A Method for Isolating Security Zones in a Campus Network Based on Streaming Authorization Label Verification
By generating a unique flow authorization tag for park network users in the SDN controller and sending flow tables on the access switch, the problem of automated access control in the park network is solved, and secure and efficient access control of park network resources is achieved.
Patent Information
- Application Number
- CN202411511708.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-28
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2044-10-28
AI Technical Summary
The prior art is difficult to automatically issue access control flow tables carrying user authorization information to network devices in the park network, resulting in administrators needing to master a large amount of user information to specify precise access control rules, which is time-consuming and labor-intensive.
A unique flow authorization tag is generated for each user in the SDN controller, and a flow table is sent to the access switch through the SDN controller, adding and verifying the flow authorization tags for communication between users, thereby achieving authorization and secure access to campus network resources.
By automatically generating and issuing stream authorization tags, secure and efficient access control of campus network resources is achieved, reducing the workload of administrators and improving the efficiency of network isolation.
Smart Images

Figure CN119402247B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a method for isolating security zones in a campus network based on flow authorization label verification, and belongs to the technical field of network security research. Background Art
[0002] A campus network generally refers to the campus network of a university and the internal network (intranet) of an enterprise. In a campus network, security zones are usually divided according to the importance of protection. Different security zones correspond to network resources with different security levels. Strict control must be carried out on the mutual access traffic between security zones. Only the permitted traffic can enter the corresponding security zone. In this way, malicious traffic attacks can be avoided to a certain extent, and the healthy and stable operation of the campus network can be ensured. At present, for the traffic isolation between security zones, only a large number of access control rules can be pre-configured by an administrator on key network devices. The administrator needs to master a large amount of information about users and the resources that users want to access in order to specify accurate access control rules, which makes this work time-consuming and laborious.
[0003] Therefore, how to automatically issue access control flow tables carrying user authorization information to network devices in a campus network, and at the same time, the network devices add or verify authorization information to the data packets generated by campus network users, so as to achieve the traffic isolation of security zones in the campus network based on flow authorization label verification, is an urgent problem to be solved in campus network security. Summary of the Invention
[0004] In view of the deficiencies of the prior art, the present invention provides a method for isolating security zones in a campus network based on flow authorization label verification. By implementing security zone isolation based on flow authorization label verification under the access switch of the campus network, an economical and efficient method for authorizing secure access to campus network resources is provided. This method generates a unique flow authorization label for each user in the campus network in the SDN controller, and adds and verifies the flow authorization label to the communication between users when the SDN controller issues a flow table to the access switch, so as to achieve the goal of authorizing secure access to campus network resources.
[0005] Specifically, a security zone isolation application based on flow authorization label verification for the campus network is developed in the SDN controller. By collecting campus network user information, a user database is established, and a unique authorization code is generated for each user. At the same time, the security zone range that the user is allowed to access in the campus network is also demarcated for the user. After the SDN controller senses the user's access, it issues an access control flow table based on flow authorization label verification to the access switch. The access switch performs access control on the user's communication in the specified security zone according to the flow table, providing a guarantee for preventing users from illegally accessing campus network resources across security zones in the campus network.
[0006] The technical solution of the present invention is as follows:
[0007] A method for isolating security zones in a campus network based on flow authorization label verification, the steps are as follows:
[0008] (1) Create a campus network user information table in the SDN controller system;
[0009] (2) Create a communication flow table through communication between access hosts via a switch;
[0010] (3) After the switch receives the ARP request packet sent by the host, it submits it to the SDN controller system through the openflow protocol;
[0011] (4) The SDN controller system extracts the MAC address and IP address of the communication initiating host in the ARP request packet information, scans and updates the campus network user information table;
[0012] (5) The SDN controller system extracts the destination host IP address in the ARP request packet information and scans the campus network user information table;
[0013] (6) Use the user ID in the entry recorded in step (5) to scan the user allowed access resource list in the record table in step (4), and create a communication flow table according to the matching record;
[0014] (7) The SDN controller system issues the communication flow table to the access switch;
[0015] (8) After the access switch receives the communication data stream entering the switch, it compares it with the matching items in the communication flow table, and performs vxlan tunnel encapsulation according to the action items after matching;
[0016] (9) When the access switch forwards the communication data out, it compares it with the matching items in the communication flow table, removes the flow label according to the action items after matching, and forwards the packet out from the port.
[0017] Preferably, according to the present invention, in step (1), the user information table includes user ID, host IP address, host MAC address, user name, user unit, user flow authorization tag ID, user allowed access to resources list, vxlan tunnel number and user access port number, wherein user ID is the current user's unique identifier, host IP address is the IP address assigned to the current user in the campus network, host MAC address is the current host network card's unique identifier, user name is the current user's name, user unit is the current user's unit name, user authorization tag ID is the network-wide unique flow authorization tag information generated by the system for the current user, the user allowed access to resources list is the set of user IDs that the current user in the campus network is allowed to access, vxlan tunnel number is the tunnel number through which the current user communicates with the target host through the vxlan tunnel, and the user access port number is the access switch interface number to which the user host is connected. The initialized campus network user information table is entered into the system by the administrator through the web interface.
[0018] According to the preferred embodiment of the present invention, in step (2), the communication flow table includes two parts: a matching item and an action item. The matching item is used to match key information in the data flow. After matching, the action item is executed to modify and forward the flow.
[0019] The matching item includes several optional fields: flow table number, source host MAC address, source host IP address, destination host MAC address, destination host IP address, flow authorization tag ID, and interface number;
[0020] The action item includes several optional fields: add flow authorization tag ID, remove flow authorization tag ID, and forwarding port number;
[0021] Among them, the flow table number is the unique identifier of the current table entry, the source host MAC address is the network card MAC address of the host initiating the communication, the source host IP address is the IP address of the host initiating the communication, the destination host MAC address is the network card MAC address of the host to be accessed for communication, the destination host IP address is the IP address of the host to be accessed, the flow authorization tag ID is the flow label embedded in the data flow that matches the interface number, the interface number for the data entering or leaving the switch, the flow authorization tag ID for adding is the flow authorization tag ID added to the data flow, the flow authorization tag removal identifier is the need to remove the flow authorization tag in the data flow after the access switch matches the table entry, the forwarding port number is the port number for forwarding the data flow, and the user communication flow table is initialized to be empty.
[0022] Preferably, according to the present invention, in step (3), the protocol also carries the access switch port number of the ARP request message.
[0023] Preferably according to the present invention, in step (4), specifically, the SDN controller system extracts the MAC address of the communication initiating host from the Sender Mac Address field in the ARP request packet and the IP address of the communication initiating host extracted from the Sender IP address field in the packet, scans the campus network user information table, records the content of the entry in the campus network user information table that is hit. At the same time, the user access port number in the entry is updated using the access switch port number obtained in step (3).
[0024] Preferably according to the present invention, in step (5), specifically, the SDN controller system extracts the target host IP address from the Target IP Address field in the ARP request packet, scans the campus network user information table, and records the content of the entry in the campus network user information table that is hit;
[0025] Preferably according to the present invention, in step (6), specifically, using the user ID in the entry recorded in step (5), scan the user allowed access resource list in the entry recorded in step (4). If there is no match, execute step (6.1). If there is a match, execute step (6.2) and step (6.3);
[0026] (6.1): Record the log information that the current user cannot access the target user, and return to step (3) to continue execution;
[0027] (6.2): Create a user communication flow table for adding a flow label. Using the host IP address, host MAC address, and user access port number in the entry recorded in step (4), and the host IP address and host MAC address in the entry recorded in step (5), fill in the source host MAC address, source host IP address, destination host MAC address, destination host IP address, and interface number in the matching item of the entry. For the action item, use the user flow authorization label ID and vxlan tunnel number in the entry recorded in step (4) to fill in the added flow authorization label ID and vxlan tunnel number;
[0028] (6.3): Create a user communication flow table for verifying the flow label. Using the host IP address, host MAC address, and user flow authorization label ID in the entry recorded in step (4), and the host IP address and host MAC address in the entry recorded in step (5), fill in the source host MAC address, source host IP address, destination host MAC address, destination host IP address, and flow authorization label ID in the matching item of the entry. For the action item, use the user access port number in the entry recorded in step (5) to fill in the forwarding port number, and set the flag for removing the flow authorization label.
[0029] Preferably according to the present invention, in step (7), specifically, the SDN controller system distributes the communication flow tables generated in steps (6.2) and (6.3) to the access switch.
[0030] Preferably according to the present invention, in step (8), specifically, after the access switch receives the communication data stream entering the switch, it is compared with the communication flow table matching item (S mac +S ip +D mac +D ip +I port );
[0031] Among them, S mac represents the source host MAC address of the communication data stream, S ip represents the source host IP address of the communication data stream, D mac represents the destination host MAC address of the communication data stream, D ip represents the destination host IP address of the communication data stream, I port represents the interface number when the communication data stream enters the switch;
[0032] After matching, vxlan tunnel encapsulation is performed according to the action item (F id +V id ), where F id represents the user flow authorization label ID, V id represents the vxlan tunnel identifier to be encapsulated, and F id is filled into the VNID field of the vxlan tunnel.
[0033] Preferably according to the present invention, in step (9), specifically, when the access switch forwards the communication data out, it is compared with the communication flow table matching item (S mac +S ip +D mac +D ip +F id ), and after matching, the flow label is removed according to the action item (M id +O port ), where M id represents the removal of the flow authorization label identification bit set, 1 means it is set, 0 means it is not set, O port represents the interface number when the packet is forwarded out of the switch, and the packet is forwarded out from port O port ).
[0034] The beneficial effects of the present invention are as follows:
[0035] The present invention realizes security zone isolation based on flow authorization label verification under the access switch of the campus network, providing an economical and efficient method for secure access authorization of campus network resources. This method generates a unique flow authorization label for each user in the campus network in the SDN controller, and adds and verifies the flow authorization label to the communication between users when the SDN controller issues a flow table to the access switch, achieving the goal of secure access authorization of campus network resources. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] Figure 1 It is a schematic connection topology diagram of an embodiment of the present invention;
[0037] Figure 2 It is a schematic diagram of the architecture of the campus network security isolation system based on flow authorization label verification according to an embodiment of the present invention;
[0038] Figure 3 It is a schematic diagram of the campus network user information according to an embodiment of the present invention;
[0039] Figure 4 It is a schematic diagram of the user communication flow according to an embodiment of the present invention;
[0040] Figure 5 It is a schematic flowchart of an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0041] The present invention will be further described below by way of embodiments in conjunction with the drawings, but is not limited thereto.
[0042] Embodiment 1:
[0043] As Figure 5 shown, this embodiment provides a method for security zone isolation of a campus network based on flow authorization label verification. The schematic connection topology diagram of the security zone isolation of the campus network based on flow authorization label verification is shown in Figure 1 , where the SDN controller is located in the network above. The SDN controller is used to manage network traffic and configure rules, generate a unique flow authorization label for each user in the campus network, add and verify the flow authorization label to the communication between users when the SDN controller issues a flow table to the access switch, achieving the goal of secure access authorization of campus network resources; the lower part shows the connection between the switch and the terminal device (i.e., the host). The terminal device accesses the switch through a port, and the switches are interconnected through a tunnel to realize communication across network regions. The core of this structure is to use the SDN controller to achieve fine control of the access network, ensure the security zone isolation of the network, and perform real-time defense against potential security threats.
[0044] The steps of the isolation method are as follows:
[0045] S100: The SDN controller system creates a campus network user information table and configures initial values. The campus network user information table is as shown in Figure 3 and includes user ID, host IP address, host MAC address, user name, user's affiliated organization, user flow authorization label ID, user's permitted access resource list, vxlan tunnel number, and user access port number.
[0046] S200: The access switch creates a user communication flow table and configures initial values. The user communication flow table is as shown in Figure 4 and includes Entry 1. The matching items are source MAC, source IP, destination MAC, destination IP, and incoming port. According to the action items, the Vxlan tunnel number and the flow authorization label ID are used for Vxlan tunnel encapsulation, and the flow authorization label ID is added to the VNID field of the tunnel; Entry 2. The matching items are source MAC, source IP, destination MAC, destination IP, and flow authorization label ID. According to the action items, the flow authorization label ID and the outgoing port are removed, the flow label is removed, and the packet is forwarded out from the outgoing port.
[0047] S300: The access switch sends the ARP request packet sent by the host and the access switch interface number where the packet is received to the SDN controller system;
[0048] S400: The SDN controller system scans the campus network user information table according to the origin host information in the ARP request packet received in step S300, records the matching entry, and updates the recorded user access port number field according to the access switch interface number obtained in step S300;
[0049] S500: The SDN controller system scans the campus network user information table according to the destination host information in the ARP request packet received in step S300 and records the entry content;
[0050] S600: According to the user ID in the entry recorded in step S500, scan the user's permitted access resource list in the record entry of S400. If there is no match, execute step S601. If there is a match, execute S602 and step S603;
[0051] S601: Record the log information and return to step S300 to continue execution;
[0052] S602: Create a user communication flow table for adding a flow authorization label and fill the entry according to the information obtained in step S400 and step S500;
[0053] S603: Create a user communication flow table for deleting a flow authorization label and fill the entry according to the information obtained in step S400 and step S500;
[0054] S700: The SDN controller system distributes the entries generated in step S602 and step S603 to the access switch;
[0055] S800: When the access switch receives the communication data stream entering the switch, it matches the matching items in the communication flow table. After successful matching, it adds the flow authorization label to the vxlan according to the action item and forwards it out;
[0056] S900: When the access switch forwards the communication data out, it matches the matching items in the flow table. After successful matching, it removes the flow authorization label according to the action item and forwards it out from a specific port.
[0057] The schematic diagram of the campus network security isolation system architecture based on flow authorization label verification is shown in Figure 2 , and the basic design idea is as follows: It is mainly composed of five parts: the front-end display layer, the access control layer, the foreground application layer, the service layer, and the data layer. Among them, the front-end display layer, as the carrier of the flow authorization label access control system, includes access devices and their front-end architectures to achieve data transmission and result display; the access control layer uses a series of proxy and gateway execution programs to achieve the interaction between the front and back ends; the foreground application layer deploys a variety of practical functions for user demand access; the service layer realizes the flow authorization label access control logic through the RYU controller and the Django background application program; the data layer provides network devices and user information data for the upper layer to obtain. Through the detailed design of each layer module, the front end calls an API interface to interact with the front and back ends of the access control layer to reach the function module of the foreground application layer, and then uses the background application program of the service layer to reach the data layer to find relevant data information, and then converges the query results to the front-end display layer for users to view.
[0058] The above are only the preferred embodiments of the present invention and are not used to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A campus network security zone isolation method based on flow authorization tag verification, characterized in that: Here are the steps: (1) Create a campus network user information table in the SDN controller system. The user information table includes user ID, host IP address, host MAC address, user name, user unit, user flow authorization tag ID, user allowed access resource list, vxlan tunnel number and user access port number, where user ID is the unique identifier of the current user, host IP address is the IP address assigned to the current user in the campus network, host MAC address is the unique identifier of the current host network card, user name is the current user name, user unit is the unit name of the current user, user authorization tag ID is the network-wide unique flow authorization tag information generated by the current user, user allowed access resource list is the user ID set that the current user is allowed to access in the campus network, vxlan tunnel number is the tunnel number through which the current user communicates with the target host through the vxlan tunnel, and user access port number is the access switch interface number to which the user host is connected; (2) The access hosts communicate with each other through switches to create a communication flow table. The communication flow table consists of two parts: matching items and action items. Matching items are used to match key information in data traffic. Once a match is found, the action items are executed to modify and forward the traffic. The matching item includes several optional fields: flow table number, source host MAC address, source host IP address, destination host MAC address, destination host IP address, flow authorization tag ID, and interface number; The action item includes several optional fields: add flow authorization tag ID, remove flow authorization tag ID, and forwarding port number; Among them, the flow table number is the unique identifier of the current table entry, the source host MAC address is the network card MAC address of the host that initiated the communication, the source host IP address is the IP address of the host that initiated the communication, the destination host MAC address is the network card MAC address of the host to be accessed for communication, the destination host IP address is the IP address of the host to be accessed, the flow authorization tag ID is the matching item with the flow tag embedded in the data flow, the interface number is the interface number of the data entering or leaving the switch, the added flow authorization tag ID is the flow authorization tag ID added to the data flow, the removed flow authorization tag identifier is the need to remove the flow authorization tag in the data flow after matching the table entry, the forwarding port number is the port number for forwarding the data flow, and the initialized user communication flow table is empty; (3) After the switch receives the ARP request message sent by the host, it submits it to the SDN controller system through the protocol; (4) The SDN controller system extracts the MAC address and IP address of the communication initiating host from the ARP request message information, scans and updates the campus network user information table; (5) The SDN controller system extracts the destination host IP address in the ARP request message information, and scans the campus network user information table. Specifically, the SDN controller system extracts the destination host IP address in the ARP request message, scans the campus network user information table, and records the content of the hit campus network user information table entry; (6) Using the user ID recorded in the table item in step (5), scan the user's allowed access resource list in the table item in step (4), and create a communication flow table based on the matching record. Specifically, using the user ID recorded in the table item in step (5), scan the user's allowed access resource list in the table item in step (4), if there is no match, execute step (6.1), if there is a match, execute steps (6.2) and (6.3); (6.1): Record the log information that the current user cannot access the target user, and return to step (3) to continue execution; (6.2): Create a user communication flow table with a flow label added, use the host IP address, host MAC address and user access port number in the table item recorded in step (4), and the host IP address and host MAC address of the table item recorded in step (5), fill in the source host MAC address, source host IP address, destination host MAC address, destination host IP address and interface number of the matching item in the table item, and use the user flow authorization tag ID and vxlan tunnel number of the table item recorded in step (4) in the action item, fill in the added flow authorization tag ID and vxlan tunnel number; (6.3): Create a user communication flow table for verifying the flow label, use the host IP address, host MAC address and user flow authorization label ID in the table item recorded in step (4), and the host IP address and host MAC address of the table item recorded in step (5), fill in the source host MAC address, source host IP address, destination host MAC address, destination host IP address and flow authorization label ID of the matching item in the table item, use the user access port number of the table item recorded in step (5) in the action item, fill in the forwarding port number, and set the remove flow authorization label flag; (7) The SDN controller system sends the communication flow table to the access switch; (8) After the access switch receives the communication data flow entering the switch, it compares it with the matching items in the communication flow table. After matching, it performs vxlan tunnel encapsulation according to the action items; (9) When the access switch forwards the communication data, it compares it with the matching item in the communication flow table. After a match is found, the flow label is removed according to the action item, and the message is forwarded out of the port. Specifically, when the access switch forwards the communication data, it compares it with the matching item in the communication flow table (S mac +S ip +D mac +D ip +F id ) to compare, and after matching, according to the action item (M id +O port ) removes the flow label, where M id Indicates that the flow authorization tag flag is removed. 1 indicates that it is set, 0 indicates that it is not set, and O port Indicates the number of the interface through which the message is forwarded from the switch, and forwards the message from port O port Forward it.
2. The campus network security area isolation method based on flow authorization tag verification as described in claim 1 is characterized in that: In step (3), the protocol also carries the access switch port number of the ARP request message.
3. The campus network security area isolation method based on flow authorization tag verification as described in claim 2 is characterized in that: In step (4), specifically, the SDN controller system extracts the MAC address of the communication initiating host and the IP address of the communication initiating host from the ARP request message, scans the campus network user information table, records the content of the hit campus network user information table entry, and at the same time, uses the access switch port number obtained in step (3) to update the user access port number in the table entry.
4. The campus network security area isolation method based on flow authorization tag verification as described in claim 3 is characterized in that: In step (7), specifically, the SDN controller system sends the communication flow table generated in step (6.2) and step (6.3) to the access switch.
5. The campus network security area isolation method based on flow authorization tag verification as described in claim 4 is characterized in that: In step (8), specifically, after the access switch receives the communication data flow entering the switch, it matches the communication flow table (S mac +S ip +D mac +D ip +I port ) for comparison; Among them, S mac Indicates the MAC address of the source host of the communication data flow, S ip Indicates the source host IP address of the communication data flow, D mac Indicates the MAC address of the destination host of the communication data flow, D ip Indicates the destination host IP address of the communication data flow, I port Indicates the interface number when the communication data stream enters the switch; After matching, the action item (F id +V id ) performs vxlan tunnel encapsulation, where F id Indicates the user flow authorization tag ID, V id Indicates the vxlan tunnel identifier to be encapsulated, and F id Fill in the VNID field of the vxlan tunnel.
Citation Information
Patent Citations
Communication method, system thereof, resource pool management system, switches, and control device
CN104954281A
Access control method and system based on SDN network path
CN107222433A