Security Protection Method Combining SRv6 SFC Technology with Security Resource Pool
By combining SRv6 SFC technology and security resource pool, targeted and unified network service security protection is achieved, resource waste and management problems in the existing technology are solved, and resource utilization and service satisfaction are improved.
Patent Information
- Application Number
- CN202510398694.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-01
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2045-04-01
AI Technical Summary
In the prior art, the security protection of network services is not targeted and the security equipment is not managed uniformly, resulting in waste of resources and the inability to meet the needs of high-demand services.
Combining SRv6 SFC technology and security resource pool, by obtaining the protection function requirements of network services, selecting suitable protection components, and SFC orchestration through virtualized orchestration networks, generating security function forwarding nodes, and building a business function chain of SRv6 SFC to achieve targeted protection and unified management.
It realizes security protection that can flexibly adjust different network services, improves resource utilization, meets the diversified needs of network services, and simplifies the management and maintenance of security equipment.
Smart Images

Figure CN119906589B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network service security, and in particular to a security protection method combining SRv6 SFC technology and a security resource pool. Background Art
[0002] Currently, for network security protection, most security services are provided by SF (Service Function) service nodes. The service nodes include, but are not limited to, firewall (FW), intrusion prevention system (IPS), load balancing (LB) devices, and network address translation (NAT) devices, etc., to meet the requirements of network security protection. However, multiple service nodes use different security devices, and the combination of the used security devices is fixed. Since network services are diverse, it is obvious that a single combination of security devices cannot meet the needs of all network services. When building a security device combination based on the highest requirements, it will cause waste of security devices when facing low-demand services. When building a security device combination based on average requirements, it will not only cause waste of security devices when facing low-demand services but also cannot meet the requirements of high-demand network services. At the same time, there are defects in terms of difficult unified management and unified operation. In industry scenarios, the defects of unified management and unified operation of multiple types and large quantities of security protection nodes are particularly obvious.
[0003] In the prior art, there are security protection methods based on network virtualization technology. However, in the process of security protection, the existing methods rely on querying the routing table and encapsulation and decapsulation operations of additional protocols for tunnels. When facing large-scale network expansion and complex security requirements, significant architecture adjustments and resource investments are required, and they cannot adapt to the rapidly changing network environment, having limitations. Summary of the Invention
[0004] In view of this, the present invention provides a security protection method combining SRv6 SFC technology and a security resource pool to solve the problems of lack of pertinence in the security protection of network services and lack of unified management for security devices in the prior art.
[0005] In a first aspect, an embodiment of the present invention provides a security protection method combining SRv6 SFC technology and a security resource pool. The method includes:
[0006] Obtain the protection function requirements, data transmission nodes, and data flow information of the target network service;
[0007] Select a target protection component from a preset security resource pool according to the protection function requirements, and perform SFC orchestration on the target protection component through a virtualized orchestration network to generate a security function forwarding node;
[0008] Through the SRv6 technology, a service function chain of SRv6 SFC is constructed according to the data flow information, the data transmission node, and the security function forwarding node, and the service data of the target network service is transmitted according to the service function chain of the SRv6 SFC;
[0009] The step of transmitting the service data of the target network service according to the service function chain of the SRv6 SFC includes:
[0010] At the head node of the SRv6 network, path information of the SRv6 TE Policy is added to the original IPv6 packet of the service data, and an SRH extension header is added to the original IPv6 packet to obtain a new packet, and the SRH extension header stores Segment List information;
[0011] Control the service data and the new packet to pass through the next node of the head node according to the path information;
[0012] When the next node of the head node corresponds to the security function forwarding node, control the security function forwarding node to match the destination IPv6 address;
[0013] If the new packet hits the local SID of the security function forwarding node, perform the action corresponding to the local SID on the service data to obtain target service data, and forward the target service data according to the path information; extract the attribute data of the new packet, match the attribute data with the in-tunnel detection policy, and if the match passes, send the service data to the in-tunnel detection module for protection detection;
[0014] If the new packet does not hit the local SID of the security function forwarding node, extract the attribute data of the new packet, and match the attribute data with the in-tunnel detection policy; if the match fails, forward the service data and the new packet according to the path information;
[0015] Perform decapsulation processing on the service data and the new packet after matching with the in-tunnel detection policy to obtain an IPv6 packet with the SRH extension header removed, and identify the packet type of the IPv6 packet with the SRH extension header removed. If the packet type of the IPv6 packet with the SRH extension header removed is still a tunnel packet, continue to perform decapsulation processing on the IPv6 packet with the SRH extension header until a service packet is obtained;
[0016] The step of, if the new packet hits the local SID of the security function forwarding node, performing the action corresponding to the local SID on the service data to obtain target service data includes:
[0017] Send the service data to the first target protection component corresponding to the local SID in the security function forwarding node, so that the first target protection component performs the action corresponding to the local SID on the service data to obtain primary service data;
[0018] Send the primary service data to the security function forwarding node, and send the primary service data to the second target protection component in the security function forwarding node that executes the local SID, so that the second target protection component performs the action corresponding to the local SID on the primary service data to obtain secondary service data, until the last target protection component in the security function forwarding node completes the security protection of the service data to obtain the target service data.
[0019] Optionally, the step of obtaining the protection function requirements of the target network service includes:
[0020] Determine the data transmission nodes and the data transmission relationships between different data transmission nodes according to the data flow information;
[0021] Determine the basic protection requirement data between different data transmission nodes based on the data transmission relationship;
[0022] Obtain the preset protection requirement data of the user between different data transmission nodes, and integrate the preset protection requirement data and the basic protection requirement data to obtain the protection function requirements between different data transmission nodes.
[0023] Optionally, before the step of selecting the target protection component in the preset security resource pool according to the protection function requirements, it further includes:
[0024] Decouple the preset protection components through the Openstack architecture to obtain the underlying protection component resources corresponding to the preset protection components, and the preset protection components include physical network security devices and virtual network security devices;
[0025] Build a resource management platform for managing the underlying protection component resources through software programming;
[0026] Build the preset security resource pool based on the resource management platform and the underlying protection component resources.
[0027] Optionally, the step of selecting the target protection component in the preset security resource pool according to the protection function requirements and performing SFC orchestration on the target protection component through virtualized orchestration network to generate the security function forwarding node includes:
[0028] Select the preset components that can meet the protection function requirements in the preset security resource pool as the target protection components;
[0029] Create an SFC for the target network service based on the logical order among the target protection components and different target protection components, where the logical order is determined according to the functions of the target protection components;
[0030] Through virtualized orchestration network, orchestrate the target protection components according to the SFC to generate a security function forwarding node including at least one target protection component, so that the service data flows through each target protection component in the logical order.
[0031] Optionally, the step of constructing the service function chain of the SRv6 SFC according to the data flow information, the data transmission node and the security function forwarding node by the SRv6 technology includes:
[0032] According to the data flow information, connect the addresses of the data transmission node and the security function forwarding node to obtain different network segments;
[0033] According to a preset protocol, make each network segment reachable through a preset route, and perform SRv6 SID planning on the preset route and the network orchestrator by the SRv6 technology to obtain the planned preset route and the planned security function forwarding node, so that the planned preset route and the planned security function forwarding node support the SRv6 SFC function;
[0034] Dynamically announce the route of the SRv6 Locator in the planned security function forwarding node by the IGP method;
[0035] Configure the TE-Policy of the route of the SRv6 Locator according to the data flow information to construct the service function chain of the SRv6 SFC.
[0036] Optionally, the step of transmitting the service data of the target network service according to the service function chain of the SRv6 SFC includes:
[0037] Add the path information of the SRv6 TE Policy to the original IPv6 packet of the service data at the head node of the SRv6 network, and add an SRH extension header to the original IPv6 packet to obtain a new packet, where the SRH extension header stores Segment List information;
[0038] Control the service data and the new packet to pass through the next node of the head node according to the path information;
[0039] When the next node of the head node corresponds to the security function forwarding node, control the security function forwarding node to match the destination IPv6 address;
[0040] If the new packet hits the local SID of the security function forwarding node, perform the actions corresponding to the local SID on the service data to obtain target service data, and forward the target service data according to the path information; match the attribute data with the in-tunnel detection policy, and if the match passes, send the service data to the in-tunnel detection module for protection detection;
[0041] If the new packet does not hit the local SID of the security function forwarding node, extract the attribute data of the new packet, and match the attribute data with the in-tunnel detection policy; if the match fails, forward the service data and the new packet according to the path information;
[0042] Perform decapsulation processing on the service data and the new packet after matching with the in-tunnel detection policy to obtain an IPv6 packet with the SRH extension header removed, and identify the packet type of the IPv6 packet with the SRH extension header removed. If the packet type of the IPv6 packet with the SRH extension header removed is still a tunnel packet, continue to perform decapsulation processing on the IPv6 packet with the SRH extension header until a service packet is obtained.
[0043] Optionally, the step of, if the new packet hits the local SID of the security function forwarding node, performing the actions corresponding to the local SID on the service data to obtain target service data includes:
[0044] Send the service data to the first target protection component corresponding to the local SID in the security function forwarding node, so that the first target protection component performs the actions corresponding to the local SID on the service data to obtain primary service data;
[0045] Send the primary service data to the security function forwarding node, and send the primary service data to the second target protection component in the security function forwarding node that executes the local SID corresponding action, so that the second target protection component performs the actions corresponding to the local SID on the primary service data to obtain secondary service data, until the last target protection component in the security function forwarding node completes the security protection of the service data to obtain target service data.
[0046] In a second aspect, an embodiment of the present invention further provides an electronic device, where the electronic device includes:
[0047] One or more processors;
[0048] A storage device for storing one or more programs;
[0049] When the one or more programs are executed by the one or more processors, the one or more processors implement the security protection method combining SRv6 SFC technology and a security resource pool in any of the embodiments of the present invention.
[0050] In a third aspect, an embodiment of the present invention further provides a storage medium containing computer-executable instructions, and the computer-executable instructions are used to execute the security protection method combining SRv6 SFC technology and a security resource pool in any of the embodiments of the present invention when executed by a computer processor.
[0051] The technical solution of the embodiment of the present invention can flexibly adjust the security protection function when planning the service data transmission path by combining SRv6 SFC technology and a security resource pool, and perform targeted protection on different service data. At the same time, the unique advantages of SRv6 technology in terms of network programmability and flexibility do not rely on tunnel encapsulation of additional protocols when transmitting data, and have better adaptability, flexibility, and scalability for large-scale network scenarios. The security resource pool can uniformly manage different security components, and at the same time, can flexibly build different combinations of security components according to different requirements, that is, build a combination of security components for specific network services, save costs on the premise of meeting the needs of network services. Specifically, according to the actual network security requirements, the security components can be allocated to the network services that most need them, improving resource utilization rate, and the security resource pool can more quickly meet the security requirements of network services. BRIEF DESCRIPTION OF THE DRAWINGS
[0052] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention, and those of ordinary skill in the art can obtain other drawings without creative efforts based on these drawings.
[0053] Among them:
[0054] Figure 1 It is a schematic flowchart of a security protection method combining SRv6 SFC technology and a security resource pool in an embodiment;
[0055] Figure 2 It is an operation scenario diagram of a security protection method combining SRv6 SFC technology and a security resource pool in an embodiment;
[0056] Figure 3 It is a schematic diagram of the operation of a security resource pool in a security protection method combining SRv6 SFC technology and a security resource pool in an embodiment;
[0057] Figure 4 It is a schematic structural diagram of an electronic device provided by an embodiment of the present application;
[0058] Figure 5 It is a schematic structural diagram of a computer-readable storage medium provided by an embodiment of the present application. Specific embodiments
[0059] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0060] In one embodiment, the present invention provides a security protection method combining SRv6 SFC technology and a security resource pool. The security protection method combining SRv6 SFC technology and a security resource pool in the embodiments of the present invention can be executed by a security protection device combining SRv6 SFC technology and a security resource pool. The security protection device combining SRv6 SFC technology and a security resource pool can be implemented by software and / or hardware.
[0061] As Figure 1 shown, the security protection method combining SRv6 SFC technology and a security resource pool in the embodiments of the present invention specifically includes the following steps:
[0062] S110. Obtain the protection function requirements, data transmission nodes, and data flow information of the target network service;
[0063] In a possible implementation manner, the step of obtaining the protection function requirements of the target network service includes:
[0064] Determine the data transmission nodes and the data transmission relationships between different data transmission nodes according to the data flow information;
[0065] Based on the data transmission relationships, determine the basic protection requirement data between different data transmission nodes;
[0066] Obtain the preset protection requirement data of the user for different data transmission nodes, and integrate the preset protection requirement data and the basic protection requirement data to obtain the protection function requirements between different data transmission nodes.
[0067] Exemplarily, the data flow information characterizes the data flow information during the execution of the target network service. For example, during the execution of the target network service, the data flow flows from end A to end B, and then from end B to end C. Then, ends A, B, and C are data transmission nodes, and the data transmission relationships between different data transmission nodes are from end A to end B and from end B to end C.
[0068] Exemplarily, due to differences in data transmission nodes, the basic protection requirement data between different data transmission nodes is also different. Therefore, it is necessary to determine the basic protection requirement data between different data transmission nodes according to the actual data transmission relationships (such as from the server to the client, from the server to the server).
[0069] Exemplarily, in practical applications, users will also set the security protection requirements between different data transmission nodes according to actual needs. For example, they pay to purchase different types of security components and use the purchased security components between specific data transmission nodes. Therefore, the preset protection requirement data and the basic protection requirement data are integrated to obtain the protection requirement data between different data transmission nodes, ensuring user requirements.
[0070] S120. Select a target protection component from a preset security resource pool according to the protection function requirement, and perform SFC orchestration on the target protection component through a virtualized orchestration network to generate a security function forwarding node;
[0071] In a possible implementation manner, the step of selecting a target protection component from a preset security resource pool according to the protection function requirement and performing SFC orchestration on the target protection component through a virtualized orchestration network to generate a security function forwarding node includes:
[0072] Select a preset protection component that can meet the protection function requirement from the preset security resource pool as the target protection component;
[0073] Create an SFC for the target network service based on the target protection component and the logical order between different target protection components, where the logical order is determined according to the functions of the target protection components;
[0074] Through the virtualized orchestration network, orchestrate the target protection component according to the SFC to generate a security function forwarding node including at least one target protection component, so that the service data flows through each target protection component in the logical order.
[0075] Specifically, the logical order between different target protection components, for example, security function forwarding node - vICG
[0076] —vWAF—vIPS, the resource management platform will send the SFC forwarding table to the virtual switch and configure relevant traffic diversion policies (realize SFC orchestration through virtualized orchestration network) to precisely divert service data to the security service chains of different tenants. The specific process is as follows: The security function forwarding node sends the service data to the virtual switch and the service traffic to the first security component. After the first security component performs security protection, it sends the service traffic to the virtual switch and forwards it to the security function forwarding node. The security function forwarding node sends the service traffic to the second security component in the same way, and so on until all target security components have completed the security protection of the service data.
[0077] S130. Through the SRv6 technology, construct the service function chain of the SRv6 SFC according to the data flow information, the data transmission node, and the security function forwarding node, and transmit the service data of the target network service according to the service function chain of the SRv6 SFC.
[0078] By combining the SRv6 SFC technology with the security resource pool, it is possible to flexibly adjust the security protection function when planning the service data transmission path, and perform targeted protection on different service data. At the same time, the unique advantages of the SRv6 technology in network programmability and flexibility do not rely on the tunnel encapsulation of additional protocols during data transmission, and it has better adaptability, flexibility, and scalability for large-scale network scenarios. The security resource pool can uniformly manage different security components. At the same time, it can also flexibly build different combinations of security components according to different needs, that is, build a combination of security components for specific network services, save costs on the premise of meeting the needs of network services. Specifically, it can also allocate security components to the network services that most need them according to the actual network security requirements, improve resource utilization rate, and can more quickly meet the security requirements of network services through the security resource pool.
[0079] In a possible implementation manner, before the step of selecting the target protection component in the preset security resource pool according to the protection function requirement, it further includes:
[0080] Decouple the preset protection component through the Openstack architecture to obtain the underlying protection component resources corresponding to the preset protection component. The preset protection component includes physical network security devices and virtual network security devices;
[0081] Build a resource management platform for managing the underlying protection component resources through software programming;
[0082] Build the preset security resource pool based on the resource management platform and the underlying protection component resources.
[0083] Exemplarily, the Openstack architecture is adopted as the underlying support technology for the virtualization resource pool, decoupling physical and virtual network security devices from their access modes, deployment methods, and implemented functions, and abstracting them as security components (underlying protection component resources) in the security resource pool at the bottom layer.
[0084] Exemplarily, through software programming in a unified manner, intelligent and automated service orchestration and management are carried out to build a resource management platform for implementing corresponding security functions. The resource management platform is used for the life cycle management, authorization activation, log collection, and security policies of local security components, and the resource management platform also provides functions such as tenant management, order work order approval, self-service, metering and billing for system users. The resource management platform provides a self-service portal and a system management portal for tenants, which are distinguished according to different login roles.
[0085] Exemplarily, as shown in Table 1, the preset protection components include but are not limited to: host security protection components, firewalls, database audit systems, bastion hosts, Web anti-tampering components, log audit components, network security audit components, intrusion detection cloud probe components, cloud vulnerability scanning components, etc.
[0086] Table 1
[0087]
[0088] In a possible implementation manner, the step of constructing the service function chain of SRv6 SFC according to the data flow information, the data transmission node, and the security function forwarding node through the SRv6 technology includes:
[0089] According to the data flow information, connect the addresses of the data transmission node and the security function forwarding node to obtain different network segments;
[0090] According to a preset protocol, make each network segment reachable through a preset route, and perform SRv6 SID planning on the preset route and the network orchestrator through the SRv6 technology to obtain the planned preset route and the planned security function forwarding node, so that the planned preset route and the planned security function forwarding node support the SRv6 SFC function;
[0091] Dynamically announce the route of SRv6Locator in the planned security function forwarding node through the IGP method;
[0092] Configure the TE Policy of the route of SRv6Locator according to the data flow information to construct the service function chain of SRv6 SFC.
[0093] Exemplarily, such as Figure 2As shown in the figure, the steps to construct the service function chain of SRv6 SFC include:
[0094] Step 1: Plan the interface addresses of each router.
[0095] The interface address of R1 is 100::1 / 64, 200::1 / 64;
[0096] The interface address of R2 is 200::2 / 64, 300::2 / 64;
[0097] The interface addresses of the security function forwarding node are eth1 100::2 / 64, eth2 300::1 / 64;
[0098] The eth1 of R1 is connected to the eth1 of the security function forwarding node interface address;
[0099] The eth1 of R2 is connected to the eth2 of the security function forwarding node interface address;
[0100] Step 2: Configure the basic routing to make the IPv6 network connected. The routes of each network segment can be reachable through IGP routing. It is recommended to use the IS-IS protocol;
[0101] Step 3: Plan the SRv6 SID and enable the SRv6 function on R1, R2, and the security function forwarding node;
[0102] R1 configures Locator fc01:: and configures End.DT4 opcode::1
[0103] The security function forwarding node configures Locator fc02:: and configures End.DT4 opcode ::1
[0104] R2 configures Locator fc03:: and configures End.DT4 opcode ::1
[0105] Step 4: Configure the SID routing. The routes of SRv6 Locator can be dynamically announced through the IGP method;
[0106] Step 5: Configure the TE-Policy;
[0107] Configure the TE-Policy on R1 as 22.22.22.0 / 24 via [fc02::1 fc03::1] dev eth1;
[0108] Configure the TE-Policy on R2 as 11.11.11.0 / 24 via [fc02::1 fc01::1] dev eth1.
[0109] In a possible implementation manner, the step of transmitting the service data of the target network service according to the service function chain of the SRv6 SFC includes:
[0110] Adding the path information of the SRv6 TE Policy to the original IPv6 packet of the service data at the head node of the SRv6 network, and adding an SRH extension header to the original IPv6 packet to obtain a new packet, where the SRH extension header stores Segment List information;
[0111] Controlling the service data and the new packet to pass through the next node of the head node according to the path information;
[0112] When the next node of the head node corresponds to the security function forwarding node, controlling the security function forwarding node to match the destination IPv6 address;
[0113] If the new packet hits the local SID of the security function forwarding node, performing the action corresponding to the local SID on the service data to obtain the target service data, and forwarding the target service data according to the path information; extracting the attribute data of the new packet, matching the attribute data with the in-tunnel detection policy, and if the matching is passed, sending the service data to the in-tunnel detection module for protection detection;
[0114] If the new packet does not hit the local SID of the security function forwarding node, extracting the attribute data of the new packet, and matching the attribute data with the in-tunnel detection policy; if the matching fails, forwarding the service data and the new packet according to the path information;
[0115] Performing a decapsulation process on the service data and the new packet after matching with the in-tunnel detection policy to obtain an IPv6 packet with the SRH extension header removed, and identifying the packet type of the IPv6 packet with the SRH extension header removed. If the packet type of the IPv6 packet with the SRH extension header removed is still a tunnel packet, continue to perform the decapsulation process on the IPv6 packet with the SRH extension header until a service packet is obtained.
[0116] Exemplarily, add the path information [fc02::1 fc03::1] of the SRv6 TE Policy to the original message to guide the message to pass through each service node in sequence according to the specified path. Among them, the service node fc02::1 is a security function forwarding node. The path of the source route reaches the security function forwarding node fc02::1. The security function forwarding node, as the proxy of the security resource pool, mainly includes the SRv6 protocol module, the detection policy within the SRv6 tunnel, and the tunnel de-encapsulation and encapsulation modules. The security function forwarding node matches the destination IPv6 address. If the local SID is hit, it executes the action corresponding to the SID. For example, query the specified MAC forwarding table during layer 2 communication, or query the specified routing table during layer 3 communication. Extract the attributes of the message and match the detection policy within the tunnel. For the SRv6 traffic that does not hit the policy, it is directly forwarded; for the SRv6 traffic that hits the detection policy within the tunnel, it is sent to the in-tunnel detection module for further security protection. The message attributes include the source address, the real destination address, that is, segments[0] of the SRv6 extension header, the security domain of the incoming interface, and the security domain of the outgoing interface. De-encapsulate the SRv6 message. For the IPv6 message after stripping the SRv6 extension header, if it is an ordinary service message, security protection is performed on it. If this IPv6 message is still a tunnel message, continue to perform tunnel de-encapsulation on it until it is de-encapsulated into an ordinary service message with a source address of 11.11.11.1 and a destination address of 22.22.22.1.
[0117] Exemplarily, an IPv6 message is composed of an IPv6 standard header + extension headers (0 to n) + payload. To implement Segment Routing based on the IPv6 forwarding plane, a new type is added to the IPv6 routing extension header (Routing Header, RH), called the SRH (Segment Routing Header) extension header. This extension header specifies an explicit path of IPv6 and stores the IPv6 Segment List information.
[0118] The head node adds an SRH extension header to the IPv6 message, and the intermediate node can forward it according to the path information contained in the SRH extension header.
[0119] IPv6 Destination Address, the destination address of the IPv6 message, abbreviated as IPv6 DA. In an ordinary IPv6 message, the IPv6 DA is fixed. In SRv6, the IPv6 DA only identifies the next node of the current message and is constantly changing.
[0120] The segment list of an SRv6 packet, similar to the MPLS label stack information in SR-MPLS, is generated at the ingress node. SegmentList [n] is the first Segment List to be processed on the SRv6 path; Segment List [n-1] is the second; Segment List [1] is the second last; Segment List [0] is the last.
[0121] In <Segment List [0], Segment List [1], ..., Segment List [n-1], SegmentList [n]>, the SID sorting is in reverse order. Sometimes, () is used for forward order writing, i.e., (Segment List [n], Segment List [n-1], ..., Segment List [1], Segment List [0]).
[0122] In SRv6, every time an SRv6 node is passed through, the Segment Left (SL) field is decremented by 1, and the IPv6 DA information is changed once. The Segment Left and Segment List fields jointly determine the IPv6 DA information.
[0123] If the SL value is n, then the IPv6 DA value is the value of SID [n].
[0124] If the SL value is n-1, then the IPv6 DA value is the value of SID [n-1]. ...
[0126] If the SL value is 1, then the IPv6 DA value is the value of SID [1].
[0127] If the SL value is 0, then the IPv6 DA value is the value of SID [0].
[0128] An SRv6 Segment is in the form of an IPv6 address and is usually also called an SRv6 SID (Segment Identifier).
[0129] The SRv6 TE Policy is a new tunnel drainage technology developed based on the SRv6 technology. The SRv6 TE Policy path is represented as a list of segments (Segment List) of the specified path, called the SID list (Segment ID List). Each SID list is an end-to-end path from the source to the destination and instructs the devices in the network to follow the specified path instead of the shortest path calculated by the IGP. If a data packet is imported into the SRv6 TE Policy, the SID list is added to the data packet by the head-end, and the remaining devices in the network execute the instructions embedded in the SID list. The path orchestration of the SRv6 Policy can be generated in various ways, mainly including static path specification, head-node path calculation, and controller path calculation.
[0130] The paths formed by different path calculation methods can be installed into the same SRv6 Policy and are reflected by different Candidate Paths. According to the default or manually specified priority, the SRv6 Policy will select an available one from the available Candidate Paths. This design enables the service to use the SRv6 Policy without caring about the details of the path calculation method. The service only needs to care about its own requirements for the network, encapsulating the details of path calculation and selection inside the SRv6 Policy, which simplifies the interaction between the service and the network.
[0131] Exemplarily, SFC generally refers to a sequence composed of a group of SF (Service Function) nodes. To meet specific commercial, security, and other requirements, for a specified service flow, it is usually required to be processed through a specified SF sequence during forwarding.
[0132] The forwarding principle of SFC based on the SRv6 TE Policy: The SRv6 TE Policy instructs the devices in the network to forward along the specified path through the Segment List, which is very suitable for the service chaining scenario. If a data packet is redirected to the SRv6 TE Policy, the Segment List of the SRv6 TE Policy is added to the data packet by the head-end, and the remaining devices in the network execute the instructions embedded in the Segment List.
[0133] In a possible implementation manner, the step of, if the new packet hits the local SID of the security function forwarding node, performing the action corresponding to the local SID on the service data to obtain the target service data includes:
[0134] Send the service data to the first target protection component corresponding to the local SID in the security function forwarding node, so that the first target protection component performs the action corresponding to the local SID on the service data to obtain primary service data;
[0135] Send the primary service data to the security function forwarding node, and send the primary service data to the second target protection component in the security function forwarding node that executes the local SID, so that the second target protection component performs the action corresponding to the local SID on the primary service data to obtain secondary service data, until the last target protection component in the security function forwarding node completes the security protection of the service data to obtain the target service data.
[0136] Exemplarily, as Figure 3 shown, SFC orchestration is achieved through virtualized orchestration network, and at the same time, relevant traffic steering policies are configured to finely steer service traffic to the security service chains of different tenants. The specific process is as follows: The security function forwarding node sends service data to the virtual switch, and sends service traffic to the first security component. After the first security component performs security protection, it sends the service traffic to the virtual switch and forwards it to the security function forwarding node. The security function forwarding node sends the service traffic to the second security component in the same way, and so on, until all target security components have completed the security protection of the service data. The security function forwarding node will re-encapsulate the IPv6 packet and insert the SRH extension header to restore it to SRv6 traffic, and continue to forward it according to the path information of the SRv6 TE Policy.
[0137] In a possible implementation manner, the method further includes:
[0138] Obtain the working status of each target protection component in the security function forwarding node, and identify the health information of the target protection component based on the working status;
[0139] If the health information of the target protection component is a fault, then remove the target protection component in the security function forwarding node.
[0140] Exemplarily, the security function forwarding node will enable the loopback detection function. When any security component on the service chain fails, the security function forwarding node will skip this security component, and other security components on the service chain will not be affected, ensuring continuous business without interruption. Specifically, the health information of the target security component obtained by the loopback detection function is displayed on the resource management platform.
[0141] In another embodiment of the present invention, an electronic device is further provided. Figure 4The block diagram of an exemplary electronic device 50 suitable for implementing the embodiments of the present invention is shown. Figure 4 The shown electronic device 50 is merely an example and should not impose any limitation on the functions and usage scope of the embodiments of the present invention.
[0142] As Figure 4 shown, the electronic device 50 is presented in the form of a general-purpose computing device. The components of the electronic device 50 may include, but are not limited to: one or more processors or processing units 501, a system memory 502, and a bus 503 connecting different system components (including the system memory 502 and the processing unit 501).
[0143] The bus 503 represents one or more of several types of bus architectures, including a memory bus or memory controller, a peripheral bus, a graphics acceleration port, a processor, or a local bus using any of the multiple bus architectures. For example, these architectures include, but are not limited to, Industry Standard Architecture (ISA) bus, Micro Channel Architecture (MAC) bus, Enhanced ISA bus, Video Electronics Standards Association (VESA) local bus, and Peripheral Component Interconnect (PCI) bus.
[0144] The electronic device 50 typically includes a variety of computer system-readable media. These media can be any available media accessible by the electronic device 50, including volatile and non-volatile media, removable and non-removable media.
[0145] The system memory 502 may include computer system-readable media in the form of volatile memory, such as random access memory (RAM) 504 and / or cache memory 505. The electronic device 50 may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, a storage system 506 can be used to read and write non-removable, non-volatile magnetic media ( Figure 4 not shown, typically referred to as a "hard disk drive"). Although Figure 4 not shown in the figure, a disk drive for reading and writing removable non-volatile disks (such as "floppy disks"), and an optical disk drive for reading and writing removable non-volatile optical disks (such as CD-ROM, DVD-ROM, or other optical media) can be provided. In these cases, each drive can be connected to the bus 503 through one or more data media interfaces. The memory 502 may include at least one program product having a set (e.g., at least one) of program modules configured to perform the functions of the embodiments of the present invention.
[0146] A program / utilities 508 having a set (at least one) of program modules 507 can be stored, for example, in a memory 502. Such program modules 507 include, but are not limited to, an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include an implementation of a network environment. The program modules 507 generally execute the functions and / or methods in the embodiments described in the present invention.
[0147] The electronic device 50 can also communicate with one or more external devices 509 (such as a keyboard, a pointing device, a display 510, etc.), and can also communicate with one or more devices that enable a user to interact with the electronic device 50, and / or communicate with any device that enables the electronic device 50 to communicate with one or more other computing devices (such as a network card, a modem, etc.). Such communication can be carried out through an input / output (I / O) interface 511. Moreover, the electronic device 50 can also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through a network adapter 512. As shown in the figure, the network adapter 512 communicates with other modules of the electronic device 50 through a bus 503. It should be understood that although Figure 4 not shown in the figure, other hardware and / or software modules can be used in combination with the electronic device 50, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.
[0148] The processing unit 501 executes various functional applications and data processing by running programs stored in the system memory 502, for example, implementing the security protection method combining the SRv6 SFC technology and the security resource pool provided by the embodiments of the present invention.
[0149] In another embodiment of the present invention, as Figure 5 shown, there is also provided a storage medium 400 containing a computer program 411, and the computer program 411 is used to execute a security protection method combining the SRv6 SFC technology and the security resource pool when executed by a computer processor. The method includes:
[0150] Obtaining the protection function requirements, data transmission nodes, and data flow information of the target network service;
[0151] Selecting a target protection component in a preset security resource pool according to the protection function requirements, and performing SFC orchestration on the target protection component through a virtualized orchestration network to generate a security function forwarding node;
[0152] Through the SRv6 technology, a service function chain of the SRv6 SFC is constructed according to the data flow information, the data transmission node, and the security function forwarding node, and the service data of the target network service is transmitted according to the service function chain of the SRv6 SFC.
[0153] The computer storage medium of the embodiments of the present invention may adopt any combination of one or more computer-readable media. The computer-readable media may be a computer-readable signal medium or a computer-readable storage medium. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (non-exhaustive list) of the computer-readable storage medium include: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this document, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.
[0154] The computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries the computer-readable program code. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium may also be any computer-readable medium other than the computer-readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device.
[0155] The program code contained on the computer-readable medium can be transmitted by any appropriate medium, including but not limited to wireless, wire, optical fiber, RF, etc., or any suitable combination of the above.
[0156] Computer program code for performing the operations of the embodiments of the present invention may be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., by connecting through the Internet using an Internet service provider).
[0157] The above disclosure is only for the preferred embodiments of the present invention, and of course, it cannot be used to limit the scope of the rights of the present invention. Therefore, equivalent changes made according to the claims of the present invention still fall within the scope covered by the present invention.
Claims
1. A security protection method combining SRv6 SFC technology with a security resource pool, characterized in that: include: Obtain the protection function requirements, data transmission nodes and data flow information of the target network business; Select a target protection component in a preset security resource pool according to the protection function requirement, and perform SFC orchestration on the target protection component through a virtualized orchestration network to generate a security function forwarding node; By using SRv6 technology, a service function chain of SRv6 SFC is constructed according to the data flow information, the data transmission node and the security function forwarding node, and the service data of the target network service is transmitted according to the service function chain of SRv6 SFC; The step of transmitting the service data of the target network service according to the service function chain of the SRv6 SFC comprises: Adding the path information of the SRv6 TE Policy to the original IPv6 message of the service data at the head node of the SRv6 network, and adding an SRH extension header to the original IPv6 message to obtain a new message, wherein the SRH extension header stores the Segment List information; Controlling the service data and the new message to pass through the next node of the head node according to the path information; When the next node of the head node corresponds to the security function forwarding node, controlling the security function forwarding node to match the destination IPv6 address; If the new message hits the local SID of the security function forwarding node, the action corresponding to the local SID is executed on the service data to obtain the target service data, and the target service data is forwarded according to the path information; the attribute data of the new message is extracted, and the attribute data is matched with the in-tunnel detection strategy. If the match is successful, the service data is sent to the in-tunnel detection module for protection detection; If the new message does not hit the local SID of the security function forwarding node, extract the attribute data of the new message and match the attribute data with the detection policy in the tunnel; if the match fails, forward the service data and the new message according to the path information; Decapsulating the service data and the new message after matching the in-tunnel detection strategy to obtain the IPv6 message without the SRH extension header, and identifying the message type of the IPv6 message without the SRH extension header; if the message type of the IPv6 message without the SRH extension header is still a tunnel message, continuing to decapsulate the IPv6 message with the SRH extension header until the service message is obtained; If the new message hits the local SID of the security function forwarding node, the step of performing an action corresponding to the local SID on the service data to obtain the target service data includes: Sending the service data to a first target protection component corresponding to the local SID in the security function forwarding node, so that the first target protection component performs an action corresponding to the local SID on the service data to obtain primary service data; The primary business data is sent to the security function forwarding node, and the primary business data is sent to the second target protection component corresponding to the local SID in the security function forwarding node, so that the second target protection component executes the action corresponding to the local SID on the primary business data to obtain secondary business data, until the last target protection component in the security function forwarding node completes the security protection of the business data and obtains the target business data.
2. The method according to claim 1, characterized in that The step of obtaining the protection function requirement of the target network service includes: Determine the data transmission node and the data transmission relationship between different data transmission nodes according to the data flow information; Determine basic protection requirement data between different data transmission nodes based on the data transmission relationship; The user's preset protection requirement data for different data transmission nodes is obtained, and the preset protection requirement data and the basic protection requirement data are integrated to obtain the protection function requirements between different data transmission nodes.
3. The method according to claim 1, characterized in that Before the step of selecting a target protection component in a preset security resource pool according to the protection function requirement, the method further includes: Decoupling the preset protection components through the Openstack architecture to obtain underlying protection component resources corresponding to the preset protection components, wherein the preset protection components include physical network security devices and virtual network security devices; Constructing a resource management platform for managing the resources of the underlying protection components by means of software programming; The preset security resource pool is built based on the resource management platform and the underlying protection component resources.
4. The method according to claim 1, characterized in that: The step of selecting a target protection component in a preset security resource pool according to the protection function requirement, and performing SFC orchestration on the target protection component through a virtualized orchestration network to generate a security function forwarding node includes: Selecting a preset protection component that can meet the protection function requirements in a preset security resource pool as the target protection component; Creating an SFC for the target network service based on the target protection component and a logical order between different target protection components, wherein the logical order is determined according to functions of the target protection components; Through the virtualized orchestration network, the target protection components are orchestrated according to the SFC, and a security function forwarding node including at least one target protection component is generated, so that the business data flows through each target protection component in the logical order.
5. The method according to claim 1, characterized in that: The step of building a service function chain of the SRv6 SFC according to the data flow information, the data transmission node and the security function forwarding node by using the SRv6 technology includes: According to the data flow information, the address of the data transmission node and the address of the security function forwarding node are connected to obtain different network segments; According to the preset protocol, each network segment route is made reachable through the preset route, and the preset route and the network orchestrator are SRv6 SID planned through the SRv6 technology to obtain the planned preset route and the planned security function forwarding node, so that the planned preset route and the planned security function forwarding node support the SRv6 SFC function; Dynamically announce the SRv6Locator route in the planned security function forwarding node through IGP; The TE Policy of the SRv6Locator route is configured according to the data flow information, and the service function chain of the SRv6 SFC is constructed.
6. The method according to claim 1, characterized in that The method further comprises: Obtaining the working status of each target protection component in the security function forwarding node, and identifying health information of the target protection component based on the working status; If the health information of the target protection component is faulty, the target protection component is removed from the security function forwarding node.
7. An electronic device, characterized in that: The electronic device comprises: One or more processors; A storage device for storing one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the security protection method combining the SRv6 SFC technology and the security resource pool as described in any one of claims 1-6.
8. A storage medium containing computer executable instructions, characterized in that: The computer executable instructions, when executed by a computer processor, are used to execute the security protection method combining the SRv6 SFC technology with a security resource pool as described in any one of claims 1-6.
Citation Information
Patent Citations
Flow arrangement method and device for solving security resource pool through SRv6
CN115914072A
Service chain deployment method and device, security pool gateway and security orchestrator
CN116488839A