Method and device for securely transmitting signaling, network equipment, chip and storage medium
By deploying signaling processing modules between network elements in 5G networks, identifying signaling types and selecting transmission lines that match the dense level, the gap in signaling security policies in cross-domain deployment of network elements is solved, and the secure transmission and differentiated security policies of signaling are realized.
Patent Information
- Application Number
- CN202311471513.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-06
- Publication Date
- 2025-05-06
AI Technical Summary
The control surface signaling security strategy for cross-domain deployment of network elements in 5G networks has not been effectively resolved, resulting in an increase in network security risks.
The first signaling processing module and the second signaling processing module are respectively deployed between the first control plane network element and the second control plane network element. These modules identify the signaling type, determine the security secret level, and select the transmission line matching the secret level for signaling transmission.
The secure transmission of signaling between control plane network elements is realized, and different security levels are corresponding to different transmission lines, and different security transmission strategies of signaling are realized, improving the overall security of the network architecture.
Smart Images

Figure CN119946614A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of wireless communication technology, and in particular to a method, device, network equipment, chip and storage medium for securely transmitting signaling. Background Art
[0002] The fifth generation (5G) mobile network communication technology is an important strategy for the layout of my country's information industry. The development and application of 5G cutting-edge technology has brought a lot of convenience to people's lives, but it has also brought new network security risks and challenges. With the rapid popularization of 5G networks among industry users, the demand for technical solutions for distributed deployment of core network elements is becoming increasingly urgent. The control plane signaling security strategy for cross-domain deployment of network elements is currently in a blank stage. Summary of the invention
[0003] To solve the above technical problems, the embodiments of the present application provide a method, apparatus, network device, chip and computer-readable storage medium for securely transmitting signaling.
[0004] In a first aspect, an embodiment of the present application provides a method for securely transmitting signaling, which is applied to a first signaling processing module, where the first signaling processing module is deployed on a first control plane network element side; the method includes:
[0005] Acquire a first signaling sent by a first control plane network element; the first signaling is a signaling sent by the first control plane network element to the second control plane network element, and the first control plane network element and the second control plane network element belong to the same core network;
[0006] Identifying a type of the first signaling, and determining a first security level corresponding to the first signaling based on the type of the first signaling;
[0007] A first transmission line matching a first security level is determined from a plurality of transmission lines, and the first signaling is sent using the first transmission line; different transmission line pairs among the plurality of transmission lines use different security levels.
[0008] In a second aspect, an embodiment of the present application provides a method for securely transmitting signaling, which is applied to a second signaling processing module, and the second signaling processing module is deployed on a second control plane network element side; the method includes:
[0009] A first signaling sent on a first transmission line is monitored from multiple transmission lines; different transmission lines in the multiple transmission lines correspond to different security levels; the first signaling is a signaling sent by a first control plane network element to a second control plane network element, and the first control plane network element and the second control plane network element belong to the same core network;
[0010] The first signaling is sent to the second control plane network element.
[0011] In a third aspect, an embodiment of the present application provides a device for securely transmitting signaling, which is applied to a first signaling processing module, and the first signaling processing module is deployed on a first control plane network element side; the device includes:
[0012] A first receiving unit is used to obtain a first signaling sent by a first control plane network element; the first signaling is a signaling sent by the first control plane network element to the second control plane network element, and the first control plane network element and the second control plane network element belong to the same core network;
[0013] A first processing unit is configured to identify a type of the first signaling, and determine a first security level corresponding to the first signaling based on the type of the first signaling; determine a first transmission line matching the first security level from a plurality of transmission lines; different transmission lines in the plurality of transmission lines correspond to different security levels;
[0014] The first sending unit is configured to send the first signaling by using a first transmission line.
[0015] In a fourth aspect, an embodiment of the present application provides a device for securely transmitting signaling, which is applied to a second signaling processing module, and the second signaling processing module is deployed on a second control plane network element side; the device includes:
[0016] A first receiving unit is configured to monitor a first signaling sent on a first transmission line from a plurality of transmission lines; different transmission lines in the plurality of transmission lines correspond to different security levels; the first signaling is a signaling sent by a first control plane network element to a second control plane network element, and the first control plane network element and the second control plane network element belong to the same core network;
[0017] The second sending unit is used to send the first signaling to the second control plane network element.
[0018] The network device provided in an embodiment of the present application includes: a processor and a memory, the memory is used to store a computer program, and the processor is used to call and run the computer program stored in the memory to execute any one of the above-mentioned secure transmission methods.
[0019] The chip provided in the embodiment of the present application includes: a processor, which is used to call and run a computer program from a memory, so that a device equipped with the chip executes any one of the above methods.
[0020] The computer-readable storage medium provided in the embodiments of the present application is used to store a computer program, and the computer program enables a computer to execute any one of the above methods.
[0021] The above-mentioned technical scheme of the embodiment of the present application deploys the first signaling processing module and the second signaling processing module on the first control plane network element and the second control plane network element side, respectively. For the first control plane network element as the sending end, the first signaling from the first control plane network element is identified by the first signaling processing module, and the first security level corresponding to the first signaling is determined based on the type of the first signaling, and the first transmission line matching the first security level is determined from multiple transmission lines, and the first transmission line is used to send the first signaling; for the second control plane network element as the receiving end, the first signaling sent on the first transmission line is monitored from multiple transmission lines, and the first signaling is sent to the second control plane network element. In this way, the secure transmission of signaling between the control plane network elements is realized through the signaling processing module. Since different transmission lines between the control plane network elements correspond to different security levels, differentiated secure transmission strategies for signaling can be implemented. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] The drawings described herein are used to provide further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute improper limitations on the present application.
[0023] Figure 1 This is a flow chart of a method for securely transmitting signaling provided in an embodiment of the present application. Figure 1 ;
[0024] Figure 2 This is a flow chart of a method for securely transmitting signaling provided in an embodiment of the present application. Figure 2 ;
[0025] Figure 3 This is a flow chart of a method for securely transmitting signaling provided in an embodiment of the present application. Figure 3 ;
[0026] Figure 4 The structure of the secure signaling transmission device provided in the embodiment of the present application is shown in FIG. Figure 1 ;
[0027] Figure 5 The structure of the secure signaling transmission device provided in the embodiment of the present application is shown in FIG. Figure 2 ;
[0028] Figure 6 is a schematic structural diagram of a communication device provided in an embodiment of the present application;
[0029] Figure 7 It is a schematic structural diagram of the chip of an embodiment of the present application. DETAILED DESCRIPTION
[0030] In order to enable a more detailed understanding of the features and technical contents of the embodiments of the present application, the implementation of the embodiments of the present application is described in detail below in conjunction with the accompanying drawings. The attached drawings are for reference only and are not used to limit the embodiments of the present application.
[0031] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art to which this application belongs. The terms used herein are only for the purpose of describing the embodiments of this application and are not intended to limit this application.
[0032] In the following description, reference is made to “some embodiments”, which describe a subset of all possible embodiments, but it will be understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.
[0033] It should also be pointed out that the terms "first\second\third" involved in the embodiments of the present application are only used to distinguish similar objects and do not represent a specific ordering of the objects. It can be understood that "first\second\third" can be interchanged in a specific order or sequence where permitted, so that the embodiments of the present application described here can be implemented in an order other than that illustrated or described here.
[0034] In the embodiments of the present application, the term "and / or" is merely a description of the association relationship between associated objects, indicating that three relationships may exist. For example, object A and / or object B may represent three situations: object A exists alone, object A and object B exist at the same time, and object B exists alone.
[0035] In addition, in the embodiments of the present application, “plurality” means two or more than two, unless otherwise clearly and specifically defined.
[0036] The 5G core network is built based on Network Function Virtualization (NFV) and Software Defined Network (SDN) technologies. Network functions no longer rely on customized hardware entities, but instead support direct deployment based on general IT information infrastructure. Compared with traditional cellular network technology, 5G core network technology provides more flexible options in terms of deployment form. At the same time, its diversified networking architecture redefines the diversified trust relationship between operators and users. And with the vigorous development of intelligent applications, the demand for advanced private network infrastructure construction in vertical industries is becoming increasingly urgent. The signaling transmission security between network elements defined by the 3rd Generation Partnership Project (3GPP) protocol standard of the traditional 5G core network no longer meets the actual needs of very few special industry users.
[0037] The local deployment of key control plane network elements (such as Unified Data Management (UDM) and Authentication Server Function (AUSF)) in the 5G core network that involve user sensitive data storage and user access authentication is a basic requirement for the construction of user networks in special fields. The multi-campus, multi-node 5G private network wide-area deployment architecture cannot avoid the risk of authentication data transmission in the public network during user network access.
[0038] In the related art, a distributed core network authentication method is proposed. The method deploys the home subscriber server in a distributed manner, adds a data acquisition process for the local home subscriber server in the user access process, and designs a process in which the core network obtains the stored user data from the centralized home subscriber server after the local home subscriber server fails to acquire the data. This technology deploys the core network network elements in a distributed manner to achieve functions such as local acquisition of user contract data, distributed multi-node networking, and hot standby of multi-node networking. However, there are certain technical gaps in the control plane signaling between network elements in the distributed deployment architecture of the core network and the security technology of service data transmission.
[0039] In order to further enhance the encryption protection capability of the network architecture for signaling, the following technical solutions are proposed in the embodiments of the present application.
[0040] It should be noted that although this article uses the 5G core network as an example of the core network, the technical solution of the embodiment of the present application is not limited to this. The technical solution of the embodiment of the present application can also be applied to other core networks, such as: 4G core network, enhanced 5G core network, 6G core network, etc.
[0041] The technical solution of the embodiment of the present application can be but is not limited to application in the cross-domain distributed deployment scenario of the core network. Here, the cross-domain distributed deployment scenario of the core network refers to: an application scenario of cross-domain deployment of a private core network that is completely isolated from the public network in multiple parks.
[0042] Figure 1 This is a flow chart of a method for securely transmitting signaling provided in an embodiment of the present application. Figure 1 , the method is applied to a first signaling processing module, and the first signaling processing module is deployed on the first control plane network element side; Figure 1 As shown, the method comprises the following steps:
[0043] Step 101: Obtain a first signaling sent by a first control plane network element.
[0044] Here, the first signaling is signaling sent by the first control plane network element to the second control plane network element, wherein the first control plane network element and the second control plane network element belong to the same core network.
[0045] It should be noted that the first control plane network element and the second control plane network element are core network elements of different types in the same core network, that is, distributed network elements.
[0046] In some implementations, the first control plane network element is an access and mobility management function (AMF), and the second control plane network element is an AUSF. Of course, this is not limited to the above, and the first control plane network element and the second control plane network element may also be other network elements in the core network.
[0047] In an embodiment of the present application, a functional module, called a signaling processing module, is added on the control plane network element side. The signaling processing module is used to divide the security levels of the signaling sent or received by the control plane network element. Different security levels correspond to different signaling transmission priorities.
[0048] The first control plane network element is used as a signaling transmitter and is deployed with a first signaling processing module. The second control plane network element is used as a signaling receiver and is deployed with a second signaling processing module.
[0049] It should be noted that the "signaling processing module" described in the embodiments of the present application may also have other names, such as "signaling identification and splitting module", etc., and the technical solution of the embodiments of the present application does not limit its name.
[0050] In the embodiment of the present application, the first control plane network element sends a first signaling to the second control plane network element through a standard interface. Here, the first signaling generally refers to any signaling sent by the first control plane network element to the second control plane network element. The data packet format of the first signaling is defined in accordance with the 3GPP standard protocol. The first signaling processing module on the first control plane network element side obtains the first signaling sent from the local end (i.e., the first control plane network element), and performs the following steps 102 to 103 on the first signaling.
[0051] In some implementations, the first signaling is the signaling exchanged between the first control plane network element and the second control plane network element during a registration process, where the registration process includes, for example: a user initial registration process and a temporary mobile subscriber identity (Temporary Mobile Subscriber Identity, TMSI) registration process.
[0052] As an example: the first signaling is a signaling carrying an access user identity identifier, or a signaling carrying a user authentication vector, or a signaling carrying user contract information, or other types of control plane signaling. Different signalings correspond to different security levels, and the division of the security levels of signaling can be flexibly defined according to the actual application scenarios. For example: the security level corresponding to the signaling carrying the access user identity identifier and the signaling carrying the user authentication vector is a high security level, the security level of the signaling carrying the user contract information is a relatively high security level, and the security level of other types of control plane signaling is no security level (or a low security level).
[0053] Step 102: Identify the type of the first signaling, and determine a first security level corresponding to the first signaling based on the type of the first signaling.
[0054] After obtaining the first signaling, the first signaling processing module records the arrival timestamp of the first signaling. Here, the first signaling processing module records the arrival timestamp of each signaling obtained, and the timestamp of the signaling is used for the first signaling processing module to process and send the signaling according to the order of the timestamps.
[0055] After obtaining the first signaling, the first signaling processing module identifies the type of the first signaling, and determines a first security level corresponding to the first signaling based on the type of the first signaling.
[0056] In some embodiments, the first signaling processing module can identify the type of the first signaling in the following manner: parsing the header information of the Hypertext Transfer Protocol (HTTP) layer of the first signaling, and determining the type of the first signaling based on the header information; determining the first security level corresponding to the first signaling based on the type of the first signaling and a preconfigured security policy; wherein the security policy is used to determine the correspondence between the signaling type and the security level.
[0057] Exemplarily, the content of the security policy is given in Table 1 below. According to the corresponding relationship shown in Table 1, it can be determined that the security level corresponding to the signaling carrying the user identity identifier and the signaling carrying the user authentication vector is a high security level, and the security level corresponding to the signaling carrying the user contract information is a medium security level. In addition to these signalings, the security levels corresponding to other types of signaling are all low security levels. The following Table 1 is only for illustrative purposes, and the division of security levels corresponding to different types of signaling may need to be flexibly defined according to actual application scenarios.
[0058]
[0059] Table 1
[0060] Here, the first signaling processing module parses the frame structure of the Ethernet layer of the first signaling, unpacks it according to the HTTP network transmission protocol, and obtains the header information of the HTTP layer. The HTTP here can be, for example, HTTP2. The first signaling processing module determines the type of the first signaling according to the header information of the HTTP layer. Here, in some embodiments, the header information can carry a signaling type field, and the type of the first signaling can be determined by the signaling type field. The first signaling processing module determines the first security level corresponding to the first signaling based on the type of the first signaling and the preconfigured security policy.
[0061] In some embodiments, after the first signaling processing module determines the first security level corresponding to the first signaling based on the type of the first signaling, the HTTP layer header of the first signaling is encapsulated, and the encapsulation here includes: adding a first security level identifier and a first timestamp in the header, wherein the first security level identifier is a security level identifier corresponding to the first security level, and the first timestamp is the timestamp of the encapsulation header.
[0062] Here, the purpose of encapsulating the HTTP layer header is to add a first security level identifier and a first timestamp, wherein the first security level identifier is used by the first signaling processing module to select a transmission line, and the first timestamp is used to ensure that the signaling is processed and sent in order.
[0063] Step 103: Determine a first transmission line that matches the first security level from multiple transmission lines, and send a first signaling via the first transmission line.
[0064] Here, different transmission lines among the multiple transmission lines correspond to different security levels, and the specific security level classification requirements will be flexibly defined according to the actual application scenarios. For example: multiple transmission lines include line A, line B and line C; among them, line A is an ordinary line without security protection, and the security level corresponding to line A is no security level (or low security level); line B is a line protected by the Internet Protocol Security (IPSEC), and the security level corresponding to line B is a higher security level; line C is a protection line realized by superposition quantum communication technology, and the security level corresponding to line C is a high security level. In this way, by having different transmission lines correspond to different security levels, differentiated transmission lines are realized, thereby achieving the purpose of signaling differentiated security level isolation transmission.
[0065] In some embodiments, different transmission lines in the plurality of transmission lines support mutual hot standby. If a fault (such as physical break) is detected on a second transmission line in the plurality of transmission lines, signaling on the second transmission line is transferred to a third transmission line in the plurality of transmission lines for transmission, wherein the third transmission line is a line that has not failed.
[0066] The third transmission line here can be understood as a backup line of the second transmission line. In some implementations, a transmission line can be selected from the multiple transmission lines as a backup line of the second transmission line according to the load, for example, a transmission line with the smallest load can be selected from the multiple transmission lines as a backup line of the second transmission line.
[0067] The technical solution of the embodiment of the present application proposes a method for securely transmitting signaling in a cross-domain distributed deployment scenario of a core network. By adding paired signaling processing modules to the transmission lines of the distributed deployment core network, the security of signaling transmission between distributed network elements is guaranteed, and the overall security of the cross-domain distributed deployment network architecture is improved. In addition, under the networking architecture proposed by the method, when a transmission line fails, the transmission lines under the architecture can achieve mutual hot standby of physical transmission lines to further improve the stability of network operation.
[0068] Figure 2 This is a flow chart of a method for securely transmitting signaling provided in an embodiment of the present application. Figure 2 , the method is applied to the second signaling processing module, and the second signaling processing module is deployed on the second control plane network element side; Figure 2 As shown, the method comprises the following steps:
[0069] Step 201: monitor a first signaling sent on a first transmission line from among multiple transmission lines.
[0070] Here, different transmission lines among the multiple transmission lines correspond to different security levels, and the specific security level division requirements will be flexibly defined according to the actual application scenarios. For example: multiple transmission lines include line A, line B and line C; among them, line A is an ordinary line without security protection, and the security level corresponding to line A is no security level (or low security level); line B is a line based on IPSEC protection, and the security level corresponding to line B is a higher security level; line C is a protection line realized by superposition quantum communication technology, and the security level corresponding to line C is a high security level. In this way, different transmission lines correspond to different security levels, and differentiated transmission lines are realized, thereby achieving the purpose of signaling differentiated security level isolation transmission.
[0071] In some implementations, different transmission lines among the multiple transmission lines support mutual hot standby, that is, after a physical break occurs on a transmission line, the signaling it carries can be load balanced by other transmission lines according to actual conditions.
[0072] Here, the first signaling is signaling sent by the first control plane network element to the second control plane network element, wherein the first control plane network element and the second control plane network element belong to the same core network.
[0073] It should be noted that the first control plane network element and the second control plane network element are core network elements of different types in the same core network, that is, distributed network elements.
[0074] In some implementations, the first control plane network element is an AMF, and the second control plane network element is an AUSF. Of course, this is not limited to this, and the first control plane network element and the second control plane network element may also be other network elements in the core network.
[0075] In an embodiment of the present application, a functional module, called a signaling processing module, is added on the control plane network element side. The signaling processing module is used to divide the security levels of the signaling sent or received by the control plane network element. Different security levels correspond to different signaling transmission priorities.
[0076] The first control plane network element is used as a signaling transmitter and is deployed with a first signaling processing module. The second control plane network element is used as a signaling receiver and is deployed with a second signaling processing module.
[0077] It should be noted that the "signaling processing module" described in the embodiments of the present application may also have other names, such as "signaling identification and splitting module", etc., and the technical solution of the embodiments of the present application does not limit its name.
[0078] In the embodiment of the present application, the second signaling processing module monitors multiple transmission lines under normal working conditions, specifically, monitors the network interfaces of multiple transmission lines.
[0079] In some embodiments, after a first signaling sent on a first transmission line is monitored from multiple transmission lines, the first signaling is placed in a receiving buffer area of a second signaling processing module. Further, the second signaling processing module parses the header information of the HTTP layer of the first signaling, and determines the type of the first signaling, the first security level identifier, and the first timestamp based on the header information, wherein the first security level identifier is the security level identifier corresponding to the first signaling, and the first timestamp is the timestamp encapsulating the header; based on the type of the first signaling, the first security level identifier, and the first timestamp, it is determined whether there is a subsequent associated signaling for the first signaling.
[0080] Here, in some implementations, the packet header information may carry a signaling type field, through which the type of the first signaling may be determined. The first signaling processing module determines the first security level corresponding to the first signaling based on the type of the first signaling and a preconfigured security policy.
[0081] Here, in some implementations, the packet header information carries a first security level identifier and a first timestamp, wherein the first security level identifier is used to determine the security level of the first signaling, and the first timestamp is used to ensure that the signaling is processed and sent in order.
[0082] In the above solution, the type of the first signaling, the first security level identifier and the first timestamp are also used to determine whether the first signaling has subsequent associated signaling. Not limited to this, part of the signaling can also determine whether there is subsequent associated signaling according to the interaction process specified in the protocol.
[0083] Step 202: Send the first signaling to the second control plane network element.
[0084] In some embodiments, if there is subsequent associated signaling for the first signaling, wait for receiving the subsequent associated signaling of the first signaling, and after receiving the subsequent associated signaling of the first signaling, send the first signaling and the subsequent associated signaling to the second control plane network element in sequence according to the timestamps of their respective packet headers; if there is no subsequent associated signaling for the first signaling, send the first signaling and the previously received signaling to the second control plane network element in sequence according to the timestamps of their respective packet headers.
[0085] The technical solution of the embodiment of the present application, in view of the general trend of distributed deployment of core network elements, constructs a differentiated transmission security strategy for element signaling, and supplements the security protection capability of cross-domain transmission of distributed core network element signaling. The technical solution of the embodiment of the present application is implemented based on the standard core network interaction process specified by the 3GPP protocol, and is compatible with commercial standardized core networks of different manufacturers.
[0086] The following is an example of the technical solution of the embodiment of the present application in conjunction with a specific application example. In this application example, the first core network element is network element A, the second core network element is network element B, the first signaling processing module is signaling processing module A, and the second signaling processing module is signaling processing module B. Figure 3 As shown, signaling processing module A is deployed on the network element A side, signaling processing module B is deployed on the network element B side, and there are lines A, B and C between signaling processing module A and signaling processing module B. Taking the process of network element A sending signaling to network element B as an example, the following steps are included:
[0087] 1) Network element A sends a first signaling to network element B through a standard interface according to the 3GPP standard protocol.
[0088] 2) Signaling processing module A identifies the structure of the Ethernet layer of the first signaling and records the arrival timestamp of the first signaling. Unpacks the first signaling according to the HTTP network transmission protocol to obtain the header information of the HTTP layer. Determines the type of the first signaling according to the header information of the HTTP layer. Determines the first security level corresponding to the first signaling based on the type of the first signaling and the configured security policy.
[0089] 3) Signaling processing module A re-encapsulates the signaling, adds the first security level identifier in the HTTP layer header, and re-time-stamps the HTTP layer header according to the encapsulation time. Signaling processing module A allocates the signaling to a matching transmission line (e.g., line A) for transmission based on the first security level identifier.
[0090] 4) When the signaling processing module B is in normal working state, it will monitor the network interfaces of multiple transmission lines. When it monitors the first signaling sent on a certain transmission line (such as line A) from multiple transmission lines, it will place the first signaling in the receiving buffer of the signaling processing module B. Parse the packet header information of the HTTP layer of the first signaling to determine the type, the first security level identifier and the first timestamp of the first signaling, and determine whether there is a subsequent associated signaling for the first signaling. If there is a subsequent associated signaling for the first signaling, wait for the subsequent associated signaling of the first signaling to be received. After the subsequent associated signaling arrives, send the first signaling and the signaling received thereafter to the network element B in sequence according to the timestamps of their respective packet headers; if there is no subsequent associated signaling for the first signaling, send the first signaling and the signaling received thereafter in sequence to the network element B in sequence according to the timestamps of their respective packet headers.
[0091] It should be noted that the above description is based on the case where network element A sends signaling to network element B, and the process of sending signaling from network element B to network element A is similar.
[0092] The technical solution of the embodiment of the present application, on the one hand, designs a multi-line communication method between network elements of the core network in the case of distributed deployment. A differentiated security transmission strategy for signaling is implemented without changing the standardized core network software. On the other hand, a customized protocol conversion technology for multi-channel data transmission is designed, which can parse the standardized TCP / IP protocol data packets and repackage them into data packets adapted to the multi-channel transmission mode proposed by the method, and select transmission lines with differentiated security protection capabilities according to the signaling type. On the other hand, a functional module for parsing and disassembling core network signaling data packets is designed, which can parse the standardized TCP / IP protocol data packets and repackage them into data packets of customized protocols. And physical lines that meet their transmission requirements can be allocated to data packets according to the preset strategies of the functional modules.
[0093] The preferred embodiments of the present application are described in detail above in conjunction with the accompanying drawings. However, the present application is not limited to the specific details in the above embodiments. Within the technical concept of the present application, the technical solution of the present application can be subjected to a variety of simple modifications, and these simple modifications all belong to the protection scope of the present application. For example, the various specific technical features described in the above specific embodiments can be combined in any suitable manner without contradiction. In order to avoid unnecessary repetition, the present application will not further explain various possible combinations. For another example, the various different embodiments of the present application can also be arbitrarily combined, as long as they do not violate the idea of the present application, they should also be regarded as the contents disclosed in the present application. For another example, under the premise of no conflict, the various embodiments and / or the technical features in the various embodiments described in the present application can be arbitrarily combined with the prior art, and the technical solution obtained after the combination should also fall within the protection scope of the present application.
[0094] It should be understood that in the various method embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0095] Based on the same inventive concept as the above embodiments, Figure 4 The structure of the secure signaling transmission device provided in the embodiment of the present application is shown in FIG. Figure 1 , applied to a first signaling processing module, wherein the first signaling processing module is deployed on a first control plane network element side; Figure 4 As shown, the secure transmission signaling device includes:
[0096] The first receiving unit 401 is used to obtain a first signaling sent by a first control plane network element.
[0097] Here, the first signaling is signaling sent by the first control plane network element to the second control plane network element, and the first control plane network element and the second control plane network element belong to the same core network.
[0098] The first processing unit 402 is configured to identify the type of the first signaling, determine a first security level corresponding to the first signaling based on the type of the first signaling, and determine a first transmission line matching the first security level from multiple transmission lines.
[0099] In some embodiments, the first processing unit 402 is also specifically used to: parse the header information of the Hypertext Transfer Protocol HTTP layer of the first signaling, and determine the type of the first signaling based on the header information; determine the first security level corresponding to the first signaling based on the type of the first signaling and a preconfigured security policy; wherein the security policy is used to determine the correspondence between the signaling type and the security level.
[0100] In some embodiments, the first processing unit 402 is also specifically used to: encapsulate the header of the HTTP layer of the first signaling, the encapsulation including: adding a first security level identifier and a first timestamp in the header, wherein the first security level identifier is a security level identifier corresponding to the first security level, and the first timestamp is the timestamp of the encapsulation header.
[0101] Here, different transmission lines among the multiple transmission lines correspond to different security levels.
[0102] The first sending unit 403 is configured to send a first signaling by using a first transmission line.
[0103] In some embodiments, the first sending unit 403 is further used to: if a fault is detected in a second transmission line among the multiple transmission lines, transfer the signaling on the second transmission line to a third transmission line among the multiple transmission lines for transmission, wherein the third transmission line is a line that has not failed.
[0104] Those skilled in the art should understand that Figure 4 The implementation functions of each unit in the secure transmission signaling device shown can be understood by referring to the relevant description of the aforementioned method. Figure 4 The functions of each unit in the secure transmission signaling device shown can be implemented by a program running on a processor, or by a specific logic circuit.
[0105] Figure 5 The structure of the secure signaling transmission device provided in the embodiment of the present application is shown in FIG. Figure 2 , applied to the second signaling processing module, such as Figure 5 As shown, the secure transmission signaling device includes:
[0106] The first receiving unit 501 is configured to monitor a first signaling sent on a first transmission line from among multiple transmission lines.
[0107] Here, different transmission lines among the multiple transmission lines correspond to different security levels; the first signaling is signaling sent by the first control plane network element to the second control plane network element, and the first control plane network element and the second control plane network element belong to the same core network.
[0108] In some embodiments, the first receiving unit 501 is also specifically used to: parse the header information of the HTTP layer of the first signaling, determine the type of the first signaling, the first security level identifier, and the first timestamp based on the header information, wherein the first security level identifier is the security level identifier corresponding to the first signaling, and the first timestamp is the timestamp that encapsulates the header; determine whether the first signaling has subsequent associated signaling based on the type of the first signaling, the first security level identifier, and the first timestamp.
[0109] The second sending unit 502 is configured to send the first signaling to the second control plane network element.
[0110] In some embodiments, the second sending unit 502 is specifically used to: if there is subsequent associated signaling for the first signaling, then after the first receiving unit 501 receives the subsequent associated signaling of the first signaling, send the first signaling and the subsequent associated signaling to the second control plane network element in sequence according to the timestamps of their respective packet headers; if there is no subsequent associated signaling for the first signaling, then send the first signaling and the previously received signaling to the second control plane network element in sequence according to the timestamps of their respective packet headers.
[0111] Those skilled in the art should understand that Figure 5 The implementation functions of each unit in the secure transmission signaling device shown can be understood by referring to the relevant description of the aforementioned method. Figure 5 The functions of each unit in the secure transmission signaling device shown can be implemented by a program running on a processor, or by a specific logic circuit.
[0112] Figure 6 600 is a schematic structural diagram of a communication device 600 provided in an embodiment of the present application. The communication device may be a terminal device or a network device. Figure 6 The communication device 600 shown includes a processor 601, and the processor 601 can call and run a computer program from a memory to implement the method in the embodiment of the present application.
[0113] Alternatively, if Figure 6 As shown, the communication device 600 may further include a memory 602. The processor 601 may call and run a computer program from the memory 602 to implement the method in the embodiment of the present application.
[0114] The memory 602 may be a separate device independent of the processor 601 , or may be integrated into the processor 601 .
[0115] Alternatively, if Figure 6 As shown, the communication device 600 may further include a transceiver 603, and the processor 601 may control the transceiver 603 to communicate with other devices, specifically, may send information or data to other devices, or receive information or data sent by other devices.
[0116] The transceiver 603 may include a transmitter and a receiver. The transceiver 603 may further include an antenna, and the number of antennas may be one or more.
[0117] Optionally, the communication device 600 may specifically be a network device of an embodiment of the present application, and the communication device 600 may implement the corresponding processes implemented by the network device in each method of the embodiment of the present application, which will not be described in detail here for the sake of brevity.
[0118] Optionally, the communication device 600 may specifically be a mobile terminal / terminal device of an embodiment of the present application, and the communication device 600 may implement the corresponding processes implemented by the mobile terminal / terminal device in each method of the embodiment of the present application, which will not be described in detail here for the sake of brevity.
[0119] Figure 7 It is a schematic structural diagram of the chip of an embodiment of the present application. Figure 7 The chip 700 shown includes a processor 701, which can call and run a computer program from a memory to implement the method in the embodiment of the present application.
[0120] Alternatively, if Figure 7 As shown, the chip 700 may further include a memory 702. The processor 701 may call and run a computer program from the memory 702 to implement the method in the embodiment of the present application.
[0121] The memory 702 may be a separate device independent of the processor 701 , or may be integrated into the processor 701 .
[0122] Optionally, the chip 700 may further include an input interface 703. The processor 701 may control the input interface 703 to communicate with other devices or chips, and specifically, may obtain information or data sent by other devices or chips.
[0123] Optionally, the chip 700 may further include an output interface 704. The processor 701 may control the output interface 704 to communicate with other devices or chips, and specifically, may output information or data to other devices or chips.
[0124] Optionally, the chip can be applied to the network device in the embodiments of the present application, and the chip can implement the corresponding processes implemented by the network device in each method of the embodiments of the present application. For the sake of brevity, they will not be repeated here.
[0125] Optionally, the chip can be applied to the mobile terminal / terminal device in the embodiments of the present application, and the chip can implement the corresponding processes implemented by the mobile terminal / terminal device in the various methods of the embodiments of the present application. For the sake of brevity, they will not be repeated here.
[0126] It should be understood that the chip mentioned in the embodiments of the present application can also be called a system-level chip, a system chip, a chip system or a system-on-chip chip, etc.
[0127] It should be understood that the processor of the embodiment of the present application may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method embodiment can be completed by the hardware integrated logic circuit or software instructions in the processor. The above processor can be a general processor, a digital signal processor (Digital Signal Processor, DSP), an application-specific integrated circuit (Application Specific Integrated Circuit, ASIC), a field programmable gate array (Field Programmable Gate Array, FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components. The methods, steps and logic block diagrams disclosed in the embodiments of the present application can be implemented or executed. The general processor can be a microprocessor or the processor can also be any conventional processor. The steps of the method disclosed in the embodiment of the present application can be directly embodied as a hardware decoding processor to perform, or the hardware and software modules in the decoding processor are combined and performed. The software module can be located in a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register, and other mature storage media in the art. The storage medium is located in the memory, and the processor reads the information in the memory and completes the steps of the above method in combination with its hardware.
[0128] It can be understood that the memory in the embodiments of the present application can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct RAM bus random access memory (DR RAM). It should be noted that the memory of the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.
[0129] It should be understood that the above-mentioned memory is exemplary but not restrictive. For example, the memory in the embodiments of the present application may also be static random access memory (static RAM, SRAM), dynamic random access memory (dynamic RAM, DRAM), synchronous dynamic random access memory (synchronous DRAM, SDRAM), double data rate synchronous dynamic random access memory (double data rate SDRAM, DDR SDRAM), enhanced synchronous dynamic random access memory (enhanced SDRAM, ESDRAM), synchronous link dynamic random access memory (synch link DRAM, SLDRAM) and direct memory bus random access memory (Direct Rambus RAM, DR RAM), etc. That is to say, the memory in the embodiments of the present application is intended to include but not limited to these and any other suitable types of memory.
[0130] An embodiment of the present application also provides a computer-readable storage medium for storing a computer program.
[0131] Optionally, the computer-readable storage medium can be applied to the network device in the embodiments of the present application, and the computer program enables the computer to execute the corresponding processes implemented by the network device in the various methods of the embodiments of the present application. For the sake of brevity, they are not repeated here.
[0132] Optionally, the computer-readable storage medium can be applied to the mobile terminal / terminal device in the embodiments of the present application, and the computer program enables the computer to execute the corresponding processes implemented by the mobile terminal / terminal device in the various methods of the embodiments of the present application. For the sake of brevity, they are not repeated here.
[0133] An embodiment of the present application also provides a computer program product, including computer program instructions.
[0134] Optionally, the computer program product can be applied to the network device in the embodiments of the present application, and the computer program instructions enable the computer to execute the corresponding processes implemented by the network device in the various methods of the embodiments of the present application. For the sake of brevity, they are not repeated here.
[0135] Optionally, the computer program product can be applied to the mobile terminal / terminal device in the embodiments of the present application, and the computer program instructions enable the computer to execute the corresponding processes implemented by the mobile terminal / terminal device in the various methods of the embodiments of the present application. For the sake of brevity, they are not repeated here.
[0136] The embodiment of the present application also provides a computer program.
[0137] Optionally, the computer program can be applied to the network device in the embodiments of the present application. When the computer program runs on a computer, the computer executes the corresponding processes implemented by the network device in the various methods in the embodiments of the present application. For the sake of brevity, they are not described here.
[0138] Optionally, the computer program can be applied to the mobile terminal / terminal device in the embodiments of the present application. When the computer program is run on a computer, the computer executes the corresponding processes implemented by the mobile terminal / terminal device in the various methods of the embodiments of the present application. For the sake of brevity, they are not repeated here.
[0139] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0140] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0141] In the several embodiments provided in the present application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0142] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0143] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0144] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application can be essentially or partly embodied in the form of a software product that contributes to the prior art. The computer software product is stored in a storage medium and includes several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the methods described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0145] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
Claims
1. A method for securely transmitting signaling, characterized in that: Applied to a first signaling processing module, the first signaling processing module is deployed on a first control plane network element side; the method includes: Obtaining a first signaling sent by the first control plane network element; the first signaling is a signaling sent by the first control plane network element to the second control plane network element, and the first control plane network element and the second control plane network element belong to the same core network; Identifying a type of the first signaling, and determining a first security level corresponding to the first signaling based on the type of the first signaling; A first transmission line matching the first security level is determined from a plurality of transmission lines, and the first signaling is sent using the first transmission line; different transmission line pairs among the plurality of transmission lines use different security levels.
2. The method according to claim 1, characterized in that The identifying the type of the first signaling, and determining a first security level corresponding to the first signaling based on the type of the first signaling, includes: Parsing packet header information of a Hypertext Transfer Protocol (HTTP) layer of the first signaling, and determining a type of the first signaling based on the packet header information; Based on the type of the first signaling and a preconfigured security policy, a first security level corresponding to the first signaling is determined; the security policy is used to determine the correspondence between the signaling type and the security level.
3. The method according to claim 1, characterized in that: After determining the first security level corresponding to the first signaling based on the type of the first signaling, the method further includes: The packet header of the HTTP layer of the first signaling is encapsulated, and the encapsulation includes: adding a first security level identifier and a first timestamp in the packet header, the first security level identifier is a security level identifier corresponding to the first security level, and the first timestamp is a timestamp for encapsulating the packet header.
4. The method according to any one of claims 1 to 3, characterized in that The method further comprises: If it is detected that a second transmission line among the plurality of transmission lines fails, the signaling on the second transmission line is transferred to a third transmission line among the plurality of transmission lines for transmission, wherein the third transmission line is a line that has not failed.
5. A method for securely transmitting signaling, characterized in that: Applied to a second signaling processing module, where the second signaling processing module is deployed on a second control plane network element side; the method includes: A first signaling sent on a first transmission line is monitored from multiple transmission lines; different transmission lines in the multiple transmission lines correspond to different security levels; the first signaling is a signaling sent by a first control plane network element to the second control plane network element, and the first control plane network element and the second control plane network element belong to the same core network; The first signaling is sent to the second control plane network element.
6. The method according to claim 5, characterized in that After monitoring the first signaling sent on the first transmission line from the plurality of transmission lines, the method further includes: Parse the header information of the HTTP layer of the first signaling, and determine the type, the first security level identifier and the first timestamp of the first signaling based on the header information, where the first security level identifier is the security level identifier corresponding to the first signaling, and the first timestamp is the timestamp of encapsulating the header; It is determined whether there is subsequent associated signaling for the first signaling based on the type of the first signaling, the first security level identifier, and the first timestamp.
7. The method according to claim 6, characterized in that The sending the first signaling to the second control plane network element includes: If there is subsequent associated signaling for the first signaling, after receiving the subsequent associated signaling of the first signaling, sending the first signaling and the subsequent associated signaling to the second control plane network element in sequence according to the timestamps of their respective packet headers; If there is no subsequent associated signaling for the first signaling, the first signaling and previously received signaling are sent to the second control plane network element in sequence according to the timestamps of their respective packet headers.
8. A device for securely transmitting signaling, characterized in that: Applied to a first signaling processing module, the first signaling processing module is deployed on a first control plane network element side; the device includes: A first receiving unit, configured to obtain a first signaling sent by the first control plane network element; the first signaling is a signaling sent by the first control plane network element to the second control plane network element, and the first control plane network element and the second control plane network element belong to the same core network; a first processing unit, configured to identify a type of the first signaling, and determine a first security level corresponding to the first signaling based on the type of the first signaling; determine a first transmission line matching the first security level from a plurality of transmission lines; different transmission lines among the plurality of transmission lines correspond to different security levels; The first sending unit is configured to send the first signaling by using the first transmission line.
9. A device for securely transmitting signaling, characterized in that: Applied to a second signaling processing module, the second signaling processing module is deployed on a second control plane network element side; the device includes: A first receiving unit is configured to monitor a first signaling sent on a first transmission line from a plurality of transmission lines; different transmission lines in the plurality of transmission lines correspond to different security levels; the first signaling is a signaling sent by a first control plane network element to a second control plane network element, and the first control plane network element and the second control plane network element belong to the same core network; The second sending unit is configured to send the first signaling to the second control plane network element.
10. A network device, characterized in that: include: A processor and a memory, the memory being used to store a computer program, the processor being used to call and run the computer program stored in the memory to execute the method according to any one of claims 1 to 4, or the method according to any one of claims 5 to 7.
11. A chip, characterized in that: include: A processor, configured to call and run a computer program from a memory, so that a device equipped with the chip executes a method as claimed in any one of claims 1 to 4, or a method as claimed in any one of claims 5 to 7.
12. A computer-readable storage medium, characterized in that: Used to store a computer program, wherein the computer program causes a computer to execute the method according to any one of claims 1 to 4, or the method according to any one of claims 5 to 7.