A path determination method and apparatus

CN118944975BActive Publication Date: 2026-09-25CHINA UNITED NETWORK COMM GRP CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411304232.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-18
Publication Date
2026-09-25
Estimated Expiration
2044-09-18

AI Technical Summary

Technical Problem

因此,当网络设备存在安全隐患或被恶意攻击时,无法保障网络传输路径的安全性和可信性,进而无法保障安全需求较高的业务的安全传输

Benefits of technology

[0044]第七方面,本申请提供了一种计算机程序产品,计算机程序产品包含计算机指令,当计算机指令在计算机上运行时,使得计算机执行如第一方面及第一方面的任一种可能的实现方式中任一项所述的路径确定方法,或第二方面及第二方面的任一种可能的实现方式中任一项所述的路径确定方法。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118944975B_ABST
    Figure CN118944975B_ABST
Patent Text Reader

Abstract

The application provides a path determination method and device, relates to the technical field of network security, and can guarantee the security and reliability of a network transmission path and ensure the safe transmission of a high-security-demand service. The method comprises the following steps: acquiring the reliability of each network node, then determining at least one transmission path for a target service based on the reliability of each network node, and finally sending the at least one transmission path to each network node. The reliability of each network node is used to represent the accuracy of the node information of the network node, and each transmission path is used to transmit the target service.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and in particular to a path determination method and apparatus. Background Technology

[0002] As businesses gradually move towards cloudification, IoT, and wireless connectivity, network boundaries are also expanding, leading to a diversification of user access methods, device types, and service types. Against this backdrop, higher demands are being placed on network security and reliability.

[0003] The trustworthiness of network devices is a crucial foundation for ensuring network security and a key element for guaranteeing the secure transmission of business requests. Therefore, when network devices have security vulnerabilities or are maliciously attacked, the security and trustworthiness of the network transmission path cannot be guaranteed, thus compromising the secure transmission of services with high security requirements. Summary of the Invention

[0004] This application provides a path determination method and apparatus that can accurately verify the legitimacy and security of network devices accessing the network, and use the security and legitimacy of network devices as evaluation factors for selecting transmission paths, thereby ensuring the security and reliability of network transmission paths and ensuring the secure transmission of services with high security requirements.

[0005] To achieve the above objectives, this application adopts the following technical solution:

[0006] Firstly, this application provides a path determination method, which can be executed by a controller, the method comprising:

[0007] Obtain the trustworthiness of each network node. The trustworthiness of each network node is used to characterize the accuracy of the node information of the network node.

[0008] Based on the trustworthiness of each network node, at least one transmission path is determined for the target service. Each transmission path is used to transmit the target service.

[0009] Send at least one transmission path to each network node.

[0010] Based on the above technical solution, the controller can determine at least one transmission path that matches the service requirements of the target service based on the trustworthiness of each network node. Thus, by using the trustworthiness of network nodes as an evaluation factor in determining the transmission path, the security and trustworthiness of the network transmission path can be guaranteed, thereby ensuring that the target service is securely transmitted along a secure and trustworthy path.

[0011] Optionally, based on the trustworthiness of each network node, at least one transmission path can be determined for the target service. This may include: determining the security level of the target service, and determining at least one transmission path for the target service based on the trustworthiness of each network node and the security level of the target service.

[0012] The security level of the target business is used to characterize the importance of the target business.

[0013] Optionally, determining at least one transmission path for the target service based on the trustworthiness of each network node may further include: obtaining the network status of each network node, and determining at least one transmission path for the target service based on the trustworthiness and network status of each network node.

[0014] Optionally, the above method may further include: for each network node, obtaining the accuracy of the node information of the network node, and determining the credibility of the network node based on the accuracy of the node information of the network node.

[0015] Secondly, this application provides a path determination method, which can be executed by a server, the method comprising:

[0016] Obtain node information for each network node.

[0017] For each network node, the node information is verified to obtain the accuracy of the node information.

[0018] The accuracy of sending data to each network node.

[0019] Based on the above technical solution, for each network node, the server can verify the node information of each network node to obtain the accuracy of the node information of each network node. In this way, it can effectively verify whether each network node is in a safe and trustworthy state, so that the controller can include safe and trustworthy network nodes in the transmission path.

[0020] Optionally, the node information for each network node includes the node identifier and configuration information. Based on this, the node information is verified to determine its accuracy, which may include:

[0021] If the node identifier of a network node is verified, the configuration information of the network node is verified to obtain the accuracy of the node information.

[0022] Optionally, the above method may further include: if the node identifier verification of the network node fails, setting the accuracy of the node information of the network node to a preset value and sending a response message to the network node.

[0023] The response message indicates that the node identifier verification of the network node failed.

[0024] Optionally, the above method may further include: receiving an identifier acquisition request sent by a network node, then calling the decentralized identifier (DID) interface to allocate a node identifier to the network node, finally storing the corresponding node identifier and network node, and sending the node identifier to the network node.

[0025] Thirdly, this application provides a path determination device located in a controller, comprising:

[0026] The processing unit is used to obtain the trustworthiness of each network node. The trustworthiness of each network node is used to characterize the accuracy of the node information of the network node.

[0027] The determining unit is used to identify at least one transmission path for the target service based on the trustworthiness of each network node. Each transmission path is used to transmit the target service.

[0028] The sending unit is used to send at least one transmission path to each network node.

[0029] Optionally, the determining unit is further configured to determine the security level of the target service, and based on the trustworthiness of each network node and the security level of the target service, determine at least one transmission path for the target service. The security level of the target service is used to characterize the importance of the target service.

[0030] Optionally, the processing unit is also used to obtain the network status of each network node.

[0031] Optionally, the determining unit is also used to determine at least one transmission path for the target service based on the trustworthiness of each network node and the network status of each network node.

[0032] Optionally, the determining unit is also used to obtain the accuracy of the node information of each network node, and determine the credibility of the network node based on the accuracy of the node information.

[0033] Fourthly, this application provides a path determination device located on a server, comprising:

[0034] The processing unit is used to obtain node information of each network node.

[0035] The verification unit is used to verify the node information of each network node to obtain the accuracy of the node information.

[0036] The sending unit is used to send the accuracy of each network node.

[0037] Optionally, the verification unit is also used to verify the configuration information of the network node if the node identifier of the network node is verified to obtain the accuracy of the node information of the network node.

[0038] Optionally, the processing unit is also configured to set the accuracy of the network node's node information to a preset value if the node identifier verification of the network node fails.

[0039] Optionally, the sending unit is also used to send a response message to the network node if the node identifier verification of the network node fails.

[0040] Optionally, the processing unit is also used to call the DID interface to assign node identifiers to network nodes and store the corresponding node representations and network nodes.

[0041] Optionally, the sending unit is also used to send a node identifier to a network node.

[0042] Fifthly, this application provides a path determination apparatus, comprising: a processor and a communication interface. The communication interface is coupled to the processor, which is configured to execute a computer program or instructions to implement the path determination method as described in any one of the first aspects and any possible implementations thereof, or the path determination method as described in any one of the second aspects and any possible implementations thereof.

[0043] In a sixth aspect, this application provides a computer-readable storage medium storing instructions that, when executed on a terminal, cause the terminal to perform a path determination method as described in any one of the first aspects and any possible implementations of the first aspect, or a path determination method as described in any one of the second aspects and any possible implementations of the second aspect.

[0044] In a seventh aspect, this application provides a computer program product comprising computer instructions that, when executed on a computer, cause the computer to perform a path determination method as described in any one of the first aspects and any possible implementations thereof, or a path determination method as described in any one of the second aspects and any possible implementations thereof.

[0045] Understandably, the beneficial effects that can be achieved by the third to seventh aspects provided above can be referred to as the beneficial effects in any possible design of the path determination method as described in any one of the first aspects and any possible implementations of the first aspect, or the beneficial effects in any possible design of the path determination method as described in any one of the second aspects and any possible implementations of the second aspect, which will not be elaborated here. Attached Figure Description

[0046] Figure 1 An architecture diagram of a path determination system provided in this application embodiment;

[0047] Figure 2 A flowchart illustrating a path determination method provided in an embodiment of this application;

[0048] Figure 3 An interactive flowchart of a path determination method provided in an embodiment of this application;

[0049] Figure 4 An interactive flowchart of another path determination method provided in an embodiment of this application;

[0050] Figure 5 This is a schematic diagram of the structure of a path determination device provided in an embodiment of this application;

[0051] Figure 6 This is a schematic diagram of another path determination device provided in an embodiment of this application;

[0052] Figure 7 This is a schematic diagram of another path determination device provided in an embodiment of this application. Detailed Implementation

[0053] The path determination method and apparatus provided in this application will now be described in detail with reference to the accompanying drawings.

[0054] In this article, the term "and / or" is merely a description of the relationship between related objects, indicating that there can be three relationships. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone.

[0055] The terms "first" and "second," etc., used in the specification and drawings of this application are used to distinguish different objects or to distinguish different treatments of the same object, rather than to describe a specific order of objects.

[0056] Furthermore, the terms "comprising" and "having," and any variations thereof, used in the description of this application are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the steps or units listed, but may optionally include other steps or units not listed, or may optionally include other steps or units inherent to such process, method, product, or apparatus.

[0057] It should be noted that in the embodiments of this application, the words "exemplary" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design scheme described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design schemes. Specifically, the use of the words "exemplary" or "for example" is intended to present the relevant concepts in a specific manner.

[0058] With the rapid development of information technology, businesses are gradually moving towards cloudification, the Internet of Things (IoT), and wireless connectivity. This trend has not only driven the extension of network boundaries but also spurred diverse application scenarios such as smart cities, telemedicine, and autonomous driving. This has led to a diversification of user access methods, device types, service types, and connection methods, while also placing higher demands on network security and reliability. Against this backdrop, the security and trustworthiness of network devices have become crucial elements in ensuring the transmission of service requests.

[0059] Currently, traditional network security protection mainly relies on a "perimeter defense + data encryption" strategy. This involves deploying security devices such as firewalls and intrusion detection systems at the network perimeter and encrypting transmitted data to defend against external threats. However, in the face of complex and ever-changing network environments, traditional network security strategies are insufficient to meet the secure transmission requirements of business requests, especially for services with high security needs. Furthermore, if network devices (such as routers) have security vulnerabilities or are maliciously attacked during the transmission of business requests, it may lead to data leakage, damage, or theft, thus compromising the secure transmission of business requests.

[0060] To address the aforementioned technical problems, this application provides a path determination method. The server can verify the node information of each acquired network node to determine its accuracy, thus effectively verifying whether the network node is in a secure and trustworthy state. Higher accuracy of the network node information indicates higher trustworthiness of the network node. Based on the trustworthiness of each network node, the controller can determine at least one transmission path matching the service requirements of the target service. By using the trustworthiness of network nodes as an evaluation factor in determining the transmission path, the security and trustworthiness of the network transmission path can be guaranteed, thereby ensuring that the target service is securely transmitted along a secure and trustworthy path.

[0061] Figure 1 An architecture diagram of a path determination system provided in this application embodiment is shown below. Figure 1 As shown, the system architecture includes: network node 101, server 102 and controller 103.

[0062] In this embodiment, network node 101 can be a gateway device that connects different networks and provides network communication and data transmission services to these networks. Network node 101 may include, but is not limited to, routers, switches, and virtual private network (VPN) devices.

[0063] This application embodiment does not specifically limit the number of network nodes 101 in the path determination system, and may include more than Figure 1 More or fewer network nodes 101.

[0064] Server 102 and controller 103 can be high-performance servers providing various services on the internet. They can be standalone physical servers, server clusters consisting of multiple physical servers, or cloud servers providing at least one of the following basic cloud computing services: cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks, and big data or artificial intelligence platforms. This application embodiment does not limit these specific features. Of course, the server can also include other functions to provide more comprehensive and diversified services.

[0065] In this embodiment, each network node 101 can send node information to the server 102. After receiving the node information sent by each network node 101, the server 102 can verify the node information of each network node 101 to obtain the accuracy of the node information, and send the accuracy of the node information of each network node 101 back to the network node 101. After receiving the accuracy of its own node information, each network node 101 can send the accuracy of its own node information to the controller 103. After receiving the accuracy of the node information of each network node 101, the controller 103 can determine the trustworthiness of each network node 101 based on the accuracy of the node information of each network node 101. Then, based on the trustworthiness of each network node 103, the controller 103 can determine at least one transmission path for the target service and send at least one transmission path to each network node 101.

[0066] Optionally, network node 101 can also send an identifier acquisition request to server 102. After receiving the identifier acquisition request from the network node, server 102 can assign a node identifier to the network node and send the node identifier to network node 101.

[0067] Network node 101 may be equipped with a blockchain-based trusted network verify (B-TNV) client. Server 102 may be equipped with a DID system and an information verification system. The DID system is used to assign node identifiers to network node 101, and the information verification system is used to verify the node information of network node 101.

[0068] Optionally, network node 101 can send an identifier acquisition request to server 102 through its installed B-TNV client. After receiving the identifier acquisition request from network node 101, the server can assign a node identifier to network node 101 by calling the DID interface.

[0069] Optionally, network node 101 can send node information to server 102 via its installed B-TNV client. After receiving the node information sent by network node 101, server 102 can call the information verification interface to verify the node information of network node 101, obtain the accuracy of the node information of network node 101, and send the accuracy of the node information of network node 101 back to network node 101.

[0070] This application embodiment does not specifically limit the number of servers 102 in the path determination system, and may include more than [a certain number]. Figure 1 More or fewer servers 102.

[0071] Optionally, the server 102 may also send the accuracy of the node information of each network node 101 to the trusted device 104. After receiving the accuracy of the node information of each network node 101, the trusted device 104 may determine the trustworthiness of each network node 101 based on the accuracy of the node information of each network node 101, and send the trustworthiness of each network node 101 to the controller 103.

[0072] Therefore, the above path determination system may also include a trusted device 104.

[0073] In this embodiment, the trusted device 104 may be a server of the same type as the server 102 and controller 103 described above, and there is no limitation thereto.

[0074] Optionally, the path determination system may further include a service request terminal 105, used to send the target service to network node 101. After receiving the target service, network node 101 can send it to controller 103. Correspondingly, after receiving the target service, controller 103 can determine at least one transmission path for the target service based on the trustworthiness of each network node 101, and send at least one transmission path to network node 101. Then, network node 101 can determine an optimal path that satisfies the target service based on the transmission path sent by controller 103, and transmit the target service according to the optimal path.

[0075] In this embodiment, the service demand side 105 can be a server or a terminal device.

[0076] The server can be of the same type as the server 102 and controller 103 mentioned above, and there are no restrictions on this.

[0077] The terminal device can be an electronic device that provides voice and / or data connectivity to a user, a device with wireless connectivity, or other devices connected to a wireless modem. The terminal device can be at least one of devices such as a desktop computer, laptop, wireless terminal, and laptop computer. In one embodiment, the electronic device has communication capabilities and can access a wired or wireless network.

[0078] Figure 2 This is a flowchart illustrating a path determination method provided in an embodiment of this application. The method comprises... Figure 1 The controller shown executes, as follows: Figure 2 As shown, the method includes:

[0079] S201, obtain the trustworthiness of each network node.

[0080] The credibility of each network node is used to characterize the accuracy of the node information of the network node. The credibility of a network node is positively correlated with the accuracy of the node information of the network node. That is, the higher the accuracy of the node information of the network node, the higher the credibility of the network node.

[0081] In some embodiments, the controller may obtain the trustworthiness of each network node through a trusted device, or it may obtain the trustworthiness of each network node through each network node itself.

[0082] For example, a trusted device can send the trustworthiness of each network node to the controller, and the controller can receive the trustworthiness of each network node sent by the trusted device. Alternatively, each network node can send the accuracy of its own node information to the controller, and the controller can receive the accuracy of the node information of each network node and determine the trustworthiness of each network node based on the accuracy of the node information of each network node.

[0083] S202, based on the trustworthiness of each network node, determines at least one transmission path for the target service.

[0084] Each transmission path is used to transmit the target service.

[0085] In some embodiments, the controller can determine the security level of the target service, and then determine at least one transmission path for the target service based on the trustworthiness of each network node and the security level of the target service.

[0086] In this embodiment, the representation of the security level of the target service and the trustworthiness of the network node is not limited. For example, the security level of the target service can be level 1, level 2, or level 3, or level A, level B, or level C, etc., and the trustworthiness of the network node can be represented by a value between 0 and 1.

[0087] For example, after receiving the target service, the network node sends it to the controller. Accordingly, upon receiving the target service, the controller determines its security level. Then, based on the security level of the target service and the trustworthiness of the network nodes, the controller can determine at least one transmission path matching the security level of the target service, where the trustworthiness of the network nodes traversed in each transmission path matches the security level of the target service. For example, if the security level of the target service is level 3, the controller can select network nodes with a trustworthiness equal to or greater than 0.3 to transmit the target service.

[0088] In other embodiments, the controller can acquire the network status of each network node, and then determine at least one transmission path for the target service based on the trustworthiness and network status of each network node.

[0089] For example, after receiving a target service, a network node can send the target service and its own network status to the controller. The network status of the network node can include network latency, uplink and downlink bandwidth between network nodes, and packet loss rate. After receiving the target service and the network node's network status, the controller can select a network node with high reliability and / or good network status to transmit the target service. For example, network node A has a reliability of 0.3, a latency of 100 milliseconds, a bandwidth of 100 megabits per second (Mega), and a packet loss rate of 1%, while network node B has a reliability of 0.2, a latency of 200 milliseconds, a bandwidth of 50 megabits per second (Mega), and a packet loss rate of 5%. The controller can choose network node A to transmit the target service.

[0090] Based on the above-mentioned determination of the security level of the target service and acquisition of the network status of network nodes, the controller can also determine at least one transmission path for the target service based on the trustworthiness of network nodes, network status, and the security level of the target service. For example, if the security level of the target service is level 2, network node A has a trustworthiness of 3, a latency of 100 milliseconds, a bandwidth of 100 Mbps, and a packet loss rate of 1%; network node B has a trustworthiness of 2, a latency of 200 milliseconds, a bandwidth of 50 Mbps, and a packet loss rate of 5%; and network node C has a trustworthiness of 1, a latency of 200 milliseconds, a bandwidth of 50 Mbps, and a packet loss rate of 5%, the controller can choose network node A and / or network node B to transmit the target service.

[0091] S203, send at least one transmission path to each network node.

[0092] In some embodiments, the controller may send at least one transmission path to each network node. Accordingly, each network node may select an optimal transmission path for the target service based on the received transmission path, and then transmit the target service according to the optimal transmission path.

[0093] Based on the above technical solution, the controller can obtain the trustworthiness of each network node, the network status of each network node, and determine the security level of the target service. Then, based on the trustworthiness of the network nodes, the security level of the target service, and / or the network status of the network nodes, it can select network nodes whose trustworthiness matches the security level of the target service, and / or network nodes with high trustworthiness and good network status to transmit the target service. In summary, the transmission path determined by the controller based on the trustworthiness of network nodes for the target service can ensure the security and reliability of the transmission path, thereby ensuring the secure transmission of target services with high security requirements.

[0094] In an optional implementation, in S201 above, the controller can obtain the trustworthiness of each network node through a trusted device, or it can obtain the trustworthiness of each network node through each network node itself. The following example illustrates the controller obtaining the trustworthiness of each network node through a trusted device, or vice versa. Figure 2 The method shown will be described in detail.

[0095] Figure 3 This is an interactive flowchart of a path determination method provided in an embodiment of this application. The method consists of... Figure 3 The network nodes, servers, controllers, and / or trusted devices shown perform the following actions: Figure 3 As shown, the method includes:

[0096] S301, each network node sends node information to the server.

[0097] The node information of a network node includes its node identifier and configuration information. The configuration information may include software configuration information such as the operating system, network protocols, and security software, as well as hardware configuration information such as the processor, memory, interfaces, and cables.

[0098] For example, each network node can send node information to the server through its own installed B-TNV client.

[0099] S302, the server verifies the node information of each network node to obtain the accuracy of the node information of each network node.

[0100] In some embodiments, after receiving the node information from each network node, the server may first call the information verification interface to verify the node identifier of the network node for each network node. If the node identifier of the network node passes verification, the server continues to call the information verification interface to verify the configuration information of the network node, obtain the accuracy of the node information, and store the node information and the accuracy of the node information in the server database.

[0101] If the node identifier verification of a network node fails, the server sets the accuracy of the network node's node information to a preset value, stores the network node and its node identifier in the database, and then sends a response message to the network node indicating that the node identifier verification failed.

[0102] The embodiments of this application do not limit the preset value. For example, the preset value can be 0, -1 or -2, etc.

[0103] For example, if the node identifier verification of a network node fails, the server can set the accuracy of the network node's node information to 0, indicating that the network node has low credibility and is not suitable for transmitting the target service.

[0104] S303, the accuracy of the node information of each network node sent by the server to the trusted device.

[0105] Optionally, the server can also send node information of each network node to trusted devices.

[0106] In some embodiments, the above S302 can be implemented as: the accuracy of the server sending the node information of the network nodes to each network node respectively.

[0107] S304, The trusted device determines the trustworthiness of each network node based on the accuracy of the node information of each network node.

[0108] The higher the accuracy of the node information of a network node, the higher the trustworthiness of the network node can be determined by a trusted device.

[0109] S305, the trusted device sends the trustworthiness of each network node to the controller.

[0110] In some embodiments, S304-S305 above can be implemented as follows: each network node sends the accuracy of its own node information to the controller. Accordingly, after receiving the accuracy of the node information sent by each network node, the controller can determine the trustworthiness of each network node based on the accuracy of the node information of each network node.

[0111] S306: The controller determines at least one transmission path for the target service based on the trustworthiness of each network node.

[0112] S307, the controller sends at least one transmission path to each network node.

[0113] In an optional implementation, before executing S301 above, the network node can send an identifier acquisition request to the server. Accordingly, after receiving the identifier acquisition request sent by the network node, the server can call the DID interface to allocate a node identifier for the network node, store the network node and the node identifier in the server's database, and then send the allocated node identifier to the network node.

[0114] Based on the above technical solution, the server can assign node identifiers to network nodes and verify the node identifiers and configuration information of network nodes to obtain the accuracy of the node information. Therefore, by verifying the legitimacy (i.e., node identifiers) and security (i.e., configuration information) of network nodes, the controller can select legitimate and secure network nodes to transmit target services, ensuring the secure transmission of services with high security requirements.

[0115] The path determination method provided in this application will be described in detail below in conjunction with the various embodiments described above. Figure 4 An interactive flowchart of another path determination method provided in the embodiments of this application is shown below. Figure 4 As shown, the method includes:

[0116] S401, the network node sends an identifier acquisition request to the server through the installed B-TNV client.

[0117] S402, the server calls the DID interface to assign node identifiers to network nodes and stores the network nodes and their node identifiers.

[0118] S403, the server sends the node identifier to the network node.

[0119] S404, network nodes send node information to the server through the installed B-TNV client.

[0120] S405, the server calls the information verification interface to verify whether the node identifier of the network node is valid.

[0121] If the verification passes, proceed to steps S406-S407; if the verification fails, proceed to steps S408-S418.

[0122] S406, the server sets the accuracy of the node information of the network nodes to a preset value.

[0123] S407, the server sends a response message to the network node.

[0124] S408, the server calls the information verification interface to verify the configuration information of the network node and obtain the accuracy of the network node information.

[0125] S409, the accuracy of the node information sent by the server to the network node.

[0126] S410, the server sends the node information of the network node and the accuracy of the node information of the network node to the trusted device.

[0127] S411, The trusted device determines the trustworthiness of a network node based on the accuracy of the node information received from the network node.

[0128] S412, the trusted device sends the trustworthiness of the network node and the node information of the network node to the controller.

[0129] S413, the service requester sends the target service to the network node.

[0130] S414, the network node sends the target service to the controller.

[0131] S415, the controller determines the security level of the target service and the network status of the network nodes.

[0132] S416, the controller determines at least one transmission path for the target service based on the trustworthiness of the network node, the security level of the target service, and the network status of the network node.

[0133] S417, the controller sends at least one transmission path to the network node.

[0134] S418: Based on the security level of the target service, the network node selects the optimal transmission path for the target service.

[0135] Figure 5 This is a schematic diagram of a path determination device provided in an embodiment of this application. The device is located in the controller, such as... Figure 5 As shown, the device includes:

[0136] The processing unit 501 is used to obtain the credibility of each network node. The credibility of each network node is used to characterize the accuracy of the node information of the network node.

[0137] The determining unit 502 is used to determine at least one transmission path for the target service based on the trustworthiness of each network node. Each transmission path is used to transmit the target service.

[0138] The sending unit 503 is used to send at least one transmission path to each network node.

[0139] Optionally, the determining unit 502 is further configured to determine the security level of the target service, and based on the trustworthiness of each network node and the security level of the target service, determine at least one transmission path for the target service. The security level of the target service is used to characterize the importance of the target service.

[0140] Optionally, the processing unit 501 is also used to obtain the network status of each network node.

[0141] Optionally, the determining unit 502 is further configured to determine at least one transmission path for the target service based on the trustworthiness of each network node and the network status of each network node.

[0142] Optionally, the determining unit 502 is further configured to, for each network node, obtain the accuracy of the node information of the network node, and determine the credibility of the network node based on the accuracy of the node information of the network node.

[0143] Figure 6 This is a schematic diagram of a path determination device provided in an embodiment of this application. The device is located on a server, such as... Figure 6 As shown, the device includes:

[0144] The processing unit 601 is used to obtain node information of each network node.

[0145] The verification unit 602 is used to verify the node information of each network node to obtain the accuracy of the node information.

[0146] The transmitting unit 603 is used to transmit the accuracy of each network node.

[0147] Optionally, the verification unit 602 is further configured to verify the configuration information of the network node if the node identifier of the network node is verified to obtain the accuracy of the node information of the network node.

[0148] Optionally, the processing unit 601 is further configured to set the accuracy of the network node's node information to a preset value if the node identifier verification of the network node fails.

[0149] Optionally, the sending unit 603 is also used to send a response message to the network node if the node identifier verification of the network node fails.

[0150] Optionally, the processing unit 601 is also used to call the DID interface to assign node identifiers to network nodes and store the corresponding node representations and network nodes.

[0151] Optionally, the sending unit 603 is also used to send a node identifier to a network node.

[0152] Figure 7 A schematic diagram of another possible structure of the path determination device involved in the above embodiments is shown. The path determination device includes a processor 701 and a communication interface 702. The processor 701 is used to control and manage the operation of the path determination device, and the communication interface 702 is used to support communication between the path determination device and other network entities. The path determination device may also include a memory 703 and a bus 704, the memory 703 being used to store the program code and data of the path determination device.

[0153] The memory 703 may be a memory in a path determination device, and the memory may include volatile memory, such as random access memory; the memory may also include non-volatile memory, such as read-only memory, flash memory, hard disk or solid-state drive; the memory may also include a combination of the above types of memory.

[0154] The processor 701 described above can implement or execute various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. The processor can be a central processing unit, a general-purpose processor, a digital signal processor, an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It can implement or execute various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. The processor can also be a combination that implements computing functions, such as including one or more microprocessor combinations, a combination of a DSP and a microprocessor, etc.

[0155] The 704 bus can be an Extended Industry Standard Architecture (EISA) bus, etc. The 704 bus can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 7 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.

[0156] Through the above description of the embodiments, those skilled in the art will clearly understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. The specific working process of the system, device, and unit described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0157] This application provides a computer program product containing instructions that, when run on a computer, cause the computer to execute the path determination method in the above method embodiments.

[0158] This application also provides a computer-readable storage medium storing instructions that, when executed on a computer, cause the computer to perform the path determination method in the method flow shown in the above method embodiments.

[0159] The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples (a non-exhaustive list) of computer-readable storage media include: electrical connections having one or more wires; portable computer disks; hard disks; random access memory (RAM); read-only memory (ROM); erasable programmable read-only memory (EPROM); registers; hard disks; optical fibers; portable compact disc read-only memory (CD-ROM); optical storage devices; magnetic storage devices; or any suitable combination thereof; or any other form of computer-readable storage medium known in the art. An exemplary storage medium is coupled to a processor, enabling the processor to read information from and write information to the storage medium. Of course, the storage medium may also be a component of the processor. The processor and the storage medium may reside in an application-specific integrated circuit (ASIC). In the embodiments of this application, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.

[0160] Embodiments of the present invention provide a computer program product containing instructions that, when executed on a computer, cause the computer to perform the path determination method described in the embodiments of this application.

[0161] Since the path determination device, computer-readable storage medium, and computer program product in the embodiments of the present invention can be applied to the above method, the technical effects obtained can also be referred to the above method embodiments, and the embodiments of the present invention will not be repeated here.

[0162] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the mutual coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.

[0163] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0164] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0165] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A path determination method, characterized in that, Applied to a controller, the method includes: The trustworthiness of each network node is obtained through a trusted device; the trustworthiness of each network node is used to characterize the accuracy of the node information of the network node; wherein, the trustworthiness of each network node is determined by the trusted device based on the node information of each network node, the network node is equipped with a blockchain-based trusted network verification client, and the accuracy of the node information of each network node is determined by the server through the node information of the network node sent by the trusted network verification client, the node information including the node identifier of the network node assigned based on the distributed identity identifier DID and the configuration information of the network node; Determine the security level of the target service; the security level of the target service is used to characterize the importance of the target service. Based on the trustworthiness of each network node and the security level of the target service, at least one transmission path is determined for the target service; each transmission path is used to transmit the target service. The at least one transmission path is sent to each of the network nodes so that each network node selects the optimal transmission path from the at least one transmission path.

2. The method according to claim 1, characterized in that, The process of determining at least one transmission path for the target service based on the trustworthiness of each network node includes: Obtain the network status of each network node; Based on the trustworthiness of each network node and the network status of each network node, at least one transmission path is determined for the target service.

3. A path determination method, characterized in that, Applied to a server connected to a network node, the method includes: Receive an identifier retrieval request sent by a network node; Call the Distributed Identity Identifier (DID) interface to assign a node identifier to the network node; The node identifier and the network node are stored accordingly, and the node identifier is sent to the network node; Obtain node information for each network node; the node information for each network node includes the node identifier of the network node assigned based on the Distributed Identity Identifier (DID) and the configuration information of the network node; For each network node, if the node identifier of the network node is verified, the configuration information of the network node is verified to obtain the accuracy of the node information of the network node. The accuracy of each network node is sent to the controller so that the controller can determine the trustworthiness of each network node based on the accuracy of each network node, and determine at least one transmission path for the target service based on the trustworthiness of each network node.

4. The method according to claim 3, characterized in that, The method further includes: If the node identifier verification of the network node fails, the accuracy of the node information of the network node is set to a preset value, and a response message is sent to the network node; the response message is used to indicate that the node identifier verification of the network node failed.

5. A path determination device, characterized in that, The device is located in the controller, and the device includes: A processing unit is configured to obtain the trustworthiness of each network node through a trusted device; the trustworthiness of each network node is used to characterize the accuracy of the node information of the network node; wherein, the trustworthiness of each network node is determined by the trusted device based on the node information of each network node, the network node is equipped with a blockchain-based trusted network verification client, and the accuracy of the node information of each network node is determined by the server through the node information of the network node sent by the trusted network verification client, the node information including the node identifier of the network node assigned based on the distributed identity identifier DID and the configuration information of the network node; A determining unit is used to determine the security level of a target service; the security level of the target service is used to characterize the importance of the target service. The determining unit is configured to determine at least one transmission path for the target service based on the trustworthiness of each network node and the security level of the target service; each transmission path is used to transmit the target service. The sending unit is configured to send the at least one transmission path to each of the network nodes, so that each network node selects the optimal transmission path from the at least one transmission path.

6. A path determination device, characterized in that, The device is located on a server, and the device includes: The processing unit is used to receive the identifier acquisition request sent by the network node; Call the Distributed Identity Identifier (DID) interface to assign a node identifier to the network node; The node identifier and the network node are stored accordingly, and the node identifier is sent to the network node; The processing unit is used to obtain node information of each network node; the node information of each network node includes the node identifier of the network node assigned based on the distributed identity identifier DID and the configuration information of the network node; The verification unit is used to verify the configuration information of each network node, provided that the node identifier of the network node is verified as valid, to obtain the accuracy of the node information of the network node. The sending unit is used to send the accuracy of each network node to the controller, so that the controller can determine the trustworthiness of each network node based on the accuracy of each network node, and determine at least one transmission path for the target service based on the trustworthiness of each network node.

7. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores instructions that, when executed by a computer, enable the computer to perform the path determination method as described in any one of claims 1-2, or the path determination method as described in any one of claims 3-4.

8. A computer program product, characterized in that, The computer program product includes computer instructions that, when executed on a computer, cause the computer to perform the path determination method as described in any one of claims 1-2, or the path determination method as described in any one of claims 3-4.

Citation Information

Patent Citations

  • Secure routing based on the physical locations of routers

    CN105103619A

  • Trusted path establishment method and device and storage medium

    CN118432934A