Communication method and device
By performing key fusion processing on the secure key in SDWAN technology, the problem that keys are easily acquired and easily cracked in communication is solved, and higher communication security and anti-quantum computing attack capabilities are achieved.
Patent Information
- Application Number
- CN202510310978.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-14
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2045-03-14
AI Technical Summary
In the existing SDWAN technology, the key is easily obtained by third parties, resulting in the communication between RR and CPE being easily cracked and leaked.
By configuring initial and additional secure exchange information in the CPE, receiving SDWAN routes sent by RR, and performing key fusion processing on the security key when specific conditions are met, generating a fused key for authentication and encryption.
Effectively prevent the key from being acquired by third parties, enhance the communication security between RR and CPE, and resist attacks from quantum computers.
Smart Images

Figure CN120034392A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology, and in particular to a communication method and device. Background Art
[0002] The development of cloud computing technology has triggered a revolution in the IT industry, and Internet+ has driven the transformation of traditional industries. The Internetization of enterprise customers (To B) surpassed that of ordinary users (To C) in 2014. Software Defined Wide Area Network (SDWAN) services focusing on the enterprise market and wide area network were born in such an industry background and expectation.
[0003] SDWAN is a VPN technology that applies SDN technology to WAN scenarios. SDWAN technology is designed to help users reduce WAN expenses, improve network connection flexibility, and provide secure and reliable interconnection services for enterprise networks and data center networks scattered across a wide geographical range.
[0004] like Figure 1 As shown, Figure 1 The following is a schematic diagram of the existing SDWAN network. Figure 1 In the example, the network includes a central site route reflector (RR), branch site 1 (Customer Provided Edge (CPE) 1), and branch site 2 (CPE2). In the network, the control channel and data channel are established as follows, taking the establishment of the control channel and data channel between RR and CPE1 as an example.
[0005] An SSL connection (control channel) is established between CPE1 and RR. CPE1 is the client of the SSL connection, called the SDWAN client, and RR is the server of SSL, called the SDWAN server. CPE1 and RR send each other transport tunnel endpoint (English: Transport Tunnel Endpoint, referred to as: TTE) information (TTE information includes SiteID, Device ID, Public IP, Private IP, SystemIP, IPsec authentication algorithm and key, IPsec encryption algorithm and key, etc.) through the SSL connection to establish an SDWAN tunnel (control channel). CPE1 and RR transmit BGP protocol messages to each other through the SDWAN tunnel, and establish a BGP SDWAN peer relationship through the site system ID of CPE1 (system-ip-cpe1) and the site system ID of RR (system-ip-rr). CPE1 generates a BGPSDWAN route based on its own TTE information and sends it to RR. RR reflects the received BGPSDWAN route to CPE2. Through this route, CPE2 obtains the TTE information of CPE1, triggering it to create an SDWAN data channel (SDWAN tunnel) to CPE1. Since the TTE information of CPE1 includes encryption information such as IPsec authentication algorithm and key, IPsec encryption algorithm and key, the SDWAN tunnels established between CPE1 and RR and CPE2 also support security features, and the messages forwarded through the SDWAN tunnel will be encrypted and authenticated.
[0006] However, in the above process, although the message is authenticated, encrypted and forwarded, the encryption key and authentication key included in the TTE information may be obtained by a third party during the transmission process. If the third party is an attacker and obtains various keys, the communication content may be easily cracked and leaked during the subsequent interactive communication between RR, CPE, etc. Summary of the invention
[0007] In view of this, the present application provides a communication method and device to solve the problem that various types of existing keys are easily obtained by a third party, and the communication content between RR and CPE is easily cracked and leaked when the third party attacks.
[0008] In a first aspect, the present application provides a communication method, the method being applied to a first CPE, wherein first initial security exchange information and first additional security exchange information have been configured in the first CPE, the first initial security exchange information including at least one first security protocol information supported by the first CPE and a first security key corresponding to each first security protocol, the first additional security exchange information including a first fusion algorithm identifier, at least one first additional algorithm information, and first additional key exchange data corresponding to each first additional algorithm, the method comprising:
[0009] Receive a first SDWAN route sent by the RR, where the first SDWAN route includes second initial security exchange information and second additional security exchange information, where the second initial security exchange information includes at least one second security protocol information supported by the second CPE, and the second additional security exchange information includes a second fusion algorithm identifier, at least one second additional algorithm information, and second additional key exchange data corresponding to each second additional algorithm;
[0010] If the first security protocol information is the same as the second security protocol information, the first additional algorithm information is the same as the second additional algorithm information, and the first fusion algorithm identifier and the second fusion algorithm identifier indicate the same fusion algorithm, each first security key is respectively fused with all the first symmetric keys to obtain a first fusion key corresponding to each first security key;
[0011] According to the usage characteristics of each first security key, using the corresponding first fusion key as a key for realizing the usage characteristics;
[0012] Each first symmetric key is calculated by the first CPE according to the first additional key exchange data and the second additional key exchange data according to a first additional algorithm, and the first additional key exchange data and the second additional key exchange data correspond to the same additional algorithm.
[0013] In a second aspect, the present application provides a communication device, the device being applied to a first CPE, wherein first initial security exchange information and first additional security exchange information have been configured in the first CPE, the first initial security exchange information including at least one first security protocol information supported by the first CPE and a first security key corresponding to each first security protocol, the first additional security exchange information including a first fusion algorithm identifier, at least one first additional algorithm information, and first additional key exchange data corresponding to each first additional algorithm, the device including:
[0014] a receiving unit, configured to receive a first SDWAN route sent by the RR, wherein the first SDWAN route includes second initial security exchange information and second additional security exchange information, wherein the second initial security exchange information includes at least one second security protocol information supported by the second CPE, and the second additional security exchange information includes a second fusion algorithm identifier, at least one second additional algorithm information, and second additional key exchange data corresponding to each second additional algorithm;
[0015] a fusion unit, configured to, if the first security protocol information is the same as the second security protocol information, the first additional algorithm information is the same as the second additional algorithm information, and the first fusion algorithm identifier and the second fusion algorithm identifier indicate the same fusion algorithm, perform key fusion processing on each first security key with all the first symmetric keys to obtain a first fusion key corresponding to each first security key;
[0016] a processing unit, configured to use, according to the usage characteristics of each first security key, the corresponding first fusion key as a key for realizing the usage characteristics;
[0017] Each first symmetric key is calculated by the first CPE according to the first additional key exchange data and the second additional key exchange data according to a first additional algorithm, and the first additional key exchange data and the second additional key exchange data correspond to the same additional algorithm.
[0018] In a third aspect, the present application provides another network device, including a processor and a machine-readable storage medium, wherein the machine-readable storage medium stores machine-executable instructions that can be executed by the processor, and the processor is prompted by the machine-executable instructions to execute the method provided in the first aspect of the present application.
[0019] Therefore, using the communication method and device provided in the present application, the first CPE receives the first SDWAN route sent by the RR, wherein the first SDWAN route includes the second initial security exchange information and the second additional security exchange information, the second initial security exchange information includes at least one second security protocol information supported by the second CPE, and the second additional security exchange information includes a second fusion algorithm identifier, at least one second additional algorithm information, and second additional key exchange data corresponding to each second additional algorithm; if the first security protocol information is the same as the second security protocol information, the first additional algorithm information is the same as the second additional algorithm information, and the first fusion algorithm identifier and the second fusion algorithm identifier indicate the same fusion algorithm, then the first CPE performs key fusion processing on each first security key with all the first symmetric keys respectively to obtain a first fusion key corresponding to each first security key; according to the usage characteristics of each first security key, the first CPE uses the corresponding first fusion key as the key to realize the usage characteristics; wherein each first symmetric key is calculated by the first CPE according to the first additional key exchange data and the second additional key exchange data according to the first additional algorithm, and the first additional key exchange data and the second additional key exchange data both correspond to the same additional algorithm.
[0020] In this way, at least one additional key exchange data is carried through the SDWAN route, so that in the CPE negotiation process, the symmetric key is obtained through the additional key exchange data, the security key and the symmetric key are fused, and the fused key is used to authenticate and / or encrypt the data message transmitted through the SDWAN tunnel. This solves the problem that the existing various types of keys are easily obtained by a third party, and the communication content between the RR and the CPE is easily cracked and leaked when the third party attacks. At the same time, it also realizes that the fused key can resist the attack of quantum computers. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] Figure 1 A flow chart of a communication method provided in an embodiment of the present application;
[0022] Figure 2 A schematic diagram of the IPSec Sub-TLV format provided in an embodiment of the present application;
[0023] Figure 3 A structural diagram of a communication device provided in an embodiment of the present application;
[0024] Figure 4 The network device hardware structure provided in the embodiment of the present application. DETAILED DESCRIPTION
[0025] Exemplary embodiments will be described in detail herein, examples of which are shown in the accompanying drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application. Instead, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.
[0026] The terms used in this application are only for the purpose of describing specific embodiments and are not intended to limit this application. The singular forms of "a", "said" and "the" used in this application and the appended claims are also intended to include plural forms unless the context clearly indicates other meanings. It should also be understood that the term "and / or" used in this article refers to and includes any or all possible combinations of one or more corresponding listed items.
[0027] It should be understood that although the terms first, second, third, etc. may be used in the present application to describe various information, these information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of the present application, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, the word "if" as used herein may be interpreted as "at the time of" or "when" or "in response to determining".
[0028] The communication method provided in the embodiment of the present application is described in detail below. Figure 1 , Figure 1 A flow chart of a communication method provided in an embodiment of the present application. The method is applied to a first CPE. The communication method provided in an embodiment of the present application may include the following steps.
[0029] Step 110: Receive a first SDWAN route sent by the RR, where the first SDWAN route includes second initial security exchange information and second additional security exchange information, where the second initial security exchange information includes at least one second security protocol information supported by the second CPE, and the second additional security exchange information includes a second fusion algorithm identifier, at least one second additional algorithm information, and second additional key exchange data corresponding to each second additional algorithm;
[0030] Specifically, in the SDWAN networking, the RR establishes a control channel with each CPE respectively, and a data channel is established between each CPE. The above control channel and data channel are both SDWAN tunnels. In the embodiment of the present application, the process of establishing the control channel can be implemented according to the existing process, which will not be repeated here.
[0031] The following is an explanation of establishing an encrypted data channel between the first CPE and the second CPE.
[0032] After the second CPE establishes a control channel with the RR, it also establishes a BGPSDWAN peer relationship with the RR. The second CPE generates the first SDWAN route according to its own TTE information.
[0033] The first SDWAN route includes second initial security exchange information and second additional security exchange information, the second initial security exchange information includes at least one second security protocol information supported by the second CPE, and the second additional security exchange information includes a second fusion algorithm identifier, at least one second additional algorithm information and second additional key exchange data corresponding to each second additional algorithm.
[0034] The second CPE sends the first SDWAN route to the RR. After receiving the first SDWAN route, the RR sends (or reflects) to the first CPE. After receiving the first SDWAN route, the first CPE obtains the second initial security exchange information and the second additional security exchange information therefrom, obtains at least one second security protocol information supported by the second CPE from the second initial security exchange information, and obtains the second fusion algorithm identifier, at least one second additional algorithm information, and the second additional key exchange data corresponding to each second additional algorithm from the second additional security exchange information.
[0035] Optionally, in an embodiment of the present application, the first SDWAN route includes an MP_REACH_NLRI attribute, the MP_REACH_NLRI attribute includes an NLRI field, the NLRI field includes a Data subfield, and the Data subfield includes an IPSecSub-TLV format.
[0036] The above IPSec Sub-TLV format is as follows Figure 2 As shown, Figure 2 The IPSec Sub-TLV format diagram provided for the embodiment of the present application. The IPSec Sub-TLV format includes a security protocol (Transform) field, a transport (Transport) field, an AH field, an ESP1 field, an ESP2 field, a Reserved field, an SPI field, a Key1 length (Length) field, a Key1 field, a Key2Length field, a Key2 field, a Key3Length field, a Key3 field, and a Duration field.
[0037] The definition and configuration of each of the above fields are the same as those defined in the existing IPSec Sub-TLV format, which are briefly described below.
[0038] The Transform field is used to indicate the security protocols supported by the CPE. The values are 1, 2, and 3. For example, a value of 1 indicates support for Authentication Header (AH) authentication, a value of 2 indicates support for Encapsulating Security Payload (ESP) authentication, and a value of 3 indicates support for both AH authentication and ESP encryption. The Transport field indicates the transport mode, and currently supports Tunnel mode. The AH field indicates the algorithm used for AH authentication. The ESP1 field indicates the algorithm used for ESP authentication. The ESP2 field indicates the algorithm used for ESP encryption. The SPI field indicates the Security Parameter Index (SPI) of the IPSec SA. The Key1Length field indicates the length of the AH authentication key. The Key1 field indicates the value of the AH authentication key. The Key2Length field indicates the length of the ESP authentication key. The Key2 field indicates the value of the ESP authentication key. The Key3Length field indicates the length of the ESP encryption key. The Key3 field indicates the value of the ESP encryption key. The Duration field indicates the lifetime of the IPSec SA.
[0039] In the embodiment of the present application, the information carried in the Transform field, the AH field, the ESP1 field, and the ESP2 field is referred to as the second security protocol information, and the Key carried in the Key1 field, the Key2 field, and the Key3 field is referred to as the second security key.
[0040] Optionally, in an embodiment of the present application, the IPSec Sub-TLV format further includes an additional key exchange number field, a key algorithm identifier (PrfID) field, and at least one additional key exchange block. Each additional key exchange block includes an additional key exchange algorithm identifier (Addition Key exchangeTransform ID) field, an additional key exchange data length field, and an additional key exchange data field.
[0041] Among them, the Addition Key Exchange Number field is used to indicate the number of additional key exchanges, with a maximum value of 7; the PrfID field is used to indicate the PRF algorithm identifier, which is used to implement key fusion (for example, the PRF algorithm can be any one of the following: PRF_HMAC_MD5, PRF_HMAC_SHA1, PRF_HMAC_TIGER, PRF_AES128_XCBC, PRF_HMAC_SHA2_256, PRF_HMAC_SHA2_384, PRF_HMAC_SHA2_512, PRF_AES128_CMAC, PRF_HMAC_STREEBOG_512); the Addition Key exchange Transform ID field is used to indicate the additional key exchange algorithm ID; the Addition Key Exchange Data Length field is used to indicate the additional key exchange data length; the Addition Key Exchange Data field is used to indicate the additional key exchange data.
[0042] In the embodiment of the present application, the information carried in the Addition Key Exchange Number field, the PrfID field, and at least one additional key exchange block is referred to as the second additional security exchange information. The information carried in the PrfID field is referred to as the second fusion algorithm identifier. The information carried in the Addition Key exchange Transform ID field is referred to as the second additional algorithm information, and the information carried in the Addition Key Exchange Data field is referred to as the second additional key exchange data.
[0043] It can be understood that the above-mentioned "second" is used to distinguish other initial security exchange information, additional security exchange information, security protocol information, fusion algorithm identifier, additional algorithm information, and additional key exchange data. In practical applications, it may also be referred to as "first", "third", etc.
[0044] Step 120: If the first security protocol information is the same as the second security protocol information, the first additional algorithm information is the same as the second additional algorithm information, and the first fusion algorithm identifier and the second fusion algorithm identifier indicate the same fusion algorithm, each first security key is respectively fused with all the first symmetric keys to obtain a first fusion key corresponding to each first security key;
[0045] Specifically, according to the description of step 110, after the first CPE obtains at least one second security protocol information, a second fusion algorithm identifier, at least one second additional algorithm information and second additional key exchange data corresponding to each second additional algorithm supported by the second CPE from the first SDWAN router, it obtains at least one first security protocol information, a first additional algorithm identifier and a first fusion algorithm identifier supported by itself locally.
[0046] The first CPE compares whether the first security protocol information is the same as the second security protocol information, whether the first additional algorithm information is the same as the second additional algorithm information, and whether the first fusion algorithm identifier and the second fusion algorithm identifier indicate the same fusion algorithm.
[0047] If the above security protocol information, additional algorithm information, and fusion algorithm identifier are all the same, the first CPE locally obtains the first security key corresponding to each first security protocol and the first additional key exchange data corresponding to each first additional algorithm.
[0048] According to each first additional algorithm or second additional algorithm, the first CPE obtains first additional key exchange data and second additional key exchange data belonging to the same additional algorithm. The first CPE operates the first additional key exchange data and the second additional key exchange data according to the corresponding additional algorithm to obtain a first symmetric key.
[0049] The first CPE repeats the above process until a first symmetric key corresponding to each additional algorithm is obtained.
[0050] The first CPE performs key fusion processing on each first security key and all first symmetric keys respectively to obtain a first fusion key corresponding to each first security key.
[0051] Optionally, in the embodiment of the present application, if there are multiple first security keys, the first CPE performs key fusion processing on each first security key with all first symmetric keys respectively, and the specific process of obtaining the first fusion key corresponding to each first security key is:
[0052] According to the fusion algorithm, the first CPE inputs a security key and all symmetric keys into the fusion algorithm to obtain a first fusion key (PQKey) corresponding to the security key; the first CPE repeatedly inputs a security key and all symmetric keys into the fusion algorithm to obtain a first fusion key corresponding to the security key until the first fusion key corresponding to each security key is obtained.
[0053] That is: PQKey1 = prf + (Key1, SK(1) | SK(2) | ... SK(n))
[0054] PQKey2=prf+(Key2,SK(1)|SK(2)|…SK(n))
[0055] PQKey3=prf+(Key3,SK(1)|SK(2)|…SK(n))
[0056] Among them, Key is the security key and SK(n) is the symmetric key.
[0057] In one example, the first CPE obtains a Transform field value of 3 from the first SDWAN route, indicating that the second CPE itself supports AH authentication and ESP encryption, and obtains an AH field value of MD5 and an ESP2 field value of DES-CBC.
[0058] The first CPE determines that it also supports AH authentication and ESP encryption, and the algorithm used for AH authentication is MD5, and the algorithm used for ESP encryption is DES-CBC. At this time, the first CPE determines that it and the second CPE both support the same authentication algorithm and encryption algorithm.
[0059] The first CPE obtains the value of the Addition Key Exchange Number field from the first SDWAN route again, and the value is 3, indicating that the first SDWAN route carries 3 additional key exchange blocks. For example, additional key exchange block 1 (hereinafter referred to as block 1), additional key exchange block 2 (hereinafter referred to as block 2), and additional key exchange block 3 (hereinafter referred to as block 3). The value of the PrfID field is PRF_HMAC_MD5.
[0060] Among them, the value of the Addition Key exchange Transform ID field in block 1 is 768-bit MODPGroup, and the value of the Addition Key Exchange Data field is additional key exchange data 1, that is, the additional key exchange data 1 is obtained by the second CPE through the 768-bit MODP Group algorithm. The value of the Addition Key exchange Transform ID field in block 2 is 1024-bit MODP Group, and the value of the Addition Key Exchange Data field is additional key exchange data 2, that is, the additional key exchange data 2 is obtained by the second CPE through the 1024-bit MODP Group algorithm. The value of the Addition Key exchange Transform ID field in block 3 is 1536-bit MODPGroup, and the value of the Addition Key Exchange Data field is additional key exchange data 3, that is, the additional key exchange data 3 is obtained by the second CPE through the 1536-bit MODP Group algorithm.
[0061] The first CPE obtains the fusion algorithm identifier (PRF_HMAC_MD5) and three additional algorithm information (768-bit MODP Group, 1024-bit MODP Group, 1536-bit MODP Group) supported by itself from the local. After comparison, the first CPE determines that the fusion algorithm identifier is the same and the three additional algorithm information are also the same.
[0062] The first CPE calculates the first additional key exchange data and the second additional key exchange data corresponding to the 768-bit MODP Group algorithm according to the 768-bit MODP Group algorithm to obtain a symmetric key 1, SK(1). Similarly, the first CPE calculates the first additional key exchange data and the second additional key exchange data corresponding to the 1024-bit MODP Group algorithm according to the 1024-bit MODP Group algorithm to obtain a symmetric key 2, SK(2). Similarly, the first CPE calculates the first additional key exchange data and the second additional key exchange data corresponding to the 1536-bit MODP Group algorithm according to the 1536-bit MODP Group algorithm to obtain a symmetric key 3, SK(3).
[0063] The first CPE continues to obtain security keys corresponding to each security protocol supported by itself, for example, obtaining initial key 1 for AH authentication and initial key 2 for ESP encryption.
[0064] According to the fusion algorithm (PRF_HMAC_MD5), the first CPE first inputs the initial key 1, symmetric key 1, symmetric key 2 and symmetric key 3 into PRF_HMAC_MD5 to obtain the fusion key 1 corresponding to the initial key 1, that is, PQKey1=prf+(Key1,SK(1)|SK(2)|SK(3)).
[0065] Similarly, the first CPE inputs the initial key 2, symmetric key 1, symmetric key 2 and symmetric key 3 into PRF_HMAC_MD5 to obtain the fusion key 2 corresponding to the initial key 2, that is, PQKey2=prf+(Key1,SK(1)|SK(2)|SK(3)).
[0066] Step 130: According to the usage characteristics of each first security key, use the corresponding first fusion key as a key for realizing the usage characteristics.
[0067] Specifically, according to the description of step 120, after the first CPE obtains the first fusion key corresponding to each first security key, it uses the corresponding first fusion key as a key for realizing the usage feature according to the usage feature of each first security key.
[0068] Optionally, in the embodiment of the present application, the usage feature includes an authentication feature and an encryption feature, wherein the authentication feature refers to the first security key being used to implement AH authentication or ESP authentication; and the encryption feature refers to the first security key being used to implement ESP encryption.
[0069] According to the usage characteristics of each first security key, the specific process of the first CPE using the corresponding first fusion key as the key for realizing the usage characteristics is as follows:
[0070] If the usage characteristic of the first security key is an authentication characteristic, the first CPE uses the first fusion key corresponding to the first security key as the key for implementing the authentication characteristic; or; if the usage characteristic of the first security key is an encryption characteristic, the first CPE uses the first fusion key corresponding to the first security key as the key for implementing the encryption characteristic.
[0071] According to the above example, security key 1 is used for AH authentication, so PQKey1 corresponding to security key 1 is subsequently used to implement AH authentication for data packets transmitted through the SDWAN tunnel; similarly, initial key 2 is used for ESP encryption, so PQKey2 corresponding to initial key 2 is subsequently used to implement ESP encryption for data packets transmitted through the SDWAN tunnel.
[0072] Therefore, by applying the communication method provided in the present application, the first CPE receives the first SDWAN route sent by the RR, wherein the first SDWAN route includes the second initial security exchange information and the second additional security exchange information, the second initial security exchange information includes at least one second security protocol information supported by the second CPE, and the second additional security exchange information includes a second fusion algorithm identifier, at least one second additional algorithm information, and second additional key exchange data corresponding to each second additional algorithm; if the first security protocol information is the same as the second security protocol information, the first additional algorithm information is the same as the second additional algorithm information, and the first fusion algorithm identifier and the second fusion algorithm identifier indicate the same fusion algorithm, then the first CPE performs key fusion processing on each first security key with all the first symmetric keys respectively to obtain a first fusion key corresponding to each first security key; according to the usage characteristics of each first security key, the first CPE uses the corresponding first fusion key as the key to realize the usage characteristics; wherein each first symmetric key is calculated by the first CPE according to the first additional key exchange data and the second additional key exchange data according to the first additional algorithm, and the first additional key exchange data and the second additional key exchange data both correspond to the same additional algorithm.
[0073] In this way, at least one symmetric key is carried through the SDWAN route, so that during the CPE negotiation process, the security key and the symmetric key are merged, and the merged key is used to authenticate and / or encrypt the data message transmitted through the SDWAN tunnel. This solves the problem that the existing various types of keys are easily obtained by a third party, and the communication content between the RR and the CPE is easily cracked and leaked when the third party attacks. At the same time, it also realizes that the merged key can resist the attack of quantum computers.
[0074] Optionally, in the embodiment of the present application, after establishing a control channel with the RR, the first CPE also establishes a BGPSDWAN peer relationship with the RR. The first CPE generates a second SDWAN route according to its own TTE information.
[0075] It can be understood that the message structure of the second SDWAN route is the same as the message structure of the aforementioned first SDWAN route, and will not be repeated here.
[0076] At the same time, the function of the second SDWAN router is the same as that of the first SDWAN router, and is sent to the second CPE through RR, so that the second CPE negotiates with the first CPE and establishes a data channel.
[0077] Specifically, the second initial security exchange information further includes a second security key corresponding to each second security protocol.
[0078] The first CPE generates a second SDWAN route, which includes first initial security exchange information and first additional security exchange information. The first initial security exchange information includes at least one first security protocol information supported by the first CPE, and the first additional security exchange information includes a first fusion algorithm identifier, at least one first additional algorithm information, and first additional key exchange data corresponding to each first additional algorithm.
[0079] The first CPE sends the second SDWAN route to the RR, and after receiving the second SDWAN route, the RR sends it to the second CPE. According to the second SDWAN route, after determining that the security exchange information corresponds to the same and the fusion algorithm identifiers indicate the same fusion algorithm, the second CPE performs key fusion processing on each second security key and all the second symmetric keys to obtain a second fusion key corresponding to each second security key; according to the usage characteristics of each second security key, the second CPE uses the corresponding second fusion key as the key to implement the usage characteristics;
[0080] Each second symmetric key is calculated by the second CPE according to the first additional key exchange data and the second additional key exchange data according to the second additional algorithm, and the first additional key exchange data and the second additional key exchange data correspond to the same additional algorithm.
[0081] It can be understood that the steps performed by the second CPE after receiving the second SDWAN route are the same as the steps performed by the first CPE after receiving the first SDWAN route, and will not be repeated here.
[0082] Optionally, in the embodiment of the present application, the first CPE also receives a configuration instruction input by a user, and locally configures the first security protocol information and the first additional algorithm information according to the configuration instruction.
[0083] Specifically, the user inputs a configuration instruction to the first CPE in the form of a command line, where the configuration instruction includes at least one first security protocol information and at least one first additional algorithm information.
[0084] After receiving the configuration instruction, the first CPE obtains at least one first security protocol information and at least one first additional algorithm information therefrom.
[0085] According to each first security protocol, the first CPE generates a corresponding first security key, and according to each first additional algorithm, generates corresponding first additional key exchange data.
[0086] The first CPE generates a second SDWAN route based on the at least one first security protocol information, each first security key, the at least one first additional algorithm information, and each first additional key exchange data.
[0087] Similarly, the user also inputs configuration instructions to the second CPE in the form of a command line, and the configuration indicators include at least one second security protocol information and at least one first additional algorithm information.
[0088] After receiving the configuration instruction, the second CPE obtains at least one second security protocol information and at least one second additional algorithm information therefrom.
[0089] According to each second security protocol, the second CPE generates a corresponding second security key, and according to each second additional algorithm, generates a corresponding first symmetric key.
[0090] The second CPE generates a first SDWAN route based on at least one second security protocol information, each second security key, at least one second additional algorithm information, and each first symmetric key.
[0091] The above security protocol information is used to enable the CPE to locally support AH authentication, or ESP authentication, or support both AH authentication and ESP encryption; the above additional algorithm information is used to enable the CPE to locally support which PRF algorithm to use to achieve key fusion, which additional algorithm to use to calculate the symmetric key, and the number of additional key exchanges.
[0092] Therefore, by carrying the above configuration information in the SDWAN route, the CPEs at both ends can achieve mutual negotiation in the process of establishing the data channel, and each end can calculate the fusion key corresponding to the security key. Subsequently, after sending the data message through the SDWAN tunnel, the corresponding fusion key is used to authenticate and / or encrypt the data message according to the usage characteristics of the security key.
[0093] Based on the same inventive concept, the present application embodiment also provides a communication device corresponding to the communication method. Figure 3 , Figure 3 In the communication device provided in the embodiment of the present application, the first initial security exchange information and the first additional security exchange information have been configured in the first CPE, the first initial security exchange information includes at least one first security protocol information supported by the first CPE and a first security key corresponding to each first security protocol, the first additional security exchange information includes a first fusion algorithm identifier, at least one first additional algorithm information and first additional key exchange data corresponding to each first additional algorithm, the device includes:
[0094] The receiving unit 310 is configured to receive a first SDWAN route sent by the RR, where the first SDWAN route includes second initial security exchange information and second additional security exchange information, where the second initial security exchange information includes at least one second security protocol information supported by the second CPE, and the second additional security exchange information includes a second fusion algorithm identifier, at least one second additional algorithm information, and second additional key exchange data corresponding to each second additional algorithm;
[0095] a fusion unit 320, configured to, if the first security protocol information is the same as the second security protocol information, the first additional algorithm information is the same as the second additional algorithm information, and the first fusion algorithm identifier and the second fusion algorithm identifier indicate the same fusion algorithm, perform key fusion processing on each first security key with all the first symmetric keys to obtain a first fusion key corresponding to each first security key;
[0096] The processing unit 330 is configured to use the corresponding first fusion key as a key for realizing the usage feature according to the usage feature of each first security key;
[0097] Each first symmetric key is calculated by the first CPE according to the first additional key exchange data and the second additional key exchange data according to a first additional algorithm, and the first additional key exchange data and the second additional key exchange data correspond to the same additional algorithm.
[0098] Optionally, the second initial security exchange information further includes a second security key corresponding to each second security protocol, and the device further includes:
[0099] a sending unit (not shown in the figure), configured to send a second SDWAN route to the RR, wherein the second SDWAN route includes the first initial security exchange information and the first additional security exchange information, so that the RR sends the second SDWAN to the second CPE, and after determining that the security exchange information corresponds to the same and the fusion algorithm identifiers indicate the same fusion algorithm, the second CPE performs key fusion processing on each second security key and all the second symmetric keys respectively to obtain a second fusion key corresponding to each second security key; according to the usage characteristics of each second security key, the corresponding second fusion key is used as a key to realize the usage characteristics;
[0100] Each second symmetric key is calculated by the second CPE according to the first additional key exchange data and the second additional key exchange data according to a second additional algorithm, and the first additional key exchange data and the second additional key exchange data correspond to the same additional algorithm.
[0101] Optionally, the receiving unit 310 is further configured to receive a configuration instruction input by a user, wherein the configuration instruction includes the at least one first security protocol information and the at least one first additional algorithm information;
[0102] The device further includes: a first generating unit (not shown in the figure), configured to generate the corresponding first security key according to each first security protocol, and to generate the corresponding first additional key exchange data according to each first additional algorithm;
[0103] The second generating unit (not shown in the figure) is used to generate the second SDWAN route according to the at least one first security protocol information, each first security key, the at least one first additional algorithm information and each first additional key exchange data.
[0104] Optionally, the fusion unit 320 is specifically configured to, according to the fusion algorithm, input a security key and all symmetric keys into the fusion algorithm to obtain a first fusion key corresponding to the security key;
[0105] The process of inputting a security key and all symmetric keys into the fusion algorithm to obtain a first fusion key corresponding to the security key is repeatedly executed until a first fusion key corresponding to each security key is obtained.
[0106] Optionally, the additional security exchange information includes an additional key exchange quantity field, a key algorithm identification field, and at least one additional key exchange block;
[0107] The additional key exchange quantity field carries the number of the additional key exchange blocks; the key algorithm identification field carries the fusion algorithm identification; each additional key exchange block includes an additional key exchange algorithm identification field, an additional key exchange data length field and an additional key exchange data field;
[0108] The additional key exchange algorithm identification field carries the identification of the key algorithm used to generate the symmetric key; the additional key exchange data length field carries the length of the symmetric key; and the additional key exchange data field carries additional key exchange data.
[0109] Optionally, the usage feature includes an authentication feature and an encryption feature;
[0110] The processing unit 330 is specifically configured to, if the usage feature of the first security key is the authentication feature, use the first fusion key corresponding to the first security key as a key for realizing the authentication feature;
[0111] or;
[0112] The processing unit 330 is specifically configured to, if the usage feature of the first security key is the encryption feature, use the first fusion key corresponding to the first security key as a key for implementing the encryption feature.
[0113] Therefore, using the communication device provided by the present application, the first CPE receives the first SDWAN route sent by the RR, the first SDWAN route includes the second initial security exchange information and the second additional security exchange information, the second initial security exchange information includes at least one second security protocol information supported by the second CPE, and the second additional security exchange information includes a second fusion algorithm identifier, at least one second additional algorithm information, and second additional key exchange data corresponding to each second additional algorithm; if the first security protocol information is the same as the second security protocol information, the first additional algorithm information is the same as the second additional algorithm information, and the first fusion algorithm identifier and the second fusion algorithm identifier indicate the same fusion algorithm, the first CPE performs key fusion processing on each first security key and all the first symmetric keys respectively to obtain a first fusion key corresponding to each first security key; according to the usage characteristics of each first security key, the first CPE uses the corresponding first fusion key as the key to implement the usage characteristics;
[0114] Each first symmetric key is calculated by the first CPE according to the first additional key exchange data and the second additional key exchange data according to the first additional algorithm, and the first additional key exchange data and the second additional key exchange data correspond to the same additional algorithm.
[0115] In this way, at least one symmetric key is carried through the SDWAN route, so that during the CPE negotiation process, the security key and the symmetric key are merged, and the merged key is used to authenticate and / or encrypt the data message transmitted through the SDWAN tunnel. This solves the problem that the existing various types of keys are easily obtained by a third party, and the communication content between the RR and the CPE is easily cracked and leaked when the third party attacks. At the same time, it also realizes that the merged key can resist the attack of quantum computers.
[0116] Based on the same inventive concept, the embodiment of the present application also provides a network device, such as Figure 4 As shown, it includes a processor 410, a transceiver 420 and a machine-readable storage medium 430, the machine-readable storage medium 430 stores machine-executable instructions that can be executed by the processor 410, and the processor 410 is prompted by the machine-executable instructions to execute the communication method provided in the embodiment of the present application. Figure 3 The communication device shown can be used as Figure 4 The network device hardware structure shown is implemented.
[0117] The computer-readable storage medium 430 may include a random access memory (RAM) or a non-volatile memory (NVM), such as at least one disk storage. Optionally, the computer-readable storage medium 430 may also be at least one storage device located away from the processor 410.
[0118] The processor 410 may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gates or transistor logic devices, or discrete hardware components.
[0119] In the embodiment of the present application, the processor 410 reads the machine executable instructions stored in the machine readable storage medium 430, and the machine executable instructions enable the processor 410 itself and the transceiver 420 to execute the communication method described in the aforementioned embodiment of the present application.
[0120] In addition, an embodiment of the present application provides a machine-readable storage medium 430, which stores machine-executable instructions. When called and executed by the processor 410, the machine-executable instructions prompt the processor 410 itself and the calling transceiver 420 to execute the communication method described in the aforementioned embodiment of the present application.
[0121] The implementation process of the functions and effects of each unit in the above-mentioned device is specifically described in the implementation process of the corresponding steps in the above-mentioned method, and will not be repeated here.
[0122] For the device embodiment, since it basically corresponds to the method embodiment, the relevant parts can refer to the partial description of the method embodiment. The device embodiment described above is only schematic, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the present application scheme. A person of ordinary skill in the art can understand and implement it without paying any creative work.
[0123] As for the communication device and machine-readable storage medium embodiments, since the method contents involved are basically similar to the aforementioned method embodiments, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiments.
[0124] The above description is only a preferred embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application shall be included in the scope of protection of the present application.
Claims
1. A communication method, characterized in that: The method is applied to a first CPE, wherein first initial security exchange information and first additional security exchange information have been configured in the first CPE, wherein the first initial security exchange information includes at least one first security protocol information supported by the first CPE and a first security key corresponding to each first security protocol, and the first additional security exchange information includes a first fusion algorithm identifier, at least one first additional algorithm information and first additional key exchange data corresponding to each first additional algorithm, and the method includes: Receive a first SDWAN route sent by the RR, where the first SDWAN route includes second initial security exchange information and second additional security exchange information, where the second initial security exchange information includes at least one second security protocol information supported by the second CPE, and the second additional security exchange information includes a second fusion algorithm identifier, at least one second additional algorithm information, and second additional key exchange data corresponding to each second additional algorithm; If the first security protocol information is the same as the second security protocol information, the first additional algorithm information is the same as the second additional algorithm information, and the first fusion algorithm identifier and the second fusion algorithm identifier indicate the same fusion algorithm, each first security key is respectively fused with all the first symmetric keys to obtain a first fusion key corresponding to each first security key; According to the usage characteristics of each first security key, using the corresponding first fusion key as a key for realizing the usage characteristics; Each first symmetric key is calculated by the first CPE according to the first additional key exchange data and the second additional key exchange data according to a first additional algorithm, and the first additional key exchange data and the second additional key exchange data correspond to the same additional algorithm.
2. The method according to claim 1, characterized in that The second initial security exchange information further includes a second security key corresponding to each second security protocol, and the method further includes: Sending a second SDWAN route to the RR, where the second SDWAN route includes the first initial security exchange information and the first additional security exchange information, so that the RR sends the second SDWAN to the second CPE, and after determining that the security exchange information all corresponds to the same and the fusion algorithm identifiers all indicate the same fusion algorithm, the second CPE performs key fusion processing on each second security key and all the second symmetric keys to obtain a second fusion key corresponding to each second security key; according to the usage characteristics of each second security key, using the corresponding second fusion key as a key to realize the usage characteristics; Each second symmetric key is calculated by the second CPE according to the first additional key exchange data and the second additional key exchange data according to a second additional algorithm, and the first additional key exchange data and the second additional key exchange data correspond to the same additional algorithm.
3. The method according to claim 2, characterized in that Before receiving the first SDWAN route sent by the RR, the method further includes: receiving a configuration instruction input by a user, wherein the configuration instruction includes the at least one first security protocol information and the at least one first additional algorithm information; According to each of the first security protocols, generate the corresponding first security key, and according to each of the first additional algorithms, generate the corresponding first additional key exchange data; The second SDWAN route is generated according to the at least one first security protocol, each of the first security keys, the at least one first additional algorithm information, and each first additional key exchange data.
4. The method according to claim 1, characterized in that The step of performing key fusion processing on each first security key and all first symmetric keys to obtain a first fusion key corresponding to each first security key specifically includes: According to the fusion algorithm, a security key and all symmetric keys are input into the fusion algorithm to obtain a first fusion key corresponding to the security key; The process of inputting a security key and all symmetric keys into the fusion algorithm to obtain a first fusion key corresponding to the security key is repeatedly executed until a first fusion key corresponding to each security key is obtained.
5. The method according to any one of claims 1 or 2, characterized in that: The additional security exchange information includes an additional key exchange quantity field, a key algorithm identification field, and at least one additional key exchange block; The additional key exchange quantity field carries the number of the additional key exchange blocks; The key algorithm identification field carries the fusion algorithm identification; each additional key exchange block includes an additional key exchange algorithm identification field, an additional key exchange data length field and an additional key exchange data field; The additional key exchange algorithm identification field carries the identification of the key algorithm used to generate the symmetric key; the additional key exchange data length field carries the length of the symmetric key; and the additional key exchange data field carries additional key exchange data.
6. The method according to claim 1, characterized in that The usage features include authentication features and encryption features; The using the corresponding first fusion key as a key for realizing the usage feature according to the usage feature of each first security key specifically includes: If the usage feature of the first security key is the authentication feature, using the first fusion key corresponding to the first security key as a key for realizing the authentication feature; or; If the usage feature of the first security key is the encryption feature, the first fusion key corresponding to the first security key serves as a key for implementing the encryption feature.
7. A communication device, characterized in that: The device is applied to a first CPE, wherein first initial security exchange information and first additional security exchange information are configured in the first CPE, wherein the first initial security exchange information includes at least one first security protocol information supported by the first CPE and a first security key corresponding to each first security protocol, and the first additional security exchange information includes a first fusion algorithm identifier, at least one first additional algorithm information and first additional key exchange data corresponding to each first additional algorithm, and the device includes: a receiving unit, configured to receive a first SDWAN route sent by the RR, wherein the first SDWAN route includes second initial security exchange information and second additional security exchange information, wherein the second initial security exchange information includes at least one second security protocol information supported by the second CPE, and the second additional security exchange information includes a second fusion algorithm identifier, at least one second additional algorithm information, and second additional key exchange data corresponding to each second additional algorithm; a fusion unit, configured to, if the first security protocol information is the same as the second security protocol information, the first additional algorithm information is the same as the second additional algorithm information, and the first fusion algorithm identifier and the second fusion algorithm identifier indicate the same fusion algorithm, perform key fusion processing on each first security key with all the first symmetric keys to obtain a first fusion key corresponding to each first security key; a processing unit, configured to use, according to the usage characteristics of each first security key, the corresponding first fusion key as a key for realizing the usage characteristics; Each first symmetric key is calculated by the first CPE according to the first additional key exchange data and the second additional key exchange data according to a first additional algorithm, and the first additional key exchange data and the second additional key exchange data correspond to the same additional algorithm.
8. The device according to claim 7, characterized in that The second initial security exchange information further includes a second security key corresponding to each second security protocol, and the device further includes: a sending unit, configured to send a second SDWAN route to the RR, wherein the second SDWAN route includes the first initial security exchange information and the first additional security exchange information, so that the RR sends the second SDWAN to the second CPE, and after determining that the security exchange information all corresponds to the same and the fusion algorithm identifiers all indicate the same fusion algorithm, the second CPE performs key fusion processing on each second security key and all the second symmetric keys respectively to obtain a second fusion key corresponding to each second security key; and according to a usage feature of each second security key, use the corresponding second fusion key as a key to realize the usage feature; Each second symmetric key is calculated by the second CPE according to the first additional key exchange data and the second additional key exchange data according to a second additional algorithm, and the first additional key exchange data and the second additional key exchange data correspond to the same additional algorithm.
9. The device according to claim 8, characterized in that The receiving unit is further used to receive a configuration instruction input by a user, wherein the configuration instruction includes the at least one first security protocol information and the at least one first additional algorithm information; The apparatus further includes: a first generating unit, configured to generate the corresponding first security key according to each first security protocol, and to generate the corresponding first additional key exchange data according to each first additional algorithm; The second generating unit is used to generate the second SDWAN route according to the at least one first security protocol information, each first security key, the at least one first additional algorithm information and each first additional key exchange data.
10. The device according to claim 7, characterized in that The fusion unit is specifically used to, according to the fusion algorithm, input a security key and all symmetric keys into the fusion algorithm to obtain a first fusion key corresponding to the security key; The process of inputting a security key and all symmetric keys into the fusion algorithm to obtain a first fusion key corresponding to the security key is repeatedly executed until a first fusion key corresponding to each security key is obtained.
11. The device according to any one of claims 7 or 8, characterized in that The additional security exchange information includes an additional key exchange quantity field, a key algorithm identification field, and at least one additional key exchange block; The additional key exchange quantity field carries the number of the additional key exchange blocks; The key algorithm identification field carries the fusion algorithm identification; each additional key exchange block includes an additional key exchange algorithm identification field, an additional key exchange data length field and an additional key exchange data field; The additional key exchange algorithm identification field carries the identification of the key algorithm used to generate the symmetric key; the additional key exchange data length field carries the length of the symmetric key; and the additional key exchange data field carries additional key exchange data.
12. The device according to claim 7, characterized in that The usage features include authentication features and encryption features; The processing unit is specifically configured to, if the usage feature of the first security key is the authentication feature, use the first fusion key corresponding to the first security key as a key for realizing the authentication feature; or; The processing unit is specifically configured to, if the usage feature of the first security key is the encryption feature, use the first fusion key corresponding to the first security key as a key for implementing the encryption feature.
Citation Information
Patent Citations
Method and system for managing keys of routing protocol
CN102420740A
EVPN-based key distribution protocol and processing method
CN117714045A
Secure Communication Method, Apparatus, and System
US20220255909A1
Internet Protocol Security (IPsec) Simplification in Border Gateway Protocol (BGP)-Controlled Software-Defined Wide Area Networks (SD-WANs)
US20230079689A1