Communication methods and devices

By integrating security keys and symmetric keys in SDWAN routing to generate a fused key, the problem of keys being easily obtained by attackers is solved, thus achieving security of communication content and resistance to quantum computing.

CN120034392BActive Publication Date: 2025-12-02NEW H3C TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510310978.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-14
Publication Date
2025-12-02
Estimated Expiration
2045-03-14

AI Technical Summary

Technical Problem

In existing SDWAN networks, the encryption keys are easily obtained by third parties, which makes communication content extremely easy to crack and leak.

Method used

By carrying additional key exchange data in the SDWAN route, the security key and symmetric key are fused to generate a fused key, which is then used to authenticate and encrypt data packets.

Benefits of technology

It effectively prevents attackers from obtaining the keys, protects communication content from being cracked and leaked, and resists attacks from quantum computers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120034392B_ABST
    Figure CN120034392B_ABST
Patent Text Reader

Abstract

This application provides a communication method and apparatus. The method includes: receiving a first SDWAN route sent by RR, which includes second initial security exchange information and second additional security exchange information. The second initial security exchange information includes second security protocol information, and the second additional security exchange information includes a second fusion algorithm identifier, at least one second additional algorithm information, and second additional key exchange data corresponding to each second additional algorithm. If the first security protocol information is the same as the second security protocol information, the first additional algorithm information is the same as the second additional algorithm information, and the first fusion algorithm identifier and the second fusion algorithm identifier indicate the same fusion algorithm, then each first security key is fused with all first symmetric keys to obtain a first fusion key. Based on the usage characteristics of each first security key, the corresponding first fusion key is used as the key to implement the usage characteristics.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to a communication method and apparatus. Background Technology

[0002] The development of cloud computing technology has triggered a transformation in the IT industry, and the "Internet Plus" strategy has driven the transformation of traditional industries. In 2014, the internetization of enterprise customers (To B) surpassed that of ordinary users (To C). Software-defined wide area network (SDWAN) services, focusing on the enterprise market and the wide area network (WAN) domain, emerged against this industry backdrop and expectation.

[0003] SDWAN is a VPN technology that applies SDN technology to WAN scenarios. SDWAN technology aims to help users reduce WAN costs, improve network connectivity flexibility, and provide secure and reliable interconnection services for enterprise networks, data center networks, and other networks distributed across a wide geographical area.

[0004] The existing SDWAN network includes a central site (Route Reflector, RR), branch site 1 (Customer Provided Edge, CPE1), and branch site 2 (CPE2). The establishment of control and data channels in this network is illustrated below, using the establishment of a control and data channel between RR and CPE1 as an example.

[0005] An SSL connection (control channel) is established between CPE1 and RR. CPE1 acts as the SSL client, referred to as the SDWAN client, while RR acts as the SSL server, referred to as the SDWAN server. CPE1 and RR exchange Transport Tunnel Endpoint (TTE) information (including SiteID, DeviceID, PublicIP, PrivateIP, SystemIP, IPsec authentication algorithm and key, IPsec encryption algorithm and key, etc.) via the SSL connection to establish an SDWAN tunnel (control channel). CPE1 and RR also exchange BGP protocol messages through the SDWAN tunnel, establishing a BGP SDWAN peer relationship using CPE1's site system ID (system-ip-cpe1) and RR's site system ID (system-ip-rr). CPE1 generates a BGP SDWAN route based on its own TTE information and sends it to RR. RR reflects the received BGP SDWAN route back to CPE2. Through this route, CPE2 obtains the TTE information of CPE1, triggering it to create an SDWAN data channel (SDWAN tunnel) to CPE1. Since the TTE information of CPE1 includes encrypted information such as IPsec authentication algorithm and key, IPsec encryption algorithm and key, the SDWAN tunnels established between CPE1 and RR and CPE2 respectively also support security features. Packets forwarded through the SDWAN tunnel will be encrypted and authenticated.

[0006] However, in the above process, although the message is authenticated and encrypted before being forwarded, the encryption key and authentication key included in the TTE information may be obtained by a third party during transmission. If the third party is an attacker and obtains various keys, the communication content can easily be cracked and leaked during subsequent interactive communication with RR, CPE, etc. Summary of the Invention

[0007] In view of this, this application provides a communication method and apparatus to solve the problem that existing types of keys are easily obtained by third parties, and that the communication content between RR and CPE can be easily cracked and leaked by third parties using attack methods.

[0008] In a first aspect, this application provides a communication method applied to a first CPE, wherein the first CPE is configured with first initial security exchange information and first additional security exchange information. The first initial security exchange information includes at least one first security protocol information supported by the first CPE and a first security key corresponding to each first security protocol. The first additional security exchange information includes a first fusion algorithm identifier, at least one first additional algorithm information, and first additional key exchange data corresponding to each first additional algorithm. The method includes:

[0009] Receive a first SDWAN route sent by RR. The first SDWAN route includes second initial security exchange information and second additional security exchange information. The second initial security exchange information includes at least one second security protocol information supported by the second CPE. The second additional security exchange information includes a second fusion algorithm identifier, at least one second additional algorithm information, and second additional key exchange data corresponding to each second additional algorithm.

[0010] If the first security protocol information is the same as the second security protocol information, the first additional algorithm information is the same as the second additional algorithm information, and the first fusion algorithm identifier and the second fusion algorithm identifier indicate the same fusion algorithm, then each first security key will be fused with all the first symmetric keys to obtain a first fusion key corresponding to each first security key.

[0011] Based on the usage characteristics of each first security key, the corresponding first fusion key is used as the key to implement the usage characteristics;

[0012] Each first symmetric key is calculated by the first CPE according to the first additional key exchange data and the second additional key exchange data using the first additional algorithm. The first additional key exchange data and the second additional key exchange data both correspond to the same additional algorithm.

[0013] Secondly, this application provides a communication device applied to a first CPE, wherein the first CPE is configured with first initial security exchange information and first additional security exchange information. The first initial security exchange information includes at least one first security protocol information supported by the first CPE and a first security key corresponding to each first security protocol. The first additional security exchange information includes a first fusion algorithm identifier, at least one first additional algorithm information, and first additional key exchange data corresponding to each first additional algorithm. The device includes:

[0014] The receiving unit is configured to receive a first SDWAN route sent by RR. The first SDWAN route includes second initial security exchange information and second additional security exchange information. The second initial security exchange information includes at least one second security protocol information supported by the second CPE. The second additional security exchange information includes a second fusion algorithm identifier, at least one second additional algorithm information, and second additional key exchange data corresponding to each second additional algorithm.

[0015] The fusion unit is configured to perform key fusion processing on each first security key with all first symmetric keys respectively, if the first security protocol information is the same as the second security protocol information, the first additional algorithm information is the same as the second additional algorithm information, and the first fusion algorithm identifier and the second fusion algorithm identifier indicate the same fusion algorithm, to obtain a first fusion key corresponding to each first security key;

[0016] The processing unit is configured to use the corresponding first fusion key as the key to implement the usage characteristics of each first security key;

[0017] Each first symmetric key is calculated by the first CPE according to the first additional key exchange data and the second additional key exchange data using the first additional algorithm. The first additional key exchange data and the second additional key exchange data both correspond to the same additional algorithm.

[0018] Thirdly, this application provides another network device, including a processor and a machine-readable storage medium storing machine-executable instructions that can be executed by the processor, which in turn causes the processor to perform the method provided in the first aspect of this application.

[0019] Therefore, using the communication method and apparatus provided in this application, the first CPE receives a first SDWAN route sent by RR. The first SDWAN route includes second initial security exchange information and second additional security exchange information. The second initial security exchange information includes at least one second security protocol information supported by the second CPE. The second additional security exchange information includes a second fusion algorithm identifier, at least one second additional algorithm information, and second additional key exchange data corresponding to each second additional algorithm. If the first security protocol information is the same as the second security protocol information, the first additional algorithm information is the same as the second additional algorithm information, and the first fusion algorithm identifier and the second fusion algorithm identifier indicate the same fusion algorithm, then the first CPE performs key fusion processing on each first security key with all first symmetric keys to obtain a first fusion key corresponding to each first security key. According to the usage characteristics of each first security key, the first CPE uses the corresponding first fusion key as the key to implement the usage characteristics. Each first symmetric key is calculated by the first CPE according to the first additional key exchange data and the second additional key exchange data according to the first additional algorithm. The first additional key exchange data and the second additional key exchange data both correspond to the same additional algorithm.

[0020] In this way, by carrying at least one additional key exchange data through SDWAN routing, a symmetric key is obtained during CPE negotiation through the additional key exchange data. The security key and the symmetric key are then fused, and the fused key is used to authenticate and / or encrypt data packets transmitted through the SDWAN tunnel. This solves the problem that existing types of keys are easily obtained by third parties, making it extremely easy for third parties to crack and leak the communication content between RR and CPE. At the same time, it also enables the fused key to resist attacks from quantum computers. Attached Figure Description

[0021] Figure 1 A flowchart illustrating the communication method provided in the embodiments of this application;

[0022] Figure 2 This is a schematic diagram of the IPSec Sub-TLV format provided in an embodiment of this application;

[0023] Figure 3 A structural diagram of a communication device provided in an embodiment of this application;

[0024] Figure 4 The network device hardware structure provided in the embodiments of this application. Detailed Implementation

[0025] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numerals in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0026] The terminology used in this application is for the purpose of describing particular embodiments only and is not intended to be limiting of the application. The singular forms “a,” “the,” and “the” used in this application and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to and includes any or all possible combinations of one or more of the corresponding listed items.

[0027] It should be understood that although the terms first, second, third, etc., may be used in this application to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, without departing from the scope of this application, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the word "if" as used herein may be interpreted as "when," "when," or "in response to determination."

[0028] The communication method provided in the embodiments of this application will be described in detail below. See also... Figure 1 , Figure 1 A flowchart illustrating a communication method provided in an embodiment of this application. This method is applied to a first CPE. The communication method provided in an embodiment of this application may include the following steps.

[0029] Step 110: Receive the first SDWAN route sent by RR. The first SDWAN route includes second initial security exchange information and second additional security exchange information. The second initial security exchange information includes at least one second security protocol information supported by the second CPE. The second additional security exchange information includes a second fusion algorithm identifier, at least one second additional algorithm information, and second additional key exchange data corresponding to each second additional algorithm.

[0030] Specifically, in an SDWAN network, the RR establishes a control channel with each CPE, and each CPE establishes a data channel with each other. Both the control channel and the data channel are SDWAN tunnels. In this embodiment, the process of establishing the control channel can be implemented according to existing procedures, and will not be repeated here.

[0031] The following explanation focuses on establishing an encrypted data channel between the first CPE and the second CPE.

[0032] After establishing a control channel with the RR, the second CPE also establishes a BGPSDWAN peer relationship with the RR. The second CPE generates the first SDWAN route based on its own TTE information.

[0033] The first SDWAN route includes second initial security exchange information and second additional security exchange information. The second initial security exchange information includes at least one second security protocol information supported by the second CPE. The second additional security exchange information includes a second fusion algorithm identifier, at least one second additional algorithm information, and second additional key exchange data corresponding to each second additional algorithm.

[0034] The second CPE sends the first SDWAN route to the RR. After receiving the first SDWAN route, the RR sends (or reflects) it back to the first CPE. After receiving the first SDWAN route, the first CPE obtains the second initial security exchange information and the second additional security exchange information from it. It also obtains at least one second security protocol information supported by the second CPE from the second initial security exchange information, and obtains the second fusion algorithm identifier, at least one second additional algorithm information, and the second additional key exchange data corresponding to each second additional algorithm from the second additional security exchange information.

[0035] Optionally, in this embodiment of the application, the first SDWAN route includes an MP_REACH_NLRI attribute, which includes an NLRI field, which includes a Data subfield, and the Data subfield includes IPSecSub-TLV format.

[0036] The above IPSec Sub-TLV format is as follows: Figure 2 As shown, Figure 2 This is a schematic diagram of the IPSec Sub-TLV format provided in an embodiment of this application. The IPSec Sub-TLV format includes a security protocol (Transform) field, a transport field, an AH field, an ESP1 field, an ESP2 field, a Reserved field, an SPI field, a Key1 length field, a Key1 field, a Key2 length field, a Key2 field, a Key3 length field, a Key3 field, and a duration field.

[0037] The definition and configuration of each of the above fields are the same as those defined in the existing IPSec Sub-TLV format, which will be briefly explained below.

[0038] The `Transform` field indicates the security protocols supported by the CPE, with values ​​of 1, 2, and 3. For example, a value of 1 indicates support for Authentication Header (AH) authentication, a value of 2 indicates support for Encapsulating Security Payload (ESP) authentication, and a value of 3 indicates support for both AH authentication and ESP encryption. The `Transport` field indicates the transmission mode; currently, `Tunnelmode` is supported. The `AH` field indicates the algorithm used for AH authentication. The `ESP1` field indicates the algorithm used for ESP authentication. The `ESP2` field indicates the algorithm used for ESP encryption. The `SPI` field indicates the Security Parameter Index (SPI) of the IPSec SA. The `Key1Length` field indicates the length of the AH authentication key. The `Key1` field indicates the value of the AH authentication key. The `Key2Length` field indicates the length of the ESP authentication key. The `Key2` field indicates the value of the ESP authentication key. The `Key3Length` field indicates the length of the ESP encryption key. The `Key3` field indicates the value of the ESP encryption key. The `Duration` field indicates the lifespan of the IPSec SA.

[0039] In this embodiment of the application, the information carried in the Transform field, AH field, ESP1 field and ESP2 field is referred to as the second security protocol information, and the Key carried in the Key1 field, Key2 field and Key3 field is referred to as the second security key.

[0040] Optionally, in this embodiment of the application, the IPSec Sub-TLV format further includes an Additional Key Exchange Number field, a Key Algorithm Identifier (PrfID) field, and at least one Additional Key Exchange Block. Each Additional Key Exchange Block includes an Additional Key Exchange Transform ID field, an Additional Key Exchange Data Length field, and an Additional Key Exchange Data field.

[0041] The Additional Key Exchange Number field indicates the number of additional key exchanges, with a maximum value of 7; the PrfID field indicates the PRF algorithm identifier, which is used to implement key fusion (for example, the PRF algorithm can be any of the following: PRF_HMAC_MD5, PRF_HMAC_SHA1, PRF_HMAC_TIGER, PRF_AES128_XCBC, PRF_HMAC_SHA2_256, PRF_HMAC_SHA2_384, PRF_HMAC_SHA2_512, PRF_AES128_CMAC, PRF_HMAC_STREEBOG_512); the Additional Key Exchange TransformID field indicates the Additional Key Exchange algorithm ID; the Additional Key Exchange Data Length field indicates the length of the Additional Key Exchange data; and the Additional Key Exchange Data field indicates the Additional Key Exchange data.

[0042] In this embodiment, the information carried in the Additional Key Exchange Number field, the PrfID field, and at least one additional key exchange block is referred to as second additional security exchange information. The information carried in the PrfID field is referred to as the second fusion algorithm identifier. The information carried in the Additional Key Exchange Transform ID field is referred to as the second additional algorithm information, and the information carried in the Additional Key Exchange Data field is referred to as the second additional key exchange data.

[0043] It is understandable that the term "second" is used to distinguish other initial security exchange information, additional security exchange information, security protocol information, fusion algorithm identifier, additional algorithm information, and additional key exchange data. In practical applications, it can also be referred to as "first," "third," etc.

[0044] Step 120: If the first security protocol information is the same as the second security protocol information, the first additional algorithm information is the same as the second additional algorithm information, and the first fusion algorithm identifier and the second fusion algorithm identifier indicate the same fusion algorithm, then each first security key is fused with all the first symmetric keys to obtain a first fusion key corresponding to each first security key.

[0045] Specifically, according to the description of step 110, after the first CPE obtains at least one second security protocol information, a second fusion algorithm identifier, at least one second additional algorithm information, and second additional key exchange data corresponding to each second additional algorithm supported by the second CPE from the first SDWAN route, it obtains at least one first security protocol information, a first additional algorithm identifier, and a first fusion algorithm identifier supported by itself from the local machine.

[0046] The first CPE compares whether the first security protocol information is the same as the second security protocol information, whether the first additional algorithm information is the same as the second additional algorithm information, and whether the first fusion algorithm identifier and the second fusion algorithm identifier indicate the same fusion algorithm.

[0047] If the security protocol information, additional algorithm information, and fusion algorithm identifier are all the same, the first CPE obtains the first security key corresponding to each first security protocol and the first additional key corresponding to each first additional algorithm from the local machine to exchange data.

[0048] According to each first or second appending algorithm, the first CPE obtains first appending key exchange data and second appending key exchange data belonging to the same appending algorithm. The first CPE performs operations on the first appending key exchange data and the second appending key exchange data according to the corresponding appending algorithm to obtain the first symmetric key.

[0049] The first CPE repeats the above process until the first symmetric key corresponding to each additional algorithm is obtained.

[0050] The first CPE performs key fusion processing on each first security key and all first symmetric keys respectively to obtain the first fusion key corresponding to each first security key.

[0051] Optionally, in this embodiment of the application, if there are multiple first security keys, the first CPE performs key fusion processing on each first security key with all the first symmetric keys to obtain a first fused key corresponding to each first security key. The specific process is as follows:

[0052] According to the fusion algorithm, the first CPE inputs a security key and all symmetric keys into the fusion algorithm to obtain the first fusion key (PQKey) corresponding to the security key; the first CPE repeats the process of inputting a security key and all symmetric keys into the fusion algorithm to obtain the first fusion key corresponding to the security key until the first fusion key corresponding to each security key is obtained.

[0053] That is: PQKey1=prf+(Key1,SK(1)|SK(2)|…SK(n))

[0054] PQKey2=prf+(Key2,SK(1)|SK(2)|…SK(n))

[0055] PQKey3=prf+(Key3,SK(1)|SK(2)|…SK(n))

[0056] Where Key is the security key and SK(n) is the symmetric key.

[0057] In one example, the first CPE obtains the Transform field value of 3 from the first SDWAN route, indicating that the second CPE itself supports AH authentication and ESP encryption, and obtains the AH field value as MD5 and the ESP2 field value as DES-CBC.

[0058] The first CPE confirms that it also supports AH authentication and ESP encryption, and that the AH authentication uses the MD5 algorithm, while the ESP encryption uses the DES-CBC algorithm. At this point, the first CPE confirms that it and the second CPE both support the same authentication and encryption algorithms.

[0059] The first CPE retrieves the Additional Key Exchange Number field from the first SDWAN route again, and the value is 3, indicating that the first SDWAN route carries three additional key exchange blocks. For example, additional key exchange block 1 (hereinafter referred to as block 1), additional key exchange block 2 (hereinafter referred to as block 2), and additional key exchange block 3 (hereinafter referred to as block 3). The value of the PrfID field is PRF_HMAC_MD5.

[0060] In Block 1, the Additional Key Exchange Transform ID field has a value of 768-bit MODPGroup, and the Additional Key Exchange Data field has a value of Additional Key Exchange Data 1, meaning that Additional Key Exchange Data 1 was obtained by the second CPE using the 768-bit MODP Group algorithm. In Block 2, the Additional Key Exchange Transform ID field has a value of 1024-bit MODP Group, and the Additional Key Exchange Data field has a value of Additional Key Exchange Data 2, meaning that Additional Key Exchange Data 2 was obtained by the second CPE using the 1024-bit MODP Group algorithm. In Block 3, the Additional Key Exchange Transform ID field has a value of 1536-bit MODPGroup, and the Additional Key Exchange Data field has a value of Additional Key Exchange Data 3, meaning that Additional Key Exchange Data 3 was obtained by the second CPE using the 1536-bit MODP Group algorithm.

[0061] The first CPE retrieves its supported fusion algorithm identifier (PRF_HMAC_MD5) and three additional algorithm information (768-bit MODP Group, 1024-bit MODP Group, and 1536-bit MODP Group) locally. After comparison, the first CPE determines that the fusion algorithm identifier and the three additional algorithm information are the same.

[0062] The first CPE calculates the symmetric key 1, SK(1) using the first and second additional key exchange data corresponding to the 768-bit MODP Group algorithm. Similarly, the first CPE calculates the symmetric key 2, SK(2) using the first and second additional key exchange data corresponding to the 1024-bit MODP Group algorithm. Similarly, the first CPE calculates the symmetric key 3, SK(3) using the first and second additional key exchange data corresponding to the 1536-bit MODP Group algorithm.

[0063] The first CPE continues to acquire the security key corresponding to each security protocol it supports. For example, it acquires the initial key 1 for AH authentication and the initial key 2 for ESP encryption.

[0064] According to the fusion algorithm (PRF_HMAC_MD5), the first CPE first inputs the initial key 1, symmetric key 1, symmetric key 2 and symmetric key 3 into PRF_HMAC_MD5 to obtain the fusion key 1 corresponding to the initial key 1, that is, PQKey1=prf+(Key1,SK(1)|SK(2)|SK(3)).

[0065] Similarly, the first CPE inputs the initial key 2, symmetric key 1, symmetric key 2 and symmetric key 3 into PRF_HMAC_MD5 to obtain the fusion key 2 corresponding to the initial key 2, that is, PQKey2=prf+(Key1,SK(1)|SK(2)|SK(3)).

[0066] Step 130: Based on the usage characteristics of each first security key, use the corresponding first fusion key as the key to implement the usage characteristics.

[0067] Specifically, according to the description of step 120, after the first CPE obtains the first fusion key corresponding to each first security key, it uses the corresponding first fusion key as the key to implement the usage characteristics according to the usage characteristics of each first security key.

[0068] Optionally, in this embodiment, the features used include authentication features and encryption features. The authentication feature refers to the first security key being used to implement AH authentication or ESP authentication; the encryption feature refers to the first security key being used to implement ESP encryption.

[0069] The specific process by which the first CPE uses the corresponding first fusion key as the key to implement the usage characteristics of each first security key is as follows:

[0070] If the usage feature of the first security key is an authentication feature, then the first CPE uses the first fusion key corresponding to the first security key as the key to implement the authentication feature; or, if the usage feature of the first security key is an encryption feature, then the first CPE uses the first fusion key corresponding to the first security key as the key to implement the encryption feature.

[0071] Based on the example above, security key 1 is used for AH authentication. Therefore, PQKey1, which corresponds to security key 1, is subsequently used to perform AH authentication on data packets transmitted through the SDWAN tunnel. Similarly, initial key 2 is used for ESP encryption. Therefore, PQKey2, which corresponds to initial key 2, is subsequently used to perform ESP encryption on data packets transmitted through the SDWAN tunnel.

[0072] Therefore, using the communication method provided in this application, the first CPE receives a first SDWAN route sent by RR. The first SDWAN route includes second initial security exchange information and second additional security exchange information. The second initial security exchange information includes at least one second security protocol information supported by the second CPE. The second additional security exchange information includes a second fusion algorithm identifier, at least one second additional algorithm information, and second additional key exchange data corresponding to each second additional algorithm. If the first security protocol information is the same as the second security protocol information, the first additional algorithm information is the same as the second additional algorithm information, and the first fusion algorithm identifier and the second fusion algorithm identifier indicate the same fusion algorithm, then the first CPE performs key fusion processing on each first security key with all first symmetric keys to obtain a first fusion key corresponding to each first security key. According to the usage characteristics of each first security key, the first CPE uses the corresponding first fusion key as the key to implement the usage characteristics. Each first symmetric key is calculated by the first CPE according to the first additional key exchange data and the second additional key exchange data according to the first additional algorithm. The first additional key exchange data and the second additional key exchange data both correspond to the same additional algorithm.

[0073] Thus, by carrying at least one symmetric key via SDWAN routing, the security key and symmetric key are fused during CPE negotiation, and the fused key is used to authenticate and / or encrypt data packets transmitted through the SDWAN tunnel. This solves the problem that existing key types are easily obtained by third parties, making it extremely easy for third-party attacks to crack and leak communication content between RR and CPE. Simultaneously, it also ensures that the fused key is resistant to attacks from quantum computers.

[0074] Optionally, in this embodiment, after establishing a control channel with the RR, the first CPE also establishes a BGPSDWAN peer relationship with the RR. The first CPE generates a second SDWAN route based on its own TTE information.

[0075] It is understandable that the packet structure of the second SDWAN route is the same as that of the first SDWAN route, and will not be repeated here.

[0076] Meanwhile, the second SDWAN route has the same function as the first SDWAN route, which is sent to the second CPE via RR so that the second CPE and the first CPE can negotiate and establish a data channel.

[0077] Specifically, the aforementioned second initial security exchange information also includes a second security key corresponding to each second security protocol.

[0078] The first CPE generates a second SDWAN route, which includes first initial security exchange information and first additional security exchange information. The first initial security exchange information includes at least one first security protocol information supported by the first CPE, and the first additional security exchange information includes a first fusion algorithm identifier, at least one first additional algorithm information, and first additional key exchange data corresponding to each first additional algorithm.

[0079] The first CPE sends the second SDWAN route to the RR. After receiving the second SDWAN route, the RR sends it to the second CPE. Based on the second SDWAN route, after determining that all security exchange information corresponds to the same fusion algorithm and that all fusion algorithm identifiers indicate the same fusion algorithm, the second CPE performs key fusion processing on each second security key with all second symmetric keys to obtain a second fusion key corresponding to each second security key. Based on the usage characteristics of each second security key, the second CPE uses the corresponding second fusion key as the key to implement the usage characteristics.

[0080] Each second symmetric key is calculated by the second CPE according to the second additional key exchange data and the second additional key exchange data, and the first additional key exchange data and the second additional key exchange data correspond to the same additional algorithm.

[0081] It is understandable that the steps performed by the second CPE after receiving the second SDWAN route are the same as those performed by the first CPE after receiving the first SDWAN route, and will not be repeated here.

[0082] Optionally, in this embodiment of the application, the first CPE also receives configuration instructions input by the user, and configures the first security protocol information and the first additional algorithm information locally according to the configuration instructions.

[0083] Specifically, the user inputs configuration instructions to the first CPE via command line. These configuration instructions include at least one first security protocol information and at least one first additional algorithm information.

[0084] After receiving the configuration command, the first CPE obtains at least one first security protocol information and at least one first additional algorithm information.

[0085] According to each first security protocol, the first CPE generates a corresponding first security key, and according to each first additional algorithm, generates corresponding first additional key exchange data.

[0086] The first CPE generates a second SDWAN route based on at least one first security protocol information, each first security key, at least one first additional algorithm information, and data exchanged for each first additional key.

[0087] Similarly, users can also input configuration instructions to the second CPE via command line. These configuration instructions include at least one second security protocol information and at least one first additional algorithm information.

[0088] After receiving the configuration command, the second CPE obtains at least one second security protocol information and at least one second additional algorithm information.

[0089] According to each second security protocol, the second CPE generates a corresponding second security key, and according to each second additional algorithm, generates a corresponding first symmetric key.

[0090] The second CPE generates the first SDWAN route based on at least one second security protocol information, each second security key, at least one second additional algorithm information, and each first symmetric key.

[0091] The aforementioned security protocol information is used to enable the CPE to locally support AH authentication, or ESP authentication, or both AH authentication and ESP encryption; the aforementioned additional algorithm information is used to enable the CPE to locally support which PRF algorithm to use for key fusion, and which additional algorithm to use to calculate the symmetric key and the number of additional key exchanges.

[0092] Therefore, by including the above configuration information in the SDWAN route, the two CPEs can negotiate with each other during the data channel establishment process, and each end can calculate a converged key corresponding to the security key. Subsequently, after sending data packets through the SDWAN tunnel, the corresponding converged key is used to authenticate and / or encrypt the data packets based on the usage characteristics of the security key.

[0093] Based on the same inventive concept, embodiments of this application also provide a communication device corresponding to the communication method. See also Figure 3 , Figure 3 The communication device provided in this application embodiment includes a first initial security exchange information and a first additional security exchange information configured within the first CPE. The first initial security exchange information includes at least one first security protocol information supported by the first CPE and a first security key corresponding to each first security protocol. The first additional security exchange information includes a first fusion algorithm identifier, at least one first additional algorithm information, and first additional key exchange data corresponding to each first additional algorithm. The device includes:

[0094] The receiving unit 310 is configured to receive a first SDWAN route sent by RR. The first SDWAN route includes second initial security exchange information and second additional security exchange information. The second initial security exchange information includes at least one second security protocol information supported by the second CPE. The second additional security exchange information includes a second fusion algorithm identifier, at least one second additional algorithm information, and second additional key exchange data corresponding to each second additional algorithm.

[0095] The fusion unit 320 is configured to perform key fusion processing on each first security key with all first symmetric keys if the first security protocol information is the same as the second security protocol information, the first additional algorithm information is the same as the second additional algorithm information, and the first fusion algorithm identifier and the second fusion algorithm identifier indicate the same fusion algorithm, so as to obtain a first fusion key corresponding to each first security key.

[0096] The processing unit 330 is configured to use the corresponding first fusion key as the key to implement the usage characteristics of each first security key;

[0097] Each first symmetric key is calculated by the first CPE according to the first additional key exchange data and the second additional key exchange data using the first additional algorithm. The first additional key exchange data and the second additional key exchange data both correspond to the same additional algorithm.

[0098] Optionally, the second initial security exchange information further includes a second security key corresponding to each second security protocol, and the device further includes:

[0099] A sending unit (not shown in the figure) is used to send a second SDWAN route to the RR. The second SDWAN route includes the first initial security exchange information and the first additional security exchange information, so that the RR sends the second SDWAN to the second CPE. After determining that all security exchange information corresponds to the same fusion algorithm and that all fusion algorithm identifiers indicate the same fusion algorithm, the second CPE performs key fusion processing on each second security key with all second symmetric keys to obtain a second fusion key corresponding to each second security key. According to the usage characteristics of each second security key, the corresponding second fusion key is used as the key to implement the usage characteristics.

[0100] Each second symmetric key is calculated by the second CPE according to the first additional key exchange data and the second additional key exchange data using the second additional algorithm. The first additional key exchange data and the second additional key exchange data both correspond to the same additional algorithm.

[0101] Optionally, the receiving unit 310 is further configured to receive a configuration instruction input by a user, the configuration instruction including the at least one first security protocol information and the at least one first additional algorithm information;

[0102] The apparatus further includes: a first generation unit (not shown in the figure), configured to generate a corresponding first security key according to each first security protocol, and generate corresponding first additional key exchange data according to each first additional algorithm;

[0103] The second generation unit (not shown in the figure) is used to generate the second SDWAN route based on the at least one first security protocol information, each first security key, the at least one first additional algorithm information, and each first additional key exchange data.

[0104] Optionally, the fusion unit 320 is specifically used to input a security key and all symmetric keys into the fusion algorithm according to the fusion algorithm to obtain a first fusion key corresponding to the security key;

[0105] The process of inputting a security key and all symmetric keys into the fusion algorithm to obtain the first fusion key corresponding to the security key is repeated until the first fusion key corresponding to each security key is obtained.

[0106] Optionally, the additional security exchange information includes an additional key exchange quantity field, a key algorithm identifier field, and at least one additional key exchange block;

[0107] The additional key exchange quantity field carries the number of additional key exchange blocks; the key algorithm identifier field carries the fusion algorithm identifier; each additional key exchange block includes an additional key exchange algorithm identifier field, an additional key exchange data length field, and an additional key exchange data field;

[0108] The additional key exchange algorithm identifier field carries the identifier of the key algorithm used to generate the symmetric key; the additional key exchange data length field carries the length of the symmetric key; and the additional key exchange data field carries the additional key exchange data.

[0109] Optionally, the usage features include authentication features and encryption features;

[0110] The processing unit 330 is specifically used to, if the usage feature of the first security key is the authentication feature, then use the first fusion key corresponding to the first security key as the key to implement the authentication feature;

[0111] or;

[0112] The processing unit 330 is specifically used to, if the usage characteristic of the first security key is the encryption characteristic, then the first fusion key corresponding to the first security key is used as the key to implement the encryption characteristic.

[0113] Therefore, using the communication device provided in this application, the first CPE receives a first SDWAN route sent by RR. The first SDWAN route includes second initial security exchange information and second additional security exchange information. The second initial security exchange information includes at least one second security protocol information supported by the second CPE. The second additional security exchange information includes a second fusion algorithm identifier, at least one second additional algorithm information, and second additional key exchange data corresponding to each second additional algorithm. If the first security protocol information is the same as the second security protocol information, the first additional algorithm information is the same as the second additional algorithm information, and the first fusion algorithm identifier and the second fusion algorithm identifier indicate the same fusion algorithm, then the first CPE performs key fusion processing on each first security key with all first symmetric keys to obtain a first fusion key corresponding to each first security key. According to the usage characteristics of each first security key, the first CPE uses the corresponding first fusion key as the key to implement the usage characteristics.

[0114] Each first symmetric key is calculated by the first CPE according to the first additional key exchange data and the second additional key exchange data using the first additional algorithm. The first additional key exchange data and the second additional key exchange data both correspond to the same additional algorithm.

[0115] Thus, by carrying at least one symmetric key via SDWAN routing, the security key and symmetric key are fused during CPE negotiation, and the fused key is used to authenticate and / or encrypt data packets transmitted through the SDWAN tunnel. This solves the problem that existing key types are easily obtained by third parties, making it extremely easy for third-party attacks to crack and leak communication content between RR and CPE. Simultaneously, it also ensures that the fused key is resistant to attacks from quantum computers.

[0116] Based on the same inventive concept, embodiments of this application also provide a network device, such as... Figure 4 As shown, the system includes a processor 410, a transceiver 420, and a machine-readable storage medium 430. The machine-readable storage medium 430 stores machine-executable instructions that can be executed by the processor 410. The processor 410 is prompted by the machine-executable instructions to execute the communication method provided in the embodiments of this application. (The foregoing...) Figure 3 The communication device shown can be used as follows: Figure 4 The hardware structure of the network device shown is implemented.

[0117] The aforementioned computer-readable storage medium 430 may include random access memory (RAM) or non-volatile memory (NVM), such as at least one disk storage device. Optionally, the computer-readable storage medium 430 may also be at least one storage device located remotely from the aforementioned processor 410.

[0118] The processor 410 mentioned above can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.

[0119] In this embodiment of the application, the processor 410 reads the machine-executable instructions stored in the machine-readable storage medium 430, and is prompted by the machine-executable instructions to enable the processor 410 itself and the transceiver 420 to execute the communication method described in the foregoing embodiment of the application.

[0120] In addition, this application provides a machine-readable storage medium 430 that stores machine-executable instructions. When called and executed by the processor 410, the machine-executable instructions cause the processor 410 itself and the transceiver 420 to execute the communication method described in the aforementioned application.

[0121] The specific implementation process of the functions and roles of each unit in the above device can be found in the implementation process of the corresponding steps in the above method, and will not be repeated here.

[0122] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to in the description of the method embodiments. The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this application according to actual needs. Those skilled in the art can understand and implement this without creative effort.

[0123] For the embodiments of communication devices and machine-readable storage media, since the methods involved are basically similar to those of the aforementioned method embodiments, the description is relatively simple, and relevant details can be found in the descriptions of the method embodiments.

[0124] The above description is merely a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.

Claims

1. A communication method, characterized in that, The method is applied to a first CPE, which has been configured with first initial security exchange information and first additional security exchange information. The first initial security exchange information includes at least one first security protocol information supported by the first CPE and a first security key corresponding to each first security protocol. The first additional security exchange information includes a first fusion algorithm identifier, at least one first additional algorithm information, and first additional key exchange data corresponding to each first additional algorithm. The method includes: Receive a first SDWAN route sent by RR. The first SDWAN route includes second initial security exchange information and second additional security exchange information. The second initial security exchange information includes at least one second security protocol information supported by the second CPE. The second additional security exchange information includes a second fusion algorithm identifier, at least one second additional algorithm information, and second additional key exchange data corresponding to each second additional algorithm. If the first security protocol information is the same as the second security protocol information, the first additional algorithm information is the same as the second additional algorithm information, and the first fusion algorithm identifier and the second fusion algorithm identifier indicate the same fusion algorithm, then each first security key will be fused with all the first symmetric keys to obtain a first fusion key corresponding to each first security key. Based on the usage characteristics of each first security key, the corresponding first fusion key is used as the key to implement the usage characteristics; Each first symmetric key is calculated by the first CPE according to the first additional key exchange data and the second additional key exchange data using the first additional algorithm. The first additional key exchange data and the second additional key exchange data both correspond to the same additional algorithm.

2. The method according to claim 1, characterized in that, The second initial security exchange information also includes a second security key corresponding to each second security protocol, and the method further includes: The RR sends a second SDWAN route, which includes the first initial security exchange information and the first additional security exchange information, so that the RR sends the second SDWAN to the second CPE. After determining that all security exchange information corresponds to the same fusion algorithm and that all fusion algorithm identifiers indicate the same fusion algorithm, the second CPE performs key fusion processing on each second security key with all second symmetric keys to obtain a second fusion key corresponding to each second security key. According to the usage characteristics of each second security key, the corresponding second fusion key is used as the key to implement the usage characteristics. Each second symmetric key is calculated by the second CPE according to the first additional key exchange data and the second additional key exchange data using the second additional algorithm. The first additional key exchange data and the second additional key exchange data both correspond to the same additional algorithm.

3. The method according to claim 2, characterized in that, Before receiving the first SDWAN route sent by RR, the method further includes: The system receives configuration instructions input by the user, the configuration instructions including at least one first security protocol information and at least one first additional algorithm information; According to each of the first security protocols, a corresponding first security key is generated, and according to each of the first additional algorithms, corresponding first additional key exchange data is generated; The second SDWAN route is generated based on the at least one first security protocol, each first security key, the at least one first additional algorithm information, and each first additional key exchange data.

4. The method according to claim 1, characterized in that, The step of performing key fusion processing on each first security key with all first symmetric keys to obtain a first fusion key corresponding to each first security key specifically includes: According to the fusion algorithm, a security key and all symmetric keys are input into the fusion algorithm to obtain a first fusion key corresponding to the security key; The process of inputting a security key and all symmetric keys into the fusion algorithm to obtain the first fusion key corresponding to the security key is repeated until the first fusion key corresponding to each security key is obtained.

5. The method according to any one of claims 1 or 2, characterized in that, The additional security exchange information includes an additional key exchange quantity field, a key algorithm identifier field, and at least one additional key exchange block; The additional key exchange quantity field carries the number of additional key exchange blocks; The key algorithm identifier field carries the fusion algorithm identifier; each additional key exchange block includes an additional key exchange algorithm identifier field, an additional key exchange data length field, and an additional key exchange data field. The additional key exchange algorithm identifier field carries the identifier of the key algorithm used to generate the symmetric key; the additional key exchange data length field carries the length of the symmetric key; and the additional key exchange data field carries the additional key exchange data.

6. The method according to claim 1, characterized in that, The usage features include authentication features and encryption features; The step of using the corresponding first fusion key as the key to implement the usage characteristics of each first security key specifically includes: If the usage characteristic of the first security key is the authentication characteristic, then the first fusion key corresponding to the first security key is used as the key to implement the authentication characteristic; or; If the usage characteristic of the first security key is the encryption characteristic, then the first fusion key corresponding to the first security key serves as the key for implementing the encryption characteristic.

7. A communication device, characterized in that, The device is applied to a first CPE, which is configured with first initial security exchange information and first additional security exchange information. The first initial security exchange information includes at least one first security protocol information supported by the first CPE and a first security key corresponding to each first security protocol. The first additional security exchange information includes a first fusion algorithm identifier, at least one first additional algorithm information, and first additional key exchange data corresponding to each first additional algorithm. The device includes: The receiving unit is configured to receive a first SDWAN route sent by RR. The first SDWAN route includes second initial security exchange information and second additional security exchange information. The second initial security exchange information includes at least one second security protocol information supported by the second CPE. The second additional security exchange information includes a second fusion algorithm identifier, at least one second additional algorithm information, and second additional key exchange data corresponding to each second additional algorithm. The fusion unit is configured to perform key fusion processing on each first security key with all first symmetric keys respectively, if the first security protocol information is the same as the second security protocol information, the first additional algorithm information is the same as the second additional algorithm information, and the first fusion algorithm identifier and the second fusion algorithm identifier indicate the same fusion algorithm, to obtain a first fusion key corresponding to each first security key; The processing unit is configured to use the corresponding first fusion key as the key to implement the usage characteristics of each first security key; Each first symmetric key is calculated by the first CPE according to the first additional key exchange data and the second additional key exchange data using the first additional algorithm. The first additional key exchange data and the second additional key exchange data both correspond to the same additional algorithm.

8. The apparatus according to claim 7, characterized in that, The second initial security exchange information also includes a second security key corresponding to each second security protocol, and the device further includes: A sending unit is configured to send a second SDWAN route to the RR, the second SDWAN route including the first initial security exchange information and the first additional security exchange information, so that the RR sends the second SDWAN to the second CPE. After determining that all security exchange information corresponds to the same fusion algorithm and that all fusion algorithm identifiers indicate the same fusion algorithm, the second CPE performs key fusion processing on each second security key with all second symmetric keys to obtain a second fusion key corresponding to each second security key; according to the usage characteristics of each second security key, the corresponding second fusion key is used as the key to implement the usage characteristics. Each second symmetric key is calculated by the second CPE according to the first additional key exchange data and the second additional key exchange data using the second additional algorithm. The first additional key exchange data and the second additional key exchange data both correspond to the same additional algorithm.

9. The apparatus according to claim 8, characterized in that, The receiving unit is further configured to receive configuration instructions input by the user, the configuration instructions including at least one first security protocol information and at least one first additional algorithm information; The apparatus further includes: a first generation unit, configured to generate a corresponding first security key according to each first security protocol, and to generate corresponding first additional key exchange data according to each first additional algorithm; The second generation unit is used to generate the second SDWAN route based on the at least one first security protocol information, each first security key, the at least one first additional algorithm information, and each first additional key exchange data.

10. The apparatus according to claim 7, characterized in that, The fusion unit is specifically used to input a security key and all symmetric keys into the fusion algorithm according to the fusion algorithm to obtain a first fusion key corresponding to the security key; The process of inputting a security key and all symmetric keys into the fusion algorithm to obtain the first fusion key corresponding to the security key is repeated until the first fusion key corresponding to each security key is obtained.

11. The apparatus according to any one of claims 7 or 8, characterized in that, The additional security exchange information includes an additional key exchange quantity field, a key algorithm identifier field, and at least one additional key exchange block; The additional key exchange quantity field carries the number of additional key exchange blocks; The key algorithm identifier field carries the fusion algorithm identifier; each additional key exchange block includes an additional key exchange algorithm identifier field, an additional key exchange data length field, and an additional key exchange data field. The additional key exchange algorithm identifier field carries the identifier of the key algorithm used to generate the symmetric key; the additional key exchange data length field carries the length of the symmetric key; and the additional key exchange data field carries the additional key exchange data.

12. The apparatus according to claim 7, characterized in that, The usage features include authentication features and encryption features; The processing unit is specifically used to, if the usage feature of the first security key is the authentication feature, then use the first fusion key corresponding to the first security key as the key to implement the authentication feature; or; The processing unit is specifically used to, if the usage characteristic of the first security key is the encryption characteristic, then the first fusion key corresponding to the first security key is used as the key to implement the encryption characteristic.

Citation Information

Patent Citations

  • Method and system for managing keys of routing protocol

    CN102420740A

  • EVPN-based key distribution protocol and processing method

    CN117714045A