Method and system for automatically restoring communication based on IPSEC after multi-route switching
Through the coordinated work of the DPD mechanism and periodic heartbeat messages, the IPSEC tunnel interrupt caused by routing handover is automatically detected and restored, which solves the problem that the traditional IPSEC communication mechanism cannot adapt to routing handover in time, and achieves the continuity and stability of communication.
Patent Information
- Application Number
- CN202510277125.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-10
- Publication Date
- 2025-05-20
- Estimated Expiration
- 2045-03-10
AI Technical Summary
The traditional IPSEC communication mechanism cannot adapt to changes in time during routing switching, resulting in IPSEC tunnel interruption and automatic recovery, affecting users' normal use and bringing security risks and economic losses.
Through the coordinated work of the DPD mechanism and periodic heartbeat messages, communication interrupts caused by routing handover are automatically detected and the reconstruction process of IPSEC tunnel is triggered to ensure the continuity and stability of communication.
Automatic IPSEC tunnel recovery during routing switching is realized, which shortens communication interruption time, improves communication recovery efficiency, reduces the impact of communication interruption on services, and ensures the continuity and stability of IPSEC communication.
Smart Images

Figure CN119788720B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of wireless communication technologies, and particularly to a method and system for automatically restoring communication of IPSEC after multi-routing switching. Background Art
[0002] At present, network security is becoming increasingly important, and basically IPSEC (Internet Protocol Security) is used for secure transmission of network data. Usually, a security gateway server is set up in the network, and the client communicates with the security gateway server through IPSEC to achieve data protection. At the same time, for transmission reliability, the client and the full gateway server use multiple WANs through routers for primary and standby operations. IPSEC can only be established on the currently used WAN. Once a certain WAN fails, the router immediately switches to an available WAN.
[0003] However, when the routing in the network switches, the traditional IPSEC communication mechanism often cannot adapt to this change in time, resulting in the interruption of the IPSEC tunnel and the inability to automatically recover, and the communication cannot proceed normally. This will not only affect the normal use of users, but also may bring serious security risks and economic losses to enterprises and organizations. Summary of the Invention
[0004] The purpose of the present invention is to propose a method and system for automatically restoring communication of IPSEC after multi-routing switching, which can automatically re-establish the IPSEC tunnel and restore normal data transmission when detecting that the communication is interrupted due to routing switching, and improve the reliability and stability of network communication.
[0005] The first aspect of the present invention proposes a method for automatically restoring communication of IPSEC after multi-routing switching, including the following steps:
[0006] Negotiate IKE SA parameters between the client and the security gateway;
[0007] Perform identity authentication and IPsec SA parameter negotiation between the client and the security gateway;
[0008] When the identity authentication and IPsec SA parameter negotiation between the client and the security gateway are completed, the IPSEC tunnel is formally established, and ESP encrypted packets are transmitted between the client and the security gateway through the IPSEC tunnel, and the security gateway records the routing information in the ESP encrypted packets;
[0009] The client sends periodic heartbeat messages to the security gateway using ESP packets at a period of t1;
[0010] When the security gateway does not receive the ESP packets transmitted by the client within time t1, the DPD delay event is triggered, and a DPD message is sent to the client through IKE packets;
[0011] When the client receives the DPD message, re-authentication is performed between the client and the security gateway, and IPsec SA parameter negotiation is carried out to reconstruct the IPSEC tunnel for resuming communication. The security gateway obtains and applies the new routing information.
[0012] A further improvement lies in that the specific method for IKE SA parameter negotiation between the client and the security gateway includes:
[0013] The client sends IKE SA parameters including encryption algorithm, authentication algorithm, and DH group information to the security gateway;
[0014] After receiving the IKE SA parameters, the security gateway searches for matching parameters in its own configuration database. If the match is successful, the security gateway returns the matching parameters to the client. The client receives and confirms, and the two parties exchange temporary random numbers. According to the DH algorithm, using the exchanged temporary random numbers and their respective private keys, a shared key material is generated to derive all the keys of the IPsec SA.
[0015] A further improvement lies in that the specific method for authentication and IPsec SA parameter negotiation between the client and the security gateway includes:
[0016] The client sends identity information to the security gateway. The security gateway uses the negotiated algorithm and key to verify the client's identity and the previously exchanged IKE SA parameter negotiation information. At the same time, the two parties further negotiate the parameters of the IPsec SA, including the ESP mode and the key lifetime; the security gateway sends identity information to the client, and the client performs the same verification operation.
[0017] A further improvement lies in that the size of t1 is consistent with the time consumed by the router to switch the WAN line.
[0018] A further improvement lies in that the encryption algorithm adopts any one of AES-128, AES-256, and 3DES.
[0019] A further improvement lies in that the authentication algorithm adopts any one of SHA-1, SHA-256, and SHA-384.
[0020] A further improvement lies in that the DH group adopts DH Group 14 or DH Group 15.
[0021] A further improvement lies in that the method for transmitting ESP encrypted packets between the client and the security gateway through an IPSEC tunnel includes:
[0022] The client encapsulates and encrypts the user's original packet according to the negotiated ESP mode and then sends it to the security gateway. After receiving the ESP encrypted packet, the security gateway decrypts and verifies it according to the previously negotiated SA parameters to ensure the authenticity and integrity of the packet.
[0023] A further improvement lies in that the periodic heartbeat message includes the unique identifier of the client and timestamp information.
[0024] The second aspect of the present invention proposes a system for automatically restoring communication based on IPSEC after multi-route switching, including:
[0025] A first negotiation module for negotiating IKE SA parameters between the client and the security gateway;
[0026] A second negotiation module for performing identity authentication and negotiating IPsec SA parameters between the client and the security gateway;
[0027] An IPSEC tunnel establishment module for establishing an IPSEC tunnel when the identity authentication and IPsec SA parameter negotiation between the client and the security gateway are completed. The client and the security gateway transmit ESP encrypted packets through the IPSEC tunnel, and the security gateway records the routing information in the ESP encrypted packet;
[0028] A heartbeat message sending module for the client to send periodic heartbeat messages to the security gateway in the form of ESP packets at a period of t1;
[0029] A DPD delay event trigger module for triggering a DPD delay event when the security gateway does not receive an ESP packet transmitted by the client within t1 time, and sending a DPD message to the client through an IKE packet;
[0030] An IPSEC tunnel reconstruction module for when the client receives the DPD message, re-performing identity authentication and negotiating IPsec SA parameters between the client and the security gateway to reconstruct the IPSEC tunnel for restoring communication, and the security gateway obtains and applies the new routing information.
[0031] The beneficial effects of the present invention are:
[0032] Through the collaborative work of the DPD mechanism and periodic heartbeat messages, the present invention can automatically, real-time, and accurately detect communication interruptions caused by route switching, and quickly and automatically trigger the reconstruction process of the IPSEC tunnel without manual intervention. This greatly shortens the communication interruption time, improves the communication recovery efficiency, and reduces the impact on services caused by communication interruptions. In a complex and changeable multi-route switching network environment, the present invention can ensure the continuity and stability of IPSEC communication. By detecting and recovering communication interruptions in a timely manner, it reduces the number of communication failures caused by route changes and improves the reliability of network communication. After testing, the IPSEC packets can be quickly restored after the router successfully switches the WAN. Under complex network conditions, at most one ping packet is lost, and the effect is very good. The present invention is applicable to base station systems, and also applicable to base station plus repeater extended coverage systems, especially applicable to distributed wireless systems, including fiber-optic remote distributed systems, cable remote frequency-shift repeaters, frequency-shift systems, maritime communications, low-altitude communications, etc. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] Figure 1 It is a network topology diagram between the client and the security gateway;
[0034] Figure 2 It is a flowchart of a method for automatically restoring communication of IPSEC based on multi-route switching in the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0035] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0036] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described here can be implemented in an order other than those illustrated or described here. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device including a series of steps or units does not necessarily have to be limited to those clearly listed steps or units, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.
[0037] In a complex and ever-changing network environment, route switching is a common phenomenon. Factors such as the dynamic change of the network topology structure, the fault repair of network devices, and the optimization and adjustment of network traffic may all lead to route switching. When route switching occurs, the traditional IPSEC communication mechanism often has difficulty quickly and effectively adapting to this change, resulting in the interruption of the IPSEC tunnel and the inability to communicate normally. As Figure 1 shown in the network topology diagram between the client and the security gateway, the router has multiple WAN lines to the internet and operates in a primary-backup mode. If a certain WAN in use has a fault, the route will be switched to use the backup WAN line.
[0038] Therefore, there is an urgent need for a method that can automatically adapt to multi-route switching and ensure the automatic connection and recovery of IPSEC communication to meet the strict requirements of modern network communication for security, stability, and reliability.
[0039] Please refer to Figure 2 , the first aspect of the embodiment of the present invention proposes a method for automatically restoring IPSEC communication after multi-route switching, including the following steps:
[0040] Step S1: Negotiate IKE SA parameters between the client and the security gateway.
[0041] It can be understood that the IKE (Internet Key Exchange) protocol is an important part of the IPSEC system and is responsible for establishing a security association (SA) between the two communication parties.
[0042] Step S2: Perform identity authentication and IPsec SA parameter negotiation between the client and the security gateway.
[0043] It can be understood that through this step, it is possible to prevent man-in-the-middle attacks from stealing and tampering with communication information, ensure the authenticity and reliability of the identities of both communication parties, and through further negotiation of IPsec SA parameters, enable both parties to customize the configuration of IPsec SA according to specific communication requirements and security requirements, improving the adaptability and security of communication.
[0044] Step S3: When the identity authentication and IPsec SA parameter negotiation between the client and the security gateway are completed, the IPSEC tunnel is formally established, and the client and the security gateway transmit ESP (Encapsulating Security Payload) encrypted packets through the IPSEC tunnel, and the security gateway records the routing information in the ESP encrypted packets.
[0045] It is understandable that after the identity authentication and the negotiation of IPsec SA parameters are completed, both parties are equipped with the conditions for establishing a secure tunnel. The establishment of the IPSEC tunnel marks the entry of the communication between the two parties into the secure phase, and the user packets are effectively protected during the transmission process. The IPSEC tunnel is realized by establishing a series of security associations (SAs) between the two parties, and these SAs define the security parameters such as the encryption algorithm, key, and authentication method used for the communication between the two parties. The ESP encrypted packet is an important way in the IPSEC protocol to protect data transmission. It ensures the confidentiality, integrity, and availability of the data during the transmission process by encrypting and authenticating the data. The security gateway records the routing information of the ESP packets, which is an important link to ensure the normal progress of the communication, and it ensures that the packets can reach the destination accurately and without error.
[0046] Step S4: The client sends periodic heartbeat messages to the security gateway using ESP packets at a period of t1.
[0047] It is understandable that by receiving the heartbeat messages sent by the client, the security gateway can know the alive state of the client and the validity of the connection in real time. If the security gateway receives the heartbeat message within the expected time, it can be considered that the connection between the client and the security gateway is normal; on the contrary, if the heartbeat message is not received for a long time, it may mean that there is a problem with the connection.
[0048] Step S5: When the security gateway does not receive the ESP packet transmitted by the client within the time t1, it triggers the DPD delay event and sends a DPD message to the client through the IKE packet.
[0049] Specifically, the security gateway listens to the network interface, captures the ESP packets from the client in real time, and records the reception time of the packets. When the security gateway does not receive the ESP packet on time, it actively sends a DPD message. The DPD (Dead Peer Detection) mechanism is a technology used to detect whether the communication peer is alive, and it is realized by periodically sending specific control messages (such as DPD messages). It should be understood that if the routing between the client and the security gateway switches and the routing information changes, but the previous routing information is retained on the security gateway, resulting in the incorrect transmission of the ESP packet after the switch. Since the periodic heartbeat message between the client application and the security gateway is transmitted using ESP packets, the periodic heartbeat message period between the client application and the security gateway is set to t1. That is to say, under normal circumstances, there must be an ESP packet in transmission within the time t1, and if not, it triggers the DPD delay event.
[0050] Step S6: When the client receives a DPD message, it is determined that the route has switched, resulting in the interruption of the IPSEC tunnel. The client and the security gateway re - authenticate and negotiate the IPsec SA parameters to reconstruct the IPSEC tunnel for resuming communication, and the security gateway obtains and applies the new routing information.
[0051] It can be understood that when the client receives a DPD message, it means that IKE packets can be transmitted normally, while ESP packets are interrupted, thus determining that the route has switched, resulting in the interruption of the IPSEC tunnel. At this time, the client and the security gateway re - authenticate and negotiate the IPsec SA parameters to reconstruct the IPSEC tunnel for resuming communication. During the negotiation process, the security gateway retains and applies the new routing information to enable the normal transmission of ESP packets.
[0052] Through the collaborative work of the DPD mechanism and periodic heartbeat messages, the present invention can automatically, real - time, and accurately detect communication interruptions caused by route switching, and quickly and automatically trigger the reconstruction process of the IPSEC tunnel without manual intervention. This greatly shortens the communication interruption time, improves the communication recovery efficiency, and reduces the impact on services caused by communication interruptions. In a complex and changeable multi - route switching network environment, the present invention can ensure the continuity and stability of IPSEC communication. By detecting and recovering communication interruptions in a timely manner, it reduces the number of communication failures caused by route changes and improves the reliability of network communication. After testing, the IPSEC packets can be quickly restored after the router successfully switches the WAN, and at most one ping packet is lost under complex network conditions, and the effect is very good.
[0053] In a preferred solution of this embodiment, the specific method for the client and the security gateway to negotiate IKE SA parameters includes:
[0054] The client sends IKE SA parameters including encryption algorithm, authentication algorithm, and DH group information to the security gateway. These parameters are generated by the client according to its own security policies and configuration requirements, representing the security algorithms and key exchange methods supported by the client.
[0055] After receiving the IKE SA parameters, the security gateway searches for matching parameters in its own configuration database. If the match is successful, it means that both parties have reached an agreement on the security algorithm and key exchange method. The security gateway returns the matching parameters to the client, and the client receives and confirms them. Then, both parties exchange temporary random numbers, and according to the DH algorithm, use the exchanged temporary random numbers and their respective private keys to generate a shared key material for deriving all the keys of the IPsec SA.
[0056] It is understandable that any one of AES-128, AES-256, and 3DES is adopted for the encryption algorithm, which is used to encrypt data to ensure the confidentiality of data during transmission; any one of SHA-1, SHA-256, and SHA-384 is adopted for the verification algorithm, which is used to verify the integrity of data and the authenticity of the source to prevent data from being tampered with and forged; DH Group 14 or DH Group 15 is adopted for the DH group, and the DH (Diffie-Hellman) group is used to implement key exchange, enabling both parties to securely generate a shared key in an insecure network environment. The introduction of a temporary random number increases the randomness and security of key generation, preventing the key from being guessed and cracked; generating a shared key material through DH exchange is the core of the entire process, and this shared key material will serve as the basis for all keys of the subsequent derived IPsec SA, providing guarantee for subsequent secure communication.
[0057] In a preferred solution of this embodiment, the specific method for the client and the security gateway to perform identity authentication and IPsec SA parameter negotiation includes:
[0058] The client sends identity information to the security gateway, and the security gateway uses the negotiated algorithm and key to verify the client's identity and the IKE SA parameter negotiation information exchanged previously. At the same time, both parties further negotiate the parameters of the IPsec SA, including the ESP mode and the key lifetime; the security gateway sends identity information to the client, and the client performs the same verification operation.
[0059] In a preferred solution of this embodiment, the size of t1 is consistent with the time consumed for the router to switch the WAN line.
[0060] It is understandable that when the router switches the WAN line, the network connection will be interrupted. If t1 is set to be consistent with the time consumed for the router to switch the WAN line, then just when the router finishes switching the line, the security gateway will just detect that the "heartbeat" of the client pauses (because the client cannot normally send heartbeat messages during the line switch), thus triggering the DPD delay event, which can promptly detect the abnormality of the network connection, quickly start the recovery mechanism, and minimize the communication interruption time to the greatest extent.
[0061] In this embodiment, the method for the client and the security gateway to transmit ESP encrypted packets through an IPSEC tunnel includes:
[0062] The client encapsulates and encrypts the user's original packet according to the negotiated ESP mode, and then sends it to the security gateway. After receiving the ESP encrypted packet, the security gateway decrypts and verifies it according to the previously negotiated SA parameters to ensure the authenticity and integrity of the packet.
[0063] Specifically, a heartbeat message is usually a simple message that contains only a small amount of identification information and is used to indicate the active state of the client. In this embodiment, the periodic heartbeat message includes the unique identifier of the client and timestamp information.
[0064] A second aspect of the embodiments of the present invention provides a system for automatically restoring communication of IPSEC after multi-routing switching, corresponding to the method for automatically restoring communication of IPSEC after multi-routing switching provided by the above embodiments of the present invention. Since the system for automatically restoring communication of IPSEC after multi-routing switching provided by the embodiments of the present invention corresponds to the method for automatically restoring communication of IPSEC after multi-routing switching provided by the above embodiments of the present invention, the implementation manners of the foregoing method for automatically restoring communication of IPSEC after multi-routing switching are also applicable to the system for automatically restoring communication of IPSEC after multi-routing switching provided by this embodiment.
[0065] Specifically, a system for automatically restoring communication of IPSEC after multi-routing switching includes:
[0066] A first negotiation module, configured to perform IKE SA parameter negotiation between the client and the security gateway.
[0067] A second negotiation module, configured to perform identity authentication and IPsec SA parameter negotiation between the client and the security gateway.
[0068] An IPSEC tunnel establishment module, configured to establish an IPSEC tunnel when the identity authentication and IPsec SA parameter negotiation between the client and the security gateway are completed. The client and the security gateway transmit ESP encrypted packets through the IPSEC tunnel, and the security gateway records the routing information in the ESP encrypted packets.
[0069] A heartbeat message sending module, configured to send a periodic heartbeat message to the security gateway by using ESP packets at a period t1 on the client side.
[0070] A DPD delay event triggering module, configured to trigger a DPD delay event when the security gateway does not receive an ESP packet transmitted by the client within the time t1, and send a DPD message to the client through an IKE packet.
[0071] An IPSEC tunnel reconstruction module, configured to, when the client receives the DPD message, re-perform identity authentication and IPsec SA parameter negotiation between the client and the security gateway to reconstruct the IPSEC tunnel for restoring communication, and the security gateway obtains and applies the new routing information.
[0072] The above-described embodiments are only used to illustrate the technical solutions of the present application, rather than to limit it; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the various embodiments of the present application, and should all be included within the protection scope of the present application.
Claims
1. A method for automatically restoring communication based on IPSEC after multi-route switching, characterized in that: The following steps are involved: IKE SA parameter negotiation between the client and the security gateway; Identity authentication and IPsec SA parameter negotiation between the client and the security gateway; After the client and the security gateway complete identity authentication and IPsec SA parameter negotiation, the IPSEC tunnel is formally established. The client and the security gateway transmit ESP encrypted messages through the IPSEC tunnel, and the security gateway records the routing information in the ESP encrypted messages. The client uses ESP messages to send periodic heartbeat messages to the security gateway at a period of t1, where the length of t1 is consistent with the time it takes for the router to switch WAN lines; When the security gateway does not receive the ESP message transmitted by the client within t1, the DPD delay event is triggered and a DPD message is sent to the client via an IKE message. When the client receives the DPD message, it means that the IKE message can be transmitted normally, but the ESP message is interrupted. Therefore, it is determined that the IPSEC tunnel is interrupted due to routing switching. The client and the security gateway re-authenticate and negotiate IPsec SA parameters to rebuild the IPSEC tunnel and restore communication. During the negotiation process, the security gateway obtains and applies the new routing information to restore the normal transmission of ESP messages.
2. A method for automatically restoring communication based on IPSEC after multi-route switching according to claim 1, characterized in that: The specific methods for IKE SA parameter negotiation between the client and the security gateway include: The client sends the IKE SA parameters including the encryption algorithm, authentication algorithm, and DH group information to the security gateway; After receiving the IKE SA parameters, the security gateway searches for matching parameters in its own configuration database. If the match is successful, the security gateway returns the matching parameters to the client. The client receives and confirms them. The two parties exchange temporary random numbers. Based on the DH algorithm, the two parties use the exchanged temporary random numbers and their respective private keys to generate a shared key material for deriving all keys of the IPsecSA.
3. A method for automatically restoring communication based on IPSEC after multi-route switching according to claim 2, characterized in that: The specific methods for identity authentication and IPsec SA parameter negotiation between the client and the security gateway include: The client sends its identity information to the security gateway, which uses the negotiated algorithm and key to verify the client's identity and the previously exchanged IKE SA parameter negotiation information. At the same time, the two parties further negotiate the parameters of the IPsec SA, including the ESP mode and key lifetime. The security gateway sends its identity information to the client, and the client performs the same verification operation.
4. A method for automatically restoring communication based on IPSEC after multi-route switching according to claim 2, characterized in that: The encryption algorithm adopts any one of AES-128, AES-256, and 3DES.
5. The method for automatically restoring communication based on IPSEC after multi-route switching according to claim 2 is characterized in that: The verification algorithm adopts any one of SHA-1, SHA-256, and SHA-384.
6. A method for automatically restoring communication based on IPSEC after multi-route switching according to claim 2, characterized in that: The DH group used is DH Group 14 or DH Group 15.
7. The method for automatically restoring communication based on IPSEC after multi-route switching according to claim 1 is characterized in that: The method of transmitting ESP encrypted messages between the client and the security gateway through the IPSEC tunnel includes: The client encapsulates and encrypts the user's original message according to the negotiated ESP mode, and then sends it to the security gateway. After receiving the ESP encrypted message, the security gateway decrypts and verifies it according to the previously negotiated SA parameters to ensure the authenticity and integrity of the message.
8. The method of automatically restoring communication based on IPSEC after multi-route switching according to claim 1, characterized in that: The periodic heartbeat message includes the unique identifier and timestamp information of the client.
9. A system based on automatic IPSEC communication recovery after multi-route switching, characterized in that: A method for automatically restoring communication based on IPSEC after multi-route switching according to any one of claims 1 to 8, comprising: A first negotiation module, used for IKE SA parameter negotiation between the client and the security gateway; The second negotiation module is used for identity authentication and IPsec SA parameter negotiation between the client and the security gateway; The IPSEC tunnel establishment module is used to establish an IPSEC tunnel after the identity authentication and IPsec SA parameter negotiation are completed between the client and the security gateway. The client and the security gateway transmit ESP encrypted messages through the IPSEC tunnel, and the security gateway records the routing information in the ESP encrypted messages; A heartbeat message sending module is used to send periodic heartbeat messages to the security gateway at a period of t1 using ESP messages on the client side; DPD delay event triggering module, used to trigger the DPD delay event when the security gateway does not receive the ESP message transmitted by the client within t1 time, and send a DPD message to the client through the IKE message; The IPSEC tunnel reconstruction module is used for re-authentication and IPsec SA parameter negotiation between the client and the security gateway to rebuild the IPSEC tunnel to restore communication when the client receives the DPD message, and the security gateway obtains and applies new routing information.
Citation Information
Patent Citations
IPSEC tunnel recovery method, branch export device and IPSEC VPN system
CN106533881A
Dynamic detection of inactive virtual private network clients
US20160021194A1