A method, device, medium and product for verifying label instructions

By building a CRC parameter list database and time seed to determine the policy number and dynamically update the verification rules, the computing compatibility and synchronization problems of label instruction verification on the network processing chip are solved, efficient and secure label instruction verification is achieved, and network security and credibility are improved.

CN119520046BActive Publication Date: 2025-07-22CHINESE PEOPLES LIBERATION ARMY UNIT 61905
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411561957.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-05
Publication Date
2025-07-22
Estimated Expiration
2044-11-05

AI Technical Summary

Technical Problem

The prior art is difficult to effectively verify tag instructions at fast and high throughput on network processing chips, and there are problems such as mismatch in computing compatibility and input data types, resulting in insufficient network security and credibility.

Method used

By constructing a CRC parameter list database, using time seeds to determine the policy number, dynamically update the verification rules, and combining protocol-independent processing, multi-field CRC calculations are performed to verify the credibility of the tag instructions.

Benefits of technology

It realizes efficient and secure label instruction verification on the network processing chip, improves the security and credibility of the network, reduces the risk of collision cracking, and adapts to the synchronization needs of multiple nodes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119520046B_ABST
    Figure CN119520046B_ABST
Patent Text Reader

Abstract

The present application discloses a label instruction verification method, device, medium and product, relating to the field of instruction verification. The method includes constructing an overall list according to the configuration information of all valid parameters obtained; selecting the parameters in the overall list according to the configuration of the centralized configuration plane and assigning a policy number; and taking the relationship between the policy number and the corresponding parameters as a policy entry; constructing a CRC parameter list database according to all the policy entries; determining a policy number based on a time seed determined by the current time value; determining the corresponding policy entry and corresponding parameters in the CRC parameter list database according to the policy number, and further determining the verification table item execution parameters; determining a CRC input field according to the verification table item execution parameters and performing protocol-independent processing. The present application can meet the compatibility requirements of the computing method of the network processing chip and improve the security and credibility of verification.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of instruction verification, and particularly to a method, device, medium and product for verifying label instructions. Background Art

[0002] Label instructions based on labels are the main protocol form of the next-generation network. Label instructions are carried by explicit labels in data packets, which can improve the schedulability of the network at a very low resource cost. According to different functional types, label instructions include different representative protocols. For the forwarding function, common label instruction protocols include MPLS, SR MPLS, etc., and the label encapsulated by the label instruction is the label of the next forwarding node; for the source routing function, common label protocols include SRv6, which encapsulates the label of the next routing node; for the policy function, common protocols include IOAM and IFIT, etc., that is, measurement instructions and measurement data types are encapsulated in the instruction; for the quality of service guarantee function, common protocols include APN, etc., that is, the quality of service requirements of the service are encapsulated in the instruction.

[0003] Since most label instructions are transmitted explicitly in the network and can directly trigger the functional behaviors of network nodes, the verification of label instructions has become increasingly important. False and forged labels pose a risk of damaging the network. For example, forged forwarding and routing instructions may damage the current routing system of the network; forged policy instructions will consume excessive node resources of the network; forged quality of service guarantee instructions can illegally obtain the quality of service guarantee services of the network, etc. Therefore, how to verify label instructions is of great significance for ensuring the safe and normal operation of the network.

[0004] Since the verification of network label instructions is different from common identity verification, and label quality works entirely in the data plane with strong data throughput requirements, there are different requirement characteristics for the compatibility of calculation methods, the type of input data, the synchronization between different network nodes, etc., resulting in the difficulty of directly applying the existing method solutions to the verification of label instructions under fast and high throughput. The existing methods mainly have the following problems:

[0005] (1) Compatibility of calculation methods: Network processing chips are good at bit calculations rather than numerical calculations, and data processing capabilities of network processing chips cannot be compatible with numerical-based encryption and verification value calculation methods. And if all data is calculated based on general-purpose chips, the delay and throughput requirements of network transmission cannot be met.

[0006] (2) Types of input data: Most network processing chips are based on hardware programming permissions and cannot recognize common data types in general operating systems (such as ASCii encoding, etc.). Most input data only supports bit encoding. Therefore, it is difficult for verification schemes based on numerical calculations to provide the required data parsing in the network data plane.

[0007] (3) Synchronization between network nodes: The network has a large scale and includes various heterogeneous network devices and institutions, etc. If establishing verification synchronization for multiple network nodes, it is one of the important challenges that need to be considered.

[0008] Therefore, based on the above problems, there is an urgent need to provide a label instruction verification method or system, which can then adapt to the compatibility requirements of the network processing chip's calculation method and improve the security and credibility of verification. Summary of the Invention

[0009] The purpose of this application is to provide a label instruction verification method, device, medium and product, which can adapt to the compatibility requirements of the network processing chip's calculation method and improve the security and credibility of verification.

[0010] To achieve the above purpose, this application provides the following solutions:

[0011] In the first aspect, this application provides a label instruction verification method, and the label instruction verification method includes:

[0012] Construct an overall list according to the configuration information of all valid parameters obtained;

[0013] Select the parameters in the overall list according to the configuration of the centralized configuration plane, and assign a policy number; and use the relationship between the policy number and the corresponding parameters as a policy entry;

[0014] Construct a CRC parameter list database according to all the policy entries;

[0015] Determine the policy number based on the time seed determined by the current time value;

[0016] Determine the corresponding policy entry and corresponding parameters in the CRC parameter list database according to the policy number, and then determine the verification table entry execution parameters;

[0017] Determine the CRC input field according to the verification table entry execution parameters, and perform protocol-independent processing.

[0018] Optionally, the determining the policy number based on the time seed determined by the current time value specifically includes:

[0019] Obtain the current time value; the current time value is determined based on Unix global time;

[0020] According to the current time value, a one-time time password is calculated to determine the time seed for the current cycle;

[0021] Determine the policy number to be executed according to the time seed of the current cycle.

[0022] Optionally, the time seed adopts a 6-digit numerical value, and the update period is 30 seconds.

[0023] Optionally, the protocol-independent processing includes: encapsulation mode and verification mode.

[0024] Optionally, the encapsulation mode specifically includes:

[0025] Extract the field parameter corresponding to the verification table item execution parameter from the label instruction data packet;

[0026] Use the extracted field parameter as the CRC input field and perform CRC16 calculation;

[0027] Encapsulate and insert the calculated result value into a specific position of the label instruction and use it as the CRC verification value.

[0028] Optionally, the verification mode specifically includes:

[0029] Parse and extract the CRC verification value;

[0030] Calculate the verification table item execution parameter sent in real time according to the parsing and extraction result;

[0031] Extract the real-time field parameter from the label instruction data packet according to the verification table item execution parameter sent in real time;

[0032] Perform CRC16 calculation according to the real-time field parameter to obtain the real-time calculation result value;

[0033] Compare the real-time calculation result value with the CRC verification value, and judge whether the label instruction is credible according to the comparison result.

[0034] In a second aspect, the present application provides a label instruction verification device, and the label instruction verification device includes:

[0035] An overall list construction module, configured to construct an overall list according to the configuration information of all valid parameters obtained;

[0036] A policy item determination module, configured to select parameters in the overall list according to the configuration of the centralized configuration plane, and assign a policy number; and use the relationship between the policy number and the corresponding parameters as a policy item;

[0037] A CRC parameter list database determination module, configured to construct a CRC parameter list database according to all policy items;

[0038] A policy number determination module, configured to determine a policy number based on a time seed determined according to a current time value;

[0039] A verification entry execution parameter determination module, configured to determine a corresponding policy entry and corresponding parameters in a CRC parameter list database according to the policy number, and further determine verification entry execution parameters;

[0040] A protocol-independent processing module, configured to determine a CRC input field according to the verification entry execution parameters and perform protocol-independent processing.

[0041] In a third aspect, the present application provides a computer device, including: a memory, a processor, and a computer program stored on the memory and executable on the processor, where the processor executes the computer program to implement the label instruction verification method.

[0042] In a fourth aspect, the present application provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the label instruction verification method is implemented.

[0043] In a fifth aspect, the present application provides a computer program product, including a computer program, characterized in that when the computer program is executed by a processor, the label instruction verification method is implemented.

[0044] According to the specific embodiments provided by the present application, the present application has the following technical effects:

[0045] The present application provides a label instruction verification method, device, medium and product. By determining a policy number based on a time seed determined according to a current time value, and further determining verification entry execution parameters; that is, establishing the ability to periodically update the policy entries to be executed in a CRC parameter list database according to the time seed, and a dynamic self-update and synchronization mechanism according to the check rules for determining multiple nodes based on the time seed, to ensure the timeliness of the CRC verification rules and reduce the risk of being cracked by collision; determining a CRC input field according to the real-time verification entry execution parameters, and then dynamically selecting a variety of cross-protocol layer data fields as the CRC input field; performing protocol-independent processing on the CRC input field to obtain a verification value; on the one hand, the present application provides the privacy of CRC value calculation through the definition of multiple configurable fields to provide the feasibility of verification, and on the other hand, the verification calculation is completely based on a programmable data plane to run, which can provide better throughput and delay performance. Description of the Drawings

[0046] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the accompanying drawings required in the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.

[0047] Figure 1 It is a schematic flowchart of a label instruction verification method in an embodiment of the present application;

[0048] Figure 2 It is a schematic overall flowchart of a label instruction verification method in an embodiment of the present application;

[0049] Figure 3 It is a schematic diagram of a CRC verification value configuration service;

[0050] Figure 4 It is a schematic flowchart of protocol-independent processing;

[0051] Figure 5 It is a schematic diagram of the deployment in the SRv6 network. Specific embodiments

[0052] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present application.

[0053] To make the above objects, features, and advantages of the present application more obvious and understandable, the present application will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0054] In an exemplary embodiment, as Figure 1 and Figure 2 shown, a label instruction verification method is provided, and the method includes the following S101 to S106. Among them:

[0055] S101, construct an overall list according to the configuration information of all valid parameters obtained; the overall list is the generation target of the control configuration plane, store all available parameters and numbers of the configuration item by item, and the structure of each item is: [valid parameter field name, valid parameter field number]; the set of multiple items is the overall list. Table 1 is an overall list with 10 fields, and Table 1 is as follows:

[0056] Table 1

[0057]

[0058] Calculate through the control configuration plane and obtain the configuration information of all valid parameters; the configuration information is specifically the field values of different protocols in the data packet, which are the MAC source / destination address, IPv4 source / destination address, IPv4 protocol number, IPv6 source / destination address, TCP / UDP port, etc. At the same time, a field number needs to be set for each field value to be used for identification in the overall list. The control configuration plane works in the configuration state, that is, it is only responsible for receiving the configured parameters sent down and storing them, and does not include real-time running functions.

[0059] S102, select the parameters in the overall list according to the configuration of the centralized configuration plane and assign a policy number; and use the relationship between the policy number and the corresponding parameters as a policy entry; the policy entry is specifically: [policy number, list of valid parameter field numbers]; for the overall list in Table 1, set 3 configuration policy numbers and establish 3 policy entries as shown in Table 2;

[0060] Table 2

[0061] Strategy Number List of Available Parameter Field Numbers 1 1,2,4,5 2 4,7,9,10 3 2,3,8

[0062] As shown in Table 2, the policy entry with a policy number of 1 means that the field selection is numbers 1, 2, 4, 5, that is, the MAC source address, MAC destination address, IPv4 source address, and IPv4 destination address are selected as the calculation inputs. If the policy number is 3, it means that the field selection is numbers 2, 3, 8, that is, the MAC destination address, Ethernet protocol number, and IP protocol number are the calculation inputs.

[0063] S103, construct a CRC parameter list database according to all policy entries; the CRC parameter list database works in the configuration state;

[0064] S104, determine the policy number based on the time seed determined by the current time value;

[0065] S104 specifically includes:

[0066] Obtain the current time value; the current time value is determined based on the Unix global time;

[0067] According to the current time value, use a one-time password to determine the time seed for the current cycle; the time seed uses a 6-digit value and the update cycle is 30 seconds.

[0068] Determine the policy number to be executed according to the time seed for the current cycle.

[0069] According to S104, the CRC verification value configuration calculation service operates in the running state, that is, real-time calculation and status update are performed during operation. The CRC verification value configuration calculation service first maintains the time seed and establishes the periodic policy update ability according to the time information during operation. The time seed is a value calculated based on the current time value, and the policy number to be executed currently is determined through this value. Subsequently, the policy number in the CRC parameter list database is matched according to the time seed information, and the selectable parameter list in the policy entry corresponding to the policy number identical to the policy reference value is obtained. Finally, the CRC verification value calculation service generates the verification table entry execution parameters according to the parameter information in the obtained selectable parameter list and distributes them to the protocol-independent data plane. As Figure 3 shown, the CRC verification value configuration service includes: time seed maintenance, policy reference value calculation, policy number matching, and policy entry distribution.

[0070] Determine the policy reference value according to the policy number to be executed. First, obtain the number of policy entries in the CRC parameter list database. Subsequently, take the remainder of the time seed by the number of policy entries and add 1 to obtain the policy reference value to be executed in the current cycle, as shown below:

[0071] Policy reference value = time seed MOD total number of policy database rules + 1;

[0072] The obtained policy reference value is the policy number of the policy entry to be executed; according to Table 2, there are a total of 3 policy numbers, that is, the number of policy entries is 3. Assume that the time seed calculated for the current time cycle is 647155. First, take the remainder of the time seed 647155 by the total number of policy numbers 3 to obtain the remainder value 1. Subsequently, add 1 to the remainder value to obtain the policy reference value 2. That is, the policy number to be executed in the current time cycle is 2.

[0073] The main objective of policy number matching is to retrieve and match in the CRC parameter list database according to the policy reference value to obtain the list of available parameter field numbers of the policy entry corresponding to the policy number. Subsequently, the verification table entry execution parameters are encoded according to the list of available parameter field numbers. The specific encoding method is as follows:

[0074] 1) Initialize the bit string bitstring with a value of 0. The length of the bitstring is determined by the specific application of this method. The bit string bitstring is mainly used to mark the parameter fields corresponding to the policy number through bit positions. For example, for the bit string 0b0101, that is, the 2nd and 4th bit positions are 1, indicating that the parameters numbered 2 and 4 should be selected;

[0075] 2) Read the list of available parameter field numbers in the policy entry corresponding to the policy number;

[0076] 3) Traverse all parameter numbers in the list of available parameter field numbers, and set the corresponding bit positions of the bitstring in step 1) to 1 in sequence according to the parameter numbers. Specifically, in this method, the bit number of the highest bit (the leftmost) of the bitstring is 1.

[0077] 4) Obtain the updated bitstring, set it as the execution parameter of the verification table entry, and output it to the policy table entry for distribution.

[0078] For example, for the overall list in Table 1, if the length of the bitstring is set to 10 bits, the initial bitstring is 0b0000000000. Suppose the current policy entry is 2, and according to Table 2, the list of available parameter field numbers corresponding to policy number 2 is [4, 7, 9, 10]. Then set the 4th, 7th, 9th, and 10th bit positions of the initialized 10-bit all-zero bitstring to 1, obtaining the binary code 0b0001001011, and output the binary code (0b0001001011) of this updated bitstring to the step of policy table entry distribution.

[0079] Policy table entry distribution: Receive the execution parameter of the verification table entry that matches the policy number, and distribute this parameter to the protocol-independent processing plane. The parameters in the distributed table entry only include the execution parameter of the verification table entry, and the specific table entry format is explained in the protocol-independent processing.

[0080] S105, Determine the corresponding policy entry and corresponding parameters in the CRC parameter list database according to the policy number, and further determine the execution parameter of the verification table entry;

[0081] S106, Determine the CRC input field according to the execution parameter of the verification table entry, and perform protocol-independent processing.

[0082] Specifically, the protocol-independent processing includes: encapsulation mode and verification mode.

[0083] Among them, the encapsulation mode specifically includes:

[0084] Extract the field parameters corresponding to the execution parameter of the verification table entry from the label instruction data packet;

[0085] Use the extracted field parameters as the CRC input field and perform CRC16 calculation;

[0086] Insert the calculated result value into a specific position of the label instruction and use it as the CRC verification value.

[0087] The verification mode specifically includes:

[0088] Parse and extract the CRC verification value;

[0089] Calculate the execution parameters of the verification table entry sent in real time according to the parsed and extracted results;

[0090] Extract the real-time field parameters from the label instruction data packet according to the execution parameters of the verification table entry sent in real time;

[0091] Perform CRC16 calculation according to the real-time field parameters to obtain the real-time calculation result value;

[0092] Compare the real-time calculation result value with the CRC verification value, and judge whether the label instruction is credible according to the comparison result.

[0093] As Figure 4 shown, establish the CRC-based label instruction verification ability in the protocol-independent control plane. The protocol-independent processing functionally includes three parts: dynamic CRC matching table entry, multi-field CRC calculation, and verification operation determination;

[0094] The CRC matching table entry is the execution parameter of the verification table entry output by the configured calculation service according to the CRC verification value. Instantiate the CRC matching table entry to actually complete functions such as the calculation of the CRC verification value, the encapsulation of the CRC verification value in the label instruction, and the verification of the CRC verification value in the label instruction.

[0095] Functionally, the CRC matching table entry is divided into two types: CRC verification value encapsulation table entry and CRC verification value check table entry;

[0096] The main function of the CRC verification value encapsulation table entry is to insert the CRC verification value calculated according to the execution parameters of the verification table entry into the data packet according to the value of the currently active label instruction during the forwarding process of the label instruction. The basic form of the CRC verification value encapsulation table entry is shown in Table 3:

[0097] Table 3

[0098]

[0099]

[0100] The main function of the CRC verification value check table entry is to read the explicitly encapsulated CRC verification value (referred to as the instruction CRC verification value) in the data packet, compare it with the CRC verification value calculated by the node, and decide to perform a forwarding operation or a discard operation based on the comparison result to verify the credibility of the label instruction. The basic form of the CRC verification value check table entry is shown in Table 4:

[0101] Table 4

[0102]

[0103] The main function of the multi - field CRC calculation is to select the indicated field as the calculation input for the CRC verification value according to the parameter indication in the verification entry execution parameter, and obtain the CRC verification value result for encapsulation or verification.

[0104] Specifically, the multi - field CRC calculation is performed using CRC16. The binary encoding of the verification entry execution parameter is used as the input, and a mask is set to perform a logical AND operation with the specified calculation in the overall list to implement the screening of the fields specified in the policy entry, and the CRC16 calculation is performed based on the screened fields. Particularly, if the field set in the binary encoding of the verification entry execution parameter does not exist in the data packet (for example, the set protocol is not included), this field is set to 0 in the calculation.

[0105] The steps of the multi - field CRC calculation are as follows:

[0106] Step 1. Sequentially read the bit positions of the binary encoding of the verification entry execution parameter to obtain the bit number of this bit position;

[0107] Step 2. Set the mask value. If the currently read bit number is 1, the binary encoding of the mask value is all 1; if the currently read bit number is 0, the binary encoding of the mask value is all 0;

[0108] Step 3. Use the bit number in Step 1 as the available parameter field number, read the corresponding available parameter field type in the overall list, and read the value of this available parameter field in the data packet;

[0109] Step 4. Perform a logical AND operation on the value of the available parameter field read in Step 3 and the mask value in Step 2, and the result obtained is the CRC verification input calculation value;

[0110] Step 5. Loop through Steps 1 - 4 until all bits in the verification entry execution parameter in Step 1 are read;

[0111] Step 6. Input all the obtained CRC verification input calculation values into the CRC16 calculation to obtain the CRC verification value;

[0112] According to the differences in the table entry information that triggers the multi - field CRC calculation, the calculated CRC verification value can be of two types: the encapsulation CRC verification value and the table entry CRC verification value.

[0113] Taking Table 1 as an example of the overall column representation, the current policy rule is Policy Number 2 in Table 2 (i.e., the binary encoding of the verification entry execution parameter is 0b0001001011) as an example for illustration. Assume that the MAC source and destination addresses of the received data packet are 01:02:03:04:05:06 and 11:22:33:33:22:11, the IP source and destination addresses of the original data packet or the encapsulated data packet with the label instruction are 10.0.0.1 and 10.0.1.0, the TCP protocol source port is 2001, and the destination port is 11451. Then the corresponding CRC calculation rule is shown in Table 5:

[0114] Table 5

[0115]

[0116] According to the setting, the CRC verification value of the current cycle will be calculated using the IPv4 source address, source port, and destination port;

[0117] In the protocol-independent program, the CRC verification value encapsulation entry is preferentially matched. If the CRC verification value encapsulation entry is hit, the calculated CRC verification value will be used as the encapsulated CRC verification value, and the encapsulation operation will be executed; if the CRC verification value encapsulation entry is not hit, the CRC verification value check entry will be matched.

[0118] If the CRC verification value check entry is hit, the trigger operation after hitting will be executed; if not hit, the label instruction will be directly read and the instruction will be executed.

[0119] This application can be applied to label instructions (such as SRv6, SR MPLS, IOAM, etc.), and the method of triggering the operation of this application is defined based on protocol-independent programmability. The following is an example description through the application in the SRv6 label:

[0120] For the carrying of the CRC verification value, the SRv6 programmability is used to define the FUNCT and ARGS fields to carry the verification value inside the SRv6 label. The common programmable format of SRv6 is shown in Table 6:

[0121] Table 6

[0122] LOC FUNCT ARGS

[0123] In Table 6, LOC represents the routable prefix of SRv6, which is the label instruction part indicating routing and forwarding. FUNCT is used for function extension, indicating the type of function carried; ARGS indicates the parameters of the function.

[0124] For the carrying of the CRC verification value, it is achieved by defining a new FUNCT type and carrying it through ARGS. That is, during the SRv6 processing, a new FUNCT type is defined. For example:

[0125] Define FUNCT to be 32 bits in length and the value of 28 is verified using this solution.

[0126] Define ARGS to be 16 bits in length as the carrying position of the CRC verification value.

[0127] Figure 5 The deployment schematic diagram in the SRv6 network is as follows. Figure 5 As shown, the same CRC check architecture is deployed at both the encapsulation node and the verification node (only shown at the encapsulation node). When the service database enters the SRv6 domain, the encapsulation node encapsulates the SRv6 list and triggers the CRC verification value encapsulation operation.

[0128] First, the time seed is updated and calculated every 30s. Then, according to the policy reference value calculated from the time seed, the set policy number is matched and selected, and the verification table entry execution parameters are encoded.

[0129] In the encapsulation node (i.e., the SRv6 encapsulation node), the matching item rule of the CRC verification value encapsulation table entry will be set to be able to match and hit. According to the rule calculated by configuring the CRC verification value calculation service, the CRC verification value is calculated and used as the encapsulated CRC verification value, and the preset FUNCT and the periodically calculated CRC verification value are encapsulated into the SRv6 SID.

[0130] In the verification node (i.e., the SRv6 transmission node), the matching item rule of the CRC verification value check table entry will be set to be able to match and hit. After the data packet arrives at the transmission node, the verification node reads the CRC verification value in the SID as the instruction CRC verification value, and compares it with the table entry CRC verification value generated by itself to decide whether to receive the SID instruction. If they are the same, it is received; if different, it is discarded.

[0131] Since the time seeds of different nodes are roughly synchronized, and the error of time synchronization and the typical value of the network transmission time are both much smaller than the set value of the period (default 30s), the periodic synchronous update of the time seeds of different nodes can ensure the consistency of the CRC verification values among multiple nodes.

[0132] The CRC verification calculation method based on random multi-fields proposed in this application introduces multiple random and cross-layer network protocol fields as the overall list. CRC-based verification can adapt to the complexity requirements of the data plane, which belongs to the type of calculation that the network data plane is good at, and can ensure the processing performance and processing delay of data packets. Introducing CRC into the trusted verification of label instructions, since CRC is a data type that the network processing chip is good at, it can adapt to the compatibility requirements of the calculation method of the network processing chip; through the selectable CRC parameter calculation list, it brings stronger privacy to the calculation of CRC values and increases the difficulty of collision and reverse cracking. The mechanism for synchronizing the CRC verification value calculation lists of multiple nodes based on the time seed can establish the synchronization of CRC verification rule updates for multiple nodes in the case of weak time synchronization without mutual interaction synchronization, further improving the security and credibility of verification.

[0133] Based on the same inventive concept, the embodiment of this application also provides a label instruction verification device for implementing the above-mentioned label instruction verification method. The implementation solutions provided by this device to solve problems are similar to the implementation solutions described in the above method. Therefore, the specific limitations in one or more embodiments of the label instruction verification device provided below can refer to the limitations on the label instruction verification method in the above text, and will not be repeated here.

[0134] In an exemplary embodiment, a label instruction verification device is provided, including:

[0135] An overall list construction module, configured to construct an overall list according to the configuration information of all valid parameters obtained;

[0136] A policy item determination module, configured to select parameters in the overall list according to the configuration of the centralized configuration plane, and assign a policy number; and use the relationship between the policy number and the corresponding parameters as a policy item;

[0137] A CRC parameter list database determination module, configured to construct a CRC parameter list database according to all policy items;

[0138] A policy number determination module, configured to determine a policy number based on the time seed determined by the current time value;

[0139] A verification table entry execution parameter determination module, configured to determine the corresponding policy item and corresponding parameters in the CRC parameter list database according to the policy number, and further determine the verification table entry execution parameters;

[0140] A protocol-independent processing module, configured to determine the CRC input field according to the verification table entry execution parameters and perform protocol-independent processing.

[0141] In an exemplary embodiment, a computer device is provided. The computer device can be a server or a terminal. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O), and a communication interface. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it implements a method for verifying label instructions.

[0142] In an exemplary embodiment, a computer-readable storage medium is provided, storing a computer program, which implements the steps in the above method embodiments when executed by a processor.

[0143] In an exemplary embodiment, a computer program product is provided, including a computer program, which implements the steps in the above method embodiments when executed by a processor.

[0144] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant regulations.

[0145] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memory can include Read-Only Memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc.

[0146] The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processors, graphics processors, digital signal processors, programmable logic devices, data processing logics based on quantum computing, etc., without limitation.

[0147] In the present application, all actions of obtaining signals, information, or data are carried out on the premise of complying with the corresponding data protection regulations and policies of the country where the location is located and obtaining authorization from the owner of the corresponding device.

[0148] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered to be within the scope described in this specification.

[0149] In this text, specific examples are used to illustrate the principle and implementation manner of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application; at the same time, for those of ordinary skill in the art, according to the idea of the present application, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present application.

Claims

1. A method for verifying label instructions, characterized in that, The described label instruction verification method includes: Constructing an overall list according to the configuration information of all valid parameters obtained; Selecting the parameters in the overall list according to the configuration of the centralized configuration plane, and assigning a policy number; and taking the relationship between the policy number and the corresponding parameters as a policy entry; Constructing a CRC parameter list database according to all the policy entries; Determining the policy number based on the time seed determined by the current time value; Determining the corresponding policy entry and corresponding parameters in the CRC parameter list database according to the policy number, and further determining the verification table item execution parameters; Determining the CRC input field according to the verification table item execution parameters and performing protocol-independent processing; The determining the policy number based on the time seed determined by the current time value specifically includes: Obtaining the current time value; the current time value is determined based on Unix global time; According to the current time value, using the time-based one-time password algorithm to determine the time seed of the current cycle; Determining the policy number to be executed according to the time seed of the current cycle; The protocol-independent processing includes: encapsulation mode and verification mode; The encapsulation mode specifically includes: Extracting the field parameters corresponding to the verification table item execution parameters from the label instruction data packet; Taking the extracted field parameters as the CRC input field and performing CRC16 calculation; Inserting the calculated result value into a specific position of the label instruction after encapsulation and using it as the CRC verification value; The verification mode specifically includes: Parsing and extracting the CRC verification value; Calculating the verification table item execution parameters sent in real time according to the parsing and extraction result; Extracting the real-time field parameters from the label instruction data packet according to the verification table item execution parameters sent in real time; Performing CRC16 calculation according to the real-time field parameters to obtain the real-time calculation result value; Comparing the real-time calculation result value with the CRC verification value, and judging whether the label instruction is credible according to the comparison result.

2. The label instruction verification method according to claim 1, wherein The time seed uses a 6-digit numerical value, and the update period is 30 seconds.

3. A label instruction verification device for implementing the label instruction verification method according to any one of claims 1-2, characterized in that, The described label instruction verification device includes: An overall list construction module for constructing an overall list according to the configuration information of all valid parameters obtained; A policy entry determination module for selecting the parameters in the overall list according to the configuration of the centralized configuration plane, and assigning a policy number; and taking the relationship between the policy number and the corresponding parameters as a policy entry; A CRC parameter list database determination module for constructing a CRC parameter list database according to all the policy entries; A policy number determination module for determining the policy number based on the time seed determined by the current time value; A verification table item execution parameter determination module for determining the corresponding policy entry and corresponding parameters in the CRC parameter list database according to the policy number, and further determining the verification table item execution parameters; A protocol-independent processing module for determining the CRC input field according to the verification table item execution parameters and performing protocol-independent processing.

4. A computer device, comprising: A memory, a processor, and a computer program stored on the memory and executable on the processor, wherein the processor executes the computer program to implement the label instruction verification method according to any one of claims 1-2.

5. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the label instruction verification method described in any one of claims 1-2.

6. A computer program product comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the label instruction verification method described in any one of claims 1-2.

Citation Information

Patent Citations

  • Configuration message verification method and device and computer storage medium

    CN112448915A

  • Message falling table verification method and device, computer equipment and readable storage medium

    CN114398276A