Methods and related devices for secure transmission of messages
By negotiating IPsec SA in the wide area network and utilizing overlay end-to-end tunnel transmission, the problem of cumbersome tunnel encryption and decryption operations is solved, enabling secure and fast transmission of VPN service packets, reducing transmission latency, and improving efficiency.
Patent Information
- Application Number
- CN202310803215.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-06-30
- Publication Date
- 2025-12-02
- Estimated Expiration
- 2043-06-30
AI Technical Summary
In existing technologies, tunnel encryption and decryption operations are cumbersome, consume a lot of equipment computing resources, and increase the delay of business message forwarding, especially when crossing multiple tunnel segments.
The IPsec SA associated with the VRF is pre-negotiated between the first and second edge sites. After the first edge site receives the VPN service packet, it is protected by security. Then it is transmitted through the upper overlay end-to-end tunnel. Security protection is only performed at the ingress point of the tunnel to avoid encryption and decryption operations on each POP.
This reduces encryption and decryption operations during tunnel transmission, saves computing resources, reduces transmission latency, and improves message transmission efficiency.
Smart Images

Figure CN119232523B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of wide area network message transmission, and in particular to methods for secure message transmission and methods and related apparatus for negotiating IPsec SA. Background Technology
[0002] An overlay network can be built on top of the underlay network by establishing tunnels between multiple network nodes. The overlay network decouples services from the underlying network, enabling rapid end-to-end delivery of service packets.
[0003] However, since the tunnel is built on the operator's network, this network cannot guarantee the security of service packets. Therefore, the tunnel itself needs to possess certain security capabilities to ensure the security of service packets. The commonly used method is to negotiate a key between the ingress and egress nodes of the tunnel using the Border Gateway Protocol (BGP) at the transport network port (TNP) granularity when establishing the tunnel on the control plane. The key is bound to the ports of both the ingress and egress nodes. After the tunnel is established, when service packets are transmitted within the tunnel, the ingress node encrypts the service packets according to the key negotiated with the egress node, ensuring the service packets are encrypted during transmission. When the service packets reach the egress node, the egress node decrypts the service packets using the negotiated key, thus ensuring the security of service packet transmission.
[0004] The aforementioned method of encrypting and decrypting packets based on the TNP granularity of network nodes requires negotiation of key information between the ingress and egress nodes for each tunnel segment. When a service packet is transmitted within a tunnel segment, it is encrypted at the ingress node according to the negotiated method and decrypted at the egress node according to the negotiated method. When the service flow needs to traverse multiple tunnel segments, the keys between each tunnel segment are different. Encryption and decryption must be performed at the ingress node and egress node of each tunnel segment, and so on, with the encryption and decryption operations being cumbersome, consuming a large amount of device computing resources, and increasing the forwarding latency of service packets. Summary of the Invention
[0005] This application provides a method for securely transmitting messages, a method for negotiating IPsec SA, and related apparatus. Using the method described in this application can improve message transmission efficiency and reduce transmission latency.
[0006] In a first aspect, this application provides a method for securely transmitting messages, described from the sending side of the data forwarding plane, the method comprising:
[0007] The first site exit device edge in the wide area network receives and forwards VPN service packets from the virtual route in the VRF;
[0008] The first edge station performs security protection on the VPN service packets according to the Internet Protocol Security Protocol Security Association (IPsecSA) associated with the VRF, which is negotiated with the second edge station, in order to obtain the first packet;
[0009] The first station edge encapsulates the tunnel information of the upper-layer overlay end-to-end tunnel established between the first station edge and the second station edge on the outer layer of the first message to obtain the second message. The underlying underlay tunnel corresponding to the overlay end-to-end tunnel includes multiple tunnel segments. The tunnel information includes the first information of the first access point (POP). The first station edge is the ingress point of the overlay end-to-end tunnel, the second station edge is the egress point of the overlay end-to-end tunnel, and the overlay end-to-end tunnel passes through the first POP.
[0010] The first edge station sends the second message to the second edge station through the overlay end-to-end tunnel.
[0011] In this application's solution, in scenarios where multiple tunnels span between the first and second site edges, the first and second site edges pre-negotiate an IPsecSA associated with the VRF. After receiving a VPN service packet from the VRF, the first site edge performs security protection on the VPN service packet according to the IPsecSA associated with the VRF negotiated with the second site edge, obtaining a first packet. Then, it encapsulates the tunnel information of the upper-layer overlay end-to-end tunnel established between the first and second site edges on the outer layer of the first packet, obtaining a second packet. Finally, the first site edge transmits the second packet to the second site edge through the upper-layer overlay end-to-end tunnel. Each POP traversed by the overlay end-to-end tunnel does not need to decrypt or encrypt the second packet; it only needs to forward it according to the tunnel information.
[0012] In scenarios where multiple tunnels span between a first edge and a second edge, this application provides a method for securely transmitting messages. This method only requires security protection at the ingress point of the overlay end-to-end tunnel established between the two edge sites. During transmission, each POP does not need to encrypt or decrypt the message, saving computing resources, reducing transmission latency, and improving message transmission efficiency.
[0013] Based on the first aspect, in possible implementations, the security protection of the VPN service packets includes: encapsulating the VPN service packets with a security payload ESP protocol encryption; and / or encapsulating the VPN service packets with an authentication header.
[0014] Based on the first aspect, in a possible implementation, the tunnel information further includes second information of the second POP, the overlay end-to-end tunnel passes through the first POP and the second POP, the first station edge accesses the wide area network through the first POP, and the second station edge accesses the wide area network through the second POP.
[0015] Based on the first aspect, in a possible implementation, the overlay end-to-end tunnel is an Internet Protocol version 6 (IPv6) segment routing SRv6 tunnel, the second message includes an IPv6 header and a segment routing header (SRH), the destination address of the IPv6 header points to the first POP, and the SRH includes the first information and the second information.
[0016] The overlay end-to-end tunnel can be an SRv6 tunnel. The first site edge encapsulates the tunnel information of the SRv6 tunnel on the outer layer of the first packet. The tunnel information of the SRv6 tunnel includes the IPv6 header and the Segmentation Routing Header (SRH). Each POP on the tunnel can forward the second packet according to the IPv6 header and the Segmentation Routing Header (SRH).
[0017] Based on the first aspect, in a possible implementation, the first information is the first endpoint segment identifier END.SID of the first POP, and the operation associated with the first endpoint segment identifier END.SID includes: matching the upper-layer overlay SRv6 Policy from the first POP to the second POP according to the next-hop SID of the END.SID.
[0018] Based on the first aspect, in a possible implementation, the overlay end-to-end tunnel is a segmented routing multiprotocol label switching traffic engineering policy (SR-MPLS TE Policy), and the second packet includes an MPLS label stack, which includes the first information and the second information.
[0019] Based on the first aspect, in a possible implementation, the first information is the first node SID of the first POP, and the operation associated with the first node SID includes: matching the upper overlay SR MPLS tunnel from the first POP to the second POP according to the next-hop SID of the first node SID in the tag stack.
[0020] Based on the first aspect, in a possible implementation, the overlay end-to-end tunnel is a tunnel encapsulated based on the Geneve protocol for general network virtualization encapsulation, and the second message is encapsulated using SRv6 in Geneve.
[0021] Based on the first aspect, in a possible implementation, the overlay end-to-end tunnel is a tunnel encapsulated based on the Generic Routing Encapsulation (GRE) protocol, and the second message is encapsulated using SRv6 over GRE.
[0022] Based on the first aspect, in a possible implementation, before the first site edge receives the service message, the method further includes:
[0023] The first edge receives a Border Gateway Protocol (BGP) route advertised by the second edge. The BGP route includes a route type RT, the IPsec SA, the identifier of the second edge, and an exported route target ExportRT. The route type RT indicates that the IPsec SA advertised by the BGP route is used to provide end-to-end security protection for the VPN service packets in the VRF forwarded by the virtual route matching the ExportRT. Based on the route type RT and the ExportRT, the first edge associates the IPsec SA with the VRF.
[0024] A new route type has been added to BGP routing, carrying an IPsec SA and an Export RT. The newly added route type RT indicates that the IPsec SA advertised by the BGP route is used for end-to-end security protection of VPN service packets in the VRF matching the Export RT. Through BGP route advertisement, the first edge and the second edge negotiate an IPsec SA associated with the VRF. This IPsec SA is used to protect VPN service packets in the VRF, especially when multiple tunnels traverse between the first and second edge sites, laying the foundation for secure and fast transmission of VPN service packets. Implementing the embodiments of this application achieves secure and fast transmission of VPN service packets, reduces transmission latency, and improves transmission efficiency.
[0025] Based on the first aspect, in possible implementations, the BGP route is a BGP software-defined wide area network SD-WAN route, and the sub-address family of the BGP SD-WAN route is the SD-WAN sub-address family; or, the BGP route is a BGP Ethernet Virtual Private Network (EVPN) route, and the sub-address family of the BGP EVPN route is the EVPN sub-address family.
[0026] Based on the first aspect, in a possible implementation, the identifier of the second site edge includes the site ID to which the second site edge belongs and the node ID of the second site edge.
[0027] Based on the first aspect, in a possible implementation, the BGP route includes Network Layer Reachability Information (NLRI), which includes the route type (RT) and the identifier of the second site edge.
[0028] Based on the first aspect, in a possible implementation, the BGP route includes a Tunnel Encapsulation Attribute Type Length Value (TLV), which includes the IPsec SA.
[0029] Based on the first aspect, in a possible implementation, the BGP route includes an extended community attribute for carrying the Export RT.
[0030] Based on the first aspect, in possible implementations, the first site edge and the second site edge are site edges in a software-defined wide area network (SD-WAN).
[0031] Secondly, this application provides a method for securely transmitting messages, described from the receiving side of the data forwarding plane, the method comprising:
[0032] The second site egress device edge in the wide area network receives a second message sent by the first site edge through an upper-layer overlay end-to-end tunnel established between the first site edge and the second site edge. The second message includes the first message and tunnel information of the overlay end-to-end tunnel encapsulated in the outer layer of the first message. The underlying underlay tunnel corresponding to the overlay end-to-end tunnel includes multiple tunnel segments. The tunnel information includes the first information of the first ingress point (POP). The first site edge is the ingress point of the overlay end-to-end tunnel, and the second site edge is the egress point of the overlay end-to-end tunnel. The overlay end-to-end tunnel passes through the first POP. The first message is a message obtained by the Internet Protocol Security Association (IPsec SA) negotiated between the second site edge and the first site edge to provide security protection for VPN service messages.
[0033] The second station edge decapsulates the second packet to obtain the first packet;
[0034] The second site edge processes the first packet according to the IPsecSA to obtain the VPN service packet.
[0035] After receiving the second packet, the second edge station receives the first packet, which includes the first packet and tunnel information encapsulated in the outer layer of the first packet. The second edge station decapsulates the second packet to obtain the first packet, and then processes the first packet according to the IPsecSA negotiated with the first edge station to obtain the VPN service packet. Throughout the entire transmission process, the second packet does not require encryption or decryption at each POP on the overlay end-to-end tunnel; it only needs to be processed once at the second edge station, improving transmission efficiency and reducing transmission latency.
[0036] Based on the second aspect, in a possible implementation, processing the first message includes: encapsulating the first message with a security payload (ESP) protocol decryption according to the IPsecSA; and / or authenticating the first message according to the IPsecSA and the authentication data carried in the Authentication Header of the first message.
[0037] Based on the second aspect, in a possible implementation, the tunnel information further includes second information of the second POP, the overlay end-to-end tunnel passes through the first POP and the second POP, the first station edge accesses the wide area network through the first POP, and the second station edge accesses the wide area network through the second POP.
[0038] Based on the second aspect, in a possible implementation, the overlay end-to-end tunnel is an Internet Protocol version 6 (IPv6) segment routing SRv6 tunnel, the second message includes an IPv6 header and a segment routing header SRH, the destination address of the IPv6 header points to the first POP, and the SRH header includes the first information and the second information.
[0039] Based on the second aspect, in a possible implementation, the first information is the first endpoint segment identifier END.SID of the first POP, and the operation associated with the first endpoint segment identifier END.SID includes: matching the upper-layer overlay SRv6 Policy from the first POP to the second POP according to the next-hop SID of the END.SID.
[0040] Based on the second aspect, in a possible implementation, the overlay end-to-end tunnel is a segmented routing multiprotocol label switching traffic engineering policy (SR-MPLS TE Policy), and the second message includes an MPLS label stack, which includes the first information and the second information.
[0041] Based on the second aspect, in a possible implementation, the first information is the SID of the first node of the first POP, and the operation associated with the first node SID includes:
[0042] Match the upper-layer overlay SR MPLS tunnel from the first POP to the second POP based on the next-hop SID of the first node SID in the tag stack.
[0043] Based on the second aspect, in a possible implementation, the overlay end-to-end tunnel is a tunnel encapsulated based on the Geneve protocol for general network virtualization encapsulation, and the second message is encapsulated using SRv6 in Geneve.
[0044] Based on the second aspect, in a possible implementation, the overlay end-to-end tunnel is a tunnel encapsulated based on the Generic Routing Encapsulation (GRE) protocol, and the second message is encapsulated using SRv6 over GRE.
[0045] Based on the second aspect, in a possible implementation, before the second site egress device edge in the wide area network receives the second message sent by the first site edge through the upper-layer overlay end-to-end tunnel, the method further includes: the second site egress device edge generating a Border Gateway Protocol (BGP) route, wherein the BGP route includes a route type RT, the IPsec SA, an identifier of the second site edge, and an exported route target ExportRT, wherein the route type RT indicates that the IPsec SA advertised by the BGP route is used for end-to-end security protection of the VPN service packets in the VRF forwarding virtual route matching the Export RT; the second site edge advertises the BGP route to the first site edge.
[0046] Based on the second aspect, in possible implementations, the BGP route is a BGP software-defined wide area network SD-WAN route, and the sub-address family of the BGP SD-WAN route is the SD-WAN sub-address family; or, the BGP route is a BGP Ethernet Virtual Private Network (EVPN) route, and the sub-address family of the BGP EVPN route is the EVPN sub-address family.
[0047] Based on the second aspect, in a possible implementation, the identifier of the second site edge includes the site ID to which the second site edge belongs and the node ID of the second site edge.
[0048] Based on the second aspect, in a possible implementation, the BGP route includes Network Layer Reachability Information (NLRI), which includes the route type (RT) and the identifier of the second site edge.
[0049] Based on the second aspect, in a possible implementation, the BGP route includes a Tunnel Encapsulation Attribute Type Length value (TLV), which includes the IPsec SA.
[0050] Based on the second aspect, in a possible implementation, the BGP route includes an extended community attribute for carrying the Export RT.
[0051] Based on the second aspect, in possible implementations, the first site edge and the second site edge are site edges in a software-defined wide area network (SD-WAN).
[0052] Thirdly, this application provides a method for negotiating an Internet Protocol Security Agreement (IPsec SA), described from the receiving side of the control plane, the method comprising:
[0053] The first site egress device edge in the wide area network receives a Border Gateway Protocol (BGP) route advertised by the second site edge. The BGP route includes a route type RT, the IPsec SA, the identifier of the second site edge, and an exported route destination ExportRT. The route type RT indicates that the IPsec SA advertised by the BGP route is used to provide end-to-end security protection for service packets in the VRF forwarding the virtual route matching the ExportRT.
[0054] Based on the route type RT and the Export RT, the first site edge associates the IPsec SA with the VRF.
[0055] This application introduces a new route type, RT, into BGP routing. The BGP route carries an IPsec SA and an exported route target, ExportRT. The newly added route type RT instructs the IPsec SA advertised by the BGP route to provide end-to-end security protection for service packets in the VRF matched by ExportRT. By advertising BGP routes within the WAN, end-to-end IPsec SA negotiation at the VRF granularity is achieved between two edge sites, enabling the subsequent use of the negotiated IPsec SA for VPN service packet transmission, thus laying the foundation for VPN service packet transmission.
[0056] Based on the third aspect, in possible implementations, the BGP route is a BGP software-defined wide area network SD-WAN route, and the sub-address family of the BGP SD-WAN route is the SD-WAN sub-address family; or, the BGP route is a BGP Ethernet Virtual Private Network (EVPN) route, and the sub-address family of the BGP EVPN route is the EVPN sub-address family.
[0057] Based on the third aspect, in a possible implementation, the identifier of the second site edge includes the site ID to which the second site edge belongs and the node ID of the second site edge.
[0058] It is understandable that the site ID and node ID can uniquely identify a node.
[0059] Based on the third aspect, in a possible implementation, the BGP route includes Network Layer Reachability Information (NLRI), which includes the route type (RT) and the identifier of the second site edge.
[0060] Based on the third aspect, in a possible implementation, the BGP route includes a Tunnel Encapsulation Attribute Type Length Value (TLV), which includes the IPsec SA.
[0061] Based on the third aspect, in a possible implementation, the BGP route includes an extended community attribute for carrying the Export RT.
[0062] Based on the third aspect, in possible implementations, the first site edge and the second site edge are site edges in a software-defined wide area network (SD-WAN).
[0063] Fourthly, this application provides a method for negotiating an Internet Protocol Security Agreement (IPsec SA), described from the control plane sending side, the method comprising:
[0064] The second site egress device edge in the wide area network generates a Border Gateway Protocol (BGP) route, wherein the BGP route includes a route type RT, the IPsec SA, the identifier of the second site edge, and an exported route target ExportRT. The route type RT indicates that the IPsec SA advertised by the BGP route is used to provide end-to-end security protection for service packets in the VRF forwarding the virtual route matching the ExportRT.
[0065] The second edge announces the BGP route to the first edge.
[0066] This application introduces a new route type, RT, into BGP routing. The BGP route carries an IPsec SA and an exported route target, ExportRT. The newly added route type RT instructs the IPsec SA advertised by the BGP route to provide end-to-end security protection for service packets in the VRF matched by ExportRT. By advertising BGP routes within the WAN, end-to-end IPsec SA negotiation at the VRF granularity is achieved between two edge sites, enabling the subsequent use of the negotiated IPsec SA for VPN service packet transmission, thus laying the foundation for VPN service packet transmission.
[0067] Based on the fourth aspect, in possible implementations, the BGP route is a BGP software-defined wide area network SD-WAN route, and the sub-address family of the BGP SD-WAN route is the SD-WAN sub-address family; or, the BGP route is a BGP Ethernet Virtual Private Network (EVPN) route, and the sub-address family of the BGP EVPN route is the EVPN sub-address family.
[0068] Based on the fourth aspect, in a possible implementation, the identifier of the second site edge includes the site ID to which the second site edge belongs and the node ID of the second site edge.
[0069] Based on the fourth aspect, in a possible implementation, the BGP route includes Network Layer Reachability Information (NLRI), which includes the route type (RT) and the identifier of the second site edge.
[0070] Based on the fourth aspect, in a possible implementation, the BGP route includes a Tunnel Encapsulation Attribute Type Length Value (TLV), which includes the IPsec SA.
[0071] Based on the fourth aspect, in a possible implementation, the BGP route includes an extended community attribute for carrying the Export RT.
[0072] Based on the fourth aspect, in possible implementations, the first site edge and the second site edge are site edges in a software-defined wide area network (SD-WAN).
[0073] Fifthly, this application provides an apparatus for securely transmitting messages, the apparatus being applied to a first site egress device (edge) in a wide area network, the apparatus comprising:
[0074] The receiving module is used to receive VPN service packets in the Virtual Router Forwarding Function (VRF).
[0075] The processing module is used to perform security protection on the VPN service packets according to the Internet Protocol Security Protocol Security Association (IPsecSA) associated with the VRF negotiated with the second site edge, so as to obtain the first packet;
[0076] The processing module is used to encapsulate the tunnel information of the upper-layer overlay end-to-end tunnel established between the first site edge and the second site edge in the outer layer of the first message to obtain the second message. The lower-layer underlay tunnel corresponding to the overlay end-to-end tunnel includes multiple tunnel segments. The tunnel information includes the first information of the first access point (POP). The first site edge is the ingress point of the overlay end-to-end tunnel, the second site edge is the egress point of the overlay end-to-end tunnel, and the overlay end-to-end tunnel passes through the first POP.
[0077] The sending module is used to send the second message to the second station edge through the overlay end-to-end tunnel.
[0078] Based on the fifth aspect, in a possible implementation, the processing module is used to: encapsulate the VPN service message with a security payload ESP protocol encryption; and / or encapsulate the VPN service message with an authentication header (AuthenticationHeader).
[0079] Based on the fifth aspect, in a possible implementation, the tunnel information further includes second information of the second POP, the overlay end-to-end tunnel passes through the first POP and the second POP, the first station edge accesses the wide area network through the first POP, and the second station edge accesses the wide area network through the second POP.
[0080] Based on the fifth aspect, in a possible implementation, the overlay end-to-end tunnel is an Internet Protocol version 6 (IPv6) segment routing SRv6 tunnel, the second message includes an IPv6 header and a segment routing header (SRH), the destination address of the IPv6 header points to the first POP, and the SRH includes the first information and the second information.
[0081] Based on the fifth aspect, in a possible implementation, the first information is the first endpoint segment identifier END.SID of the first POP, and the operation associated with the first endpoint segment identifier END.SID includes: matching the upper-layer overly SRv6 Policy from the first POP to the second POP according to the next-hop SID of the END.SID.
[0082] Based on the fifth aspect, in a possible implementation, the overlay end-to-end tunnel is a segmented routing multiprotocol label switching traffic engineering policy (SR-MPLS TE Policy), and the second packet includes an MPLS label stack, which includes the first information and the second information.
[0083] Based on the fifth aspect, in a possible implementation, the first information is the first node SID of the first POP, and the operation associated with the first node SID includes: matching the upper-layer overly SR MPLS tunnel from the first POP to the second POP according to the next-hop SID of the first node SID in the tag stack.
[0084] Based on the fifth aspect, in a possible implementation, the overlay end-to-end tunnel is a tunnel encapsulated based on the Geneve protocol of general network virtualization encapsulation, and the second message is encapsulated using SRv6 in Geneve.
[0085] Based on the fifth aspect, in a possible implementation, the overlay end-to-end tunnel is a tunnel encapsulated based on the Generic Routing Encapsulation (GRE) protocol, and the second message is encapsulated using SRv6 over GRE.
[0086] Based on the fifth aspect, in a possible implementation, the receiving module is further configured to receive a Border Gateway Protocol (BGP) route advertised by the second site edge, the BGP route including a route type RT, the IPsec SA, an identifier of the second site edge, and an exported route target ExportRT, wherein the route type RT indicates that the IPsec SA advertised by the BGP route is used to perform end-to-end security protection on the VPN service packets in the VRF forwarded by the virtual route matching the ExportRT; the processing module is further configured to associate the IPsec SA with the VRF according to the route type RT and the ExportRT.
[0087] Based on the fifth aspect, in possible implementations, the BGP route is a BGP software-defined wide area network SD-WAN route, and the sub-address family of the BGP SD-WAN route is the SD-WAN sub-address family; or, the BGP route is a BGP Ethernet Virtual Private Network (EVPN) route, and the sub-address family of the BGP EVPN route is the EVPN sub-address family.
[0088] Based on the fifth aspect, in a possible implementation, the identifier of the second site edge includes the site ID to which the second site edge belongs and the node ID of the second site edge.
[0089] Based on the fifth aspect, in a possible implementation, the BGP route includes Network Layer Reachability Information (NLRI), which includes the route type (RT) and the identifier of the second site edge.
[0090] Based on the fifth aspect, in a possible implementation, the BGP route includes a Tunnel Encapsulation Attribute Type Length Value (TLV), which includes the IPsec SA.
[0091] Based on the fifth aspect, in a possible implementation, the BGP route includes an extended community attribute for carrying the Export RT.
[0092] Based on the fifth aspect, in possible implementations, the first site edge and the second site edge are site edges in a software-defined wide area network (SD-WAN).
[0093] The functional modules in the fifth aspect are used to implement the methods described in the first aspect and any possible implementation of the first aspect.
[0094] Sixthly, this application provides an apparatus for securely transmitting messages, the apparatus being applied to a second station (edge) in a wide area network, characterized in that the apparatus comprises:
[0095] The receiving module is configured to receive a second message sent by a first site edge through an upper-layer overlay end-to-end tunnel established between the first site edge and the second site edge. The second message includes a first message and tunnel information of the overlay end-to-end tunnel encapsulated in the outer layer of the first message. The underlying underlay tunnel corresponding to the overlay end-to-end tunnel includes multiple tunnel segments. The tunnel information includes first information of a first ingress point (POP). The first site edge is the ingress point of the overlay end-to-end tunnel, and the second site edge is the egress point of the overlay end-to-end tunnel. The overlay end-to-end tunnel passes through the first POP. The first message is a message obtained by the Internet Protocol Security Association (IPsec SA) negotiated between the second site edge and the first site edge to provide security protection for VPN service messages.
[0096] The processing module is used to decapsulate the second message to obtain the first message;
[0097] The processing module is further configured to process the first packet according to the IPsecSA to obtain the VPN service packet.
[0098] Based on the sixth aspect, in a possible implementation, the processing module is configured to: encapsulate the first packet with a security payload (ESP) protocol decryption according to the IPsecSA; and / or authenticate the first packet according to the IPsecSA and the authentication data carried in the Authentication Header of the first packet.
[0099] Based on the sixth aspect, in a possible implementation, the tunnel information further includes second information of the second POP, the overlay end-to-end tunnel passes through the first POP and the second POP, the first station edge accesses the wide area network through the first POP, and the second station edge accesses the wide area network through the second POP.
[0100] Based on the sixth aspect, in a possible implementation, the overlay end-to-end tunnel is an Internet Protocol version 6 (IPv6) segment routing SRv6 tunnel, the second message includes an IPv6 header and a segment routing header SRH, the destination address of the IPv6 header points to the first POP, and the SRH header includes the first information and the second information.
[0101] Based on the sixth aspect, in a possible implementation, the first information is the first endpoint segment identifier END.SID of the first POP, and the operation associated with the first endpoint segment identifier END.SID includes: matching the upper-layer overly SRv6 Policy from the first POP to the second POP according to the next-hop SID of the END.SID.
[0102] Based on the sixth aspect, in a possible implementation, the overlay end-to-end tunnel is a segmented routing multiprotocol label switching traffic engineering policy (SR-MPLS TE Policy), and the second message includes an MPLS label stack, which includes the first information and the second information.
[0103] Based on the sixth aspect, in a possible implementation, the first information is the first node SID of the first POP, and the operation associated with the first node SID includes: matching the upper-layer overly SR MPLS tunnel from the first POP to the second POP according to the next-hop SID of the first node SID in the tag stack.
[0104] Based on the sixth aspect, in a possible implementation, the overlay end-to-end tunnel is a tunnel encapsulated based on the Geneve protocol of general network virtualization encapsulation, and the second message is encapsulated using SRv6 in Geneve.
[0105] Based on the sixth aspect, in a possible implementation, the overlay end-to-end tunnel is a tunnel encapsulated based on the Generic Routing Encapsulation (GRE) protocol, and the second message is encapsulated using SRv6 over GRE.
[0106] Based on the sixth aspect, among the possible implementation methods,
[0107] The processing module is further configured to generate a Border Gateway Protocol (BGP) route, wherein the BGP route includes a route type RT, the IPsec SA, the identifier of the second site edge, and an exported route target ExportRT, wherein the route type RT indicates that the IPsec SA advertised by the BGP route is used to provide end-to-end security protection for the VPN service packets in the forwarding VRF of the virtual route matching the ExportRT.
[0108] The sending module is used to announce the BGP route to the first site edge.
[0109] Based on the sixth aspect, in possible implementations, the BGP route is a BGP software-defined wide area network SD-WAN route, and the sub-address family of the BGP SD-WAN route is the SD-WAN sub-address family; or, the BGP route is a BGP Ethernet Virtual Private Network (EVPN) route, and the sub-address family of the BGP EVPN route is the EVPN sub-address family.
[0110] Based on the sixth aspect, in a possible implementation, the identifier of the second site edge includes the site ID to which the second site edge belongs and the node ID of the second site edge.
[0111] Based on the sixth aspect, in a possible implementation, the BGP route includes Network Layer Reachability Information (NLRI), which includes the route type (RT) and the identifier of the second site edge.
[0112] Based on the sixth aspect, in a possible implementation, the BGP route includes a Tunnel Encapsulation Attribute Type Length Value (TLV), which includes the IPsec SA.
[0113] Based on the sixth aspect, in a possible implementation, the BGP route includes an extended community attribute for carrying the Export RT.
[0114] Based on the sixth aspect, in a possible implementation, the first site edge and the second site edge are site edges in a software-defined wide area network (SD-WAN).
[0115] The various functional modules in the sixth aspect are used to implement the methods described in the second aspect and any possible implementation of the second aspect.
[0116] In a seventh aspect, this application provides an apparatus for negotiating the Internet Protocol Security Protocol Security Association (IPsec SA), the apparatus being applied to a first site edge in a wide area network, the apparatus comprising:
[0117] The receiving module is used to receive a Border Gateway Protocol (BGP) route advertised by a second site edge. The BGP route includes a route type RT, the IPsec SA, the identifier of the second site edge, and an exported route target ExportRT. The route type RT indicates that the IPsec SA advertised by the BGP route is used to perform end-to-end security protection for service packets in the VRF forwarding the virtual route matching the ExportRT.
[0118] The processing module is used to associate the IPsec SA with the VRF based on the routing type RT and the Export RT.
[0119] Based on the seventh aspect, in possible implementations, the BGP route is a BGP software-defined wide area network SD-WAN route, and the sub-address family of the BGP SD-WAN route is the SD-WAN sub-address family; or, the BGP route is a BGP Ethernet Virtual Private Network (EVPN) route, and the sub-address family of the BGP EVPN route is the EVPN sub-address family.
[0120] Based on the seventh aspect, in a possible implementation, the identifier of the second site edge includes the site ID to which the second site edge belongs and the node ID of the second site edge.
[0121] Based on the seventh aspect, in a possible implementation, the BGP route includes Network Layer Reachability Information (NLRI), which includes the route type (RT) and the identifier of the second site edge.
[0122] Based on the seventh aspect, in a possible implementation, the BGP route includes a Tunnel Encapsulation Attribute Type Length Value (TLV), which includes the IPsec SA.
[0123] Based on the seventh aspect, in a possible implementation, the BGP route includes an extended community attribute for carrying the Export RT.
[0124] Based on the seventh aspect, in a possible implementation, the first site edge and the second site edge are site edges in a software-defined wide area network (SD-WAN).
[0125] The functional modules in the seventh aspect are used to implement the methods described in the third aspect and any possible implementation of the third aspect.
[0126] Eighthly, this application provides an apparatus for negotiating the Internet Protocol Security Protocol Security Association (IPsec SA), the apparatus being applied to a second site edge in a wide area network, the apparatus comprising:
[0127] The processing module is used to generate Border Gateway Protocol (BGP) routes, wherein the BGP routes include route type RT, the IPsec SA, the identifier of the second site edge, and exported route target ExportRT, wherein the route type RT indicates that the IPsec SA advertised by the BGP route is used to perform end-to-end security protection for service packets in the VRF forwarding virtual routes matching the ExportRT;
[0128] The sending module is used to advertise the BGP route to the first site edge.
[0129] Based on the eighth aspect, in possible implementations, the BGP route is a BGP software-defined wide area network SD-WAN route, and the sub-address family of the BGP SD-WAN route is the SD-WAN sub-address family; or, the BGP route is a BGP Ethernet Virtual Private Network (EVPN) route, and the sub-address family of the BGP EVPN route is the EVPN sub-address family.
[0130] Based on the eighth aspect, in a possible implementation, the identifier of the second site edge includes the site ID to which the second site edge belongs and the node ID of the second site edge.
[0131] Based on the eighth aspect, in a possible implementation, the BGP route includes Network Layer Reachability Information (NLRI), which includes the route type (RT) and the identifier of the second site edge.
[0132] Based on the eighth aspect, in a possible implementation, the BGP route includes a Tunnel Encapsulation Attribute TLV, which includes the IPsec SA.
[0133] Based on the eighth aspect, in a possible implementation, the BGP route includes an extended community attribute for carrying the Export RT.
[0134] Based on the eighth aspect, in a possible implementation, the first site edge and the second site edge are site edges in a software-defined wide area network (SD-WAN).
[0135] The functional modules in the eighth aspect are used to implement the methods described in the fourth aspect and any possible implementation of the fourth aspect.
[0136] Ninthly, this application provides a network device including a memory and a processor, the memory being used to store instructions, and the processor being used to execute the instructions stored in the memory to implement the method described in the first aspect and any possible implementation thereof, or to implement the method described in the second aspect and any possible implementation thereof, or to implement the method described in the third aspect and any possible implementation thereof, or to implement the method described in the fourth aspect and any possible implementation thereof.
[0137] In a tenth aspect, this application provides a system including a first site exit device edge and a second site edge, wherein the first site edge is used to perform the method described in the first aspect and any possible implementation thereof, and the second site edge is used to perform the method described in the second aspect and any possible implementation thereof; or, the first site edge is used to perform the method described in the third aspect and any possible implementation thereof, and the second site edge is used to perform the method described in the fourth aspect and any possible implementation thereof.
[0138] Eleventhly, this application provides a computer storage medium, characterized in that it includes program instructions, which, when executed on a processor, cause the processor to implement the method described in the first aspect and any possible implementation of the first aspect, or cause the processor to implement the method described in the second aspect and any possible implementation of the second aspect, or cause the processor to implement the method described in the third aspect and any possible implementation of the third aspect, or cause the processor to implement the method described in the fourth aspect and any possible implementation of the fourth aspect.
[0139] In a twelfth aspect, this application provides a computer program product including program instructions that, when executed on a processor, cause the processor to implement the method described in the first aspect and any possible implementation thereof, or cause the processor to implement the method described in the second aspect and any possible implementation thereof, or cause the processor to implement the method described in the third aspect and any possible implementation thereof, or cause the processor to implement the method described in the fourth aspect and any possible implementation thereof. Attached Figure Description
[0140] Figure 1 A scenario illustration provided for this application;
[0141] Figure 2 A flowchart illustrating a method for negotiating an IPsec SA provided in this application;
[0142] Figure 3 This application provides a partial structural diagram of a BGP SD-WAN routing message;
[0143] Figure 4 A partial structural diagram of a BGP EVPN routing message provided in this application;
[0144] Figure 5 A flowchart illustrating a method for securely transmitting messages provided in this application;
[0145] Figure 6A A schematic diagram of the structure of a VPN service message provided in this application;
[0146] Figure 6B A schematic diagram of the structure of the first message provided in this application;
[0147] Figure 6C A schematic diagram of the structure of the second message provided in this application;
[0148] Figure 7 A schematic diagram of the structure of a second message provided in this application;
[0149] Figure 8 A schematic diagram of the structure of yet another second message provided in this application;
[0150] Figure 9 A flowchart illustrating a method for securely transmitting messages provided in this application;
[0151] Figure 10 A schematic diagram of the structure of a device for securely transmitting messages provided in this application;
[0152] Figure 11 A schematic diagram of the structure of another device for securely transmitting messages provided in this application;
[0153] Figure 12 This is a schematic diagram of the structure of a network device provided in this application. Detailed Implementation
[0154] The technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings.
[0155] See Figure 1 , Figure 1 This is a schematic diagram of a scenario provided for this application. Figure 1 In the software-defined wide-area network (SD-WAN) shown, SD-WAN tunnels are established between points of presence (POPs) in the underlay network. Tunnel 1 is established between customer premises equipment (CPE) 1 and edge point of presence (EPOP) 1; tunnel 2 is established between EPOP1 and backbone point of presence (BPOP) 1; tunnel 3 is established between BPOP1 and BPOP2; tunnel 4 is established between BPOP2 and EPOP2; and tunnel 5 is established between EPOP2 and CPE2. CPE1 is located at site 1, and CPE2 is located at site 2. Key negotiation between the ingress and egress nodes of each tunnel segment is performed at the TNP granularity.
[0156] In one application scenario, based on actual business needs, the business flow (business messages) needs to travel from CPE1 to CPE2, meaning the business messages need to traverse multiple tunnels from CPE1 to CPE2. First, the CPE1 node encrypts the business message using the key negotiated between CPE1 and EPOP1 on tunnel 1. When the business message reaches the EPOP1 node, the EPOP1 node decrypts the message using the negotiated key. When the business message arrives at tunnel 2, the EPOP1 node encrypts the business message using the key negotiated between EPOP1 and BPOP1 on tunnel 2. When the business message reaches the BPOP1 node, the BPOP1 node decrypts the business message using the negotiated key. This process continues until the message reaches tunnel 5, where the EPOP2 node encrypts the business message using the key negotiated between EPOP2 and CPE2 on tunnel 5. When the business message reaches the CPE2 node, the CPE2 node decrypts the business message using the negotiated key, parses the message, and obtains the data.
[0157] For application scenarios that require transmission across multiple tunnels, multiple encryption and decryption operations are required, which is cumbersome, consumes the computing resources of network devices, and increases the forwarding delay of service packets.
[0158] This application provides a method for negotiating an Internet Protocol Security (IPsec) Security Association (SA) for use in wide area networks (WANs). An IPsec SA is a security protocol used to provide confidentiality, integrity, and authentication of data over IP networks. An IPsec SA is a set of security parameters established between two network devices to protect the transmission of IP packets. It includes encryption algorithms, authentication protocols, key lengths, key management, and other security parameters. Before establishing an IPsec SA, the two devices must negotiate the security parameters to ensure they use the same security parameters. Once the IPsec SA is established, packets will be encrypted and authenticated using these security parameters to ensure data confidentiality and integrity.
[0159] See Figure 2 As shown, Figure 2 This application provides a flowchart illustrating a method for negotiating an IPsec SA, the method including but not limited to the following description.
[0160] S101. The second site's egress device edge in the WAN generates a BGP route. The BGP route includes route type RT, IPsec SA, the identifier of the second site edge, and the exported route destination ExportRT.
[0161] BGP routes include a route distinguisher (RD) and an export route target (Export RT). The route distinguisher (RD) is used to identify the virtual routing forwarding (VRF) of the second site edge, and the export route target (Export RT) is used to perform VRF matching for the second site edge.
[0162] BGP routes also include the identifier of the second site edge. In one implementation, the identifier of the second site edge includes the site ID to which the second site edge belongs and the node ID of the second site edge; that is, the edge can be identified by the site ID and the node ID. In another implementation, the node ID in the wide area network is globally unique. In this case, the identifier of the second site edge may only include the node ID; that is, the edge can be uniquely identified by the node ID.
[0163] BGP routes also include Route Type (RT) and IPsec SA. The Route Type RT indicates that the IPsec SA advertised by the BGP route is used to provide end-to-end security protection for service packets in the Virtual RF (VRF) that matches the Export RT of the exported route. For example, if the VRF that matches the Export RT of the exported route is the VRF of the first site edge, then the Route Type RT indicates that the IPsec SA advertised by the BGP route is used to provide end-to-end security protection for service packets between the second site edge and the first site edge.
[0164] Optionally, the BGP route can be a BGP SD-WAN route, with its sub-address family being the SD-WAN sub-address family. Alternatively, the BGP route can be a BGP Ethernet Virtual Private Network (EVPN) route, with its sub-address family being the EVPN sub-address family. The BGP route can also be other types of routes, and its sub-address families can be other sub-address families; this application does not impose any limitations on this.
[0165] BGP routes include network layer reachability information (NLRI), where the route type (RT), route distinguisher (RD), and identifier of the second site edge are all located within the NLRI. For example, see... Figure 3 , Figure 3This is a partial structural diagram of a BGP SD-WAN route provided in this application. Figure 3 In this context, Route Type (RT) represents the route type, which can be 2 bytes long. In the SD-WAN sub-address family, route type 2 can be defined. Route Distinguisher (RD) represents the route distinguisher, which can be 8 bytes long. SD-WAN-Color is used to represent the site identifier, which can be 4 bytes long. SD-WAN-Node-ID is used to represent the node identifier, which can be 4 bytes or 16 bytes long. For example, see [link to example]. Figure 4 , Figure 4 This application provides a partial structural diagram of a BGP EVPN route. Figure 4 In, each field and Figure 3 All fields in the diagram have the same meaning. The only difference is that in the EVPN sub-address family, the route type RT is defined as 10. It should be noted that defining the route type RT as 2 here is merely an example within the SD-WAN sub-address family. Other values can be used to represent new route types in the SD-WAN address family. Defining the route type RT as 10 is just one example within the EVPN sub-address family; other values can be used to represent new route types in the EVPN address family, and this application does not impose specific limitations.
[0166] BGP routes also include type-length-value (TLV) data. Specifically, BGP routes include Tunnel Encapsulation Attribute (TEA) TLV data, where the TEA TLV includes the IPsec SA, meaning the IPsec SA is carried in the TEA TLV field of the BGP route. Specifically, the IPsec SA is carried in a sub-TLV of the TEA TLV. BGP routes also include extended community attribute TLV data, which includes the Export RT, meaning the Export RT is carried in the extended community attribute TLV field of the BGP route. It should be noted that the positions of the IPsec SA and Export RT here are just examples; the IPsec SA and Export RT can also be carried in other TLV fields of the BGP route, and this application does not impose specific limitations on this.
[0167] For example, in Figure 1 In the wide area network scenario diagram shown, the second site edge can be CPE1 or CPE2.
[0168] S102, the second site edge advertises the BGP route to the first site edge.
[0169] The second site, edge, advertises BGP routes across the wide area network. For example, in... Figure 1 In the wide area network shown, assuming the second site edge is CPE1, after CPE1 generates a BGP route, it can reflect the BGP route to EPOP1 through the area route reflector (RR). EPOP1 then reflects the BGP route to BPOP1, BPOP2, and EPOP2 through the managed service provider (MSP) RR. EPOP2 then reflects the BGP route to CPE2 through the area RR, thus realizing the advertisement of BGP routes.
[0170] The first edge in the wide area network receives the BGP route advertised by the second edge. For example, Figure 1 In this context, if the second station edge is CPE1, then the first station edge can be CPE2; if the second station edge is CPE2, then the first station edge can be CPE1.
[0171] S103. Based on the routing type RT and Export RT, the first site edge associates the IPsec SA with the VRF.
[0172] When the first edge receives the BGP route advertised by the second edge, it associates the IPsec SA with the VRF based on the route type RT and the exported route destination Export RT in the BGP route. Specifically, the Export RT is used to match the VRF of the second edge, and the route type RT indicates that the IPsec SA advertised by the BGP route is used to provide end-to-end security protection for service packets in the VRF that matches the Export RT. Therefore, after receiving the BGP route, the first edge first determines whether its own VRF matches the Export RT. If they match, the first edge associates the IPsec SA with its own VRF. Since the IPsec SA is also associated with the second edge, it can be understood that the VRFs of both the first and second edges are associated with the IPsec SA. If they do not match, the first edge does not associate with the IPsec SA.
[0173] In one implementation, the matching strategy can be set as follows: Each edge in the WAN can have an import route target and an export route target (Export RT). The import route target is stored locally on the edge, while the export route target is carried in the BGP route. The BGP route sent by the second edge carries the export route target. After receiving the BGP route sent by the second edge, the first edge compares the export route target in the BGP route with the import route target stored locally on the first edge. If they match, the first edge's VRF matches the Export RT in the BGP route, and the first edge associates the IPsec SA in the BGP route with the first edge's VRF. If they do not match, the first edge's VRF does not match the Export RT in the BGP route, and the IPsec SA is not associated with the first edge's VRF. For example, if the BGP route sent by the second edge site carries an Export RT of 100, and the local import route destination of the first edge site is also 100, after receiving the BGP route, the first edge site compares the Export RT with its local import route destination. If they match, the first edge site associates the IPsec SA carried in the BGP route with its own VRF. This is just one possible implementation of the matching strategy; other implementations are possible and not limited in this application.
[0174] The method described in this application can be applied to wide area networks (WANs), such as software-defined wide area networks (SD-WANs), where the first and second site edges can be site edges within the SD-WAN. The method described in this application can also be applied to other wide area networks, and this application does not limit its application to such applications.
[0175] In practical applications, the first and second site edges can be determined according to actual business needs and business flows. The import and export route targets of the first site edge, as well as the import and export route targets of the second site edge, can all be set according to actual business needs.
[0176] It is understandable that, through the BGP routing announcement, the VRF of both the first and second edge sites are associated with the IPsec SA. That is, the first and second edge sites have negotiated the IPsec SA used to transmit service packets. Therefore, when the first and second edge sites transmit service packets, they can use the negotiated IPsec SA to protect the service packets and transmit VPN service packets by forwarding the VRF through virtual routing. This enables end-to-end tunnel transmission between the first and second edge sites, requiring only one security protection and one decapsulation process, thus reducing transmission latency.
[0177] As can be seen, this application provides a method for negotiating IPsec SAs. A new route type is added to the BGP route, carrying the IPsec SA and the exported route target. The newly added route type instructs the IPsec SA advertised by the BGP route to provide end-to-end security protection for service packets in a VRF matching the exported target route. This new route type implements IPsec SA negotiation at the VRF granularity. Through the advertisement of the BGP route, an IPsec SA method is negotiated between the first and second edge sites. This allows subsequent transmission of service packets between the first and second edge sites to be secured based on the negotiated IPsec SA method, and VPN service packets to be transmitted via virtual routing forwarding of VRFs.
[0178] Based on the IPsec SA negotiation method provided above, this application also provides a method for securely transmitting messages. See Figure 5 , Figure 5 This application provides a flowchart illustrating a method for securely transmitting messages, which is applied to a wide area network and includes, but is not limited to, the following description.
[0179] S201. The first site exit device edge in the wide area network receives and forwards VPN service packets from the virtual route forwarding VRF.
[0180] The first site egress device edge in the WAN receives VPN service packets from the VRF. These VPN service packets can be sent to the first site edge by the controller or by other network devices in the WAN.
[0181] exist Figure 1 In the scene diagram shown, the first station edge can be CPE1 or CPE2.
[0182] S202. The first edge station performs security protection on VPN service packets according to the Internet Protocol Security Association (IPsecSA) associated with VRF, which is negotiated with the second edge station, and obtains the first packet.
[0183] Through BGP route advertisement, the first and second edge sites negotiated an IPsecSA, and both the first and second edge sites' VRFs were associated with the IPsecSA. The IPsecSA is used to provide end-to-end protection for service packets between the VRFs of the first and second edge sites. Based on this, after the first edge site receives a VPN service packet from its VRF, it performs security protection on the VPN service packet according to the IPsecSA associated with the VRF negotiated with the second edge site, thus obtaining the first packet.
[0184] In one implementation, security protection of VPN service packets includes encrypting the VPN service packets using the Encapsulate Security Payload (ESP) protocol. In another implementation, security protection of VPN service packets includes encapsulating the VPN service packets with an Authentication Header (AH). In yet another implementation, security protection of VPN service packets includes both ESP protocol encryption and AH encapsulation. Security protection of VPN service packets can also be implemented in other ways, and this application does not limit the scope of such protection.
[0185] S203. The first station edge encapsulates the tunnel information of the upper-layer overlay end-to-end tunnel established between the first station edge and the second station edge outside the first message, and obtains the second message.
[0186] The first edge encapsulates the tunnel information of the upper-layer overlay end-to-end tunnel established between the first edge and the second edge outside the first message, thus obtaining the second message. The underlying underlay tunnel corresponding to the overlay end-to-end tunnel between the first and second edges comprises multiple tunnel segments. For example, Figure 1In the scenario diagram shown, if the first station edge is CPE1 and the second station edge is CPE2, then the underlying underlay tunnel corresponding to the overlay end-to-end tunnel between the first station edge and the second station edge includes tunnel 1 (CPE1 to EPOP1), tunnel 2 (EPOP1 to BPOP1), tunnel 3 (BPOP1 to BPOP2), tunnel 4 (BPOP2 to EPOP2), and tunnel 5 (EPOP2 to CPE2).
[0187] The overlay end-to-end tunnel includes at least one inbound point (POP), and the tunnel information includes information about at least one inbound point. In one example, the overlay end-to-end tunnel includes one inbound point (POP), referred to as the first inbound point (POP) for ease of description. The first station edge is the inbound endpoint of the overlay end-to-end tunnel, and the second station edge is the outbound endpoint of the overlay end-to-end tunnel. The overlay end-to-end tunnel passes through the first inbound point (POP). The first inbound point (POP) can be either an EPOP or a BPOP; this application does not limit the type of POP. The tunnel information of the overlay end-to-end tunnel includes first information about the first inbound point.
[0188] In another example, the overlay end-to-end tunnel includes multiple inbound points (POPs), including a first inbound POP and a second inbound POP. The first site edge is the inbound endpoint of the overlay end-to-end tunnel, and the second site edge is the outbound endpoint. The first site edge accesses the wide area network (WAN) through the first POP, and the second site edge accesses the WAN through the second POP. For example, in... Figure 1 In the scenario diagram shown, if the first site edge is CPE1 and the second site edge is CPE2, then the overlay end-to-end tunnel between the first and second site edges includes multiple access points. The first site edge accesses the WAN via EPOP1, and the second site edge accesses the WAN via EPOP2. Therefore, EPOP1 is the first POP, and EPOP2 is the second POP. The tunnel information of the overlay end-to-end tunnel includes the first information of the first access point and the second information of the second access point.
[0189] In one implementation, the overlay end-to-end tunnel is an SRv6 segment routing tunnel using Internet Protocol version 6 (IPv6). The first edge station encapsulates the SRv6 tunnel information outside the first packet to obtain a second packet. The second packet includes an IPv6 header and a segment routing header (SRH). If the overlay end-to-end tunnel includes a first ingress point and a second ingress point, the destination address in the IPv6 header points to the first ingress point, and the SRH includes both first and second information.
[0190] For example, see Figures 6A to 6C As shown, Figures 6A to 6C An example diagram provided for this application. Figure 6A This refers to VPN service packets, including the Inner IP HDR header and the Inner Payload. Figure 6B This refers to the first message, which is obtained by encrypting VPN service messages using the ESP protocol. Figure 6C This refers to the second message, which is obtained by encapsulating the tunnel information of the SRv6 tunnel between the first site edge and the second site edge outside the first message. Here, IPv6 Hdr(Src IP, Dst IP) represents the IPv6 message header, and SRH(...,vpnsid) represents the segmented routing header SRH. The IPv6 message header and SRH together form the tunnel information of the overlay end-to-end tunnel.
[0191] For example, in Figure 1 In the scenario diagram shown, assuming CPE1 is the first site edge and CPE2 is the second site edge, and the overlay end-to-end tunnel between CPE1 and CPE2 is an SRv6 tunnel, then CPE1 encapsulates the tunnel information of the SRv6 tunnel between CPE1 and CPE2 outside the first message to obtain the second message. For example... Figure 7 As shown, Figure 7This is a schematic diagram provided for this application. At CPE1, in the second packet, IPv6 Hdr(cpe1, epop1-sid) is the IPv6 packet header, and SRH(vpnsid, epop2-sid, bpop2-sid, bpop1-sid, epop1-sid) is the segmented routing header SRH. Here, epop1-sid represents the first endpoint segment identifier END.SID of CPE1, bpop1-sid represents the first endpoint segment identifier END.SID of BPOP1, bpop2-sid represents the first endpoint segment identifier END.SID of BPOP2, and epop2-sid represents the first endpoint segment identifier END.SID of EPOP2. vpnsid is generated by CPE2 during BGP route advertisement, and vpnsid is associated with the VRF of CPE2. Wherein, EPOP1 is the first inbound point POP, and the first endpoint segment identifier epop1-sid of EPOP1 is the first information of the first inbound point POP. EPOP2 is the second inbound point POP, and the first endpoint segment identifier epop2-sid of EPOP2 is the second information of the second inbound point POP. The operation associated with the first endpoint segment identifier epop1-sid of EPOP1 includes: matching the upper-layer overly SRv6 policy between the first POP and the second POP based on the next-hop SID of epop1-sid. Figure 7 The messages at each POP point shown can be seen to illustrate the operations associated with the segment identifier END.SID.
[0192] The upper-layer overlay network is built upon the lower-layer underlay network. When the second packet is transmitted through the overlay end-to-end tunnel, it is actually transmitted on the lower-layer underlay network; however, the upper-layer overlay network is unaware of how the packet is transmitted within the lower-layer underlay network. Therefore, it is necessary to encapsulate the tunnel information of the underlay tunnel on the outer layer of the second packet. The packet encapsulated with the tunnel information of the underlay tunnel is transmitted through the overlay end-to-end tunnel (the actual transmission of the packet encapsulated with the tunnel information of the underlay tunnel is on the lower-layer underlay tunnel). For example, in... Figure 1 In the scenario shown, since the WAN is an SD-WAN, the packets need to traverse the carrier network during transmission. The devices in the carrier network cannot recognize the upper-layer overly IPv6 address. Therefore, an underlay IP header is encapsulated in the outer layer to represent the lower-layer underlay tunnel.
[0193] In one implementation, the overlay end-to-end tunnel is a segment routing multi-protocol label switching traffic engine (SR-MPLS TE) policy. The second packet includes an MPLS label stack, which contains first information of the first POP and second information of the second POP. The first information is the first node SID of the first POP. The operation associated with the first node SID includes matching the upper-layer overlay SR MPLS tunnel from the first POP to the second POP based on the next-hop SID of the first node SID in the label stack.
[0194] For example, in Figure 1 In the scenario diagram shown, assuming CPE1 is the first site edge and CPE2 is the second site edge, and the overlay end-to-end tunnel between CPE1 and CPE2 is an SR-MPLS TE Policy, then CPE1 encapsulates the SR-MPLS TE Policy information between CPE1 and CPE2 outside the first packet to obtain the second packet. See also... Figure 8 As shown, Figure 8 This is a schematic diagram provided for this application. At CPE1, in the second message, (epop1-sid, bpop1-sid, bpop2-sid, epop2-sid, cpe2-sid) represents the tunnel information of the overlay end-to-end tunnel, i.e., the MPLS label stack. Here, epop1-sid represents the first node SID of EPOP1, bpop1-sid represents the first node SID of BPOP1, bpop2-sid represents the first node SID of BPOP2, epop2-sid represents the first node SID of EPOP2, and cpe2-sid represents the first node SID of CPE2. EPOP1 is the first inbound point POP, and the first node segment identifier epop1-sid of EPOP1 represents the first information of the first inbound point POP. EPOP2 is the second inbound point POP, and the first node segment identifier epop2-sid of EPOP2 represents the second information of the second inbound point POP. The operations for associating the first node SID include: matching the upper-layer overly SR MPLS tunnel from the first POP to the second POP based on the next-hop SID of the first node SID in the label stack. Figure 8 The messages at each POP point shown indicate the operations associated with the node segment identifier (SID). Figure 8 The underlay IP in the message is the tunnel information for the underlay tunnel.
[0195] In another implementation, where the overlay end-to-end tunnel is an SRv6 tunnel, the second packet can be encapsulated using the generic network virtualization encapsulation (GENEVE) protocol, thus employing SRv6 in GENEVE encapsulation. For example, the second packet includes: an outer IP header, a user datagram protocol (UDP) header, a GENEVE encapsulation, an SRH, an ESP, and a payload. The payload includes the aforementioned VPN service packet; the GENEVE encapsulation includes the VPN identifier of the VPN service carried by the VPN service packet. In one example, a metadata field may also be included between the SRH and ESP to carry service intent information. Of course, the second message can also use SRv6 over GENEVE encapsulation. The difference between SRv6 over GENEVE encapsulation and SRv6 in GENEVE encapsulation is that an IPv6 header is included between the GENEVE encapsulation and the SRH. SRv6 over GENEVE encapsulation has a larger encapsulation overhead than SRv6 in GENEVE encapsulation, but SRv6 over GENEVE encapsulation conforms to the standard SRv6 encapsulation format.
[0196] In another implementation, the overlay end-to-end tunnel is a tunnel encapsulated using the generic routing encapsulation (GRE) protocol, and the second packet uses SRv6 over GRE encapsulation. In one example, the second packet includes: an outer IP header, a UDP header, an outer GRE encapsulation, an IPv6 header, an SRH, an inner GRE encapsulation, an ESP, and a payload. The payload includes the aforementioned VPN service packet; the inner GRE encapsulation includes the VPN identifier of the VPN service carried by the VPN service packet. The VPN identifier is carried in the inner GRE encapsulation. When the second packet is transmitted in the network, the intermediate nodes traversed by the overlay end-to-end tunnel do not parse the VPN identifier (VNI), meaning the intermediate nodes are unaware of the VPN. In one example, a metadata field may also be included between the SRH and the inner GRE encapsulation to carry service intent information.
[0197] The service intent information in this application embodiment may include one or more pieces of information indicating the service intent. In one example, the service intent information may include quality of service parameters, which include, but are not limited to, one or more parameters such as latency, packet loss, jitter, bandwidth utilization, and bit error rate. In another example, the service intent parameters may include gateway constraint information that the end-to-end path from site edge1 to site edge2 must satisfy, which includes, but is not limited to, the gateways that need to be traversed and / or the gateways that need to be bypassed.
[0198] S204. The first edge station sends a second message to the second edge station through the overlay end-to-end tunnel.
[0199] The first edge sends a second message to the second edge via an overlay end-to-end tunnel. In possible implementations, the first edge sends the second message to the second edge via an SRv6 tunnel or an SR-MPLS TE Policy.
[0200] It should be noted that the various inbound points (POPs) between the first and second edge stations are unaware of the second packet and do not decrypt it. They simply forward it according to the tunnel information of the overlay end-to-end tunnel until the second packet reaches the second edge station. Therefore, during the transmission of service packets, security protection only needs to be performed once at the first edge station. Decryption is not required at other inbound points (POPs), which reduces the consumption of computing resources, improves forwarding efficiency, and reduces transmission latency.
[0201] The secure message transmission method provided in this embodiment can be applied to SD-WAN, where the first site edge and the second site edge are site edges in SD-WAN. The method can also be applied to other wide area networks, and this application does not limit it.
[0202] This application introduces a new route type, RT, into BGP routing. The BGP route carries an IPsec SA and an exported route target, ExportRT. The newly added route type RT instructs the IPsec SA advertised by the BGP route to provide end-to-end security protection for service packets in the VRF matched by ExportRT. By advertising BGP routes within the WAN, end-to-end IPsec SA negotiation at the VRF granularity is achieved between two edge sites, enabling subsequent transmission of VPN service packets using the negotiated IPsec SA, thus laying the foundation for VPN service packet transmission. Compared to existing IPsec SA negotiation based on TNP granularity, the various inbound points (POPs) between the first and second edge sites are unaware of the inner VPN service packets. End-to-end encryption and decryption between the two edge sites reduces computational resource consumption, improves forwarding efficiency, and reduces transmission latency.
[0203] Based on the aforementioned methods for negotiating IPsecSA and secure message transmission, this application also provides a method for secure message transmission. See [link to application]. Figure 9 , Figure 9 This application provides a flowchart illustrating a method for securely transmitting messages, the method including but not limited to the following description.
[0204] S301. The second station edge in the wide area network receives a second message sent by the first station edge through the upper-layer overlay end-to-end tunnel established between the first station edge and the second station edge. The second message includes the first message and the tunnel information of the overlay end-to-end tunnel encapsulated in the outer layer of the first message.
[0205] In this embodiment, the method for securely transmitting messages can be applied to SD-WAN. The first site edge and the second site edge are site edges in SD-WAN. The method can also be applied to other wide area networks, and this application does not limit it.
[0206] The second site's egress device (edge) receives a second message sent by the first site's edge through the upper-layer overlay end-to-end tunnel established between the first and second site edges. The underlying underlay tunnel corresponding to the upper-layer overlay end-to-end tunnel established between the first and second site edges comprises multiple tunnel segments. For example, see... Figure 1The scenario diagram shown illustrates that the first site edge can be CPE1, and the second site edge can be CPE2; or, the first site edge can be CPE2, and the second site edge can be CPE1. The underlying underlay tunnel corresponding to the overlay end-to-end tunnel established between CPE1 and CPE2 includes multiple tunnel segments, specifically: Tunnel 1 (CPE1 to EPOP1), Tunnel 2 (EPOP1 to BPOP1), Tunnel 3 (BPOP1 to BPOP2), Tunnel 4 (BPOP2 to EPOP2), and Tunnel 5 (EPOP2 to CPE2).
[0207] The overlay end-to-end tunnel includes at least one inbound point of access (POP), and the tunnel information includes information about at least one inbound point. In one example, the overlay end-to-end tunnel includes a first inbound point of access (POP), then the tunnel information includes first information about the first inbound point. In another example, the overlay end-to-end tunnel includes multiple inbound point of access (POPs), including a first inbound point of access (POP) and a second inbound point of access (POP), then the tunnel information includes first information about the first inbound point of access (POP) and second information about the second inbound point of access (POP). Here, the first site edge is the inbound endpoint of the overlay end-to-end tunnel, and the second site edge is the outbound endpoint of the overlay end-to-end tunnel. The first site edge accesses the wide area network (WAN) through the first POP, and the second site edge accesses the WAN through the second POP.
[0208] In one implementation, the overlay end-to-end tunnel is an SRv6 tunnel. The second edge receives a second packet sent by the first edge through the SRv6 tunnel. The second packet includes the first packet and tunnel information of the SRv6 tunnel encapsulated in the outer layer of the first packet. The first packet is obtained by securing VPN service packets with IPsecSA negotiated between the second and first edges. The SRv6 tunnel information includes an IPv6 header and a Segmentation Routing Header (SRH). The destination address in the IPv6 header points to the first POP, and the SRH header includes first and second information. For the formats of the service packet, the first packet, and the second packet, please refer to [reference needed]. Figures 6A to 6C The schematic diagram shown is omitted here for the sake of brevity.
[0209] In one implementation, the overlay end-to-end tunnel is an SR-MPLS TE Policy. The second message includes the first message and SR-MPLS TE Policy information encapsulated in the outer layer of the first message. The SR-MPLS TE Policy information includes an MPLS tag stack, which includes first information of the first POP and second information of the second POP. The format of the second message can be found in the description of the above method embodiments; for brevity, it will not be repeated here.
[0210] In possible implementations, the second message may also include the header of the underlying underlay tunnel. For example, as described above... Figure 1 In the SD-WAN scenario shown, since the packets need to traverse the carrier network during transmission, the devices in the carrier network cannot recognize the upper-layer overly IPv6 address. Therefore, an underlay IP header is encapsulated in the outer layer to represent the underlying underlay tunnel.
[0211] S302, the second station edge decapsulates the second message to obtain the first message.
[0212] The second edge station decapsulates the second message to obtain the first message. In one implementation, the overlay end-to-end tunnel is an SRv6 tunnel. The second message includes the tunnel information of the first message and the SRv6 tunnel. Therefore, the second edge station decapsulates the second message, removing the SRv6 tunnel information to obtain the first message. A schematic diagram of the first message format is shown below. Figure 6B As shown, it will not be elaborated further here.
[0213] In one implementation, the overlay end-to-end tunnel is an SR-MPLS TE Policy. The second packet includes the first packet and the SR-MPLS TE Policy information encapsulated in the outer layer of the first packet. The second edge station then decapsulates the second packet, removing the MPLS SR-TE tunnel information to obtain the first packet. A schematic diagram of the first packet format is shown below. Figure 6B As shown, it will not be elaborated further here.
[0214] In one implementation, the overlay end-to-end tunnel is a tunnel encapsulated with the GENEVE protocol. The second message is encapsulated using SRv6 in GENEVE. The second edge station then decapsulates the second message, removing the SRv6 in GENEVE header to obtain the first message. A schematic diagram of the first message format is shown below. Figure 6B As shown, it will not be elaborated further here.
[0215] In another implementation, the overlay end-to-end tunnel is a tunnel encapsulated based on the GRE protocol. The second message uses SRv6 over GRE encapsulation. The second edge station decapsulates the second message, removing the SRv6 over GRE encapsulation header to obtain the first message. A schematic diagram of the first message format is shown below. Figure 6B As shown, it will not be elaborated further here.
[0216] S303, the second site edge processes the first packet according to IPsecSA to obtain the Virtual Private Network (VPN) service packet.
[0217] In one implementation, the second edge station performs ESP protocol processing on the first packet according to the IPsecSA to obtain the VPN service packet. In another implementation, the second edge station authenticates the first packet based on the IPsecSA and the authentication data carried in the authentication header (AH) of the first packet to obtain the VPN service packet. In yet another implementation, the second edge station decrypts the first packet using the ESP protocol based on the IPsecSA, and then authenticates the first packet based on the authentication data carried in the authentication header (AH) of the first packet to obtain the VPN service packet.
[0218] It should be noted that either the first edge site generates the BGP route and informs the second edge site of it, or the second edge site generates the BGP route and advertises it to the first edge site. Both methods can associate the VRFs of both the first and second edge sites with the IPsec SA. After associating the VRFs of both sites with the IPsec SA using either method, the first edge site can perform security protection and encapsulation on VPN service packets based on the negotiated IPsec SA, and then send them to the second edge site. The second edge site then decapsulates and decrypts the packets according to the negotiated IPsec SA to obtain the VPN service packets.
[0219] As can be seen, this application provides a method for securely transmitting packets. Through BGP route advertisement, the first edge and the second edge negotiate an IPsec SA, and associate the IPsec SA with the VRFs of both the first and second edges. When transmitting VPN service packets across multiple tunnels, the first edge only needs to securely protect the VPN service packets according to the negotiated IPsec SA to obtain the first packet. Then, the tunnel information of the overlay end-to-end tunnel established between the first and second edges is encapsulated around the first packet to obtain the second packet. The second packet is then sent to the second edge through the overlay end-to-end tunnel.
[0220] In scenarios spanning multiple underlay tunnels, only one IPsec SA security protection is required at the first edge site, and another IPsec SA processing is required at the second edge site. Intermediate entry points do not need to encrypt or decrypt packets; they only need to forward them according to the tunnel information. Therefore, implementing this embodiment reduces the consumption of network node computing resources, improves forwarding efficiency, and reduces transmission latency.
[0221] The above is a description of the method embodiments provided in this application. The following are device embodiments corresponding to the method embodiments provided in this application.
[0222] See Figure 10 , Figure 10 A schematic diagram of a secure message transmission device 600 provided for embodiments of this application is shown. The secure message transmission device 600 can be configured as a first station edge in a wide area network. The device 600 includes:
[0223] The receiving module 610 is used to receive VPN service packets in the Virtual Router Forwarding Function (VRF).
[0224] Processing module 620 is used to perform security protection on VPN service packets according to the Internet Protocol Security Association (IPsecSA) associated with the VRF negotiated with the second site edge, so as to obtain the first packet;
[0225] The processing module 620 is further configured to encapsulate the tunnel information of the upper-layer overlay end-to-end tunnel established between the first site edge and the second site edge in the outer layer of the first message to obtain the second message. The underlying underlay tunnel corresponding to the overlay end-to-end tunnel includes multiple tunnel segments. The tunnel information includes the first information of the first access point POP. The first site edge is the ingress point of the overlay end-to-end tunnel, the second site edge is the egress point of the overlay end-to-end tunnel, and the overlay end-to-end tunnel passes through the first POP.
[0226] The sending module 630 is used to send a second message to the second site edge through the overlay end-to-end tunnel.
[0227] In a possible implementation, the processing module 620 is used to: encapsulate VPN service messages with a security payload ESP protocol encryption; and / or encapsulate VPN service messages with an authentication header.
[0228] In possible implementations, the tunnel information also includes the second information of the second POP. The overlay end-to-end tunnel passes through the first POP and the second POP. The first site edge accesses the wide area network through the first POP, and the second site edge accesses the wide area network through the second POP.
[0229] In a possible implementation, the overlay end-to-end tunnel is an Internet Protocol version 6 (IPv6) segment routing SRv6 tunnel. The second message includes an IPv6 header and a segment routing header (SRH). The destination address of the IPv6 header points to the first POP, and the SRH includes first information and second information.
[0230] In a possible implementation, the first information is the first endpoint segment identifier END.SID of the first POP, and the operation associated with the first endpoint segment identifier END.SID includes: matching the upper-layer overlay SRv6 Policy from the first POP to the second POP based on the next-hop SID of END.SID.
[0231] In a possible implementation, the overlay end-to-end tunnel is an SR-MPLS TE Policy, and the second message includes an MPLS label stack, which includes first information and second information.
[0232] In a possible implementation, the first information is the first node SID of the first POP, and the operation associated with the first node SID includes: matching the upper-layer overlay SR MPLS tunnel from the first POP to the second POP based on the next-hop SID of the first node SID in the tag stack.
[0233] In a possible implementation, the overlay end-to-end tunnel is a tunnel encapsulated using the GENEVE protocol based on general network virtualization encapsulation, and the second message is encapsulated using SRv6 in GENEVE.
[0234] In a possible implementation, the overlay end-to-end tunnel is a tunnel encapsulated based on the Generic Routing Encapsulation (GRE) protocol, and the second packet uses SRv6 over GRE encapsulation.
[0235] In a possible implementation, the receiving module 610 is further configured to receive a Border Gateway Protocol (BGP) route advertised by the second site edge. The BGP route includes a route type RT, an IPsec SA, an identifier of the second site edge, and an exported route destination ExportRT. The route type RT indicates that the IPsec SA advertised by the BGP route is used to provide end-to-end security protection for VPN service packets in the VRF that are forwarded by the virtual route matching the ExportRT. The processing module 620 is configured to associate the IPsec SA with the VRF based on the route type RT and the ExportRT.
[0236] In possible implementations, the BGP route is a BGP software-defined wide area network (SD-WAN) route, the sub-address family of which is the SD-WAN sub-address family; or, the BGP route is a BGP Ethernet Virtual Private Network (EVPN) route, the sub-address family of which is the EVPN sub-address family.
[0237] In a possible implementation, the identifier of the second site edge includes the site ID to which the second site edge belongs and the node ID of the second site edge.
[0238] In a possible implementation, BGP routing includes Network Layer Reachability Information (NLRI), which includes the route type (RT) and the identifier of the second site edge.
[0239] In possible implementations, BGP routing includes a TunnelEncapsulation Attribute TLV, which includes an IPsec SA.
[0240] In a possible implementation, BGP routes include extended community attributes, which are used to carry ExportRT.
[0241] In possible implementations, the first site edge and the second site edge are site edges in a software-defined wide area network (SD-WAN).
[0242] The secure message transmission device 600 can be used to implement Figure 5 The corresponding method implementation, namely the method implementation on the data forwarding plane sending side, can also be used to implement... Figure 2 The method steps executed by the first station edge in the method embodiment, i.e., the method embodiment corresponding to the control plane receiving side, can be found in the following reference. Figure 2 or Figure 5 For the sake of brevity, the detailed description of the method embodiments is omitted here. When the secure message transmission device 600 is used to implement the method embodiments corresponding to the control plane receiving side, the secure message transmission device 600 can also be referred to as a device for negotiating IPsec SA.
[0243] Understandable. Figure 10 The division of the various functional modules and the corresponding execution steps of each functional module are merely examples. In other embodiments, the device 600 may be divided into more or fewer functional modules according to the specific execution steps.
[0244] See Figure 11 , Figure 11 This is a schematic diagram of the structure of another secure message transmission device 700 provided in an embodiment of this application. The secure message transmission device 700 can be configured as a second station edge in a wide area network. The device 700 includes:
[0245] The receiving module 710 is used to receive a second message sent by the first site edge through the upper-layer overlay end-to-end tunnel established between the first site edge and the second site edge. The second message includes the first message and the tunnel information of the overlay end-to-end tunnel encapsulated in the outer layer of the first message. The underlying underlay tunnel corresponding to the overlay end-to-end tunnel includes multiple tunnel segments. The tunnel information includes the first information of the first ingress point (POP). The first site edge is the ingress point of the overlay end-to-end tunnel, and the second site edge is the egress point of the overlay end-to-end tunnel. The overlay end-to-end tunnel passes through the first POP. The first message is a message obtained by the Internet Protocol Security Association (IPsec SA) negotiated between the second site edge and the first site edge to protect the VPN service message.
[0246] Processing module 720 is used to decapsulate the second message to obtain the first message;
[0247] Processing module 720 is used to process the first packet according to IPsecSA to obtain VPN service packets.
[0248] In a possible implementation, the processing module 720 is used to: encapsulate the first message with a security payload (ESP) according to the IPsecSA and decrypt it; and / or authenticate the first message according to the IPsecSA and the authentication data carried in the Authentication Header of the first message.
[0249] In possible implementations, the tunnel information also includes the second information of the second POP. The overlay end-to-end tunnel passes through the first POP and the second POP. The first site edge accesses the wide area network through the first POP, and the second site edge accesses the wide area network through the second POP.
[0250] In a possible implementation, the overlay end-to-end tunnel is an Internet Protocol version 6 (IPv6) segment routing SRv6 tunnel. The second message includes an IPv6 header and a segment routing header (SRH). The destination address of the IPv6 header points to the first POP, and the SRH header includes first information and second information.
[0251] In a possible implementation, the first information is the first endpoint segment identifier END.SID of the first POP, and the operation associated with the first endpoint segment identifier END.SID includes: matching the upper-layer overlay SRv6 Policy from the first POP to the second POP based on the next-hop SID of END.SID.
[0252] In a possible implementation, the overlay end-to-end tunnel is a segmented routing multiprotocol label switching traffic engineering policy (SR-MPLS TE Policy), and the second packet includes an MPLS label stack, which includes first information and second information.
[0253] In a possible implementation, the first information is the first node SID of the first POP, and the operation associated with the first node SID includes: matching the upper-layer overlay SR MPLS tunnel from the first POP to the second POP based on the next-hop SID of the first node SID in the tag stack.
[0254] In a possible implementation, the overlay end-to-end tunnel is a tunnel encapsulated using the GENEVE protocol based on general network virtualization encapsulation, and the second message is encapsulated using SRv6 in GENEVE.
[0255] In a possible implementation, the overlay end-to-end tunnel is a tunnel encapsulated based on the Generic Routing Encapsulation (GRE) protocol, and the second packet uses SRv6 over GRE encapsulation.
[0256] Among the possible implementations,
[0257] Processing module 720 is used to generate Border Gateway Protocol (BGP) routes, wherein the BGP routes include route type RT, IPsec SA, identifier of the second site edge, and exported route destination ExportRT. The route type RT indicates that the IPsec SA advertised by the BGP route is used to provide end-to-end security protection for VPN service packets in the VRF forwarding virtual routes that match the ExportRT.
[0258] The sending module 730 is used for the second edge to advertise BGP routes to the first edge.
[0259] In possible implementations, the BGP route is a BGP software-defined wide area network (SD-WAN) route, the sub-address family of which is the SD-WAN sub-address family; or, the BGP route is a BGP Ethernet Virtual Private Network (EVPN) route, the sub-address family of which is the EVPN sub-address family.
[0260] In a possible implementation, the identifier of the second site edge includes the site ID to which the second site edge belongs and the node ID of the second site edge.
[0261] In a possible implementation, BGP routing includes Network Layer Reachability Information (NLRI), which includes the route type (RT) and the identifier of the second site edge.
[0262] In possible implementations, BGP routing includes a TunnelEncapsulation Attribute TLV, which includes an IPsec SA.
[0263] In a possible implementation, BGP routes include extended community attributes, which are used to carry ExportRT.
[0264] In possible implementations, the first site edge and the second site edge are site edges in a software-defined wide area network (SD-WAN).
[0265] The secure message transmission device 700 can be used to implement Figure 9 The corresponding method implementation, namely the method implementation on the data forwarding plane receiving side, can also be used to implement... Figure 2The method steps executed by the second station edge in the corresponding method embodiment are the method embodiments corresponding to the control plane transmission side. For details, please refer to... Figure 2 or Figure 9 For the sake of brevity, the detailed description of the method embodiments is omitted here. When the secure message transmission device 700 is used to implement the method embodiments corresponding to the control plane sending side, the secure message transmission device 700 can also be referred to as a device for negotiating IPsec SA.
[0266] Understandable. Figure 11 The division of the various functional modules and the corresponding execution steps of each functional module are merely examples. In other embodiments, the device 700 may be divided into more or fewer functional modules according to the specific execution steps.
[0267] See Figure 12 , Figure 12 This application provides a schematic diagram of the structure of a network device 800, which can be configured as a first edge station in a wide area network (WAN) or a second edge station in a WAN. The network device 800 can be implemented using a general bus architecture.
[0268] The network device 800 includes at least one processor 801, a memory 803, and at least one communication interface 804.
[0269] The processor 801 can be a general-purpose CPU, NP, microprocessor, or one or more integrated circuits for implementing the solutions of this application. For example, it can be an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The PLD can be a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.
[0270] The network device 800 may also include a communication bus 802 for transmitting information between the various components. The communication bus 802 can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 12 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.
[0271] The memory 803 can be a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions; it can also be a random access memory (RAM) or other type of dynamic storage device capable of storing information and instructions; it can also be an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.), magnetic disk storage media, or other magnetic storage devices; or it can be any other medium capable of carrying or storing program code in the form of instructions or data structures that can be accessed by a computer, but is not limited thereto. The memory 803 can exist independently and be connected to the processor 801 via the communication bus 802; the memory 803 can also be integrated with the processor 801.
[0272] Communication interface 804 is used to communicate with other devices or communication networks. Communication interface 804 may include a wired communication interface and a wireless communication interface. The wired communication interface may be, for example, an Ethernet interface, which can be an optical interface, an electrical interface, or a combination thereof. The wireless communication interface may be a wireless local area network (WLAN) interface, a cellular network communication interface, or a combination thereof.
[0273] In a specific implementation, as one example, the processor 801 may include one or more CPUs, for example, Figure 12 CPU0 and CPU1 are shown in the diagram.
[0274] In a specific implementation, as one example, the network device 800 may include multiple processors, such as... Figure 12 The processors 801 and 805 are shown. Each of these processors can be a single-core processor or a multi-core processor. Here, "processor" can refer to one or more devices, circuits, and / or processing cores used to process data (such as computer program instructions).
[0275] In some embodiments, memory 803 is used to store program code 810 of the present application scheme, and processor 801 is used to execute the program code 810 stored in memory 803. That is, network device 800 can be implemented using processor 801 and program code 810 in memory 803. Figure 2 or Figure 5 or Figure 9 The method provided in the method implementation examples.
[0276] The network device 800 of this application embodiment can correspond to the first site edge or the second site edge in the above-described method embodiments. Furthermore, the processor 801, communication interface 804, etc. in the network device 800 can implement the functions and / or various steps and methods implemented by the devices in the above-described method embodiments. For the sake of brevity, further details are omitted here.
[0277] When the network device 800 is configured as the first site edge, corresponding to the above-mentioned secure message transmission device 600, the receiving module 610 and the sending module 630 in the secure message transmission device 600 can be located in the communication interface 804 in the network device 800; the processing module 620 can be located in the processor 801 or the processor 805 in the network device 800.
[0278] When the network device 800 is configured as the second site edge, corresponding to the above-mentioned secure message transmission device 700, the receiving module 710 and the sending module 730 in the secure message transmission device 700 can be located in the communication interface 804 in the network device 800; the processing module 720 can be located in the processor 801 or the processor 805 in the network device 800.
[0279] The various hardware components, modules, and other operations and / or functions in the network device 800 are various steps and methods implemented by the device 600 or the device 700 for secure message transmission. For details on how the network device 800 implements message processing, please refer to the above method embodiments. For the sake of brevity, these details will not be repeated here.
[0280] Among them, the above text Figure 2 or Figure 5 or Figure 9 Each step is completed through integrated logic circuits in the hardware or software instructions in the processor of the network device 800. The methods and steps disclosed in the embodiments of this application can be directly implemented by a hardware processor, or by a combination of hardware and software modules (software units) in the processor. The software modules can reside in one or more storage media mature in the art, such as random access memory, flash memory, programmable read-only memory, electrically erasable programmable memory, and registers. The storage medium is located in memory, and the processor reads information from the memory and, in conjunction with the hardware, executes the steps in the above method. For the sake of brevity, detailed descriptions are omitted here.
[0281] This application embodiment also provides a system, the system including a first site edge and a second site edge. The first site edge can be the aforementioned secure message transmission device 600 or network device 800, and the second site edge can be the aforementioned secure message transmission device 700 or network device 800. The first site edge can be used to implement the above... Figure 2 or Figure 5 In the embodiments of the method described above, the second site edge can be used to implement the above. Figure 2 or Figure 9 The specific implementation examples of the method described above can be found in the above description. Figure 2 or Figure 5 or Figure 9 The description of the method implementation examples will not be repeated here.
[0282] This application also provides a computer storage medium including program instructions that, when executed on a processor, cause the processor to perform the above-described functions. Figure 2 or Figure 5 or Figure 9 Each step in the method embodiment.
[0283] This application also provides a computer program product including program instructions, which, when executed on a processor, cause the processor to perform the above-described... Figure 2 or Figure 5 or Figure 9 Each step in the method embodiment.
[0284] Those skilled in the art will recognize that the method steps and units described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the steps and components of each embodiment have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0285] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be found in the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0286] In the several embodiments provided in this application, the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative. For instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or units, or it may be an electrical, mechanical, or other form of connection.
[0287] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of the embodiments of this application, depending on actual needs.
[0288] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0289] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0290] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. This computer program product includes one or more computer program instructions. When these computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer program instructions can be transferred from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., digital video disc (DVD), or a semiconductor medium (e.g., solid-state drive), etc.
[0291] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and these modifications or substitutions should all be covered within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A method for securely transmitting messages, characterized in that, The method includes: The first site exit device edge in the wide area network receives and forwards VPN service packets from the virtual route in the VRF; The first site egress device edge performs security protection on the VPN service packets according to the Internet Protocol Security Protocol Security Association (IPsecSA) associated with the VRF, which is negotiated with the second site egress device edge, in order to obtain the first packet; The first site egress device edge encapsulates the tunnel information of the upper-layer overlay end-to-end tunnel established between the first site egress device edge and the second site egress device edge on the outer layer of the first message to obtain the second message. The lower-layer underlay tunnel corresponding to the overlay end-to-end tunnel includes multiple tunnel segments. The tunnel information includes the first information of the first access point POP. The first site egress device edge is the ingress point of the overlay end-to-end tunnel, and the second site egress device edge is the egress point of the overlay end-to-end tunnel. The overlay end-to-end tunnel passes through the first POP. The first site egress device edge sends the second message to the second site egress device edge through the overlay end-to-end tunnel.
2. The method according to claim 1, characterized in that, The security protection of the VPN service packets includes: The VPN service packets are encapsulated with a security payload and encrypted using the ESP protocol; and / or, The VPN service message is encapsulated with an Authentication Header.
3. The method according to claim 1 or 2, characterized in that, The tunnel information also includes second information of the second POP. The overlay end-to-end tunnel passes through the first POP and the second POP. The first site egress device edge accesses the wide area network through the first POP, and the second site egress device edge accesses the wide area network through the second POP.
4. The method according to claim 3, characterized in that, The overlay end-to-end tunnel is an Internet Protocol version 6 (IPv6) segment routing SRv6 tunnel. The second message includes an IPv6 header and a segment routing header (SRH). The destination address of the IPv6 header points to the first POP, and the SRH includes the first information and the second information.
5. The method according to claim 4, characterized in that, The first information is the first endpoint segment identifier END.SID of the first POP. The operation associated with the first endpoint segment identifier END.SID includes: matching the upper-layer overlay SRv6 Policy from the first POP to the second POP based on the next-hop SID of the END.SID.
6. The method according to claim 3, characterized in that, The overlay end-to-end tunnel is a segmented routing multiprotocol label switching traffic engineering policy (SR-MPLS TE Policy). The second packet includes an MPLS label stack, which includes the first information and the second information.
7. The method according to claim 6, characterized in that, The first information is the SID of the first node of the first POP, and the operations associated with the first node SID include: Match the upper-layer overlay SR MPLS tunnel from the first POP to the second POP based on the next-hop SID of the first node SID in the tag stack.
8. The method according to claim 3, characterized in that, The overlay end-to-end tunnel is a tunnel encapsulated based on the Geneve protocol for general network virtualization encapsulation, and the second message is encapsulated using SRv6 in Geneve.
9. The method according to claim 3, characterized in that, The overlay end-to-end tunnel is a tunnel encapsulated based on the Generic Routing Encapsulation (GRE) protocol, and the second message uses SRv6 over GRE encapsulation.
10. The method according to any one of claims 1 to 9, characterized in that, Before the first site's egress device (edge) receives the service message, the method further includes: The first site egress device edge receives a Border Gateway Protocol (BGP) route advertised by the second site egress device edge. The BGP route includes a route type RT, the IPsec SA, the identifier of the second site egress device edge, and an exported route target ExportRT. The route type RT indicates that the IPsec SA advertised by the BGP route is used to provide end-to-end security protection for the VPN service packets in the VRF forwarding the virtual route that matches the ExportRT. Based on the routing type RT and the Export RT, the first site egress device edge associates the IPsec SA with the VRF.
11. The method according to claim 10, characterized in that, The BGP route is a BGP software-defined wide area network (SD-WAN) route, and the sub-address family of the BGP SD-WAN route is the SD-WAN sub-address family. Alternatively, the BGP route is a BGP Ethernet Virtual Private Network (EVPN) route, and the sub-address family of the BGP PEVPN route is the EVPN sub-address family.
12. The method according to claim 10 or 11, characterized in that, The identifier of the second site exit device edge includes the site ID to which the second site exit device edge belongs and the node ID of the second site exit device edge.
13. The method according to any one of claims 10-12, characterized in that, The BGP route includes Network Layer Reachability Information (NLRI), which includes the route type (RT) and the identifier of the second site egress device (edge).
14. The method according to any one of claims 10-13, characterized in that, The BGP route includes a Tunnel Encapsulation Attribute Type Length Value (TLV), which includes the IPsec SA.
15. The method according to any one of claims 10 to 14, characterized in that, The BGP route includes extended community attributes, which are used to carry the Export RT.
16. The method according to any one of claims 10-15, characterized in that, The first site egress device edge and the second site egress device edge are site egress devices edge in a software-defined wide area network (SD-WAN).
17. A method for securely transmitting messages, characterized in that, The method includes: In a wide area network (WAN), a second site egress device (edge) receives a second message sent by a first site egress device (edge) through an overlay end-to-end tunnel established between the first and second site egress devices (edges). The second message includes a first message and tunnel information of the overlay end-to-end tunnel encapsulated in the outer layer of the first message. The underlying underlay tunnel corresponding to the overlay end-to-end tunnel comprises multiple tunnel segments. The tunnel information includes first information of a first point of access (POP). The first site egress device (edge) is the ingress point of the overlay end-to-end tunnel, and the second site egress device (edge) is the egress point of the overlay end-to-end tunnel. The overlay end-to-end tunnel passes through the first POP. The first message is a message obtained by securing VPN service packets through an Internet Protocol Security Association (IPsec SA) negotiated between the second and first site egress devices (edges). The second site egress device (edge) decapsulates the second message to obtain the first message. The second site's egress device, edge, processes the first packet according to the IPsecSA to obtain the VPN service packet.
18. The method according to claim 17, characterized in that, The processing of the first message includes: According to the IPsecSA, the first packet is encapsulated with a security payload (ESP) and decrypted using the ESP protocol; and / or, The first packet is authenticated based on the IPsec SA and the authentication data carried in the Authentication Header of the first packet.
19. The method according to claim 17 or 18, characterized in that, The tunnel information also includes second information of the second POP. The overlay end-to-end tunnel passes through the first POP and the second POP. The first site egress device edge accesses the wide area network through the first POP, and the second site egress device edge accesses the wide area network through the second POP.
20. The method according to claim 19, characterized in that, The overlay end-to-end tunnel is an Internet Protocol version 6 (IPv6) segment routing SRv6 tunnel. The second message includes an IPv6 header and a segment routing header (SRH). The destination address of the IPv6 header points to the first POP, and the SRH header includes the first information and the second information.
21. The method according to claim 20, characterized in that, The first information is the first endpoint segment identifier END.SID of the first POP. The operation associated with the first endpoint segment identifier END.SID includes: matching the upper-layer overlay SRv6 Policy from the first POP to the second POP based on the next-hop SID of the END.SID.
22. The method according to claim 19, characterized in that, The overlay end-to-end tunnel is a segmented routing multiprotocol label switching traffic engineering policy (SR-MPLSTE Policy). The second packet includes an MPLS label stack, which includes the first information and the second information.
23. The method according to claim 22, characterized in that, The first information is the SID of the first node of the first POP, and the operations associated with the first node SID include: Match the upper-layer overlay SR MPLS tunnel from the first POP to the second POP based on the next-hop SID of the first node SID in the tag stack.
24. The method according to claim 19, characterized in that, The overlay end-to-end tunnel is a tunnel encapsulated based on the Geneve protocol for general network virtualization encapsulation, and the second message is encapsulated using SRv6 in Geneve.
25. The method according to claim 19, characterized in that, The overlay end-to-end tunnel is a tunnel encapsulated based on the Generic Routing Encapsulation (GRE) protocol, and the second message uses SRv6 over GRE encapsulation.
26. The method according to any one of claims 17 to 25, characterized in that, Before the second site egress device edge in the wide area network receives the second message sent by the first site egress device edge through the upper-layer overlay end-to-end tunnel, the method further includes: The second site egress device edge generates a Border Gateway Protocol (BGP) route, wherein the BGP route includes a route type RT, the IPsec SA, the identifier of the second site egress device edge, and an exported route target ExportRT, wherein the route type RT indicates that the IPsec SA advertised by the BGP route is used to provide end-to-end security protection for the VPN service packets in the VRF forwarding virtual route matching the ExportRT; The second site's egress device (edge) advertises the BGP route to the first site's egress device (edge).
27. The method according to claim 26, characterized in that, The BGP route is a BGP software-defined wide area network (SD-WAN) route, and the sub-address family of the BGP SD-WAN route is the SD-WAN sub-address family. Alternatively, the BGP route is a BGP Ethernet Virtual Private Network (EVPN) route, and the sub-address family of the BGP PEVPN route is the EVPN sub-address family.
28. The method according to claim 26 or 27, characterized in that, The identifier of the second site exit device edge includes the site ID to which the second site exit device edge belongs and the node ID of the second site exit device edge.
29. The method according to any one of claims 26 to 28, characterized in that, The BGP route includes Network Layer Reachability Information (NLRI), which includes the route type (RT) and the identifier of the second site egress device (edge).
30. The method according to any one of claims 26 to 29, characterized in that, The BGP route includes a Tunnel Encapsulation Attribute Type Length Value (TLV), which includes the IPsec SA.
31. The method according to any one of claims 26 to 30, characterized in that, The BGP route includes extended community attributes, which are used to carry the Export RT.
32. The method according to any one of claims 26 to 31, characterized in that, The first site egress device edge and the second site egress device edge are site egress devices edge in a software-defined wide area network (SD-WAN).
33. A method for negotiating the Internet Protocol Security Protocol Security Association (IPsec SA), characterized in that, The method includes: In a wide area network, the first site egress device (edge) receives a Border Gateway Protocol (BGP) route advertised by the second site egress device (edge). The BGP route includes a route type (RT), the IPsec SA, the identifier of the second site egress device (edge), and an exported route destination (ExportRT). The route type (RT) indicates that the IPsec SA advertised by the BGP route is used to provide end-to-end security protection for service packets in the Virtual RF (VRF) that are forwarded to the virtual route that matches the ExportRT. Based on the routing type RT and the Export RT, the first site egress device edge associates the IPsec SA with the VRF.
34. The method according to claim 33, characterized in that, The BGP route is a BGP software-defined wide area network (SD-WAN) route, and the sub-address family of the BGP SD-WAN route is the SD-WAN sub-address family. Alternatively, the BGP route is a BGP Ethernet Virtual Private Network (EVPN) route, and the sub-address family of the BGP PEVPN route is the EVPN sub-address family.
35. The method according to claim 33 or 34, characterized in that, The identifier of the second site exit device edge includes the site ID to which the second site exit device edge belongs and the node ID of the second site exit device edge.
36. The method according to any one of claims 33 to 35, characterized in that, The BGP route includes Network Layer Reachability Information (NLRI), which includes the route type (RT) and the identifier of the second site egress device (edge).
37. The method according to any one of claims 33 to 36, characterized in that, The BGP route includes a Tunnel Encapsulation Attribute Type Length Value (TLV), which includes the IPsec SA.
38. The method according to any one of claims 33 to 37, characterized in that, The BGP route includes extended community attributes, which are used to carry the Export RT.
39. The method according to any one of claims 33 to 38, characterized in that, The first site egress device edge and the second site egress device edge are site egress devices edge in a software-defined wide area network (SD-WAN).
40. A method for negotiating the Internet Protocol Security Protocol Security Association (IPsec SA), characterized in that, The method includes: The second site egress device edge in the wide area network generates a Border Gateway Protocol (BGP) route, wherein the BGP route includes a route type RT, the IPsec SA, the identifier of the second site egress device edge, and an exported route target ExportRT. The route type RT indicates that the IPsec SA advertised by the BGP route is used to provide end-to-end security protection for service packets in the VRF forwarding the virtual route matching the ExportRT. The second site's egress device edge advertises the BGP route to the first site's egress device edge.
41. The method according to claim 40, characterized in that, The BGP route is a BGP software-defined wide area network (SD-WAN) route, and the sub-address family of the BGP SD-WAN route is the SD-WAN sub-address family. Alternatively, the BGP route is a BGP Ethernet Virtual Private Network (EVPN) route, and the sub-address family of the BGP PEVPN route is the EVPN sub-address family.
42. The method according to claim 40 or 41, characterized in that, The identifier of the second site exit device edge includes the site ID to which the second site exit device edge belongs and the node ID of the second site exit device edge.
43. The method according to any one of claims 40 to 42, characterized in that, The BGP route includes Network Layer Reachability Information (NLRI), which includes the route type (RT) and the identifier of the second site egress device (edge).
44. The method according to any one of claims 40 to 43, characterized in that, The BGP route includes a Tunnel Encapsulation Attribute Type Length Value (TLV), which includes the IPsec SA.
45. The method according to any one of claims 40 to 44, characterized in that, The BGP route includes extended community attributes, which are used to carry the Export RT.
46. The method according to any one of claims 40 to 45, characterized in that, The first site egress device edge and the second site egress device edge are site egress devices edge in a software-defined wide area network (SD-WAN).
47. A device for securely transmitting messages, characterized in that, The apparatus includes modules for implementing the method as described in any one of claims 1-16.
48. A device for securely transmitting messages, characterized in that, The apparatus includes modules for implementing the method as described in any one of claims 17-32.
49. An apparatus for negotiating the Internet Protocol Security Protocol Security Association (IPsec SA), characterized in that, The apparatus includes modules for implementing the method as described in any one of claims 33-39.
50. An apparatus for negotiating the Internet Protocol Security Protocol Security Association (IPsec SA), characterized in that, The apparatus includes modules for implementing the method as described in any one of claims 40-46.
51. A network device, characterized in that, The method includes a memory and a processor, the memory being used to store instructions, and the processor being used to execute the instructions stored in the memory to implement the method as claimed in any one of claims 1 to 16, or to implement the method as claimed in any one of claims 17 to 32, or to implement the method as claimed in any one of claims 33 to 39, or to implement the method as claimed in any one of claims 40 to 46.
52. A system, characterized in that, It includes a first station exit device edge and a second station exit device edge, wherein the first station exit device edge is used to perform the method as described in any one of claims 1 to 16, and the second station exit device edge is used to perform the method as described in any one of claims 17 to 32; or, the first station exit device edge is used to perform the method as described in any one of claims 33 to 39, and the second station exit device edge is used to perform the method as described in any one of claims 40 to 46.
53. A computer storage medium, characterized in that, Includes program instructions that, when executed on a processor, cause the processor to implement the method as claimed in any one of claims 1 to 16, or cause the processor to implement the method as claimed in any one of claims 17 to 32, or cause the processor to implement the method as claimed in any one of claims 33 to 39, or cause the processor to implement the method as claimed in any one of claims 40 to 46.
54. A computer program product comprising program instructions, characterized in that, When the program instructions are executed on the processor, the processor is caused to implement the method as claimed in any one of claims 1 to 16, or the processor is caused to implement the method as claimed in any one of claims 17 to 32, or the processor is caused to implement the method as claimed in any one of claims 33 to 39, or the processor is caused to implement the method as claimed in any one of claims 40 to 46.
Citation Information
Patent Citations
Method and equipment for transmitting service in network
CN113472622A
Encryption transmission method and device and SD-WAN network system
CN114338116A
Cited By
Method for securely transmitting packet, and related device
EP4708784A1
Method for securely transmitting packet, and related device
WO2025001496A1