Routing security configuration methods, devices, equipment, storage media, and software products
By carrying a security policy identifier in the Function field of SRv6 messages, security functions are pre-assembled and a security resource pool is utilized, solving the problem that existing routing security schemes cannot resist dynamic attacks, and achieving flexible security configuration and efficient security function response.
Patent Information
- Application Number
- CN202410514440.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-26
- Publication Date
- 2026-01-30
- Estimated Expiration
- 2044-04-26
AI Technical Summary
Existing routing security solutions cannot effectively resist dynamic attacks during the routing process, lack flexibility, and cannot achieve real-time secure resource scheduling in dynamic environments.
By carrying the security policy identifier in the Function field of the Segment Identifier (SID) of the SRv6 message, security functions are pre-assembled, and the security configuration of network nodes is realized through the security resource pool. The corresponding security functions are activated according to the security policy identifier by using the security configuration mapping table and the security function assembly module.
It improves the flexibility of routing security configuration, effectively resists dynamic attacks, enhances the response efficiency of security functions, and enables real-time security resource scheduling under dynamic attacks.
Smart Images

Figure CN118802304B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, and in particular to a routing security configuration method and device, equipment, a storage medium and a program product. BACKGROUND
[0002] Routing security has always been one of the important security issues in the Internet field. The infrastructure of the Internet relies on routers and routing protocols to deliver data traffic, so the security of routing is crucial to the reliability and security of the network. The severity of the routing security problem lies in that once routing tampering, hijacking or misconfiguration occurs, attackers can manipulate the path of network traffic, leading to serious consequences such as data leakage, service interruption, man-in-the-middle attacks, network partitioning, and malicious traffic injection. In past real cases, some malicious attackers have successfully launched large-scale routing hijacking and tampering attacks by exploiting routing security vulnerabilities and improper configurations, resulting in network interruption, data leakage, and service unavailability.
[0003] Currently, existing routing security solutions mainly include RPKI (Resource Public Key Infrastructure), BGPsec (BGP Security), and IRR (Internet Routing Registry). Among them, RPKI is a technology based on public key infrastructure, which is used to verify and authorize the source of BGP routing; it can effectively prevent routing hijacking and fake routing problems. BGPsec is an extension that provides security in the BGP protocol, which uses digital signatures to verify and protect the transmission of BGP routing; BGPsec can prevent routing hijacking and routing tampering, and improve the credibility and security of BGP routing. IRR is a public database that stores and distributes autonomous system (AS) routing policy information; by using IRR, network administrators can verify and authorize the propagation of BGP routing, reducing the risk of routing hijacking and routing leakage. However, the existing three routing security solutions can only guarantee the security of the static configuration of routing nodes, and have poor flexibility, and cannot resist dynamic attacks in the routing process. SUMMARY
[0004] To solve the problems existing in the prior art, the embodiments of the present application provide a routing security configuration method, device, equipment, storage medium and program product, which can improve the flexibility of routing security configuration, thereby effectively resisting dynamic attacks in the routing process.
[0005] In a first aspect, the embodiments of the present application provide a routing security configuration method, comprising:
[0006] receiving an SRv6 packet; wherein a preset field of the SRv6 packet carries a security policy identifier;
[0007] Configure the configuration information indicated by the security policy identifier according to the security policy identifier, so as to execute its corresponding security function after the configuration information is completed.
[0008] As an improvement to the above solution, the configuration information includes configuration command lines.
[0009] As an improvement to the above solution, the security functions are pre-assembled by a security resource pool according to the security policy corresponding to the security policy identifier.
[0010] As an improvement to the above solution, the configuration information indicated by the security policy identifier is configured according to the security policy identifier, including:
[0011] According to the pre-stored security configuration mapping table, find the configuration command line corresponding to the security policy identifier, and configure the found configuration command line;
[0012] The security configuration mapping table includes a one-to-one correspondence between different security policy identifiers and different configuration command lines.
[0013] As an improvement to the above scheme, the preset field is the Function field in the Segment Identifier (SID) of the SRv6 message.
[0014] As an improvement to the above solution, the method further includes:
[0015] Generate local security policies and their security policy identifiers, or receive security policies and their security policy identifiers issued by the controller;
[0016] The security policy is assembled into a security function by invoking the security resource pool.
[0017] As an improvement to the above solution, the method further includes:
[0018] When a local security policy and its security policy identifier are generated, the generated security policy and its security policy identifier are synchronized to the controller.
[0019] Secondly, embodiments of the present invention provide a routing security configuration device, including:
[0020] A message receiving module is used to receive SRv6 messages; wherein, the preset field of the SRv6 message carries a security policy identifier;
[0021] The security configuration module is used to configure the configuration information indicated by the security policy identifier according to the security policy identifier, so as to execute its corresponding security function after the configuration information is completed.
[0022] Thirdly, embodiments of the present invention provide a routing security configuration device, comprising: a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein the processor executes the computer program to implement the routing security configuration method as described in any one of the first aspects.
[0023] Fourthly, embodiments of the present invention provide a computer-readable storage medium storing a computer program, wherein, when the computer program is executed, it controls the device where the computer-readable storage medium is located to perform the routing security configuration method as described in any one of the first aspects.
[0024] Fifthly, embodiments of the present invention provide a computer program product, including a computer program / instruction that, when executed by a processor, implements the routing security configuration method as described in any one of the first aspects.
[0025] Compared to existing technologies, this invention provides a routing security configuration method, apparatus, device, storage medium, and program product. A network node receives an SRv6 message; wherein a preset field of the SRv6 message carries a security policy identifier; then, based on the security policy identifier, configuration information indicated by the security policy identifier is configured to execute the corresponding security function after the configuration information is completed. This invention uses a preset field of the SRv6 message carrying a security policy identifier to achieve secure configuration of the network node. This allows the network node to initiate and execute the corresponding security function based on the correspondence between the security policy identifier and the security function. This solves the security configuration problem during real-time security resource scheduling under dynamic attack conditions, improves the flexibility of routing security configuration, and effectively resists dynamic attacks during the routing process. Attached Figure Description
[0026] To more clearly illustrate the technical solution of the present invention, the accompanying drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0027] Figure 1 This is a schematic diagram of the structure of an SRv6 message provided in an embodiment of the present invention;
[0028] Figure 2 This is a schematic diagram of the SID structure of an SRv6 message provided in an embodiment of the present invention;
[0029] Figure 3 This is a flowchart of a routing security configuration method provided by an embodiment of the present invention;
[0030] Figure 4 This is a schematic diagram of the security policy synchronization process provided in an embodiment of the present invention;
[0031] Figure 5 This is a schematic diagram of the security policy distribution process provided in an embodiment of the present invention;
[0032] Figure 6 This is a schematic diagram of the assembly process of the security functions provided in an embodiment of the present invention;
[0033] Figure 7 This is a structural block diagram of a routing security configuration device provided in an embodiment of the present invention;
[0034] Figure 8 This is a structural block diagram of a routing security configuration device provided in an embodiment of the present invention. Detailed Implementation
[0035] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0036] It should be noted that, in the embodiments of the present invention, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0037] The following explains some terms and concepts involved in the embodiments of the present invention.
[0038] SRv6 (Segment Routing IPv6) is a routing protocol and network programming technology based on IPv6. It extends the IPv6 (Internet Protocol Version 6) protocol, providing flexible path selection and service functions for data packets in the network. The core idea of SRv6 is to embed a series of router path identifiers (segments) into the source address of IPv6 data packets. These path identifiers indicate the path and processing operation of the packet in the network. By specifying the path in the packet, SRv6 allows network administrators to define and control the forwarding path of data packets in the network without relying on traditional routing protocols. Figure 1 As shown, an SRv6 message includes an SRv6 header, an SRH (Segment Routing Header), and a payload. The SRv6 header includes a source IPv6 address and a destination IPv6 address. The SRH includes multiple segment lists (also called segment identifiers, SIDs), which can be freely combined. A custom SID structure specifically includes a Locator, a Function, and Arguments, such as... Figure 2 As shown.
[0039] A Locator is an identifier assigned to a network node in the network. It can be used to route and forward data packets, and the Locator is unique across the entire network.
[0040] Function is an ID value assigned by the device to local forwarding instructions. Different forwarding behaviors are expressed by different function IDs. This value can be used to express the forwarding action that the device needs to perform when it receives an SRV6 message. It is equivalent to the opcode of a computer instruction. Function determines whether to forward the data to a node or link, decapsulate and look up the routing table for forwarding, or decapsulate and send it to an instance, etc.
[0041] Arguments are optional parameters required when the forwarding command is executed. These parameters may include other variable information related to the stream, service, or task.
[0042] Please see Figure 3 , Figure 3 This is a flowchart of a routing security configuration method provided in an embodiment of the present invention. The routing security configuration method specifically includes:
[0043] S1: Receive SRv6 message; wherein, the preset field of the SRv6 message carries a security policy identifier;
[0044] S2: Configure the configuration information indicated by the security policy identifier according to the security policy identifier, so as to execute its corresponding security function after the configuration information is completed.
[0045] It should be noted that the routing security configuration method described in this embodiment of the invention can be executed by a network node, wherein the network node includes security devices that provide security processing, such as proprietary virtual security devices that provide virtualization security functions (e.g., firewalls, IPS (Intrusion Prevention System), IDS (Intrusion Detection System), etc.) and physical security devices that provide security processing themselves (e.g., routing devices and other network devices).
[0046] The security functions are pre-assembled by a security resource pool according to the security policy corresponding to the security policy identifier. In this embodiment of the invention, the security policy identifier is carried in a preset field of the SRv6 message to realize the security configuration of network nodes. This allows network nodes to start and execute the corresponding pre-assembled security functions based on the correspondence between the security policy identifier and the security function, solving the security configuration problem in real-time security resource scheduling under dynamic attack conditions, improving the flexibility of routing security configuration, and effectively resisting dynamic attacks during the routing process.
[0047] Specifically, the preset field is the Function field in the Segment Identifier (SID) of the SRv6 message.
[0048] In this embodiment of the invention, the usage of the Function field in the Segment Identifier (SID) of the SRv6 message is extended, and the Function field is used to carry a security policy identifier. For example, the information in the Function field can be END.SP, indicating that it carries a security policy identifier. Based on END.SP, the required locally available security functions can be queried. The security functions in this embodiment of the invention are pre-assembled according to security policies. The security policies include security policies that can provide dedicated security services, such as encryption security policies for firewalls, or security policies that provide security for network nodes and routing itself, such as security policies that prevent routing table tampering for routers. No specific limitations are imposed in this embodiment of the invention.
[0049] In this embodiment of the invention, the security policy identifier carried in the Function field of the SRv6 message is sent to the network node via SRH during the SRV6 path distribution. The corresponding security function can be activated based on the security policy identifier. Since the security function is pre-assembled, there is no need to distribute, configure and assemble the security policy during the security configuration process. This avoids the resource consumption caused by configuring specific security policies in the SRV6 message and improves the response efficiency of security function activation.
[0050] Specifically, the configuration information includes configuration command lines. For example, a security policy identifier carried in a preset field of an SRv6 message received by a network node indicates a configuration command line; that is, one security policy identifier indicates one configuration command line.
[0051] It should be understood that proprietary virtual security devices such as firewalls and IPS require configuration command lines to be configured before they can be started and used to execute corresponding security functions. Physical security devices such as routing devices and network devices, which can provide security services themselves, can receive the security policy identifier carried in the Function field of SRv6 packets, configure the configuration command line indicated by the security policy identifier, and then execute the corresponding security functions. For example, the information in the Function field is: END.SP, where END.SP indicates that it carries a security policy identifier and indicates a configuration command line (INDS). By configuring the configuration command line (INDS) indicated by the security policy identifier END.SP locally on the network node, the security function corresponding to the configuration command line (INDS) can be started and executed.
[0052] Further, based on the security policy identifier, the configuration information indicated by the security policy identifier is configured, including:
[0053] According to the pre-stored security configuration mapping table, find the configuration command line corresponding to the security policy identifier, and configure the found configuration command line;
[0054] In this embodiment of the invention, the network node locally stores a security configuration mapping table, which records the one-to-one correspondence between different security policy identifiers and different configuration command lines. A specific example of the security configuration mapping table is shown in the table below.
[0055]
[0056]
[0057] Simultaneously, a mapping table between security features and configuration command lines (also known as configuration commands) is maintained locally. A configuration command line is used to implement an actual security policy. It should be understood that a security policy only possesses complete security capabilities after being assembled into a security feature through a security resource pool assembly operation. A specific example of the mapping table between security features and configuration command lines is shown in the table below.
[0058] Configure command line Security function INDS 1 Start INDS 2 Filter INDS 3 Scan
[0059] After a network node receives the security policy identifier carried in the Function field of an SRv6 message, it can find the corresponding configuration command line through the security configuration mapping table to perform security configuration. After the configuration is completed, the corresponding security functions, such as startup, filtering, and scanning, can be started.
[0060] Specifically, the method further includes:
[0061] Generate local security policies and their security policy identifiers, or receive security policies and their security policy identifiers issued by the controller;
[0062] The security policy is assembled into a security function by invoking the security resource pool.
[0063] Furthermore, the method also includes:
[0064] When a local security policy and its security policy identifier are generated, the generated security policy and its security policy identifier are synchronized to the controller.
[0065] For example, the controller may be a programming controller center. In this embodiment of the invention, the security policy involved in the pre-assembled security functions may be generated locally by the network node or issued by the programming controller center.
[0066] When security policies are generated locally, each policy is identified by a unique number. A unique security policy identifier is generated for each policy, and the security policy and its identifier are synchronized to the programming controller center. Figure 4 As shown.
[0067] When the Programmable Controller Center (PCCNC) issues a security policy, it uniformly issues the security policy and its identifier to all network nodes of the same type, and issues it via out-of-band data, such as... Figure 5 As shown.
[0068] like Figure 6 As shown, taking the issuance of security policies by the programming controller center as an example, the assembly process of security functions is as follows:
[0069] The security policies and their identifiers are issued by the programming controller center to the network nodes.
[0070] Network nodes need to send security features to the security resource pool;
[0071] The security resource pool acquires the corresponding security policies based on the security function requirements, assembles the security functions, and returns them to the network nodes.
[0072] After receiving the assembled and usable security functions, the network node returns a response message to the programming control center confirming receipt of the policy, thus completing the pre-assembly of the security functions.
[0073] In this embodiment of the invention, network nodes invoke a security resource pool. The security resource pool assembles the required security functions according to the security policy. After assembly, the overall security functions are completed and provided to the network nodes for use. Based on the atomic security capabilities provided by the security resource pool, a complete security capability can be formed from locally generated security policies or security policies issued by the programming controller center through the assembly operation.
[0074] Compared to existing technologies, in this embodiment of the invention, the security configuration of network nodes is achieved by using the Function field of the SRv6 message to carry a security policy identifier. This allows network nodes to start and execute pre-assembled security functions based on the correspondence between the security policy identifier and the security function. This solves the security configuration problem in real-time security resource scheduling under dynamic attack conditions, has high flexibility, and can effectively resist dynamic attacks during the routing process.
[0075] Meanwhile, network nodes invoke the security resource pool, which pre-assembles the required security functions according to the security policy. After assembly, the overall security functions are completed and provided to the network nodes. Combined with the security configuration mapping table between the security policy identifier and the configuration command line (i.e., the actual security policy), the network nodes can receive the security policy identifier carried in the Function field of the SRv6 message and configure the corresponding configuration command line, thereby enabling the required security functions. Since the security functions are pre-assembled, there is no need to distribute, configure, and assemble the security policy during the security configuration process. This avoids the resource consumption caused by configuring specific security policies in the SRV6 message and improves the response efficiency of security function startup.
[0076] Please see Figure 7 , Figure 7 This is a structural block diagram of a routing security configuration device provided in an embodiment of the present invention. The routing security configuration device includes:
[0077] The message receiving module 1 is used to receive SRv6 messages; wherein, the preset field of the SRv6 message carries a security policy identifier;
[0078] The security configuration module 2 is used to configure the configuration information indicated by the security policy identifier according to the security policy identifier, so as to execute its corresponding security function after the configuration information is completed.
[0079] In one alternative embodiment, the configuration information includes a configuration command line.
[0080] In one optional embodiment, the security functions are pre-assembled by a security resource pool according to the security policy corresponding to the security policy identifier.
[0081] In one optional embodiment, the security configuration module 2 includes:
[0082] The configuration command line lookup unit is used to look up the configuration command line corresponding to the security policy identifier according to the pre-stored security configuration mapping table.
[0083] Configure the command-line configuration unit, used to name the configuration command lines retrieved by the configuration settings;
[0084] The security configuration mapping table includes a one-to-one correspondence between different security policy identifiers and different configuration command lines.
[0085] In one optional embodiment, the preset field is the Function field in the Segment Identifier (SID) of the SRv6 message.
[0086] In an optional embodiment, the device further includes:
[0087] The security policy acquisition module is used to generate local security policies and their security policy identifiers, or to receive security policies and their security policy identifiers issued by the controller.
[0088] The security function assembly module is used to call the security resource pool to assemble the security policy into a security function.
[0089] In an optional embodiment, the device further includes:
[0090] The security policy synchronization module is used to synchronize the generated security policy and its security policy identifier to the controller when a local security policy and its security policy identifier are generated.
[0091] It should be noted that the working process of each module in the routing security configuration device described in this embodiment of the invention can refer to the working process of the routing security configuration method described above, and the technical effect achieved is the same as that of the routing security configuration method described above, so it will not be repeated here.
[0092] See Figure 8 , Figure 8This is a structural block diagram of a routing security configuration device provided in an embodiment of the present invention. The routing security configuration device includes a processor 21, a memory 22, and a computer program stored in the memory 22 and executable on the processor 21. When the processor 21 executes the computer program, it implements the steps in the various routing security configuration method embodiments described above, such as steps S1 to S2.
[0093] For example, the computer program may be divided into one or more modules / units, which are stored in the memory 22 and executed by the processor 21 to complete the present invention. The one or more modules / units may be a series of computer program instruction segments capable of performing specific functions, which describe the execution process of the computer program in the routing security configuration device.
[0094] The routing security configuration device may include, but is not limited to, processor 21 and memory 22. Those skilled in the art will understand that the schematic diagram is merely an example of a routing security configuration device and does not constitute a limitation on the routing security configuration device. It may include more or fewer components than illustrated, or combine certain components, or different components. For example, the routing security configuration device may also include input / output devices, network access devices, buses, etc.
[0095] The processor 21 can be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor. The processor 21 is the control center of the routing security configuration device, connecting various parts of the entire routing security configuration device via various interfaces and lines.
[0096] The memory 22 can be used to store the computer programs and / or modules. The processor 21 implements various functions of the routing security configuration device by running or executing the computer programs and / or modules stored in the memory 22 and calling the data stored in the memory 22. The memory 22 may mainly include a program storage area and a data storage area. The program storage area may store the operating system, at least one application program required for a function (such as sound playback function, image playback function, etc.), etc.; the data storage area may store data created according to the use of the mobile phone (such as audio data, phonebook, etc.). In addition, the memory 22 may include high-speed random access memory, and may also include non-volatile memory, such as hard disk, memory, plug-in hard disk, smart memory card (SMC), secure digital (SD) card, flash card, at least one disk storage device, flash memory device, or other volatile solid-state storage device.
[0097] Wherein, if the modules / units integrated into the routing security configuration device are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments of the present invention can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when the computer program is executed by the processor 21, it can implement the steps of the various method embodiments described above. Wherein, the computer program includes computer program code, which can be in the form of source code, object code, executable file, or some intermediate form, etc. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, portable hard drive, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium, etc.
[0098] It should be noted that the device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Furthermore, in the accompanying drawings of the device embodiments provided by this invention, the connection relationships between modules indicate that they have communication connections, which can be specifically implemented as one or more communication buses or signal lines. Those skilled in the art can understand and implement this without any creative effort.
[0099] The above description is a preferred embodiment of the present invention. It should be noted that, for those skilled in the art, many improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications are also considered to be within the scope of protection of the present invention.
Claims
1. A method of configuring routing security, characterized by, The method comprises: receiving an SRv6 packet; wherein a preset field of the SRv6 packet carries a security policy identifier; configuring configuration information indicated by the security policy identifier according to the security policy identifier, so as to execute corresponding security functions after the configuration of the configuration information is completed; the configuration information comprises a configuration command line; the security functions are pre-assembled by a security resource pool according to security policies corresponding to the security policy identifier; The method further comprises: generating a local security policy and a security policy identifier thereof, or receiving a security policy and a security policy identifier thereof issued by a controller; 2. The method of claim 1, wherein, calling the security resource pool to assemble the security policy into a security function.
3. The method of claim 1, wherein the security configuration of the route is performed by a network management system. The method further comprises:
4. The method of claim 1, wherein the security configuration of the route is performed by a network management system. when the local security policy and the security policy identifier thereof are generated, synchronizing the generated security policy and the security policy identifier thereof to the controller. The method comprises: a packet receiving module configured to receive an SRv6 packet; wherein a preset field of the SRv6 packet carries a security policy identifier; 5. The method of claim 4, wherein, a security configuration module configured to configure configuration information indicated by the security policy identifier according to the security policy identifier, so as to execute corresponding security functions after the configuration of the configuration information is completed; the configuration information comprises a configuration command line; the security functions are pre-assembled by a security resource pool according to security policies corresponding to the security policy identifier; The security configuration module comprises:
6. A configuration apparatus for routing security, characterized by comprising: a configuration command line finding unit configured to find a configuration command line corresponding to the security policy identifier according to a pre-stored security configuration mapping table; a configuration command line configuration unit configured to name the found configuration command line. The method comprises: a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein the processor executes the computer program to implement the method for configuring security of a route according to any one of claims 1 to 5. The computer readable storage medium stores a computer program, wherein the computer program controls a device where the computer readable storage medium is located to execute the method for configuring security of a route according to any one of claims 1 to 5 when the computer program is running. The computer program / instruction is executed by the processor to implement the method for configuring security of a route according to any one of claims 1 to 5.
7. A routing security configuration device, characterized by, 8. A computer-readable storage medium, characterized in that, 9. A computer program product comprising computer programs / instructions, characterized in that,
Citation Information
Patent Citations
Data processing method, device and equipment
CN116455586A