Trusted path establishment systems, methods, apparatuses, devices, and storage media

By constructing a trusted path topology through network orchestrators, link management platforms, and device verification network elements, the problem of data leakage caused by the single trusted state of network devices in existing technologies is solved, thereby improving the security and reliability of the network system.

CN119583385BActive Publication Date: 2026-05-05CHINA UNITED NETWORK COMM GRP CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA UNITED NETWORK COMM GRP CO LTD
Filing Date
2024-11-27
Publication Date
2026-05-05

AI Technical Summary

Technical Problem

In existing technologies, network orchestrators mainly perform path orchestration based on the trusted state of network devices. The orchestration method is relatively simple, which leads to data leakage problems and cannot effectively guarantee the security of data transmission between network devices.

Method used

A trusted path topology is constructed by using a network orchestrator, a link management platform, and device verification network elements. By obtaining the trusted status of links and devices, a mapping relationship between network devices and network links is established, thereby improving the security and reliability of the network system.

Benefits of technology

It effectively avoids the security risks of malicious tampering and data theft of the network system, improves the reliability of trusted paths in trusted path topology, and ensures the security of network devices and links.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119583385B_ABST
    Figure CN119583385B_ABST
Patent Text Reader

Abstract

This application provides a trusted path establishment system, method, apparatus, device, and storage medium, relating to the field of computer technology. It effectively improves the reliability of trusted paths and ensures the security and privacy of data within the trusted paths. The system includes a network orchestrator, a device verification network element connected to the network orchestrator, and a link management platform. The link management platform is used to obtain the trusted status of the corresponding network links and send the trusted status to the network orchestrator; the trusted status describes the reliability of the network links. The device verification network element is used to obtain the trusted status of the corresponding network devices and send the trusted status to the network orchestrator; the trusted status describes the reliability of the network devices. The network orchestrator receives the trusted status of the links and the trusted status of the devices; based on the trusted status of the links and the trusted status of the devices, it obtains a trusted path topology, which includes at least one trusted path.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular to a trusted path establishment system, method, apparatus, device and storage medium, which can effectively improve the reliability of trusted paths. Background Technology

[0002] Software-defined networking (SDN) is a network architecture that separates the control plane from the data plane, simplifying network management and enabling efficient utilization and dynamic adjustment of network resources.

[0003] As specific business requirements for data privacy and security continue to increase, the demands on the security and reliability of SDN architecture are also rising. In related technologies, the network orchestrator generates a trusted path orchestration policy based on trusted path requirements and the trusted state of network devices, and then the SDN controller establishes trusted paths based on the trusted path orchestration policy.

[0004] However, network orchestrators in related technologies mainly perform path orchestration based on the trusted state of network devices, resulting in a relatively simple orchestration method and the potential for data leakage. Summary of the Invention

[0005] This application provides a trusted path establishment system, method, apparatus, device, and storage medium, which effectively improves data security and privacy.

[0006] To achieve the above objectives, this application adopts the following technical solution:

[0007] In a first aspect, this application provides a trusted path establishment system, which includes: a network orchestrator, a device verification network element connected to the network orchestrator, and a link management platform.

[0008] The link management platform is used to obtain the link trust status corresponding to the network link and send the link trust status to the network orchestrator.

[0009] The device verification network element is used to obtain the trusted status of the network device and send the trusted status of the device to the network orchestrator.

[0010] The network orchestrator receives link trust status and device trust status; based on the link trust status and device trust status, it obtains the trusted path topology.

[0011] Among them, the link trust status is used to describe the reliability of the network link, the device trust status is used to describe the reliability of the network device, and the trusted path topology includes at least one trusted path.

[0012] The solution provided in this application constructs a trusted path topology using the trusted link status obtained from the link management platform and the trusted device status obtained from the device verification network element during trusted path orchestration. This ensures the security of both network devices and network links, improves the reliability of trusted paths in the trusted path topology, and effectively avoids the security risks of malicious tampering and data theft of the network system.

[0013] One possible implementation involves a link management platform that also receives link status information corresponding to network links. It then performs link reliability analysis on this information to obtain the link reliability status. Link reliability analysis refers to assessing the reliability of network links based on link status information. The link reliability status is obtained by analyzing the link status information, which includes various aspects such as bandwidth, latency, and packet loss rate. This enables a comprehensive assessment of network link reliability and provides a more accurate evaluation of the link reliability status.

[0014] Another possible implementation involves the link management platform also used to: send link status query requests to link monitoring devices; and receive link status information reported by the link monitoring devices based on these requests. By sending link status query requests to link monitoring devices, the real-time status of network links can be obtained promptly, thereby providing a quick understanding of network operation.

[0015] Another possible implementation involves a link management platform that also receives link status information proactively reported by link monitoring devices after triggering link status reporting conditions. This proactive reporting of link status information by link monitoring devices makes the reporting and updating of link status information more timely and efficient.

[0016] Another possible implementation involves link status reporting conditions including at least one of the following: a change in network link status or periodic reporting of link status information. Multiple link reporting conditions allow for flexible adjustments to link status information reporting based on different situations and needs, adapting to reporting requirements in various scenarios. Furthermore, multiple reporting conditions can improve the efficiency and reliability of information reporting, preventing information loss or omission.

[0017] Another possible implementation involves the device verification network element, which is also used to: receive device status information corresponding to the network device; perform device trustworthiness analysis on the device status information to obtain the device's trustworthiness status. Device trustworthiness analysis refers to evaluating the reliability of network devices based on device status information. The device trustworthiness status is obtained by analyzing the device status information, which includes information on multiple aspects of the network device such as device performance, reliability, and security, achieving a comprehensive assessment of the network device's trustworthiness and making the assessment of the device's trustworthiness status more accurate.

[0018] Another possible implementation is that the device verification network element is also used to: send device status query requests to network devices; and receive device status information reported by network devices based on the device status query requests. By actively querying the device status information of network devices, the device verification network element can obtain the real-time status of network devices in a timely manner, thereby quickly understanding the network operation status.

[0019] Another possible implementation is that the device verification network element is also used to receive device status information proactively reported by network devices after triggering the device status reporting condition. The proactive reporting of device status information by the device verification network element makes the reporting or updating of device status information more timely and efficient.

[0020] Another possible implementation involves device status reporting conditions including at least one of the following: a change in network device status, or periodic reporting of device status information. Multiple reporting conditions allow for flexible adjustments to device status information reporting based on different situations and needs, adapting to reporting requirements in various scenarios. Furthermore, multiple reporting conditions can improve the efficiency and reliability of information reporting, preventing the loss or omission of reported information.

[0021] Another possible implementation, the network orchestrator, is also used to: establish a mapping relationship between network devices and network links based on the trusted state of links and devices, thereby obtaining a trusted path topology. The trusted path topology intuitively displays the connection relationship between network devices and network links, enabling convenient network management and trusted path optimization selection, and allowing direct selection of the required trusted path from the trusted path topology.

[0022] Another possible implementation, the network orchestrator, is also used to: associate and map the device identifiers corresponding to network devices with the link identifiers corresponding to network links to obtain a trusted path topology. By associating and mapping device identifiers with link identifiers, the relationship between each trusted network device and trusted network link in the network can be clearly understood, enabling precise location of network devices and network links and simplifying the management of the trusted path topology.

[0023] Secondly, a trusted path establishment method is provided, which is applied to a network orchestrator. This method includes:

[0024] Obtain the link trust status corresponding to the network link and the device trust status corresponding to the network device. Based on the link trust status and device trust status, obtain the trusted path topology. The link trust status describes the reliability of the network link, and the device trust status describes the reliability of the network device. The trusted path topology includes at least one trusted path.

[0025] The trusted path establishment method provided in this application uses a network orchestrator to acquire the trusted state of links and the trusted state of devices to construct a trusted path topology, thereby ensuring the security of network devices and network links simultaneously, improving the reliability of trusted paths in the trusted path topology, and effectively avoiding the security risks of malicious tampering and data theft of the network system.

[0026] One possible implementation is that the link trust status is obtained by the link management platform after performing link trustworthiness analysis on the link status information. Link status information includes multiple aspects such as network link bandwidth, latency, and packet loss rate. By analyzing the trustworthiness of the link status information, a comprehensive assessment of network link reliability is achieved, resulting in a more accurate assessment of the link trust status.

[0027] Another possible implementation is that the device trust status is obtained by the device verification network element after performing device trustworthiness analysis on the device status information. The device status information includes multiple aspects such as the network device's performance, reliability, and security. By analyzing the trustworthiness of the device status information, a comprehensive assessment of the network device's trustworthiness is achieved, making the assessment of the device trustworthiness more accurate.

[0028] Another possible implementation involves obtaining a trusted path topology based on the trusted state of links and devices. Specifically, this can be achieved by establishing a mapping relationship between network devices and network links based on the trusted state of links and devices, thus obtaining the trusted path topology. The trusted path topology visually displays the connection relationships between network devices and network links, enabling convenient network management and trusted path optimization selection. Users can directly select the desired trusted path from the trusted path topology.

[0029] Another possible implementation involves establishing a mapping relationship between network devices and network links to obtain a trusted path topology. Specifically, this can be achieved by associating the device identifier of a network device with the link identifier of a network link. By associating device identifiers with link identifiers, the relationship between each trusted network device and trusted network link in the network can be clearly understood, enabling precise location of network devices and links and simplifying the management of the trusted path topology.

[0030] Thirdly, a trusted path establishment method is provided, which is applied to a link management platform. This method includes:

[0031] Obtain the link trust status corresponding to the network link. Send the link trust status to the network orchestrator. The link trust status is used to describe the reliability of the network link and also to construct the trusted path topology; the trusted path topology includes at least one trusted path.

[0032] The trusted path establishment method provided in this application allows the link management platform to send the acquired link trusted status to the network orchestrator, enabling the network orchestrator to construct a trusted path topology based on the link trusted status, thereby ensuring the security of network links and improving the reliability of trusted paths in the trusted path topology, effectively avoiding the security risks of malicious tampering and data theft of the network system.

[0033] One possible implementation for obtaining the link trust status of a network link can be as follows: Receiving link state information corresponding to the network link; performing link trustworthiness analysis on the link state information to obtain the link trustworthiness status. Link trustworthiness analysis refers to evaluating the reliability of the network link based on the link state information. Link state information includes multiple aspects such as bandwidth, latency, and packet loss rate. By performing trustworthiness analysis on the link state information, a comprehensive assessment of the network link's reliability is achieved, resulting in a more accurate assessment of the link trustworthiness status.

[0034] Another possible implementation involves receiving link status information corresponding to network links. Specifically, this can be achieved by sending a link status query request to the link monitoring device and receiving the link status information reported by the link monitoring device based on the query request. By sending a link status query request to the link monitoring device, the real-time status of network links can be obtained promptly, thereby quickly understanding the network's operational status.

[0035] Another possible implementation involves receiving link status information corresponding to the network link. Specifically, this can be achieved by receiving link status information proactively reported by the link monitoring device after triggering the link status reporting condition. This proactive reporting of link status information by the link monitoring device results in more timely and efficient reporting and updating of the link status information.

[0036] Another possible implementation is that the link status reporting conditions include at least one of the following: a change in network link status or periodic reporting. Multiple link reporting conditions allow for flexible adjustments to link status information reporting based on different situations and needs, adapting to reporting requirements in various scenarios. Furthermore, multiple reporting conditions can improve the efficiency and reliability of information reporting, preventing the loss or omission of reported information.

[0037] Fourthly, a trusted path establishment apparatus is provided, the apparatus comprising: an acquisition module and a construction module.

[0038] The acquisition module is used to acquire the link trust status corresponding to the network link and the device trust status corresponding to the network device.

[0039] The module is used to obtain the trusted path topology based on the trusted state of the links and the trusted state of the devices.

[0040] Among them, the link trust status is used to describe the reliability of the network link, the device trust status is used to describe the reliability of the network device, and the trusted path topology includes at least one trusted path.

[0041] One possible implementation is that the link trust status is obtained by the link management platform after performing link trust analysis on the link status information.

[0042] Another possible implementation is that the device trust status is obtained by the device verification network element after performing device trust analysis on the device status information.

[0043] In another possible implementation, the aforementioned building module is also used to: establish a mapping relationship between network devices and network links based on the link trust status and device trust status, thereby obtaining a trusted path topology.

[0044] In another possible implementation, the aforementioned building module is also used to: associate and map the device identifier corresponding to the network device and the link identifier corresponding to the network link to obtain a trusted path topology.

[0045] The technical effects of any implementation method in the fourth aspect can be found in the technical effects of any implementation method in the second aspect above, and will not be repeated here.

[0046] Fifthly, a trusted path establishment device is provided, the device comprising: an acquisition module and a sending module.

[0047] Acquisition module: Used to obtain the trusted status of the network link.

[0048] Sending module: Used to send link trust status to the network orchestrator.

[0049] The link trust status is used to describe the reliability of network links and to construct a trusted path topology; the trusted path topology includes at least one trusted path.

[0050] In one possible implementation, the acquisition module is further configured to: receive link status information corresponding to the network link; perform link reliability analysis on the link status information to obtain the link reliability status, wherein link reliability analysis refers to evaluating the reliability of the network link based on the link status information.

[0051] In another possible implementation, the acquisition module is also used to: send a link status query request to the link monitoring device, and construct the link status information reported by the link monitoring device based on the link status query request.

[0052] In another possible implementation, the above-mentioned acquisition module is also used to: receive link status information actively reported by the link monitoring device after triggering the link status reporting condition.

[0053] Another possible implementation is that the link status reporting conditions include at least one of the following: a change in network link status or periodic reporting.

[0054] The technical effects of any implementation method in the fifth aspect can be found in the technical effects of any implementation method in the third aspect above, and will not be repeated here.

[0055] In a sixth aspect, a computer device is provided, comprising: a processor and a memory, wherein the memory stores at least one computer program, and the at least one computer program is loaded and executed by the processor to implement the trusted path establishment method described above.

[0056] In a seventh aspect, a computer-readable storage medium is provided, wherein at least one computer program is stored in the computer-readable storage medium, and the at least one computer program is loaded and executed by a processor to implement the trusted path establishment method of the above aspect.

[0057] Eighthly, a computer program product is provided, comprising a computer program or instructions, which, when executed by a processor, implements the trusted path establishment method described above.

[0058] Ninthly, embodiments of this application provide a chip system including at least one processor and at least one interface circuit. The at least one interface circuit is used to perform transceiver functions and send instructions to the at least one processor. When the at least one processor executes the instructions, the at least one processor performs the trusted path establishment method as described above.

[0059] The solutions provided in aspects six through nine above are used to implement the methods provided in aspects two and three above, and their specific implementations will not be described in detail here. The technical effects corresponding to any implementation method of the solutions provided in aspects six through nine above can be found in the technical effects corresponding to any implementation method of aspects two and three above, and will not be described in detail here.

[0060] It should be noted that any of the possible implementations of any of the above aspects can be combined, provided that the solutions do not contradict each other. Attached Figure Description

[0061] Figure 1 A schematic diagram of an SDN architecture is provided as an exemplary embodiment;

[0062] Figure 2 A schematic diagram of a TPCM framework structure is provided for an exemplary embodiment;

[0063] Figure 3A schematic diagram of the structure of a computer system provided as an exemplary embodiment;

[0064] Figure 4 A schematic diagram of a trusted path establishment system provided as an exemplary embodiment;

[0065] Figure 5 An example diagram of a trusted path topology is provided for an exemplary embodiment;

[0066] Figure 6 A flowchart illustrating a trusted path establishment method provided for an exemplary embodiment;

[0067] Figure 7 A flowchart illustrating a trusted path establishment method provided for an exemplary embodiment;

[0068] Figure 8 A schematic diagram of the structure of a link management platform provided as an exemplary embodiment;

[0069] Figure 9 A flowchart illustrating a trusted path establishment method provided for an exemplary embodiment;

[0070] Figure 10 A flowchart illustrating a trusted path establishment method provided for an exemplary embodiment;

[0071] Figure 11 A schematic diagram of a trusted path establishment system provided as an exemplary embodiment;

[0072] Figure 12 A schematic diagram of a trusted path establishment apparatus provided for an exemplary embodiment;

[0073] Figure 13 A schematic diagram of a trusted path establishment apparatus provided for an exemplary embodiment;

[0074] Figure 14 A schematic diagram of the structure of a computer device provided for an exemplary embodiment. Detailed Implementation

[0075] In the embodiments of this application, in order to clearly describe the technical solutions of the embodiments of this application, the terms "first" and "second" are used to distinguish identical or similar items with essentially the same function and effect. Those skilled in the art will understand that the terms "first" and "second" do not limit the quantity or execution order, and the terms "first" and "second" are not necessarily different. The technical features described by "first" and "second" have no sequential or size order.

[0076] In the embodiments of this application, the words "exemplarily" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design described as "exemplarily" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design solutions. Specifically, the use of the words "exemplarily" or "for example" is intended to present the relevant concepts in a specific manner to facilitate understanding.

[0077] In the embodiments of this application, at least one can also be described as one or more, and multiple can be two, three, four or more, and this application does not impose any restrictions.

[0078] Furthermore, the network architecture and scenarios described in the embodiments of this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided in the embodiments of this application. As those skilled in the art will know, with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.

[0079] To facilitate understanding, the terms used in the embodiments of this application will be explained first.

[0080] SDN architecture: A network architecture whose core idea is to separate network control functions from network devices (such as switches and routers) and centralize them in an independent control plane. This allows network devices to simply forward data according to the controller's instructions, while complex routing decisions and policy configurations are handled centrally by the controller. Specifically, for example... Figure 1 The diagram illustrates the structure of an SDN architecture, which can be divided into three layers. The top layer is the service layer, encompassing various business applications. The middle control layer primarily includes software-defined network controllers, responsible for providing network services such as data plane resource orchestration, network topology, and state information maintenance. The bottom forwarding layer comprises several network devices responsible for data processing, forwarding, and state collection. This architecture transfers network control functions from network devices to external computing devices (controllers), allowing network administrators to more easily configure, manage, and monitor the network, thereby achieving more granular network resource allocation and traffic management. Network devices generate forwarding tables by receiving control signaling from the control layer and process traffic data according to these tables, eliminating the need for complex distributed network protocols for data forwarding.

[0081] Trusted computing is a computer security technology that combines cryptographic operations with protection, aiming to ensure that every step of the computing process is detectable and monitorable. The principle of trusted computing is to improve the security of computer systems by introducing Trusted Platform Module (TPM), Trusted Platform Control Module (TPCM), and Trusted Cryptography Module (TCM) into the hardware platform. Trusted computing employs a whitelist mechanism, allowing only certified kernels, kernel modules, and applications to run on the system; uncertified components are not allowed to run, thereby enhancing system security.

[0082] TPM (Trusted Product Manager) is a security chip or module integrated into a computer motherboard to provide essential security-related functions. For example, encryption keys generated by the TPM can encrypt sensitive data, ensuring its security during transmission and storage. Specifically, the TPM communicates with the rest of the system via a hardware bus. Devices containing the TPM can create and encrypt encryption keys so that these keys can only be decrypted by the TPM. This process, often called "wrapping" or "binding" keys, prevents key leakage. Each TPM has a master wrapping key, called the storage root key, which is stored within the TPM itself. The private portion of the storage root key, or authentication key, is never exposed to any other component, software, process, or user. The TPM provides platform integrity measurement and remote authentication capabilities, evaluating the integrity of the platform's startup and runtime processes and the integrity of its running code, as well as externally verifying the trustworthiness of the TPM platform itself. The TPM can also acquire the trusted characteristics of the hardware and software of the device platform it resides on, recording the execution integrity status of all hardware and software modules, thus constructing a trust chain for the trusted computing platform. When any hardware or software module is maliciously infected, the value of the trust chain changes.

[0083] TPCM: A core hardware control module integrated into a trusted computing platform, used to establish and secure trusted sources. It provides trusted platform control, integrity measurement, secure storage, trusted reporting, and cryptographic services. Figure 2The diagram shows the framework structure of TPCM. TPCM mainly includes modules such as basic software, basic hardware, and functional services. Specifically, it interacts with computing components through the computing component interface, with the Trusted Cryptographic Module (TCM) through the Trusted Cryptographic Module interface, and with the Trusted Software Base and Trusted Platform Control Module through functional interfaces. TCM is a Trusted Cryptographic Module that uses the Commercial Cryptography (SM) series of national cryptographic algorithms, providing trusted roots and cryptographic operation functions. Similar to TPM, TPCM and TCM also have integrity measurement and remote proof functions.

[0084] A network link is a passive, point-to-point physical connection used to transmit data between devices. In wired communication, a link refers to the physical line between two nodes, such as a cable or optical fiber; in radio communication, a link refers to the path space through which electromagnetic waves propagate between a base station and a terminal, or the path space in underwater acoustic communication.

[0085] Trusted path: A trusted path is a communication path established and maintained between a security function and a user to protect communication data from modification and leakage, enabling trusted communication between the user and the database management system or other security functions. Establishing a trusted path typically involves selecting and arranging verified, secure communication paths within the network, aiming to improve the security and reliability of network communication and protect the transmission of sensitive information and services.

[0086] It should be noted that all information (including but not limited to device information, personal information of the target, etc.), data (including but not limited to data used for analysis, stored data, displayed data, etc.) and signals involved in this application have been authorized by the target or fully authorized by all parties, and the collection, use and processing of related data must comply with relevant laws, regulations and standards. For example, the link trust status, link status information, device trust status and device status information involved in this application were all obtained with full authorization.

[0087] For example, the industry-standard trusted path establishment method is often based on the trusted path requirement information and the trusted status of the network device, which will be briefly explained below.

[0088] The network orchestrator obtains the trusted status of network devices from the device verification network element and the trusted path requirement information, such as source address information and destination address information, from the business system. Based on the trusted status of the network devices and the trusted path requirement information, it generates an orchestration strategy for the trusted path, enabling controllers and other execution devices to establish trusted paths based on the orchestration strategy. This method ensures the trustworthiness of network devices in the trusted path and avoids problems such as data leakage or unauthorized access.

[0089] However, the scheme of establishing trusted paths based on the trusted status of network devices can only ensure the trustworthiness of the network devices themselves on the trusted path, and cannot solve the problem of data leakage when data is transmitted between network devices. In addition, the establishment of trusted paths also needs to be based on the requirements information (business requirements information) of trusted paths. The trusted path is established only when business requirements arise, which cannot guarantee the efficiency of the trusted path establishment process.

[0090] Based on this, this application provides a trusted path establishment system. The system includes a network orchestrator, a link management platform connected to the network orchestrator, and a device verification network element. When performing trusted path orchestration, the network orchestrator constructs a trusted path topology using the trusted link status obtained from the link management platform and the trusted device status obtained from the device verification network element. This ensures the security of network devices and network links simultaneously, improves the reliability of trusted paths in the trusted path topology, and effectively avoids the security risks of malicious tampering and data theft of the network system.

[0091] The solutions provided by the embodiments of this application will be described in detail below with reference to the accompanying drawings.

[0092] The solution provided in this application can be applied to Figure 3 In the computer system shown, such as Figure 3 The diagram shows the architecture of a computer system. This computer system may include a network orchestrator 300, a link management platform 301, a device authentication network element 302, and an SDN controller 303.

[0093] The link management platform 301 can be a platform for creating, managing, monitoring and configuring link connections between network devices, server devices, video devices, microwave devices and PON devices.

[0094] Specifically, the link management platform 301 can automatically discover link connections of various devices; it can create links by selecting link type, device, and port, and supports batch creation of planned links between devices; after a link is connected to the platform, the link management platform 301 also supports viewing basic link information, performing operations such as quick link search, export, deletion, and topology location; in addition, it can configure links as needed to meet specific business requirements. The link management platform 301 in this embodiment is mainly used to monitor or analyze the status and information of links, realizing the collection, updating, and maintenance of the trusted status of network links. The status and information of the links include link status, name, bandwidth, names of network elements at both ends, network element IP, network element MAC, and port IP, port management status, and port operating status at both ends, and sends the trusted status of the monitored or analyzed network links to the network orchestrator 300. The link management platform 301 can be supported by hardware such as routers, switches, and servers.

[0095] Device authentication network element 302 is a network element used to manage information related to network devices. Network devices are fundamental elements in a network system, including non-transparent forwarding network devices such as Internet Protocol (IP) devices, switches, routers, transmission network devices, and access network devices. They are responsible for data transmission, processing, and storage. Device authentication network element 302 can verify the identity and permissions of network devices, ensuring that only legitimate network devices can access the network. It can also check the performance and stability of network devices, monitor their operating status, and ensure that network devices meet network requirements.

[0096] Specifically, the device verification network element 302 remotely obtains the security status information of network devices through network communication, such as obtaining device status information from chips like TPM and TPCM. Then, it assesses or obtains the trusted status of the network device based on this information, and finally sends the trusted status to the network orchestrator 300. The device verification network element 302 can be supported by authentication servers, security routers, or other network monitoring and management devices during operation.

[0097] A network orchestrator 300 is a technical tool for managing and orchestrating network resources and services. Specifically, it coordinates and manages various devices, connections, and services in the network through automated processes and policies, achieving effective management and scheduling of network resources to meet business needs and improve the efficiency and quality of network services. In this embodiment, the network orchestrator 300 is mainly used to collect, verify, update, and maintain the trusted status of network devices, and also to establish and maintain trusted path topologies. The network orchestrator 300 can be supported by hardware such as servers, storage devices, and network interface cards.

[0098] The SDN Controller 303 is an application within SDN, used to collect network state information, make routing decisions and configure policies, send instructions to data forwarding devices (network devices), and manage and coordinate network traffic. Specifically, the SDN Controller 303 communicates and controls network devices through open and standardized interfaces. Specifically, it communicates with network devices via the Southbound Interface and with network management applications or third-party services via the Northbound Interface. The most commonly used protocol for the Southbound Interface is OpenFlow, which defines how the SDN Controller 303 controls the behavior of data forwarding devices, such as link discovery, topology management, and flow table distribution. The Northbound Interface allows network administrators or applications to programmatically control network resources, effectively scheduling and configuring resources at the underlying network level to achieve automatic and flexible network management.

[0099] The SDN controller 303 in this embodiment is mainly used to establish trusted paths based on the trusted path topology and orchestration strategy sent by the network orchestrator 300. The SDN controller can issue control commands to network devices to instruct them to forward traffic, but it does not execute the control commands itself. The SDN controller 303 can be supported by high-performance, high-reliability hardware such as servers and processors.

[0100] In some embodiments, the network orchestrator 300, link management platform 301, device authentication network element 302, and SDN controller 303 can be deployed in the same server, processor, or other hardware device, or they can be deployed in different hardware devices. The network orchestrator 300, link management platform 301, device authentication network element 302, and software-defined networking (SDN) controller 303 can all be replaced by applications or platforms with the same functions.

[0101] The network orchestrator 300, link management platform 301, device verification network element 302, and SDN controller 303 can communicate with each other via a network, such as a wired or wireless network.

[0102] Figure 3 An exemplary embodiment is shown, comprising a network orchestrator 300, a link management platform 301, a device authentication network element 302, and an SDN controller 303. Figure 3 The number and names of the various devices are not limited. This application's embodiments are for... Figure 3 The implementation methods and application scenarios of each device are not limited. Except... Figure 3 In addition to the devices shown, a computer system may also include other devices, such as network devices, business management devices, etc.

[0103] Figure 4 This is a schematic diagram of the structure of a trusted path establishment system provided in an embodiment of this application.

[0104] like Figure 4 As shown, the trusted path establishment system of this application embodiment includes: a network orchestrator 400, a link management platform 401 connected to the network orchestrator 400, and a device verification network element 402. The link management platform 401 is connected to at least one link monitoring device 403, and the device verification network element 402 is connected to at least one network device 404.

[0105] The link management platform 401 is used to obtain the link trust status corresponding to the network link and send the link trust status to the network orchestrator 400.

[0106] Link trust status describes the reliability of network links. Link trust status can be divided into different levels, reflecting the current operational status and trustworthiness of the link.

[0107] Optionally, the link trust status includes: link status good, link status normal, link status abnormal, link status fault, etc., but is not limited thereto, and the embodiments of this application do not specifically limit it.

[0108] A good link status means that the link is operating normally and the data transmission quality is good. For example, the bit error rate and packet loss rate during data transmission are low, and the bandwidth utilization is high, both exceeding the standard level.

[0109] Bit error rate (BER) refers to the proportion of erroneous bits received by the data receiver during data transmission out of the total number of transmitted bits, reflecting the accuracy of data transmission. Packet loss rate refers to the proportion of data packets lost during data transmission due to various reasons such as network congestion, hardware failure, and routing errors, reflecting the stability and reliability of the network. Broadband utilization rate, also known as bandwidth efficiency, is the ratio of the actual bandwidth used to the available bandwidth during network transmission, used to measure the efficiency of network resource utilization. Stable equipment operation data and all status quantities conforming to standards indicate that the equipment is operating efficiently and without any problems.

[0110] A normal link status means that the link is operating normally and the data transmission quality is within the standard range. For example, the bit error rate, packet loss rate and bandwidth utilization during data transmission are all within the standard range.

[0111] Link status anomalies refer to unstable link connections and data transmission quality that is significantly lower than the standard level. For example, the bit error rate, packet loss rate, and / or bandwidth utilization during data transmission are lower than the standard level. Although the link can still operate, the reliability of data transmission is low.

[0112] Link status failure refers to a link that is completely unable to function properly, resulting in a complete interruption of network communication and severely affecting the normal data transmission process, requiring timely maintenance and repair.

[0113] In some embodiments, the link management platform 401 is further configured to receive link status information corresponding to the network link, perform link trustworthiness analysis on the link status information, and obtain the link trustworthiness status.

[0114] Link status information describes the parameters and status of the link and the signals transmitted within it. For example, link status information may include signal frequency, bandwidth, attenuation, interference noise, strength, transmission error rate, signal-to-noise ratio, link transmission rate, and encoding method, but is not limited thereto, and this application does not specifically limit it.

[0115] Link reliability analysis refers to assessing the reliability of network links based on link state information.

[0116] For example, link reliability analysis is based on bit error rate, packet loss rate and bandwidth utilization to evaluate the reliability of network links. The lower the bit error rate and / or packet loss rate and the higher the bandwidth utilization, the higher the reliability of the network link.

[0117] For example, link credibility analysis can be performed in at least one of the following ways, but is not limited thereto, and the embodiments of this application do not specifically limit this.

[0118] Method 1: When the bit error rate and packet loss rate of the network link are lower than their respective standard ranges, and the bandwidth utilization is higher than the standard range corresponding to the bandwidth utilization, the network link is evaluated as being in good condition.

[0119] If either the bit error rate or packet loss rate of a network link is lower than its corresponding standard range, and the bandwidth utilization is higher than the standard range corresponding to the bandwidth utilization; or if the bit error rate and packet loss rate of a network link are lower than their respective standard ranges, then the network link is assessed as being in normal condition.

[0120] If either the bit error rate or the packet loss rate of a network link exceeds its corresponding standard range, and the bandwidth utilization is lower than the standard range corresponding to the bandwidth utilization; or if both the bit error rate and the packet loss rate exceed their respective standard ranges, then the network link is assessed as having an abnormal link status.

[0121] When the bit error rate and packet loss rate of a network link are higher than their respective standard ranges, and the bandwidth utilization is lower than the standard range corresponding to bandwidth utilization, the network link is assessed as a link state failure.

[0122] Network links with good or normal link status are considered as trusted network links, with priority given to those with good link status.

[0123] Method 2: Evaluate the bit error rate, packet loss rate, and (1-bandwidth utilization) of the network link, and see if the weighted sum is lower than the trust threshold. If it is lower than the trust threshold, then the network link is evaluated as a trustworthy network link.

[0124] The standard range and the confidence threshold are default values ​​or preset values, but are not limited to these. The embodiments of this application do not specifically limit them.

[0125] In some embodiments, the link management platform 401 is further connected to a link monitoring device 403. The link monitoring device 403 is used to monitor network links and obtain link status information.

[0126] Optionally, the link monitoring device 403 can be at least one of a link anti-eavesdropping device, an optical fiber link monitoring device, and a network link monitoring device, but is not limited thereto, and the embodiments of this application do not specifically limit it.

[0127] Network link security devices are devices that protect network communication links and prevent illegal eavesdropping and data leakage. They detect and block potential eavesdropping activities by monitoring and analyzing signals and data traffic in the network link in real time. Examples include intrusion detection systems and intrusion prevention systems.

[0128] Fiber optic link monitoring equipment is used to ensure the stable operation of communication networks connected by optical fibers. Examples include optical time domain reflectometers and optical power meters.

[0129] Network link monitoring equipment is used to ensure the stable and secure operation of network communication links. Examples include network performance testers, network analyzers, and link connectivity testers.

[0130] In some embodiments, the link monitoring device 403 can obtain link status information through active monitoring or passive monitoring.

[0131] Active monitoring detects the status of the link by sending test data packets.

[0132] For example, the connectivity status of a network link can be detected using a specific network protocol.

[0133] For example, the connectivity status of a network link can be probed using the User Datagram Protocol (UDP). Specifically, a specific string is sent to the target being monitored, and the response is checked to see if the specific string is included. If it is included, it indicates that the network link between the target and the monitored network is working properly.

[0134] Passive monitoring methods obtain link status information by listening to the communication between network devices via 404.

[0135] For example, network traffic can be captured and analyzed using traffic analysis tools to extract link state information.

[0136] For example, by using traffic analysis tools to send test data packets to the monitoring target and receive response packets, the quantity and content of the response packets can be analyzed, and the bit error rate and packet loss rate of the network link between the target and the monitoring target can be calculated.

[0137] In some embodiments, the link management platform 401 receives link status information sent by the link monitoring device 403 in at least one of the following ways, but is not limited thereto, and the embodiments of this application do not specifically limit this.

[0138] Method 1: The link management platform 401 sends a link status query request to the link monitoring device 403; and receives the link status information reported by the link monitoring device 403 based on the link status query request.

[0139] For example, the link management platform 401 sends a link status query request to all link monitoring devices 403 and receives the link status information reported by all link monitoring devices 403.

[0140] In some embodiments, the link management platform 401 sends a link status query request to the designated link monitoring device 403 based on the link identifier, and receives the link status information reported by the designated link monitoring device 403.

[0141] Among them, the link identifier is an identifier used to identify different links in communication. The link monitoring device 403 can report the link status information corresponding to the network link based on the link identifier.

[0142] For example, in a multi-protocol label switching network, the link identifier can be a multi-protocol label switching (MPLS) label.

[0143] Method 2: The link management platform 401 receives the link status information actively reported by the link monitoring device 403 after the link status reporting conditions are triggered.

[0144] The link status reporting conditions include at least one of the following: a change in network link status or periodic reporting of link status information.

[0145] A change in network link status refers to a change in link status information or a change in the link's trusted status.

[0146] For example, the link monitoring device 403 analyzes whether the link status information has changed. For example, if the bit error rate of the network link changes from above the standard range to below the standard range, the link monitoring device 403 reports the bit error rate of the network link after the change to the link management platform 401.

[0147] Periodic reporting of link status information refers to automatically or manually reporting link status information according to a predetermined time period.

[0148] For example, the link monitoring device 403 actively reports link status information at certain time intervals. For instance, the link monitoring device 403 reports link status information once per hour.

[0149] In some embodiments, the link monitoring device 403 can also directly perform link trustworthiness analysis based on link status information to obtain the link trustworthiness status. Then, the link monitoring device 403 reports the link trustworthiness status to the link management platform 401.

[0150] The link monitoring device 403 reports the link trust status to the link management platform 401 in at least one of the following ways, but is not limited thereto, and the embodiments of this application do not specifically limit this.

[0151] Method 1: The link management platform 401 sends a link query request to the link monitoring device 403; and receives the link trust status reported by the link monitoring device 403 based on the link query request.

[0152] For example, the link management platform 401 sends a link query request to all link monitoring devices 403 and receives the link trust status reported by all link monitoring devices 403.

[0153] In some embodiments, the link management platform 401 sends a link query request to the designated link monitoring device 403 based on the link identifier, and receives the link trust status reported by the designated link monitoring device 403.

[0154] Method 2: The link management platform 401 receives the link trust status actively reported by the link monitoring device 403 after the link status reporting conditions are triggered.

[0155] For example, the link monitoring device 403 analyzes whether the link trust status has changed. For instance, if the link trust status changes from a normal link status to an abnormal link status, the link monitoring device 403 reports the changed link trust status to the link management platform 401.

[0156] In some embodiments, the device verification network element 402 is used to obtain the device trust status corresponding to the network device 404 and send the device trust status to the network orchestrator 400.

[0157] The device trust status is used to describe the reliability of network devices (404 errors). Device trust status can be divided into different levels, reflecting the current operating status and trustworthiness of the device.

[0158] Optionally, the trusted status of the device includes: normal device status, abnormal device status, and device status failure, but is not limited thereto, and the embodiments of this application do not specifically limit it.

[0159] A normal device status means that the performance indicators, security, and reliability of the network device (404) are within the standard range. For example, the performance indicators of the network device (404) such as memory and resource utilization are within or exceed the standard range; the network device (404) does not have known security vulnerabilities or potential security risks; and the integrity of the code or data in the network device (404) is high.

[0160] An abnormal device status means that the performance indicators, security and / or reliability of the network device are below the standard range.

[0161] Equipment status failure refers to a situation where the equipment is completely unable to guarantee the security and integrity of data, requiring timely maintenance and repair.

[0162] Specifically, the device verification network element 402 is used to receive the device status information corresponding to the network device 404, perform device trustworthiness analysis on the device status information, and obtain the device trustworthiness status.

[0163] Device status information refers to various types of information describing the current operating status, security performance, and identity trustworthiness of network device 404. For example, device status information can be the trustworthiness measurement information of network device 404.

[0164] Trust measurement information includes information on multiple aspects such as network device 404 authentication, configuration and status, security performance, integrity and trustworthiness verification, logs and auditing.

[0165] Device reliability analysis refers to assessing the reliability of network devices based on device status information.

[0166] For example, the device verification network element 402 compares the trust measurement information with the preset benchmark value to quantify and score or classify the trust status of the network device 404.

[0167] For example, when the trust metrics of network device 404 are all higher than the baseline value, network device 404 is a trustworthy network device.

[0168] Among them, the device verification network element 402 can be a network element for remote verification of network devices.

[0169] Optionally, network device 404 may include at least one of TPM module, TPCM module and TCM module, but is not limited thereto, and the embodiments of this application do not specifically limit this.

[0170] In some embodiments, the device authentication network element 402 receives device status information sent by the network device 404 in at least one of the following ways, but is not limited thereto, and the embodiments of this application do not specifically limit this:

[0171] Method 1: Device verification network element 402 sends a device status query request to network device 404 and receives device status information reported by network device 404 based on the device status query request.

[0172] For example, the device verification network element 402 sends a network status query request to all network devices 404 and receives device status information reported by all network devices 404.

[0173] In some embodiments, the device verification network element 402 sends a device status query request to the designated network device 404 based on the device identifier, and receives device status information reported by the designated network device 404.

[0174] Among them, the device identifier is an identifier used to identify different devices in communication. The device verification network element 402 can report the device status information corresponding to the network device 404 based on the device identifier.

[0175] For example, device identification can be the device's serial number, physical address (Media Access Control Address, MAC address), or universally unique identifier.

[0176] Method 2: The device verification network element 402 receives the device status information actively reported by the network device 404 after the device status reporting conditions are triggered.

[0177] The conditions for reporting device status include at least one of the following: a change in the status of the network device or periodic reporting of device status information.

[0178] A change in network device status refers to a change in device status information, or a change in the trusted status of a device as determined by a device trustworthiness analysis.

[0179] For example, network device 404 analyzes whether the device status information has changed. For instance, when the trusted measurement information of network device 404 changes, it reports the changed trusted measurement information to device verification network element 402.

[0180] For example, when network device 404 performs device trustworthiness analysis based on device status information, it analyzes whether the device trustworthiness status has changed. For instance, if the device trustworthiness status changes from a normal state to an abnormal state, then network device 404 reports the changed device trustworthiness status to device verification network element 402.

[0181] Periodic reporting of equipment status information refers to the automatic or manual reporting of equipment status information according to a predetermined time period.

[0182] For example, network device 404 proactively reports device status information at certain time intervals. For instance, network device 404 reports device status information once per hour.

[0183] In some embodiments, the device verification network element 402 can verify the device status information reported by the network device 404.

[0184] For example, the trusted computing module in network device 404 generates a public-private key pair for Access Key Id (AK) signature verification.

[0185] AK signature verification is an authentication and authorization mechanism.

[0186] For example, the device status query request sent by device authentication network element 402 to network device 404 includes a generated random number. Network device 404 performs AK signature on the random number and device status information based on its private key, and sends the device status information, AK signature, and AK certificate to device authentication network element 402.

[0187] The trusted computing module includes security chips and application systems such as TPM, TPCM, TCM and Secure Element (SE), and has capabilities such as network device 404 hardware and software and runtime status trusted measurement, key generation, key storage and remote proof capabilities.

[0188] For example, network device 404 may have one or more trusted computing modules internally, depending on the actual deployment.

[0189] In some embodiments, the network orchestrator 400 is configured to receive link trust status and device trust status, and obtain a trusted path topology based on the link trust status and device trust status.

[0190] In network communication, a trusted path topology refers to a network structure composed of trusted paths to ensure the reliability and security of data transmission. A trusted path topology includes at least two network devices (404) and at least one trusted path.

[0191] The specific methods by which the Network Orchestrator 400 constructs trusted paths are as follows, but not limited to:

[0192] Based on the trusted state of links and devices, the network orchestrator 400 establishes a mapping relationship between network devices 404 and network links to obtain a trusted path topology.

[0193] The mapping relationship refers to the connection and correspondence between network device 404 and network links in the network environment. The connection between network device 404 and network links includes physical connection and logical connection.

[0194] For example, network device 404 is physically connected to the network link through a physical interface (such as an Ethernet port, fiber optic interface, etc.). Based on the physical connection, logical connections are established between network devices 404, such as virtual local area networks (VLANs) and virtual private networks (VPNs).

[0195] In some embodiments, the network orchestrator 400 establishes a mapping relationship by associating the device identifier corresponding to the network device 404 with the link identifier corresponding to the network link, thereby obtaining a trusted path topology.

[0196] For example, the network orchestrator 400 determines network links with normal trusted status based on the link trusted status, determines network devices 404 with normal trusted status based on the device trusted status, and then associates the link identifiers corresponding to the network links with normal trusted status with the device identifiers corresponding to the network devices 404 with normal trusted status, thereby connecting all trusted paths to form a trusted path topology.

[0197] For example, if two network devices 404 are trusted, and the network link between the two network devices 404 is also trusted, then the path formed by the connection between the two network devices 404 and the network link between the two network devices 404 is considered a trusted path.

[0198] In some embodiments, the network orchestrator 400 can receive business requirement information from the business system and filter trusted paths that meet the business requirements from a pre-established and stored trusted path topology.

[0199] The business system refers to the system used to process business processes, data, and information. Business requirement information includes trusted slice information, source address information, destination address information, routing information, network service quality information, latency information, etc., for the trusted paths required by the business.

[0200] Trusted slice information refers to logically independent, secure, and reliable virtual network information provided to different tenants or applications on a multi-tenant shared physical infrastructure through SDN architecture and network function virtualization technology.

[0201] For example, trusted paths that satisfy the source address, destination address, and network service quality information of a certain service can be selected from the trusted path topology.

[0202] For example: First, filter all trusted paths between the source address and the destination address of the service in the trusted path topology, and then select trusted paths with network service quality higher than the service requirements from all trusted paths as trusted paths for the service.

[0203] In some embodiments, the network orchestrator 400 can receive business requirement information from the business system and establish a trusted path topology corresponding to the business requirement information based on the business requirement information.

[0204] For example, the network orchestrator 400 filters all network devices 404 and network links that may be involved between the source address and the destination address of a certain service, obtains the device identifier of the network device 404 and the link identifier of the network link, queries the trusted status of the corresponding network device 404 based on the device identifier, queries the trusted status of the corresponding network link based on the link identifier, constructs a trusted path topology based on the obtained trusted device and trusted link statuses, and then filters trusted paths that meet the service requirements from the trusted path topology based on network service quality, latency information, etc.

[0205] In some embodiments, the network orchestrator 400 receives link trust status and device trust status in the following manner, but is not limited thereto:

[0206] Method 1: The network orchestrator 400 actively sends a link query request to the link management platform 401 to query the link trust status, and sends a device query request to the device verification network element 402 to query the device trust status.

[0207] In some embodiments, network orchestrator 400 queries the link trust status of all network links and the device trust status of all network devices 404.

[0208] In other embodiments, network orchestrator 400 queries the link trust status of a specified network link and the device trust status of a specified network device 404.

[0209] For example, a link query request includes a link identifier, and the link management platform 401 queries the trusted status of a specified network link based on the link identifier. A device query request includes a device identifier, and the link management platform 401 queries the trusted status of a specified device based on the device identifier.

[0210] The link management platform 401 can store link trust status, for example, in the form of a link trust status table. When it receives a link status query request, the link management platform 401 can report the link trust status of the corresponding network link based on the link identifier. The device verification network element 402 can store device trust status. When it receives a device status query request, it can report the device trust status of the corresponding network device 404 based on the device identifier.

[0211] Method 2: The network orchestrator 400 receives the link trust status actively reported by the link management platform 401, and the link trust status actively reported by the device verification network element 402.

[0212] For example, after receiving the link status information proactively reported by the link monitoring device 403, the link management platform 401 proactively reports the trusted status of the link to the network orchestrator 400. After receiving the device status information proactively reported by the network device 404, the device verification network element 402 proactively reports the trusted status of the device to the network orchestrator 400.

[0213] For example, the link management platform 401 reports the link trust status to the network orchestrator 400 at certain time intervals, and the device verification network element 402 reports the device trust status to the network orchestrator 400 at certain time intervals. For instance, the link management platform 401 reports the link trust status to the network orchestrator 400 every hour, and the device verification network element 402 reports the device trust status to the network orchestrator 400 every hour.

[0214] Method 3: The network orchestrator 400 can be directly connected to the network device 404 or the network link monitoring device 403 to receive the device trust status of the network device 404 and the link trust status of the network link.

[0215] In some embodiments, the network device 404 in the trusted path established by the network orchestrator 400 may belong to one network domain or multiple network domains.

[0216] When belonging to a network domain, network devices 404 within the network domain are connected to the same SDN controller, and network orchestrator 400 is connected to the SDN controller to establish a trusted path.

[0217] When belonging to multiple network domains, each network domain is connected to an SDN controller. The network orchestrator 400 is connected to each SDN controller and establishes a trusted path within the corresponding network domain through the connection of each SDN controller.

[0218] For example, different network domains may have different SDN controllers, network devices 404, and link monitoring devices 403. For instance, the network devices 404 of different network domains may be different IP devices, transmission devices, etc.

[0219] For example, the trusted computing modules of network devices in different network domains may have different trusted status management methods. For instance, the trusted computing module may directly connect to the device to verify the device status information reported by the network element, or forward the reported device status information through the network management function network element.

[0220] For example, different network domains may have different connection methods for network device 404 and link monitoring device 403. For instance, network orchestrator 400 may be directly connected to network device 404 and link monitoring device 403, or it may be connected to network device 404 through device authentication network element 402, or to link monitoring device 403 through link management platform 401.

[0221] In summary, the trusted path establishment system proposed in this application constructs a trusted path topology using the trusted link status obtained from the link management platform 401 and the trusted device status obtained from the device verification network element 402 during trusted path orchestration. This ensures the security of both network devices 404 and network links, improves the reliability of trusted paths in the trusted path topology, and effectively avoids the security risks of malicious tampering and data theft of the network system.

[0222] The above embodiments describe in detail an exemplary trusted path establishment system of this application, and a trusted path topology constructed based on the above trusted path establishment system is as follows: Figure 5 As shown.

[0223] Figure 5 An example diagram of a trusted path topology is provided as an exemplary embodiment.

[0224] Figure 5 The network structure includes 6 network devices and 8 network links. The network orchestrator receives the device trust status of all network devices and the link trust status of all network links, and determines whether the trust status of the network devices and the network links are normal.

[0225] Assume that network devices 51, 53, 54, and 56 are trusted and in normal condition, and network links 500, 501, 506, and 507 are trusted and in normal condition. The path formed by connecting network devices 51, 54, and 56 with network links 500 and 501 is a trusted path; the path formed by connecting network devices 53, 54, and 56 with network links 501 and 507 is a trusted path; the path formed by connecting network devices 53, 54, and 51 with network links 500 and 507 is a trusted path; the path formed by connecting network devices 52, 56, and 506 with network link 506 is a trusted path; the path formed by connecting network devices 51, 54, and 500 with network link 500 is a trusted path; the path formed by connecting network devices 53, 54, and 507 with network link 507 is a trusted path; and the path formed by connecting network devices 54, 56, and 501 with network link 501 is a trusted path.

[0226] The network orchestrator receives the service requirement information from the service system. Assuming that the service requirement information indicates that the source address of a certain service data transmission is network device 51 and the destination address is 56, then in the trusted path topology formed by the above trusted paths, the path formed by connecting network devices 51, 54, 56 and network links 500 and 501 is selected as the trusted path for this service.

[0227] In summary, the trusted path establishment system of this application constructs a trusted path topology that can intuitively display the connection relationship between network devices and network links, as well as all trusted paths formed by the connection of network devices and network links. Users can directly select the required trusted path from the trusted path topology based on business requirements, making trusted path establishment more efficient and convenient.

[0228] The above embodiments describe in detail the trusted path establishment system and its trusted path topology according to the embodiments of this application. The trusted path establishment method according to the embodiments of this application will be described in detail below.

[0229] Figure 6 This is a flowchart illustrating a trusted path establishment method as an exemplary embodiment, which can be executed by a network orchestrator. The method includes:

[0230] Step S601: The network orchestrator obtains the link trust status corresponding to the network link.

[0231] Among them, the link trust status is used to describe the reliability of the network link.

[0232] For example, the link trust status is obtained by the link management platform after performing link trust analysis on the link status information.

[0233] Link reliability analysis refers to assessing the reliability of network links based on link state information.

[0234] For example, the reliability of a network link can be evaluated based on bit error rate, packet loss rate, and bandwidth utilization. The lower the bit error rate and packet loss rate, the higher the bandwidth utilization, and the higher the reliability of the network link.

[0235] In some embodiments, the method of obtaining the link trust status includes at least one of the following methods, but is not limited thereto, and the embodiments of this application do not specifically limit it:

[0236] Method 1: The network orchestrator actively sends a link query request to the link management platform to query the link trust status.

[0237] In some embodiments, the network orchestrator queries the link trust status of all network links.

[0238] In other embodiments, the network orchestrator queries the link trust status of a specified network link.

[0239] For example, a link query request includes a link identifier, and the link management platform queries the trusted status of a specified link based on the link identifier.

[0240] The link management platform can store the trusted status of links and, upon receiving a link status query request, can report the trusted status of the corresponding network link based on the link identifier.

[0241] Method 2: The network orchestrator receives the link trust status actively reported by the link management platform.

[0242] For example, after receiving the link status information proactively reported by the link monitoring device, the link management platform proactively reports the trusted status of the link to the network orchestrator.

[0243] For example, the link management platform reports the link trust status to the network orchestrator at regular intervals. For instance, the link management platform reports the link trust status to the network orchestrator every hour.

[0244] Method 3: The device verification network element can be directly connected to the network link monitoring device to receive the link trust status of the network link.

[0245] Step S602: The network orchestrator obtains the trusted status of the network device.

[0246] Among them, the device trust status is used to describe the reliability of network devices.

[0247] For example, the trusted state of a device is obtained by the device verification network element after performing a device trustworthiness analysis on the device status information.

[0248] Device trustworthiness analysis refers to assessing the reliability of network devices based on device status information. For example, when the integrity of a network device is maliciously tampered with or damaged, the device's trustworthiness status changes to abnormal.

[0249] In some embodiments, the method of obtaining the trusted status of the device includes at least one of the following methods, but is not limited thereto, and the embodiments of this application do not specifically limit this:

[0250] Method 1: The network orchestrator actively sends a device query request to the device verification network element to query the device's trusted status.

[0251] In some embodiments, the network orchestrator queries the device trust status of all network devices.

[0252] In other embodiments, the network orchestrator queries the trusted status of a specified network device.

[0253] For example, the device query request includes a device identifier, and the link management platform queries the trusted status of the specified device based on the device identifier.

[0254] Among them, the device verification network element can store the trusted status of the device, and when it receives a device query status request, it can report the trusted status of the corresponding network device according to the device identifier.

[0255] Method 2: The network orchestrator receives the link trust status actively reported by the network element and verifies it.

[0256] For example, after receiving the device status information actively reported by the network device, the device verification network element actively reports the trusted status of the device to the network orchestrator.

[0257] For example, the device authentication network element reports the device's trusted status to the network orchestrator at regular time intervals. For instance, the device authentication network element reports the device's trusted status to the network orchestrator every hour.

[0258] Method 3: The device verification network element can directly connect to the network device and receive the device trust status of the network device.

[0259] Step S603: The network orchestrator obtains the trusted path topology based on the trusted state of the links and the trusted state of the devices.

[0260] Trusted path topology refers to a network structure composed of trusted paths in network communication to ensure the reliability and security of data transmission.

[0261] The trusted path topology includes at least one trusted path.

[0262] Specifically, based on the trusted state of links and devices, a mapping relationship between network devices and network links is established to obtain a trusted path topology.

[0263] The mapping relationship between network devices and network links refers to the connection and correspondence between network devices (such as routers, switches, servers, etc.) and network links (such as fiber optic cables, copper wires, wireless networks, etc.) in a network environment.

[0264] For example, the device identifier corresponding to the network device and the link identifier corresponding to the network link are associated and mapped to obtain a trusted path topology.

[0265] For example, the network orchestrator determines network links with normal trust status based on the link trust status, determines network devices with normal trust status based on the device trust status, and then associates the link identifiers corresponding to the network links with normal trust status with the device identifiers corresponding to the network devices with normal trust status, thereby connecting all trusted paths to form a trusted path topology.

[0266] In summary, the aforementioned trusted path establishment method based on network orchestrator execution allows the network orchestrator to acquire the trusted state of links and devices to construct a trusted path topology. This ensures the security of both network devices and network links, improves the reliability of trusted paths within the trusted path topology, and effectively avoids the security risks of malicious tampering and data theft in the network system.

[0267] Figure 7 This is a flowchart illustrating a trusted path establishment method as an exemplary embodiment, which can be executed by a link management platform. The method includes:

[0268] Step S701: The link management platform obtains the link trust status corresponding to the network link.

[0269] Link trust status describes the reliability of network links. Link trust status is used to construct a trusted path topology.

[0270] Trusted path topology refers to a network structure composed of trusted paths in network communication to ensure the reliability and security of data transmission.

[0271] The trusted path topology includes at least one trusted path.

[0272] Specifically, it receives link status information corresponding to network links. It then performs link reliability analysis on this link status information to obtain the link's reliability status.

[0273] In some embodiments, the link management platform receives link status information in at least one of the following ways, but is not limited thereto, and the embodiments of this application do not specifically limit this:

[0274] Method 1: The link management platform sends a link status query request to the link monitoring device; and receives the link status information reported by the link monitoring device based on the link status query request.

[0275] For example, the link management platform sends a link status query request to all link monitoring devices and receives link status information reported by all link monitoring devices.

[0276] In some embodiments, the link management platform sends a link status query request to a designated link monitoring device based on the link identifier, and receives link status information reported by the designated link monitoring device.

[0277] Link identifiers are identifiers used in communication to identify different links. Link monitoring devices can report the link status information corresponding to the network links based on the link identifiers.

[0278] For example, in a multi-protocol label switching network, the link identifier can be a multi-protocol label switching (MPLS) label.

[0279] Method 2: The link management platform receives link status information proactively reported by the link monitoring device after the link status reporting conditions are triggered.

[0280] The link status reporting conditions include at least one of the following: a change in network link status or periodic reporting of link status information.

[0281] A change in network link status refers to a change in link status information, or a change in the link trust status obtained after link trust analysis.

[0282] For example, the link monitoring device analyzes whether the link status information has changed. For instance, if the bit error rate of the network link changes from above the standard range to below the standard range, the link monitoring device reports the bit error rate of the network link after the change to the link management platform.

[0283] For example, when a link monitoring device performs link trustworthiness analysis based on link status information, it analyzes whether the link trustworthiness status has changed. For instance, if the link trustworthiness status changes from a normal link status to an abnormal link status, the link monitoring device reports the changed link trustworthiness status to the link management platform.

[0284] Periodic reporting of link status information refers to automatically or manually reporting link status information according to a predetermined time period.

[0285] For example, the link monitoring device actively reports link status information at certain time intervals. For instance, the link monitoring device reports link status information once per hour.

[0286] Step S702: The link management platform sends the link trust status to the network orchestrator.

[0287] In some embodiments, after receiving the proactively reported link status information, the link management platform sends the link trust status obtained based on the proactively reported link status information to the network orchestrator.

[0288] In other embodiments, the link management platform sends the link trust status to the network orchestrator based on the link query request sent by the network orchestrator.

[0289] For example, a link query request includes a link identifier, and the link management platform queries the trusted status of a specified network link based on the link identifier.

[0290] The link management platform can store the trusted status of links. When it receives a link query status request, it can send the trusted status of the corresponding network link to the network orchestrator based on the link identifier.

[0291] For example, Figure 8 This is a schematic diagram of the structure of a link management platform provided in an embodiment of this application. Figure 8 The system includes six network devices 802, a link management platform 801, and six link monitoring devices 800. The link monitoring devices 800 are installed on the network links connecting the network devices 802. The link monitoring devices 800 are used to acquire link status information of the network links and report it to the link management platform 801. Each link monitoring device 800 can directly perform link trustworthiness analysis based on the link status information to obtain the link trustworthiness status and report it to the link management platform 801, or the link management platform 801 can perform link trustworthiness analysis based on the link status information to obtain the link trustworthiness status. The number and connection location of the link management platform 801 and the link monitoring devices 800 are not limited to... Figure 8 As shown in the embodiments of this application, this application does not limit this.

[0292] In summary, the aforementioned trusted path method based on the link management platform allows the platform to send the acquired link trust status to the network orchestrator. This enables the network orchestrator to construct a trusted path topology based on the link trust status, ensuring the security of network links and improving the reliability of trusted paths within the trusted path topology. This effectively avoids the security risks of malicious tampering and data theft in the network system.

[0293] Figure 9This is a flowchart illustrating a trusted path establishment method provided in an embodiment of this application. This method can be executed by a device verification network element. The method includes:

[0294] Step S901: The device verification network element obtains the trusted status of the network device.

[0295] Among them, the device trusted state is used to describe the reliability of network devices and also to build trusted path topologies.

[0296] Trusted path topology refers to a network structure composed of trusted paths in network communication to ensure the reliability and security of data transmission.

[0297] The trusted path topology includes at least one trusted path.

[0298] Specifically, it receives device status information corresponding to network devices. It then performs device trustworthiness analysis on this information to determine the device's trustworthiness status.

[0299] In some embodiments, the method of receiving device status information corresponding to a network device includes at least one of the following methods, but is not limited thereto, and the embodiments of this application do not specifically limit this:

[0300] Method 1: The device verification network element sends a device status query request to the network device and receives the device status information reported by the network device based on the device status query request.

[0301] For example, the device verification network element sends a network status query request to all network devices and receives device status information reported by all network devices.

[0302] In some embodiments, the device authentication network element sends a device status query request to a designated network device based on the device identifier, and receives device status information reported by the designated network device.

[0303] Among them, device identifier refers to an identifier used to identify different devices in communication. The device verification network element can report the device status information corresponding to the network device based on the device identifier.

[0304] For example, device identification can be the device's serial number, physical address (Media Access Control Address, MAC address), or universally unique identifier.

[0305] Method 2: The device verification network element receives the device status information actively reported by the network device after the device status reporting conditions are triggered.

[0306] The conditions for reporting device status include at least one of the following: a change in the status of the network device or periodic reporting of device status information.

[0307] A change in network device status refers to a change in device status information, or a change in the trusted status of a device as determined by a device trustworthiness analysis.

[0308] For example, the network device analyzes whether the device status information has changed. For instance, when the network device's trusted measurement information changes, the network device reports the changed trusted measurement information to the device verification network element.

[0309] For example, when a network device performs device trustworthiness analysis based on device status information, it analyzes whether the device's trustworthiness status has changed. For instance, if the device's trustworthiness status changes from a normal state to an abnormal state, the network device reports the changed device trustworthiness status to the device verification network element.

[0310] Periodic reporting of equipment status information refers to the automatic or manual reporting of equipment status information according to a predetermined time period.

[0311] For example, network devices proactively report device status information at regular time intervals. For instance, a network device reports its device status information once per hour.

[0312] Step S902: The device verification network element sends the device trust status to the network orchestrator.

[0313] In some embodiments, after receiving the actively reported device status information, the device verification network element sends the trusted device status obtained based on the actively reported device status information to the network orchestrator.

[0314] In other embodiments, the device verification network element sends the device trusted status to the network orchestrator based on the device query request sent by the network orchestrator.

[0315] For example, a device query request includes a device identifier, and the device verification network element queries the trusted status of a specified network device based on the device identifier.

[0316] Among them, the device verification network element can store the trusted status of the device. When it receives a device query status request, it can send the trusted status of the corresponding network device to the network orchestrator according to the device identifier.

[0317] In summary, the aforementioned trusted path establishment method based on the device verification network element sends the acquired device trusted status to the network orchestrator, enabling the network orchestrator to construct a trusted path topology based on the device trusted status. This ensures the security of network devices and improves the reliability of trusted paths within the trusted path topology, effectively avoiding the security risks of malicious tampering and data theft of the network system.

[0318] The trusted path establishment methods have been described above from the perspectives of the network orchestrator, link management platform, and device verification network element. The following section will describe the trusted path establishment methods from the perspective of the overall system.

[0319] For example, such as Figure 10 The flowchart shown illustrates the trusted path establishment method.

[0320] Step S1001: The network orchestrator receives the service requirement information sent by the service system.

[0321] Business requirement information includes trusted slice information, source address information, destination address information, routing information, network service quality information, latency information, etc., for the trusted paths required by the business.

[0322] Step S1002: The network orchestrator generates an orchestration strategy based on business requirements and trusted path topology.

[0323] Trusted path topology refers to a network structure composed of trusted paths in network communication to ensure the reliability and security of data transmission.

[0324] Orchestration strategies include the selection of trusted paths and the configuration of network devices and network links within those trusted paths.

[0325] Step S1003: The network orchestrator sends the orchestration policy to the SDN controller.

[0326] In an SDN architecture, it is difficult for a single SDN controller to control all the forwarding capabilities of the network layer. Therefore, the network orchestrator is connected to all SDN controllers.

[0327] Step S1004: The SDN controller configures the connection relationships between network devices based on the orchestration policy and establishes trusted paths.

[0328] For example, Figure 10 The trusted path establishment method shown can be achieved through, for example... Figure 11 The trusted path establishment system shown is used to implement this. This system includes a network orchestrator 1100, a link management platform 1101, a device authentication network element 1102, a service system 1103, and an SDN controller 1104 connected to the network orchestrator 1100, a link monitoring device 1105 connected to the link management platform 1101, and a network device 1106 connected to the device authentication network element 1102. The network orchestrator 1100 generates a trusted path topology based on the device trusted status sent by the device authentication network element 1102 and the link trusted status sent by the link management platform 1101. Then, it receives service requirement information sent by the service system 1103, selects a trusted path that meets the service requirements from the trusted path topology, and establishes the trusted path through the SDN controller 1104.

[0329] Optional, Figure 11 The SDN controller 1104 in the middle can also be an Element Management System (EMS) or a Network Management System (NMS).

[0330] The EMS and NMS systems can perform functions such as device management, performance management, fault management, and security management for network device 1106. When the EMS and NMS systems have the function of collecting and evaluating the trust measurement information of network device 1106, the device verification network element 1102 can also obtain the device status information and trust status of network device 1106 from the EMS and NMS systems.

[0331] In summary, the network orchestrator selects trusted paths that meet the business requirements from the trusted path topology based on the business requirement information, and the SDN controller establishes the trusted path for the business. The establishment of the trusted path is efficient and convenient, ensuring the security and reliability of the data transmission of the business.

[0332] The foregoing mainly describes the solution provided in this application. Accordingly, this application also provides the following trusted path establishment apparatus, which is used to implement the above method embodiments.

[0333] like Figure 12 The schematic diagram shown illustrates the structure of a trusted path establishment device, which may include an acquisition module 1201 and a construction module 1202. The acquisition module 1201 is used to execute... Figure 6 The illustrated method includes steps S601 and S602; the construction module 1202 is used to execute these steps. Figure 6 The operation of step S603.

[0334] like Figure 13 The schematic diagram shown illustrates the structure of a trusted path establishment device, which may include an acquisition module 1300 and a sending module 1310. The acquisition module 1300 is used to perform... Figure 7 In the illustrated method, step S701 is performed by the sending module 1310. Figure 7 The illustrated method includes step S702.

[0335] In some embodiments, the trusted path establishment apparatus includes hardware structures and / or software modules corresponding to the execution of each function in order to achieve the above-described functions. Those skilled in the art will readily recognize that, based on the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0336] This application embodiment can divide the trusted path establishment device into functional modules according to the above method embodiment. For example, each function can be divided into a separate functional module, or two or more functions can be integrated into one processing module. The integrated module can be implemented in hardware or as a software functional module. It should be noted that the module division in this application embodiment is illustrative and only represents one logical functional division. In actual implementation, there may be other division methods.

[0337] like Figure 14 As shown, the computer device provided in this application embodiment may include a processor 1401, a bus 1402, a communication interface 1403, and a memory 1404. The processor 1401, the memory 1404, and the communication interface 1403 communicate with each other via the bus 1402. It should be understood that this application does not limit the number of processors and memories in the network device.

[0338] Bus 1402 can be a PCI bus, an Extended Industry Standard Architecture (EISA) bus, or a UB bus, etc. Buses can be divided into address buses, data buses, control buses, etc. For ease of representation, Figure 14 The bus 1402 may be represented by a single line, but this does not mean that there is only one bus or one type of bus. The bus 1402 may include a path for transmitting information between various components of a computer device (e.g., memory 1404, processor 1401, communication interface 1403).

[0339] Processor 1401 may include any one or more processors such as CPU, graphics processing unit (GPU), microprocessor (MP), or digital signal processor (DSP).

[0340] The memory 1404 may include volatile memory, such as random access memory (RAM). The processor 1401 may also include non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid state drive (SSD).

[0341] The communication interface 1403 uses transceiver modules, such as, but not limited to, network interface cards and transceivers, to enable communication between network devices and other devices or communication networks.

[0342] The memory 1404 stores executable program code, and the processor 1401 executes the executable program code to implement the functions of the aforementioned method embodiments. That is, the memory 1404 stores instructions for executing the aforementioned trusted path establishment method.

[0343] In another aspect, a computer-readable storage medium is provided, wherein at least one computer program is stored in the computer-readable storage medium, and the at least one computer program is loaded and executed by a processor to implement the trusted path establishment method as provided in the above-described method embodiments.

[0344] On the other hand, a computer program product is provided, which includes a computer program or instructions, and when the computer program or instructions are executed by a processor, the trusted path establishment method described above is implemented.

[0345] In another aspect, a chip system is provided, including at least one processor and at least one interface circuit, wherein the at least one interface circuit is used to perform transceiver functions and send instructions to the at least one processor, and when the at least one processor executes the instructions, the at least one processor executes to implement the trusted path establishment method as described above.

[0346] Through the above description of the implementation methods, those skilled in the art will clearly understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the module can be divided into different functional modules to complete all or part of the functions described above. The specific working process of the system, modules, and units described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0347] Since the trusted path establishment module, computer-readable storage medium, and computer program product in the embodiments of the present invention can be applied to the above methods, the technical effects they can achieve can also be referred to the above method embodiments. The embodiments of the present invention will not be repeated here.

[0348] The method steps in this embodiment can be implemented in hardware or by a processor executing software instructions. The software instructions can consist of corresponding software modules, which can be stored in random access memory (RAM), flash memory, read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), registers, hard disks, portable hard disks, CD-ROMs, or any other form of storage medium known in the art. One exemplary embodiment couples a storage medium to a processor, enabling the processor to read information from and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and storage medium can reside in an ASIC. Alternatively, the ASIC can reside in a network device. Of course, the processor and storage medium can also exist as discrete components in the network device.

[0349] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented, in whole or in part, as a computer program product. A computer program product includes one or more computer programs or instructions. When a computer program or instruction is loaded and executed on a computer, the processes or functions of the embodiments of this application are performed, in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user equipment, or other programmable module. The computer program or instructions can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, a computer program or instructions can be transferred from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium, such as a floppy disk, hard disk, or magnetic tape; it can also be an optical medium, such as a digital video disc (DVD); or it can be a semiconductor medium, such as a solid-state drive (SSD). The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and these modifications or substitutions should all be covered within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A trusted path establishment system, characterized in that, The system includes a network orchestrator, a device verification network element connected to the network orchestrator, and a link management platform; The link management platform is used to obtain the link trust status corresponding to the network link and send the link trust status to the network orchestrator. The link trust status is used to describe the reliability of the network link. The link management platform is specifically used to obtain link status information corresponding to network links from link monitoring devices; wherein, the link status information includes bit error rate, packet loss rate, bandwidth utilization, and data traffic; the data traffic is used to identify whether eavesdropping has occurred on the corresponding network link; and link trustworthiness analysis is performed based on the link status information to obtain the link trustworthiness status corresponding to the network link. The device verification network element is used to obtain the device trust status corresponding to the network device and send the device trust status to the network orchestrator. The device trust status is used to describe the reliability of the network device. The network orchestrator is configured to receive the link trust status and the device trust status; and based on the link trust status and the device trust status, obtain a trusted path topology, wherein the trusted path topology includes at least one trusted path.

2. The system according to claim 1, characterized in that, The link management platform is also used to send a link status query request to the link monitoring device and receive the link status information reported by the link monitoring device based on the link status query request. Alternatively, the link management platform is also used to receive the link status information actively reported by the link monitoring device after triggering the link status reporting condition.

3. The system according to claim 2, characterized in that, The link status reporting conditions include at least one of the following: a change in network link status or periodic reporting of link status information.

4. The system according to any one of claims 1 to 3, characterized in that, The device verification network element is also used to receive device status information corresponding to the network device; perform device trustworthiness analysis on the device status information to obtain the device trustworthiness status, wherein the device trustworthiness analysis refers to evaluating the reliability of the network device based on the device status information.

5. The system according to claim 4, characterized in that, The device verification network element is also used to send a device status query request to the network device and receive the device status information reported by the network device based on the device status query request; Alternatively, the device verification network element is further configured to receive the device status information actively reported by the network device after triggering the device status reporting condition.

6. The system according to claim 5, characterized in that, The device status reporting conditions include at least one of the following: a change in network device status or periodic reporting of device status information.

7. The system according to any one of claims 1 to 3, characterized in that, The network orchestrator is further configured to establish a mapping relationship between the network device and the network link based on the link trust status and the device trust status, thereby obtaining the trusted path topology.

8. The system according to claim 7, characterized in that, The network orchestrator is further configured to associate and map the device identifier corresponding to the network device and the link identifier corresponding to the network link to obtain the trusted path topology.

9. A method for establishing a trusted path, characterized in that, Applied to a network orchestrator, the method includes: The system acquires the link trust status corresponding to the network link and the device trust status corresponding to the network device. The link trust status describes the reliability of the network link, and the device trust status describes the reliability of the network device. The link trust status is obtained by the link management platform after performing link trust analysis on the link status information. The link status information is obtained by the link management platform from the link monitoring device and includes bit error rate, packet loss rate, bandwidth utilization, and data traffic. The data traffic is used to identify whether eavesdropping has occurred on the corresponding network link. Based on the link trust status and the device trust status, a trusted path topology is obtained, which includes at least one trusted path.

10. The method according to claim 9, characterized in that, The device trust status is obtained by the device verification network element after performing device trust analysis on the device status information.

11. The method according to claim 9 or 10, characterized in that, The process of obtaining the trusted path topology based on the trusted state of the link and the trusted state of the device includes: Based on the trusted state of the link and the trusted state of the device, a mapping relationship is established between the network device and the network link to obtain the trusted path topology.

12. The method according to claim 11, characterized in that, The step of establishing the mapping relationship between the network device and the network link to obtain the trusted path topology includes: The trusted path topology is obtained by associating and mapping the device identifier corresponding to the network device with the link identifier corresponding to the network link.

13. A method for establishing a trusted path, characterized in that, Applied to a link management platform, the method includes: Obtain the link trust status corresponding to the network link; The link trust status is sent to the network orchestrator so that the network orchestrator can obtain a trusted path topology based on the link trust status and the device trust status corresponding to the network device; wherein, the device trust status is used to describe the reliability of the network device, the link trust status is used to describe the reliability of the network link, and the trusted path topology includes at least one trusted path. The step of obtaining the link trust status corresponding to the network link includes: Link status information corresponding to the network link is obtained from the link monitoring device; wherein, the link status information includes bit error rate, packet loss rate, bandwidth utilization and data traffic; the data traffic is used to identify whether eavesdropping has occurred on the corresponding network link; Based on the link state information, link trustworthiness analysis is performed to obtain the link trustworthiness status corresponding to the network link.

14. The method according to claim 13, characterized in that, The step of obtaining the link status information corresponding to the network link includes: Send a link status query request to the link monitoring device; receive the link status information reported by the link monitoring device based on the link status query request; Alternatively, the link status information can be received by the link monitoring device after the link status reporting condition is triggered.

15. The method according to claim 14, characterized in that, The link status reporting conditions include at least one of the following: network link status change or periodic reporting.

16. A trusted path establishment device, characterized in that, The device includes: The acquisition module is used to acquire the link trust status corresponding to the network link and the device trust status corresponding to the network device; wherein, the link trust status is used to describe the reliability of the network link, and the device trust status is used to describe the reliability of the network device; the link trust status is obtained by the link management platform after performing link trust analysis on the link status information, and the link status information is obtained by the link management platform from the link monitoring device, and the link status information includes bit error rate, packet loss rate, bandwidth utilization, and data traffic; the data traffic is used to identify whether eavesdropping has occurred on the corresponding network link; A construction module is used to obtain a trusted path topology based on the trusted state of the link and the trusted state of the device, wherein the trusted path topology includes at least one trusted path.

17. A trusted path establishment device, characterized in that, The device includes: The acquisition module is used to acquire the link trust status corresponding to the network link, and the link trust status is used to describe the reliability of the network link; The acquisition module is specifically used to acquire link status information corresponding to a network link from a link monitoring device; wherein, the link status information includes bit error rate, packet loss rate, bandwidth utilization, and data traffic; the data traffic is used to identify whether eavesdropping has occurred on the corresponding network link; and link trustworthiness analysis is performed based on the link status information to obtain the link trustworthiness status corresponding to the network link. The sending module is used to send the link trust status to the network orchestrator so that the network orchestrator can obtain a trusted path topology based on the link trust status and the device trust status corresponding to the network device; wherein, the device trust status is used to describe the reliability of the network device.

18. A computer device, characterized in that, The computer includes a processor and a memory, the memory storing at least one computer program, the at least one computer program being loaded and executed by the processor to implement the trusted path establishment method as described in any one of claims 9 to 15.

19. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores at least one computer program, which is loaded and executed by a processor to implement the trusted path establishment method as described in any one of claims 9 to 15.

20. A computer program product, characterized in that, The computer program product includes a computer program or instructions that, when executed by a processor, implement the trusted path establishment method as described in any one of claims 9 to 15.

Citation Information

Patent Citations

  • Trusted path establishment method and device and storage medium

    CN118432934A

  • Method and apparatus for routing based on trust in cloud service networking

    KR1020190091659A