result and put it into the validation_record_queue (verification result queue), decrement the value of v_num, and then continue to execute step (1).

[0079] Example 3, the function or behavior of the synchronization thread

[0080] The main process of the synchronization thread is as follows:

[0081] (1) Try to obtain a synchronization task from the sync_queue (i.e., the synchronization task queue). If successful, go to step (3); if failed, go to step (2).

[0082] (2) Try to obtain a synchronization task from the p_sync_queue (i.e., the prior synchronization task queue). If successful, proceed to step (3); if failed, proceed to step (1).

[0083] (3) Obtain the mutex lock and check whether the publication point corresponding to the synchronization task is running_pubpoint (i.e., the publication point being synchronized) or done_pubpoint (i.e., the publication point with synchronization completed). If so, it means that there is already a thread synchronizing or has completed synchronizing the same publication point. Discard the task, release the mutex lock, and proceed to step (1); if not, use the publication point corresponding to this task as running_pubpoint, add it to HashSet A1, release the mutex lock, and proceed to step (4).

[0084] (4) Synchronize the publication point, and then proceed to step (5). Synchronizing the publication point refers to the RPKI data object of the publication point, that is, obtain the RPKI data object in the publication point, such as resource certificates, ROAs, etc.

[0085] (5) Add the publication point to HashSet A2 and remove it from HashSet A1, and then continue to execute step (1).

[0086] Example 4, functions or behaviors of the scheduler

[0087] The scheduler is responsible for allocating tasks to other worker threads, terminating other processes after synchronization verification is completed, collecting the results of synchronization verification, etc. Its main process is as follows:

[0088] (1) Remove the RPKI resource certificates that have completed synchronization (i.e., their corresponding publication points appear in HashSet A1) from the current sync_cert_queue (i.e., the queue of RPKI resource certificates for the publication points that need to be synchronized currently) and add them to the validation_queue (i.e., the verification task queue), and proceed to step (2).

[0089] (2) Check the newly emerged verification records in the validation_record_queue (i.e., the verification result queue), mark them as processed, add the RPKI resource certificates that have passed verification in these verification records to the sync_cert_queue, and add the publication points corresponding to these resource certificates to the sync_queue (i.e., the synchronization task queue), and proceed to step (3).

[0090] (3) Check whether both the sync_queue and the p_sync_queue are empty. If empty, proceed to step (4); if not empty, proceed to step (5).

[0091] (4) Retrieve p_map (prior knowledge), attempt to select the publishing points in HashSet A1 or HashSet A2 that are equivalent to the number of synchronization threads and have not appeared in these two sets, and add them to p_sync_queue (i.e., the prior synchronization task queue), then proceed to step (5).

[0092] (5) Determine whether the value of v_num is 0, whether validation_queue is empty, whether sync_cert_queue is empty, and whether there are no unprocessed verification records in Validation_record_queue. If all are true, it means there are no more RPKI resource certificates to be processed, indicating that this synchronization verification process has ended, and proceed to step (6); otherwise, proceed to step (1).

[0093] (6) Shut down all verification threads and synchronization threads, construct the valid ROAs of this synchronization verification process and the dependency relationships between the publishing points of this synchronization verification process through validation_record_queue, and persist them locally for subsequent use.

[0094] (7) The scheduler can send the RPKI data objects that have passed the legality verification to the BGP router for the BGP router to identify whether the newly issued ROA is an illegal ROA.

[0095] In summary, the embodiment of the present invention provides a method for synchronizing and validating data objects. This method is another expression form of the above-mentioned synchronization and validation of data objects, and the specific implementation manner of this method can refer to the introduction of the synchronization and validation of data object solutions above.

[0096] This method is applied to the relying party RP in the public key infrastructure RPKI of Internet number resources. The RP is used to synchronize and validate the RPKI data objects in the publishing points of the RPKI, and send the RPKI data objects that have passed the validation to one or more BGP routers between autonomous systems in the Internet.

[0097] Refer to Figure 1 , this method includes the following steps.

[0098] Step 101, when the RP starts the synchronization and validation of RPKI data objects in the current round, obtain at least one publishing point involved in the synchronization and validation of RPKI data objects by the RP in the previous round before the current round.

[0099] Step 102, synchronize the RPKI data objects in the at least one publishing point.

[0100] Step 103: Validate the legality of the RPKI data objects synchronized from the at least one issuing point, and send the RPKI data objects that pass the legality validation to the router.

[0101] In some embodiments, the Internet number resource public key infrastructure further includes a first issuing point; wherein, the RPKI data objects in the first issuing point depend on the RPKI data objects in a second issuing point among the at least one issuing point; the method further includes: after the RPKI data objects in the at least one issuing point pass the legality validation, synchronize the RPKI data objects in the first issuing point; validate the legality of the RPKI data objects synchronized from the first issuing point.

[0102] In some embodiments, the RP has a preset issuing point, and the method further includes: the synchronizing the RPKI data objects in the at least one issuing point includes: synchronizing the RPKI data objects in the at least one issuing point and the RPKI data objects in the preset issuing point simultaneously; the validating the legality of the RPKI data objects synchronized from the at least one issuing point: validating the legality of the RPKI data objects in the at least one issuing point and the RPKI data objects in the preset issuing point simultaneously.

[0103] In some embodiments, the at least one issuing point includes multiple issuing points, and the RP includes a scheduler and multiple synchronization threads for synchronizing RPKI data objects from the issuing points; wherein, the synchronizing the RPKI data objects in the at least one issuing point includes: the scheduler takes the multiple issuing points as multiple synchronization tasks and adds them to a synchronization task queue, where one issuing point is taken as one synchronization task; each of the multiple synchronization threads obtains one synchronization task from the synchronization task queue and executes the obtained synchronization task to synchronize the RPKI data objects from the issuing point corresponding to the synchronization task.

[0104] In an example of this embodiment, the method further includes: before the synchronization thread executes the obtained synchronization task, determine whether the issuing point corresponding to the synchronization task obtained by the synchronization thread is in a synchronization-in-progress state or a synchronization-completed state; when it is confirmed that the issuing point corresponding to the synchronization task obtained by the synchronization thread is not in a synchronization-in-progress state and a synchronization-completed state, execute the synchronization task obtained by the synchronization thread.

[0105] In another example of this embodiment, the RP further includes: at least one verification thread for verifying the legality of RPKI data objects; the verification of the legality of the RPKI data objects synchronized from the at least one publishing point includes: the scheduler takes the RPKI data objects synchronized by the synchronization thread as verification tasks and adds them to the verification task queue; each verification thread in the at least one verification thread obtains a verification task from the verification task queue and executes the obtained verification task.

[0106] In an example of this embodiment, the RP includes a scheduler, a verification thread, and a synchronization thread; multiple synchronization threads need to acquire a mutex when reading and writing the same RPKI data object; among them, the scheduler, the verification thread, and the multiple synchronization threads are connected through a verification task queue, a prior synchronization task queue, a synchronization task queue, a verification result queue, a first HashSet for accommodating the publishing points being synchronized, a second HashSet for accommodating the publishing points with synchronization completed, and an int variable for representing the number of verification threads executing verification tasks; the scheduler is used to put tasks into the task queue, the verification thread is used to take tasks from the verification task queue and execute the taken tasks, and the synchronization thread is used to take tasks from the thread task queue and execute the taken tasks

[0107] The method includes:

[0108] Set the number of threads according to user configuration; among them, the default number of synchronization threads is 2×(number of CPU cores - 1), and the default number of verification threads is 1; the verification task queue is initialized as an empty queue; the verification result queue is initialized as an empty queue; the prior synchronization task queue is initialized as an empty queue; the synchronization task queue is initialized as a queue containing the publishing points corresponding to the trust anchors configured by the user; the first HashSet is initialized as an empty HashSet; the second HashSet is initialized as an empty HashSet; the value of the int variable is initialized to 0;

[0109] The verification thread executes steps 11 - 13;

[0110] The synchronization thread executes steps 21 - 25;

[0111] The scheduler executes steps 31 - 36;

[0112] Among them,

[0113] Step 11 includes: the verification thread attempts to obtain a verification task from the verification task queue. If successful, it enters step 12; if failed, it continues with step 11;

[0114] Step 12 includes: incrementing the value of an int variable, performing a verification operation on the RPKI data object issued by the verification task indication, and proceeding to Step 13;

[0115] Step 13 includes: packing the verification result as a publishing point verification result and placing it in the verification result queue, and decrementing the value of the int variable;

[0116] After Step 13, the verification thread executes Step 11 again;

[0117] Step 21 includes: attempting to obtain a synchronization task from the synchronization task queue. If successful, proceed to Step 23; if failed, proceed to Step 22;

[0118] Step 22 includes: attempting to obtain a synchronization task from the prior synchronization task queue. If successful, proceed to Step 23; if failed, proceed to Step 21;

[0119] Step 23 includes: obtaining a mutex lock, checking whether the publishing point corresponding to the synchronization task is in the first HashSet or the second HashSet. If it is in the first HashSet or the second HashSet, discard the task, release the mutex lock, and proceed to Step 21. If it is not in the first HashSet or the second HashSet, add the publishing point corresponding to the task to the first HashSet, release the mutex lock, and proceed to Step 24;

[0120] Step 24 includes: synchronizing the RPKI data object from the publishing points in the first HashSet;

[0121] Step 25 includes: adding the publishing points for which the RPKI data object synchronization is completed to the second HashSet and removing them from the first HashSet;

[0122] After Step 25, the synchronization thread executes Step 21 again;

[0123] Step 31 includes: removing the RPKI resource certificates that have been synchronized from the RPKI resource certificate queue of the publishing points that currently need to be synchronized and adding them to the verification task queue;

[0124] Step 32 includes: checking the newly emerged verification records in the verification result queue, marking them as passing the legality verification; adding the RPKI resource certificates that pass the legality verification to the RPKI resource certificate queue of the publishing points that currently need to be synchronized, and adding the publishing points corresponding to the newly added resource certificates in the RPKI resource certificate queue of the publishing points that currently need to be synchronized to the synchronization task queue;

[0125] Step 33 includes: checking whether both the synchronization task queue and the prior synchronization task queue are empty. If they are empty, proceed to Step 34; if not, proceed to Step 35;

[0126] Step 34 includes: retrieving prior knowledge, attempting to select publishing points that are equivalent to the number of synchronization threads and depend on the publishing points in the first HashSet or the second HashSet and have not appeared in these two sets, and adding them to the prior synchronization task queue, then proceeding to Step 35;

[0127] Step 35 includes: judging whether the value of the int variable is 0, verifying whether the task queue is empty, whether the RPKI resource certificate queue of the publishing points that need to be synchronized currently is empty, and whether there are no unprocessed verification records in the verification result queue. If all are yes, proceed to Step (6);

[0128] Step 36 includes: closing the verification thread and the synchronization thread, constructing valid route origin statements and the dependency relationships between the publishing points in this synchronization verification process through the verification result queue, and persisting them locally for subsequent use;

[0129] Among them, prior knowledge refers to the dependency relationships between publishing points constructed through the previous synchronization verification process.

[0130] The data object synchronization verification method provided by the embodiments of the present invention constructs prior knowledge through the previous synchronization verification process. By using the prior knowledge, the publishing points that may need to be synchronized and verified can be obtained, enabling the synchronization threads to perform synchronization in a timely manner, reducing the idle time of the synchronization threads, thereby reducing the synchronization time consumption and improving the efficiency of synchronization verification.

[0131] The embodiments of the present invention also provide a data object synchronization verification device. The device is applied to a relying party RP in the public key infrastructure RPKI of Internet number resources. The RP is used to synchronize and verify RPKI data objects in the publishing points of the RPKI and send the verified RPKI data objects to one or more routers between autonomous systems in the Internet.

[0132] As Figure 2 shown, the device includes:

[0133] An obtaining unit 210, configured to obtain at least one publishing point involved in the synchronization verification of RPKI data objects in the previous round before the current round when starting the synchronization verification of RPKI data objects in the current round;

[0134] A synchronization unit 220, configured to synchronize the RPKI data objects in the at least one publishing point;

[0135] A verification unit 230 is configured to verify the legality of the RPKI data objects synchronized from the at least one publishing point, and send the RPKI data objects that pass the legality verification to the router.

[0136] Refer to Figure 3 , an embodiment of the present invention provides an RP 300, including a processor 310 and a memory 320. Among them, the memory 320 is used to store computer instructions. The processor 310 is configured to execute the computer instructions stored in the memory 320, so that the RP300 can execute the method embodiments described above Figure 1 shown.

[0137] It can be understood that the processor in the embodiments of the present application may be a central processing unit (CPU), or may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.

[0138] The embodiments of the present application also provide a computer storage medium, including computer software instructions, and the computer software instructions include a program for implementing Figure 1 the method shown. The computer-readable storage medium may be any available medium capable of storing data or a data storage device including one or more available media. The available medium may be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a DVD), or a semiconductor medium (for example, a solid-state drive), etc.

[0139] The embodiments of the present application also provide a computer program product, including a program for implementing Figure 1 the method shown. The computer program product is software or a program product that can run on a processor or be stored in any available medium.

[0140] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, and are not intended to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the protection scope of the technical solutions of the embodiments of the present application.

Claims

1. A method for synchronously verifying data objects, characterized in that, The method is applied to a relying party (RP) in the Resource Public Key Infrastructure (RPKI) for Internet number resources. The RP is used to synchronize and verify RPKI data objects in the RPKI's publication points, and send the verified RPKI data objects to one or more Border Gateway Protocol (BGP) routers between autonomous systems in the Internet. The method includes: When starting to synchronize and verify RPKI data objects in the current round, the RP obtains at least one publication point involved in the synchronization and verification of RPKI data objects in the previous round of the current round by the RP. Synchronize the RPKI data objects in the at least one publication point. Verify the legality of the RPKI data objects synchronized from the at least one publication point, and send the RPKI data objects that pass the legality verification to the router. Among them, the at least one publication point includes multiple publication points, and the RP includes a scheduler and multiple synchronization threads for synchronizing RPKI data objects from publication points. Among them, The synchronizing the RPKI data objects in the at least one publication point includes: The scheduler takes the multiple publication points as multiple synchronization tasks and adds them to a synchronization task queue, where one publication point is used as one synchronization task. Each of the multiple synchronization threads obtains a synchronization task from the synchronization task queue and executes the obtained synchronization task to synchronize RPKI data objects from the publication point corresponding to the synchronization task. The RP further includes at least one verification thread for verifying the legality of RPKI data objects. The verifying the legality of the RPKI data objects synchronized from the at least one publication point includes: The scheduler takes the RPKI data objects synchronized by the synchronization threads as verification tasks and adds them to a verification task queue. Each of the at least one verification threads obtains a verification task from the verification task queue and executes the obtained verification task.

2. The method according to claim 1, wherein The Resource Public Key Infrastructure for Internet number resources further includes a first publication point. Among them, the RPKI data objects in the first publication point depend on the RPKI data objects in a second publication point among the at least one publication point. The method further includes: After the RPKI data objects in the at least one publication point pass the legality verification, synchronize the RPKI data objects in the first publication point. Verify the legality of the RPKI data objects synchronized from the first publication point.

3. The method according to claim 1, characterized in that The RP has a preset publication point, and the method further includes: The synchronizing the RPKI data objects in the at least one publication point includes: synchronizing the RPKI data objects in the at least one publication point and the RPKI data objects in the preset publication point simultaneously. The verifying the legality of the RPKI data objects synchronized from the at least one publication point: verifying the legality of the RPKI data objects in the at least one publication point and the RPKI data objects in the preset publication point simultaneously.

4. The method according to claim 1, wherein The method further includes: Before the synchronization thread executes the obtained synchronization task, it determines whether the publication point corresponding to the synchronization task obtained by the synchronization thread is in a synchronization-in-progress state or a synchronization-completed state; When it is confirmed that the publication point corresponding to the synchronization task obtained by the synchronization thread is not in a synchronization-in-progress state and a synchronization-completed state, the synchronization task obtained by the synchronization thread is executed.

5. The method according to claim 1, wherein The RP includes a scheduler, a verification thread, and a synchronization thread; multiple synchronization threads need to obtain a mutex lock when reading and writing the same RPKI data object; among them, the scheduler, the verification thread, and multiple synchronization threads are connected through a verification task queue, a prior synchronization task queue, a synchronization task queue, a verification result queue, a first HashSet for accommodating publication points being synchronized, a second HashSet for accommodating publication points with synchronization completed, and an int variable for representing the number of verification threads executing verification tasks; the scheduler is used to put tasks into the task queue, the verification thread is used to take tasks from the verification task queue and execute the taken tasks, and the synchronization thread is used to take tasks from the thread task queue and execute the taken tasks The method includes: Setting the number of threads according to user configuration; among them, the default number of synchronization threads is 2×(number of CPU cores - 1), and the default number of verification threads is 1; the verification task queue is initialized as an empty queue; the verification result queue is initialized as an empty queue; the prior synchronization task queue is initialized as an empty queue; the synchronization task queue is initialized as a queue containing the publication points corresponding to the trust anchors configured by the user; the first Hashset is initialized as an empty HashSet; the second Hashset is initialized as an empty HashSet; the value of the int variable is initialized to 0; The verification thread executes steps 11-13; The synchronization thread executes steps 21-25; The scheduler executes steps 31-36; Among them, Step 11 includes: The verification thread attempts to obtain a verification task from the verification task queue. If successful, it proceeds to step 12; if failed, it continues with step 11; Step 12 includes: Incrementing the value of the int variable by one, performing a verification operation on the RPKI data object signed by the RPKI data object indicated by the verification task, and proceeding to step 13; Step 13 includes: Packing the verification result as a publication point verification result and putting it into the verification result queue, and decrementing the value of the int variable by one; After step 13, the verification thread executes step 11 again; Step 21 includes: Attempting to obtain a synchronization task from the synchronization task queue. If successful, it proceeds to step 23; if failed, it proceeds to step 22; Step 22 includes: Attempting to obtain a synchronization task from the prior synchronization task queue. If successful, it proceeds to step 23; if failed, it proceeds to step 21; Step 23 includes: acquiring a mutex lock, checking whether the publishing point corresponding to the synchronization task is in the first HashSet or the second HashSet. If it is in the first HashSet or the second HashSet, discard the task, release the mutex lock, and enter Step 21. If it is not in the first HashSet or the second HashSet, add the publishing point corresponding to the task to the first HashSet, release the mutex lock, and enter Step 24; Step 24 includes: synchronizing RPKI data objects from the publishing points in the first HashSet; Step 25 includes: adding the publishing points for which the RPKI data object synchronization is completed to the second HashSet and removing them from the first HashSet; After Step 25, the synchronization thread executes Step 21 again; Step 31 includes: removing the RPKI resource certificates that have been synchronized from the RPKI resource certificate queue of the currently required RPKI resources to be synchronized and adding them to the verification task queue; Step 32 includes: checking the newly emerged verification records in the verification result queue, marking them as passing the legality verification; adding the RPKI resource certificates passing the legality verification to the RPKI resource certificate queue of the currently required publishing points to be synchronized, and adding the publishing points corresponding to the newly added resource certificates in the RPKI resource certificate queue of the currently required publishing points to be synchronized to the synchronization task queue; Step 33 includes: checking whether both the synchronization task queue and the prior synchronization task queue are empty. If they are empty, enter Step 34; if not, enter Step 35; Step 34 includes: retrieving prior knowledge, attempting to select publishing points that depend on the publishing points in the first HashSet or the second HashSet and that have not appeared in these two sets and are equivalent to the number of synchronization threads, and adding them to the prior synchronization task queue, then enter Step 35; Step 35 includes: judging whether the value of the int variable is 0, whether the verification task queue is empty, whether the RPKI resource certificate queue of the currently required publishing points to be synchronized is empty, and whether there are no unprocessed verification records in the verification result queue. If all are yes, enter Step (6); Step 36 includes: closing the verification thread and the synchronization thread, constructing a valid route origin statement for the current synchronization verification process and the dependency relationship between the publishing points in the current synchronization verification process, and persisting them locally for subsequent use; Among them, prior knowledge refers to the dependency relationship between publishing points constructed through the previous synchronization verification process.

6. A data object synchronization verification device, characterized in that, The device is applied to a relying party RP in the Resource Public Key Infrastructure (RPKI) of Internet number resources. The RP is used to synchronize and verify RPKI data objects in the publishing points of the RPKI and send the RPKI data objects passing the verification to one or more routers between autonomous systems in the Internet. The device includes: An acquisition unit, configured to acquire at least one publishing point involved in the RPKI data object synchronization verification in the previous round before the current round when starting the RPKI data object synchronization verification in the current round; A synchronization unit, configured to synchronize RPKI data objects in the at least one publishing point; A verification unit for verifying the legality of the RPKI data objects synchronized from the at least one issuing point and sending the RPKI data objects that pass the legality verification to the router; Wherein, the at least one issuing point includes a plurality of issuing points, and the RP includes a scheduler and a plurality of synchronization threads for synchronizing RPKI data objects from the issuing points; wherein, The scheduler is configured to: add the plurality of issuing points as a plurality of synchronization tasks to a synchronization task queue, wherein one issuing point is used as one synchronization task; Each of the plurality of synchronization threads is configured to: obtain a synchronization task from the synchronization task queue and execute the obtained synchronization task to synchronize RPKI data objects from the issuing point corresponding to the synchronization task; The RP further includes: at least one verification thread for verifying the legality of the RPKI data objects; The scheduler is configured to: add the RPKI data objects synchronized by the synchronization threads as verification tasks to a verification task queue; Each of the at least one verification threads is configured to: obtain a verification task from the verification task queue and execute the obtained verification task.

7. An RP, characterized in that, It includes a processor and a memory, and the processor is configured to execute instructions stored in the memory to execute the method according to any one of claims 1-5.

8. A computer-readable storage medium, characterized in that, It includes computer program instructions, and when the computer program instructions are executed by a computing device, the computing device executes the method according to any one of claims 1-5.

Citation Information

Patent Citations

  • Active synchronizing method and system for RPKI (Resource Public Key Infrastructure) data

    CN104539578A

  • Verification method, system and equipment for processor and storage medium

    CN115480989A