Secure programmable in-band network telemetering method and system based on programmable switch P4
By using P4 switches to encrypt and protect the telemetry data in in-band network telemetry and dynamically adjusting the encryption algorithm, the problems of in-band network telemetry data security threats and performance balance are solved, and efficient and secure telemetry data transmission is achieved.
Patent Information
- Application Number
- CN202510101635.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-22
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2045-01-22
AI Technical Summary
The existing in-band network telemetry data poses a security threat and it is difficult to effectively balance security and transmission performance.
The secure programmable in-band network telemetry method based on programmable switch P4 is adopted. The target user sets security policies, uses the P4 switch to encrypt and protect the telemetry data, and monitors the network status in real time on the server side, and dynamically adjusts the encryption algorithm to balance security and performance.
It realizes the confidentiality and integrity protection of telemetry data, solves the security threat problems in the transmission of telemetry data, and takes into account network performance and lowers the threshold for deployment and configuration.
Smart Images

Figure CN119945778A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of in-band network telemetry, and in particular to a secure programmable in-band network telemetry method and system based on a programmable switch P4. Background Art
[0002] With the rapid update of Internet business applications and the continuous growth of user scale, modern networks are showing the characteristics of "high speed, large scale, multi-access, and unpredictable". The requirements for network performance and security are becoming increasingly complex, and correspondingly, high requirements are also put forward for network management, which all rely on timely and effective network measurement and monitoring. Traditional network measurement and software-defined measurement methods are difficult to meet efficient, accurate, and personalized services. The emergence of in-band network telemetry technology based on programmable data planes has brought new opportunities to the field of network telemetry. Using P4 programmable switches, network managers can customize the processing logic of data packets to achieve efficient in-band network telemetry, thereby monitoring the network status in real time and with high precision. Working groups such as P4.0rg and EETF IPPM are studying and standardizing the architecture and protocols of in-band network telemetry. Many RFC documents are being formed and have received widespread attention from equipment manufacturers. These have greatly promoted research based on INT technology.
[0003] On this basis, J. Vestin et al. proposed the FS-INT scheme, which supports two sampling strategies, rate-based and event-based, to meet different monitoring needs. M. Ji proposed an online learning-based algorithm (INTaaS) to dynamically allocate resources for INT tasks to maximize the quality of service (QoS). Liu Zhengzheng et al. proposed an active network telemetry mechanism, which supports flexible acquisition of telemetry data on demand by designing a dual-stack probe data packet format. Most of these studies focus on improving the reliability and effectiveness of in-band network telemetry data acquisition, but related studies ignore the data security of in-band network telemetry. Potential software vulnerabilities, backdoors, viruses, etc. in the network may cause the in-band network telemetry data to be maliciously stolen and tampered with. The potential security risks of this telemetry data directly affect the system evaluation and decision-making of network security, and while causing data loss, it also brings huge costs to users and network operation and maintenance. At present, some researchers have paid attention to the security of programmable data planes. Chen Xiaoqi proposed an AES encryption method based on scrambled lookup table technology, and F. Hauser proposed an IPsec encryption method to ensure the security of forwarded data. However, these methods are mainly used to encrypt forwarding data and are not suitable for telemetry data encryption. Moreover, while the encryption algorithm ensures security, it also brings more resource overhead, especially the AES algorithm, which takes up a lot of memory and takes a long time to compile, resulting in reduced network throughput. How to balance security and transmission performance is an issue that must be considered in the actual application of in-band network telemetry. Summary of the invention
[0004] To this end, the present invention provides a secure programmable in-band network telemetry method and system based on a programmable switch P4 to solve the problems of security threats to existing in-band network telemetry data and the inability to effectively balance security and transmission performance.
[0005] According to the design scheme provided by the present invention, on the one hand, a secure programmable in-band network telemetry method based on a programmable switch P4 is provided, comprising:
[0006] The target user sets a security policy according to the telemetry service business requirements and stores it on the server using a security policy mapping database. The target user is a legal registered user of the telemetry service business platform. The security policy includes: a custom telemetry data type and a data security level corresponding to the telemetry data type, wherein different data security levels use corresponding specified encryption algorithms to meet the security requirements of the telemetry data type;
[0007] The controller generates telemetry data packet instructions based on telemetry service business requirements and security policies, and sends the telemetry data packet instructions to the P4 switch at the data layer;
[0008] The P4 switch performs in-band network telemetry according to the telemetry data packet instructions and encrypts and protects the telemetry data of the corresponding telemetry data type according to the security policy to generate telemetry result data and feed it back to the server;
[0009] The server receives the telemetry result data and decrypts and stores it. During the in-band network telemetry process, the server monitors the network status of the P4 switch in real time and dynamically adjusts the security policy based on the network status and business needs.
[0010] As a secure programmable in-band network telemetry method based on a programmable switch P4 of the present invention, further, the target user sets a security policy according to the telemetry service business requirements, including:
[0011] The target user uses the interactive interface in the telemetry service business platform to set the corresponding data security level for each telemetry data type according to the telemetry service business requirements. The telemetry data type includes: switch ID, ingress port number, hop-by-hop delay, queue occupancy, ingress timestamp, egress timestamp, egress port number and transmission rate;
[0012] Obtain the security policy required by the target user based on each telemetry data type and the corresponding data security level.
[0013] As a secure programmable in-band network telemetry method based on a programmable switch P4 of the present invention, further, the target user sets a security policy according to the telemetry service business requirements, and also includes:
[0014] The target user utilizes the interactive interface in the telemetry service business platform and adjusts the telemetry data type according to the telemetry service business requirements and sets the telemetry range corresponding to the telemetry data type, wherein the telemetry data type adjustment includes: type addition, type deletion and / or type modification, and the telemetry range is the business network, the network link in the business network, or the switch node in the network link.
[0015] As a secure programmable in-band network telemetry method based on a programmable switch P4 of the present invention, further, the P4 switch encrypts and protects the corresponding type of telemetry data according to the security policy during the in-band network telemetry execution process, including:
[0016] Obtaining a type of telemetry data to be encrypted and a type of telemetry data not to be encrypted according to a security policy matching table, and encrypting and protecting the telemetry data corresponding to the type of telemetry data to be encrypted using a data security level corresponding to the type of telemetry data to be encrypted, wherein the security policy matching table stores the type of telemetry data to be encrypted corresponding to the target user security policy;
[0017] The encrypted telemetry data and the telemetry data that does not need to be encrypted are sent to the forwarding processing flow, so that the telemetry data can be matched and forwarded or discarded according to the forwarding matching table in the forwarding processing flow.
[0018] As a secure programmable in-band network telemetry method based on the programmable switch P4 of the present invention, further, the telemetry data is encrypted and protected, including:
[0019] Matching an encryption algorithm from an encryption table item according to the data security level, the encryption algorithm comprising a first encryption algorithm for securely encrypting the telemetry data and a second encryption algorithm for integrity encryption of the telemetry data, the encryption table item pre-stores a plurality of data security levels and an encryption algorithm corresponding to each data security level;
[0020] The telemetry data is doubly encrypted for security and integrity protection using the matched encryption algorithm.
[0021] As a secure programmable in-band network telemetry method based on a programmable switch P4 of the present invention, further, dynamically adjusting the security policy according to the network status and business requirements includes:
[0022] Obtain the network link security weight based on the data security level set by the user, the corresponding data security level in the current network, and the highest data security level;
[0023] The network transmission performance weight is obtained based on the network link security weight and the network transmission delay obtained from the most recent telemetry and the maximum transmission delay of the network link;
[0024] The network link security weight and network link transmission performance weight are used to obtain a comprehensive evaluation index of network security and performance;
[0025] The data security level in the security policy is dynamically adjusted based on comprehensive evaluation indicators and the complexity of the encryption algorithm corresponding to each data security level to balance in-band network security and network performance loss.
[0026] As a secure programmable in-band network telemetry method based on a programmable switch P4 of the present invention, further, dynamically adjusting the data security level in the security policy includes:
[0027] Using the encryption algorithm complexity corresponding to the data security level in the current network and the encryption algorithm complexity corresponding to the adjacent data security level to estimate the network performance loss of the adjacent data security level, the adjacent data security level includes: a high data security level one level higher than the data security level in the current network, and a low data security level one level lower than the data security level in the current network;
[0028] If the comprehensive evaluation index is greater than the network performance loss of selecting a high data security level, the data security level in the current network is adjusted to a high data security level and the current security policy is updated, and the updated security policy is sent to the P4 switch through the controller;
[0029] If the comprehensive evaluation index is less than the network performance loss of selecting a low data security level, the data security level in the current network is adjusted to a low data security level and the current security policy is updated, and the updated security policy is sent to the P4 switch through the controller.
[0030] On the other hand, the present invention also provides a secure programmable in-band network telemetry system based on a programmable switch P4, comprising: a server, a controller and a P4 switch, wherein:
[0031] A server is used for a target user to set a security policy according to the telemetry service business requirements and store it on the server using a security policy mapping database. The target user is a legal registered user of the telemetry service business platform. The security policy includes: a custom telemetry data type and a data security level corresponding to the telemetry data type, wherein different data security levels use corresponding specified encryption algorithms to meet the security requirements of the telemetry data type;
[0032] A controller, used to generate telemetry data packet instructions according to telemetry service business requirements and security policies, and send the telemetry data packet instructions to the P4 switch at the data layer;
[0033] The P4 switch is used to perform in-band network telemetry according to the telemetry data packet instructions and encrypt and protect the telemetry data of the corresponding telemetry data type according to the security policy, generate telemetry result data and feed it back to the server, so that the server receives the telemetry result data and decrypts and stores it. During the in-band network telemetry process, the server monitors the network status of the P4 switch in real time and dynamically adjusts the security policy according to the network status and business needs.
[0034] Beneficial effects of the present invention:
[0035] The present invention utilizes the programmable data plane characteristics of P4, integrates encryption algorithms such as national encryption with in-band network telemetry technology, and introduces an encryption and decryption processing mechanism to realize secure programmable telemetry based on P4, thereby protecting the confidentiality and integrity of telemetry data and solving the security threat problem in the process of telemetry data transmission; and based on the idea of feedback scheduling, dynamically adjusts the encryption algorithm according to the real-time state of the network and the security needs of users, and can take into account both security and transmission performance in the process of in-band network telemetry, and can solve the problem of mismatch between encryption algorithms and data security requirements in the existing security forwarding mechanism, and can be deployed in the network in a mode where the client and the server are separated, so that users can upload telemetry requirements to the server through simple configuration operations on the client, and the server deploys and completes the telemetry task, and uses a user-friendly interactive interface to realize in-band secure telemetry, solving the problem of high threshold and difficulty in telemetry deployment and configuration. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] Figure 1 This is a schematic diagram of a secure programmable in-band network telemetry process based on a programmable switch P4 in an embodiment;
[0037] Figure 2 It is a schematic diagram of the deployment architecture of the secure programmable in-band network telemetry network in the embodiment;
[0038] Figure 3 This is a schematic diagram of the encryption mechanism process in the embodiment;
[0039] Figure 4 This is a schematic diagram of the structure of an encrypted telemetry data packet in the embodiment;
[0040] Figure 5 FIG. 1 is a schematic diagram of the INT data packet format in the embodiment.
[0041] Figure 6 This is a schematic diagram of the telemetry data packet decryption process in the embodiment;
[0042] Figure 7 The figure is a schematic diagram of the feedback scheduling process in the embodiment. DETAILED DESCRIPTION
[0043] In order to make the purpose, technical solutions and advantages of the present invention clearer and more understandable, the present invention is further described in detail below in conjunction with the accompanying drawings and technical solutions.
[0044] In view of the security threats existing in the existing in-band network telemetry data, the inability to balance data security and transmission performance, and the high threshold for deployment and configuration, the embodiments of the present invention refer to Figure 1 As shown, a secure programmable in-band network telemetry method based on a programmable switch P4 is provided, comprising:
[0045] S101. The target user sets a security policy according to the telemetry service business requirements and stores it on the server using a security policy mapping database. The target user is a legally registered user of the telemetry service business platform. The security policy includes: a custom telemetry data type and a data security level corresponding to the telemetry data type, wherein different data security levels use corresponding specified encryption algorithms to meet the security requirements of the telemetry data type.
[0046] Specifically, the target user sets the security policy based on the telemetry service business requirements, which can be set to include:
[0047] The target user uses the interactive interface in the telemetry service business platform to set the corresponding data security level for each telemetry data type according to the telemetry service business requirements. The telemetry data type includes: switch ID, ingress port number, hop-by-hop delay, queue occupancy, ingress timestamp, egress timestamp, egress port number and transmission rate;
[0048] Obtain the security policy required by the target user based on each telemetry data type and the corresponding data security level.
[0049] The target user utilizes the interactive interface in the telemetry service business platform and adjusts the telemetry data type according to the telemetry service business requirements and sets the telemetry range corresponding to the telemetry data type, wherein the telemetry data type adjustment includes: type addition, type deletion and / or type modification, and the telemetry range is the business network, the network link in the business network, or the switch node in the network link.
[0050] like Figure 2As shown in the figure, an INT domain contains three main functional nodes, namely INT Source, INT Sink and INT Transit Hop. Among them, INT Source and INT Sink can be considered as the starting point and end point of the telemetry line. INT Source is responsible for indicating the traffic and information to be collected, and INT Sink is responsible for sorting the received information and reporting it to the monitoring device; INT Transit Hop can be considered as all devices on the line that support INT telemetry. For telemetry managers, the business traffic that needs to be telemetered will add an INT header on the source node, which contains an instruction set (INT Instruction) that indicates the type of information to be collected, thus becoming an INT message. When it reaches the INT Transit Hop node of interest, the collected information (INT Metadata) will be inserted into the INT message according to the instruction set, and finally all INT information will pop up on the INT Sink node and send it to the monitoring device. For business users, the above INT processing of traffic is completely transparent, and users cannot and do not need to perceive this information. In the in-band network telemetry architecture, the switching device forwards and processes data packets carrying telemetry instructions. These telemetry instructions tell network devices with network telemetry capabilities what network status information should be collected and written when telemetry packets pass through the device.
[0051] In this case, the server front end provides users with a friendly operation interface, which is convenient for users to customize secure telemetry services according to their needs. The server back end implements four major functions: identity authentication, security policy, key management, and telemetry data processing. Identity authentication ensures that only users who have passed legal verification can access and operate the system; using security policies and custom encryption mechanisms, different encryption methods can be used for different telemetry data. At the same time, the dynamic feedback scheduling mechanism is used to dynamically adjust the encryption algorithm according to the network status, taking into account both security and transmission performance; key management is used to achieve key generation and update, key storage, and key revocation and termination in the encryption and decryption process; telemetry data processing is used to decrypt, process and store the collected telemetry data to achieve telemetry data analysis. The controller communicates with the server, receives the administrator's intention, converts the user's telemetry requirements into specific instruction information through intention conversion, and configures the P4 switch at the data level, so that the P4 switch can realize the secure network telemetry function as required. The P4 switch is used to add and protect telemetry data. When performing in-band network telemetry, the corresponding encryption algorithm can be selected according to the user-defined security policy to encrypt different telemetry data to ensure the security and integrity of the data.
[0052] In the specific workflow, the network administrator connects to the SecPro telemetry platform and the INT server through the client. Using the user-friendly interface, the administrator can customize the telemetry data type, telemetry range, and select the required security policy. The server's requirements are converted into executable instructions through intent conversion, and the executable instructions are transmitted to the controller. The controller then receives the instructions from the server and configures the switch as instructed, loading the corresponding confidentiality function in the in-band telemetry. After receiving the control instructions from the controller, the P4 switch obtains the required various parameter information telemetry functions and works according to the information. During the entire telemetry process, the server monitors the network status in real time and the switch encrypts the algorithm according to the security policy requirements.
[0053] Customized telemetry services can be achieved by selecting different telemetry data combinations. Different telemetry data have different security requirements. At the same time, in actual applications, different networks have different security level requirements. For example, special units such as government agencies and scientific research institutes usually have higher levels of protection requirements for network information and data. In response to the above requirements, this case design has a flexible and definable encryption mechanism so that administrators can choose the telemetry data to be encrypted and the encryption algorithm to implement a definable encryption mechanism.
[0054] like Figure 3 As shown in the figure, after the controller is connected to the switch for the first time, the security policy mapping database is queried to obtain the user-defined security policy, generate the corresponding flow table, and send it to the security policy function block and encryption function block of the P4 switch. When the switch obtains the telemetry content, it will first match the security policy function block. The security policy matching table is used to filter the telemetry data types that meet the encryption conditions. If the match is successful, it will be sent to the encryption function block; if the match fails, it will be sent to the forwarding module and matched with the forwarding matching table. The encryption function block selects the corresponding encryption method for different telemetry data types through the encryption policy sent by the controller. The encrypted telemetry data will be sent to the forwarding function block to match the forwarding or discarding operation.
[0055] S102. The controller generates a telemetry data packet instruction according to the telemetry service business requirements and security policies, and sends the telemetry data packet instruction to the P4 switch at the data layer.
[0056] The S103 and P4 switches execute in-band network telemetry according to the telemetry data packet instructions and encrypt and protect the telemetry data of the corresponding telemetry data type according to the security policy to generate telemetry result data and feed it back to the server.
[0057] In the embodiment of this case, a telemetry data encryption mechanism can be added to the P4 switch to implement the data encryption function, wherein the telemetry data encryption mechanism can be implemented using Extern functions such as SIMON, SM4, MD5, and other algorithms and parameters required for encryption. The processing flow is as follows: First, a data packet is received from the security policy function block, and then matched with the encryption table item that has been sent in advance by the controller and stored locally. Different encryption algorithms are used for encryption for different telemetry data types, and a hash algorithm is used for integrity verification. The structure of the encrypted telemetry data packet is as follows: Figure 4 As shown, the structure of the in-band network telemetry data packet is as follows Figure 5 As shown, Instruction Bitmap is the telemetry requirement instruction bitmap, each bit represents a telemetry data, and the specific meaning is shown in Table 1.
[0058] Table 1 Meaning of Instruction Bitmap bits
[0059]
[0060] The telemetry task sets the corresponding bit position to 1 for the data that needs to be measured.
[0061] After uploading the telemetry requirements, users can select the relevant network information that needs to be telemetered. Common network telemetry metadata is shown in Table 2 below:
[0062] Table 2 Network telemetry metadata
[0063]
[0064]
[0065] In addition to customizing the telemetry data type, users can also select the scope of telemetry, which can be the entire network, a specific link, or a switch node.
[0066] Specifically, the P4 switch encrypts and protects the corresponding type of telemetry data according to the security policy during the in-band network telemetry execution process, which can be designed to include:
[0067] Obtaining a type of telemetry data to be encrypted and a type of telemetry data not to be encrypted according to a security policy matching table, and encrypting and protecting the telemetry data corresponding to the type of telemetry data to be encrypted using a data security level corresponding to the type of telemetry data to be encrypted, wherein the security policy matching table stores the type of telemetry data to be encrypted corresponding to the target user security policy;
[0068] The encrypted telemetry data and the telemetry data that does not need to be encrypted are sent to the forwarding processing flow, so that the telemetry data can be matched and forwarded or discarded according to the forwarding matching table in the forwarding processing flow.
[0069] During the telemetry data encryption process, an encryption algorithm can be matched from an encryption table item according to the data security level. The encryption algorithm includes a first encryption algorithm for securely encrypting the telemetry data and a second encryption algorithm for integrity encrypting the telemetry data. The encryption table item pre-stores multiple data security levels and encryption algorithms corresponding to each data security level. The matched encryption algorithm is used to perform dual encryption protection of security and integrity on the telemetry data.
[0070] S104. The server receives the telemetry result data and decrypts and stores it. During the in-band network telemetry process, the server monitors the network status of the P4 switch in real time and dynamically adjusts the security policy according to the network status and business needs.
[0071] A decryption mechanism can be installed in the telemetry data processing of the telemetry server, so that after receiving the telemetry data uploaded by the last hop switch, the server first decrypts it and then checks the specific telemetry information. Figure 6 As shown, during the decryption process, the encryption algorithm corresponding to each telemetry data type can be obtained by viewing the security policy mapping table, so as to select the corresponding key for decryption.
[0072] Among them, the security policy is dynamically adjusted according to the network status and business needs, which can be designed to include:
[0073] Obtain the network link security weight based on the data security level set by the user, the corresponding data security level in the current network, and the highest data security level;
[0074] The network transmission performance weight is obtained based on the network link security weight and the network transmission delay obtained from the most recent telemetry and the maximum transmission delay of the network link;
[0075] The network link security weight and network link transmission performance weight are used to obtain a comprehensive evaluation index of network security and performance;
[0076] The data security level in the security policy is dynamically adjusted based on comprehensive evaluation indicators and the complexity of the encryption algorithm corresponding to each data security level to balance in-band network security and network performance loss.
[0077] Specifically, dynamically adjusting the data security level in the security policy may include:
[0078] Using the encryption algorithm complexity corresponding to the data security level in the current network and the encryption algorithm complexity corresponding to the adjacent data security level to estimate the network performance loss of the adjacent data security level, the adjacent data security level includes: a high data security level one level higher than the data security level in the current network, and a low data security level one level lower than the data security level in the current network;
[0079] If the comprehensive evaluation index is greater than the network performance loss of selecting a high data security level, the data security level in the current network is adjusted to a high data security level and the current security policy is updated, and the updated security policy is sent to the P4 switch through the controller;
[0080] If the comprehensive evaluation index is less than the network performance loss of selecting a low data security level, the data security level in the current network is adjusted to a low data security level and the current security policy is updated, and the updated security policy is sent to the P4 switch through the controller.
[0081] The user-defined encryption method improves the flexibility of encryption for the confidentiality of telemetry data. However, while ensuring the security of telemetry information, it also brings more resource overhead, especially encryption algorithms with higher computational complexity, which have a more significant impact on network performance. How to balance security and transmission performance is an issue that must be considered in practical applications.
[0082] Based on the above-mentioned dynamic adjustment security policy content, in this case solution, the dynamic feedback encryption algorithm scheduling mechanism of "performance loss + security level" is implemented based on the idea of feedback scheduling. This mechanism dynamically adjusts the encryption algorithm according to the network status, balancing the transmission performance while ensuring data security. Under the premise of setting different security levels and encryption algorithms used, the feedback scheduling algorithm mainly defines the comprehensive evaluation index G of security and system performance, and switches the encryption algorithm according to the index.
[0083] According to the differentiation of different telemetry data types, security requirements and the feasibility of encryption algorithms, three security levels are divided from low to high, as shown in Table 3.
[0084] Table 3 Correspondence between security levels and security requirements
[0085]
[0086] Set the comprehensive evaluation index G of security and system performance:
[0087]
[0088] Among them, W s is the link security weight, W p is the link transmission performance weight, and G is the ratio of the two.
[0089] W s The values of are as follows:
[0090]
[0091] S′ is the user's security level requirement, S is the current network security level, and S max The highest security level defined.
[0092] Transmission performance weight W p Adjust according to current security risks, network latency, and throughput changes. The values are as follows:
[0093]
[0094] D is the network transmission delay obtained from the most recent telemetry, D max The maximum delay specified for normal transmission of the link. When analyzing the transmission performance of the network, we usually focus on the two key performance indicators of throughput and delay. And throughput is often affected by the system network delay, so W p Only W is calculated s and delays.
[0095] With the evaluation index G and the calculation formula, the encryption algorithm can be switched by specifying the judgment criteria. The switching criteria are as follows:
[0096]
[0097] Arrange them from high to low according to processing performance, and generate a set Q (P1, P2, ..., P n ), P i Represents the processing performance loss of the i-th encryption algorithm. The size of the performance loss is positively correlated with the computational complexity of various encryption algorithms.
[0098] In this case, by introducing the weight feedback algorithm, such as Figure 7 As shown, the security weight Ws and the transmission performance weight Wp are adjusted according to the network security status and link status, and then a suitable encryption algorithm is selected to avoid unnecessary performance loss caused by using encryption algorithms with too high computational complexity, thereby balancing security and transmission performance.
[0099] Further, based on the above method, an embodiment of the present invention also provides a secure programmable in-band network telemetry system based on a programmable switch P4, comprising: a server, a controller and a P4 switch, wherein:
[0100] A server is used for a target user to set a security policy according to the telemetry service business requirements and store it on the server using a security policy mapping database. The target user is a legal registered user of the telemetry service business platform. The security policy includes: a custom telemetry data type and a data security level corresponding to the telemetry data type, wherein different data security levels use corresponding specified encryption algorithms to meet the security requirements of the telemetry data type;
[0101] A controller, used to generate telemetry data packet instructions according to telemetry service business requirements and security policies, and send the telemetry data packet instructions to the P4 switch at the data layer;
[0102] The P4 switch is used to perform in-band network telemetry according to the telemetry data packet instructions and encrypt and protect the telemetry data of the corresponding telemetry data type according to the security policy, generate telemetry result data and feed it back to the server, so that the server receives the telemetry result data and decrypts and stores it. During the in-band network telemetry process, the server monitors the network status of the P4 switch in real time and dynamically adjusts the security policy according to the network status and business needs.
[0103] Unless otherwise specifically stated, the relative steps, numerical expressions and values of the components and steps set forth in these embodiments do not limit the scope of the present invention.
[0104] In this specification, each embodiment is described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the embodiments can be referred to each other. For the system disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the method part.
[0105] The units and method steps of each example described in conjunction with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in the above description according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. A person of ordinary skill in the art may use different methods to implement the described functions for each specific application, but such implementation is not considered to be beyond the scope of the present invention.
[0106] Those skilled in the art will appreciate that all or part of the steps in the above method can be completed by instructing related hardware through a program, and the program can be stored in a computer-readable storage medium, such as a read-only memory, a disk or an optical disk. Optionally, all or part of the steps in the above embodiment can also be implemented using one or more integrated circuits, and accordingly, each module / unit in the above embodiment can be implemented in the form of hardware or in the form of software function modules. The present invention is not limited to any specific form of combination of hardware and software.
[0107] Finally, it should be noted that the above-described embodiments are only specific implementations of the present invention, which are used to illustrate the technical solutions of the present invention, rather than to limit them. The protection scope of the present invention is not limited thereto. Although the present invention is described in detail with reference to the above-described embodiments, ordinary technicians in the field should understand that any technician familiar with the technical field can still modify the technical solutions recorded in the above-described embodiments within the technical scope disclosed by the present invention, or can easily think of changes, or make equivalent replacements for some of the technical features therein; and these modifications, changes or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should be included in the protection scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the protection scope of the claims.
Claims
1. A secure programmable in-band network telemetry method based on a programmable switch P4, characterized in that: Include: The target user sets a security policy according to the telemetry service business requirements and stores it on the server using a security policy mapping database. The target user is a legal registered user of the telemetry service business platform. The security policy includes: a custom telemetry data type and a data security level corresponding to the telemetry data type, wherein different data security levels use corresponding specified encryption algorithms to meet the security requirements of the telemetry data type; The controller generates telemetry data packet instructions based on telemetry service business requirements and security policies, and sends the telemetry data packet instructions to the P4 switch at the data layer; The P4 switch performs in-band network telemetry according to the telemetry data packet instructions and encrypts and protects the telemetry data of the corresponding telemetry data type according to the security policy to generate telemetry result data and feed it back to the server; The server receives the telemetry result data and decrypts and stores it. During the in-band network telemetry process, the server monitors the network status of the P4 switch in real time and dynamically adjusts the security policy based on the network status and business needs.
2. The secure programmable in-band network telemetry method based on programmable switch P4 according to claim 1 is characterized in that: The target user sets security policies based on the telemetry service business requirements, including: The target user uses the interactive interface in the telemetry service business platform to set the corresponding data security level for each telemetry data type according to the telemetry service business requirements. The telemetry data type includes: switch ID, ingress port number, hop-by-hop delay, queue occupancy, ingress timestamp, egress timestamp, egress port number and transmission rate; Obtain the security policy required by the target user based on each telemetry data type and the corresponding data security level.
3. The secure programmable in-band network telemetry method based on programmable switch P4 according to claim 2 is characterized in that: The target user sets security policies based on the telemetry service business requirements, including: The target user utilizes the interactive interface in the telemetry service business platform and adjusts the telemetry data type according to the telemetry service business requirements and sets the telemetry range corresponding to the telemetry data type, wherein the telemetry data type adjustment includes: type addition, type deletion and / or type modification, and the telemetry range is the business network, the network link in the business network, or the switch node in the network link.
4. The secure programmable in-band network telemetry method based on programmable switch P4 according to claim 1 is characterized in that: During the in-band network telemetry execution process, the P4 switch encrypts and protects the corresponding type of telemetry data according to the security policy, including: Obtaining a type of telemetry data to be encrypted and a type of telemetry data not to be encrypted according to a security policy matching table, and encrypting and protecting the telemetry data corresponding to the type of telemetry data to be encrypted using a data security level corresponding to the type of telemetry data to be encrypted, wherein the security policy matching table stores the type of telemetry data to be encrypted corresponding to the target user security policy; The encrypted telemetry data and the telemetry data that does not need to be encrypted are sent to the forwarding processing flow, so that the telemetry data can be matched and forwarded or discarded according to the forwarding matching table in the forwarding processing flow.
5. The secure programmable in-band network telemetry method based on programmable switch P4 according to claim 1 or 4, characterized in that: Encrypt and protect telemetry data, including: Matching an encryption algorithm from an encryption table item according to the data security level, the encryption algorithm comprising a first encryption algorithm for securely encrypting the telemetry data and a second encryption algorithm for integrity encryption of the telemetry data, the encryption table item pre-stores a plurality of data security levels and an encryption algorithm corresponding to each data security level; The telemetry data is doubly encrypted for security and integrity protection using the matched encryption algorithm.
6. The secure programmable in-band network telemetry method based on programmable switch P4 according to claim 1, characterized in that: Dynamically adjust security policies based on network status and business needs, including: Obtain the network link security weight based on the data security level set by the user, the corresponding data security level in the current network, and the highest data security level; The network transmission performance weight is obtained based on the network link security weight and the network transmission delay obtained from the most recent telemetry and the maximum transmission delay of the network link; The network link security weight and network link transmission performance weight are used to obtain a comprehensive evaluation index of network security and performance; The data security level in the security policy is dynamically adjusted based on comprehensive evaluation indicators and the complexity of the encryption algorithm corresponding to each data security level to balance in-band network security and network performance loss.
7. The secure programmable in-band network telemetry method based on programmable switch P4 according to claim 6 is characterized in that: Dynamically adjust the data security level in the security policy, including: Using the encryption algorithm complexity corresponding to the data security level in the current network and the encryption algorithm complexity corresponding to the adjacent data security level to estimate the network performance loss of the adjacent data security level, the adjacent data security level includes: a high data security level one level higher than the data security level in the current network, and a low data security level one level lower than the data security level in the current network; If the comprehensive evaluation index is greater than the network performance loss of selecting a high data security level, the data security level in the current network is adjusted to a high data security level and the current security policy is updated, and the updated security policy is sent to the P4 switch through the controller; If the comprehensive evaluation index is less than the network performance loss of selecting a low data security level, the data security level in the current network is adjusted to a low data security level and the current security policy is updated, and the updated security policy is sent to the P4 switch through the controller.
8. A secure programmable in-band network telemetry system based on a programmable switch P4, characterized in that: Includes: servers, controllers and P4 switches, among which: A server is used for a target user to set a security policy according to the telemetry service business requirements and store it on the server using a security policy mapping database. The target user is a legal registered user of the telemetry service business platform. The security policy includes: a custom telemetry data type and a data security level corresponding to the telemetry data type, wherein different data security levels use corresponding specified encryption algorithms to meet the security requirements of the telemetry data type; A controller, used to generate telemetry data packet instructions according to telemetry service business requirements and security policies, and send the telemetry data packet instructions to the P4 switch at the data layer; The P4 switch is used to perform in-band network telemetry according to the telemetry data packet instructions and encrypt and protect the telemetry data of the corresponding telemetry data type according to the security policy, generate telemetry result data and feed it back to the server, so that the server can decrypt and store the received telemetry result data. During the in-band network telemetry process, the server monitors the network status of the P4 switch in real time and dynamically adjusts the security policy according to the network status and business needs.
9. An electronic device, characterized in that: include: at least one processor, and a memory coupled to the at least one processor; The memory stores a computer program, and the computer program can be executed by the at least one processor to implement the method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed, the method according to any one of claims 1 to 7 can be implemented.
Citation Information
Patent Citations
In-band network telemetering method based on clustering
CN113676376A
Dynamic encryption method and system, computer equipment and storage medium
CN117131484A
Dynamic security policy selection method and device, electronic equipment and storage medium
CN118074963A
Encryption algorithm dynamic selection method and system, and cloud computing-based secure communication method and system
CN119051936A
Cited By
Equipment service quality enhancement method and device, equipment and storage medium
CN120321114A
Device service quality enhancement method, apparatus, device, and storage medium
CN120321114B