Zero-trust secure flow label method for improving security of mobile network

By allocating and encapsulating security flow tags for service flows in mobile communication networks, the problem of difficult to achieve fine-grained security authentication in mobile communication networks is solved, and the effect of stream-level security checking and zero-trust network security is achieved.

CN119946628APending Publication Date: 2025-05-06INSPUR COMM TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510091788.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-21
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

The prior art is difficult to achieve fine-grained security authentication in mobile communication networks, resulting in traffic forgery and other security risks.

Method used

By assigning security flow tags to service flows on the control plane and encapsulating these tags in the forwarding plane IPv6 extension header, security authentication, tracking and monitoring is performed based on security flow tags, the security of mobile networks is enhanced.

Benefits of technology

It realizes flow-level security inspection of service traffic, improves network security level, prevents network security intrusions, and achieves the ideal state of zero trust in network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119946628A_ABST
    Figure CN119946628A_ABST
Patent Text Reader

Abstract

The invention provides a zero-trust secure flow labeling method for improving the security of a mobile network, which belongs to the field of computing power networks, and comprises the following steps of: distributing secure flow labels for service flows on a control plane, and packaging the secure flow labels for the service flows in an IPv6 (Internet Protocol Version 6) extension head on a forwarding plane. And security authentication, security tracking and security monitoring are carried out based on the security flow label, so that the security of the mobile network is enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computing power networks, and in particular to a method for improving zero-trust security flow labels for mobile network security. Background Art

[0002] In the fields of computing power networks and mobile communication networks, network security issues are even more serious. The conventional method is to perform security authentication and secondary authentication on the terminal. After the device passes the authentication, the traffic sent from the device will be "considered" to be safe. Invading devices can intercept and forge traffic by means of forged IP addresses and redirection, creating security risks. Therefore, more fine-grained security authentication is needed, such as performing new authentication and authentication every time a user accesses an application, and performing security checks on each flow, in order to improve network security. Summary of the invention

[0003] In order to solve the above technical problems, the present invention provides a method for improving zero-trust security flow labels for mobile network security.

[0004] The technical solution of the present invention is:

[0005] A method for improving zero-trust security flow labels for mobile network security, by allocating security flow labels to service flows on the control plane, encapsulating security flow labels for service flows in IPv6 extension headers on the forwarding plane, and performing security authentication, security tracking, and security monitoring based on the security flow labels, thereby enhancing the security of the mobile network.

[0006] Furthermore,

[0007] It is required that the related devices participating in security management on the forwarding plane be registered with the control center and establish a link with the control center, and the control center will grant security authorization to these devices. The service terminal applies for a security flow label from the control center and carries it in the service flow on the forwarding plane. The security-related devices on the forwarding plane can perform a series of security authentication, security tracking, and security monitoring on the security flow label to enhance the security of the mobile network.

[0008] Furthermore,

[0009] The related devices participating in security management on the forwarding plane register with the control center, and the control center grants security authorization to these devices. The forwarding plane messages are authenticated and checked by the method authorized by the control center. The devices participating in security management on the forwarding plane should establish a secure connection with the control center.

[0010] Going further,

[0011] Apply for security flow labels through the control plane method. The service terminal applies for security flow labels, and the security center is responsible for the allocation of security flow labels. When the service terminal requests the control center to allocate security flow labels, it should carry terminal information, application information, security policies, etc. in the request. The control center allocates security flow labels to the terminal based on the terminal, application, security and other policies, and carries them in the response message and sends them to the service terminal.

[0012] Going further,

[0013] The terminal carries a security flow label in the service flow IPv6 extension header. The forwarding plane security gateway, intermediate equipment, etc. perform security authentication and message inspection based on the security flow label carried in the service message, identify forged messages, including but not limited to forged source addresses, replay attacks, etc., and forward (routing policy scheduling) / blocking operations based on the inspection results, and record them for backtracking and security analysis.

[0014] Going further,

[0015] The composition of the security flow label is divided into multiple segments, including the security center ID segment, the flow feature segment, and the sequence number segment. The proportion of the length of each segment can be adjusted according to the total length of the security flow label. The total length of the security flow label can be customized.

[0016] Going further,

[0017] The flow feature segment carries the characteristic information of the terminal service flow (including source IP, destination IP, protocol number, port, etc.). This segment is invisible to the terminal, and the control center, forwarding plane security gateway, intermediate equipment, etc. encrypt it in an agreed manner.

[0018] The sequence number segment can be used for flow information management and can be used for functions such as backtracking, review, and statistics.

[0019] The beneficial effects of the present invention are

[0020] When this method is used for business access, the business flow-level security flow label application allocation, encapsulation, security authentication and other functions are provided, and flow-level security checks are performed on the access device, forwarding device, and security device on the business traffic. This can improve the security level of the network and achieve the ideal state of zero trust in network security in terms of preventing network security intrusions. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] Figure 1 It is a schematic diagram of the process of applying for security flow labels and forwarding business flows;

[0022] Figure 2 This is a schematic diagram of the composition of a security flow label. DETAILED DESCRIPTION

[0023] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments in the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.

[0024] The present invention proposes a method for improving the zero-trust security flow label of mobile network security. By allocating security flow labels to service flows on the control plane, encapsulating security flow labels for service flows in the IPv6 extension header on the forwarding plane, and performing security authentication, security tracking, and security monitoring based on the security flow labels, the security of the mobile network is enhanced. When a terminal requests the control center to allocate a security flow label, it should carry terminal information, application information, security policies, etc. in the request, and the control center allocates a security flow label to the terminal. The terminal carries the security flow label in the IPv6 extension header of the service flow, and the forwarding plane security gateway, intermediate equipment, etc. perform security checks based on the identifier assigned to the terminal, and forward (routing policy scheduling) / blocking and other operations are performed on the terminal based on the inspection results.

[0025] The present invention requires that the related devices participating in security management on the forwarding plane be registered with the control center, and a link be established with the control center, and the control center performs security authorization on these devices. The service terminal applies for a security flow label from the control center and carries it in the service flow on the forwarding plane. The security-related devices on the forwarding plane can perform a series of security authentication, security tracking, and security monitoring on the security flow label to enhance the security of the mobile network.

[0026] The details are as follows:

[0027] 1. Enhance the security of mobile networks by allocating security flow labels to service flows on the control plane, encapsulating security flow labels for service flows in the IPv6 extension header on the forwarding plane, and performing security authentication, security tracking, and security monitoring based on security flow labels.

[0028] 2. The forwarding plane related equipment is required to have the ability to process security flow labels and establish a link with the control center, and be authorized by the control center to perform security authentication, message detection and other functions, such as Figure 1 As shown in step 0, access devices, routing devices, etc. are pre-registered with the control center.

[0029] 3. The business terminal applies for a security flow label. Figure 1As shown in steps 1 to 2, when the service terminal requests the control center to allocate a security flow label, it should carry terminal information, application information, security policy, etc. in the request. The control center allocates a security flow label to the terminal based on the terminal, application, security and other policies, and carries it in the response message and sends it to the service terminal.

[0030] 4. The terminal carries a security flow label in the service flow IPv6 extension header. Figure 1 As shown in steps 3 to 4, the forwarding plane security gateway, intermediate equipment, etc. perform security authentication and message inspection based on the security flow label carried in the business message, identify forged messages, including but not limited to forged source addresses, replay attacks, etc., and forward (routing policy scheduling) / blocking operations based on the inspection results, and record them for backtracking and security analysis.

[0031] 5. The composition of security flow labels, such as Figure 2 As shown in the figure, the security flow label is divided into multiple segments, including:

[0032] 1) Flow feature segment: This segment carries the characteristic information of the terminal service flow (including source IP, destination IP, protocol number, port, etc.). This segment is invisible to the terminal and is encrypted by the control center, forwarding plane security gateway, intermediate equipment, etc. in an agreed manner.

[0033] 2) Sequence number segment: This segment is used for flow information management and can be used for functions such as backtracking, review, and statistics;

[0034] like Figure 1 As shown, the specific operations are as follows

[0035] 1. The business terminal initiates a registration request to the control center. The request message carries node information such as terminal information, application services, and security policies.

[0036] 2. The control center sends a response to the service terminal, which carries the assigned feature flow label information;

[0037] 3. The service terminal initiates an uplink service and carries the security flow label information in the service. Access devices, routing devices and other equipment perform security authentication on the security flow label of the service flow based on the authorization of the control center;

[0038] 4. The application service forwards the downlink traffic to the service terminal;

[0039] The above description is only a preferred embodiment of the present invention, which is only used to illustrate the technical solution of the present invention, and is not used to limit the protection scope of the present invention. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention are included in the protection scope of the present invention.

Claims

1. A method for improving zero-trust security flow labeling of mobile network security, characterized in that: By allocating security flow labels to service flows on the control plane, encapsulating security flow labels for service flows in the IPv6 extension header on the forwarding plane, and performing security authentication, security tracking, and security monitoring based on the security flow labels.

2. The method according to claim 1, characterized in that The related equipment on the forwarding plane has the ability to process security flow labels and establish a link with the control center, and is authorized by the control center to perform security authentication and message detection functions.

3. The method according to claim 1, characterized in that When a terminal requests the control center to allocate a security flow label, it should carry terminal information, application information, and security policy in the request, and the control center allocates a security flow label to the terminal.

4. The method according to claim 3, characterized in that When a service terminal requests the control center to allocate a security flow label, the control center allocates a security flow label to the terminal based on the terminal, application, and security policies, and carries the label in a response message and sends it to the service terminal.

5. The method according to claim 1, characterized in that The terminal carries a security flow label in the service flow IPv6 extension header, and forwarding is based on a security check of the identifier assigned to the terminal, and forwarding / blocking operations are performed on the packet based on the check result.

6. The method according to claim 5, characterized in that The forwarding plane security gateway and intermediate devices perform security authentication and message inspection based on the security flow labels carried in the business messages, identify forged messages, forward the messages based on the inspection results, and record them for backtracking and security analysis.

7. The method according to claim 6, characterized in that The security flow label is divided into several segments, including the security center ID segment, the flow feature segment, and the sequence number segment. The proportion of each segment length can be adjusted according to the total length of the security flow label. The total length of the security flow label can be customized.

8. The method according to claim 7, characterized in that The security flow label is divided into two parts: 1) Flow feature segment: This segment carries the feature information of the terminal service flow; this segment is invisible to the terminal and is encrypted by the control center, forwarding plane security gateway, and intermediate devices in an agreed manner; 2) Sequence number segment: This segment is used for flow information management and can be used for backtracking, review, and statistical functions.