Route verification information generation method and device and related equipment
By introducing the IBC system into RPKI technology, the system identification and routing prefix information of AS are used to generate the identification private key, which solves the problem of low storage and transmission efficiency caused by the large amount of ROA data, and realizes more efficient network data processing and transmission.
Patent Information
- Application Number
- CN202510192402.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-20
- Publication Date
- 2025-05-27
AI Technical Summary
In RPKI technology, the amount of ROA is large, resulting in low storage and transmission efficiency, affecting the stability and reliability of the network.
By introducing the IBC system, the system identification and published routing prefix information of the AS are directly used to generate the identification private key, and the signature generates authorization signature information, thereby reducing the amount of certificate data stored in the ROA.
It reduces the amount of ROA data, improves storage and transmission efficiency, reduces computing resource consumption, and improves the overall efficiency and stability of the network.
Smart Images

Figure CN120050085A_ABST
Abstract
Description
Background Art
[0002] Resource Public Key Infrastructure (RPKI) is a technology based on Public Key Infrastructure (PKI) that aims to verify the authenticity and legitimacy of routing information published by Border Gateway Protocol (BGP), thereby effectively preventing network security issues such as routing hijacking. In the RPKI system, the authentication of Internet number resource allocation relationships such as IP addresses and Autonomous System (AS) numbers is achieved by extending X.509 digital certificates. In addition, RPKI further authenticates the authorization relationship of IP addresses by issuing a series of Route Origin Authorization (ROA) data objects, thereby ensuring the legitimacy of the originating AS in the BGP routing announcement.
[0003] In related technologies, upper-level allocation agencies (such as the Internet Assigned Numbers Authority IANA, Regional Internet Registries RIRs, etc.) will issue Certificate Authority (CA) certificates to Internet Service Providers (ISPs). The ISP uses the private key of the CA certificate to further issue an End Entity (EE) certificate. Subsequently, the ISP uses the private key of the EE certificate to issue the ROA. It is worth noting that the EE certificate is stored as an important field of the ROA to prove the identity of the issuer of the ROA and the legitimacy of its authorization relationship.
[0004] However, since RPKI stipulates that the EE certificate should be stored as a field of ROA, this practice results in a relatively large amount of data in ROA. Since the EE certificate contains multiple fields such as public key, certificate authority information, validity period, etc., the storage of these fields in ROA not only increases the complexity of the data, but also may affect the storage efficiency and transmission speed of ROA. Therefore, how to reduce the data volume of ROA and improve the storage and transmission efficiency of ROA has become a key issue that needs to be solved in the current development of RPKI technology.
[0005] It should be noted that the information disclosed in the above background technology section is only used to enhance the understanding of the background of the present disclosure, and therefore may include information that does not constitute the prior art known to ordinary technicians in the field. Summary of the invention
[0006] The present disclosure provides a method, an apparatus and related devices for generating routing verification information, achieving the goal of reducing the number of stored certificates and saving the corresponding storage space.
[0007] Other features and advantages of the present disclosure will become apparent from the following detailed description or will be learned in part through the practice of the present disclosure.
[0008] According to one aspect of the present disclosure, there is provided a method for generating routing verification information, the method including: obtaining the system identifier of a routing autonomous system (AS) and the routing prefix information published by the AS; using the identity private key of the IBC system to sign the system identifier of the AS and the routing prefix information published by the AS to generate authorized signature information, where the identity private key is generated by the IBC system according to the system identifier of the AS and the routing prefix information published by the AS; generating routing verification information according to the authorized signature information, the identifier of the generating institution, the system identifier of the AS, and the routing prefix information published by the AS.
[0009] In some embodiments, the IBC system includes an IBC key generation center. Before using the identity private key of the IBC system to sign the system identifier of the AS and the routing prefix information published by the AS to generate authorized signature information, the method further includes: using the IBC key generation center to generate IBC system basic parameters and an IBC system master key, where the IBC system master key is used to calculate the system identifier of the AS and the routing prefix information published by the AS to generate the identity private key and the identity public key.
[0010] In some embodiments, the method further includes: obtaining the private key corresponding to the digital certificate of the generating institution, where the digital certificate of the generating institution is issued by a trusted digital certificate issuing institution; signing the IBC system parameters with the private key corresponding to the digital certificate to generate an IBC system parameter certificate; where there is a one-to-one correspondence between the identifier of the generating institution and the IBC system parameter certificate.
[0011] In some embodiments, the method further includes: verifying the routing verification information according to the identifier of the generating institution, the IBC system parameter certificate, and the routing verification information.
[0012] In some embodiments, verifying the routing verification information according to the identifier of the generation institution, the IBC system parameter certificate, and the routing verification information includes: determining, according to the identifier of the generation institution in the routing verification information, the IBC system parameter certificate corresponding to the identifier of the generation institution and the public key corresponding to the digital certificate of the generation institution; determining whether the IBC system parameter certificate is valid according to the public key corresponding to the digital certificate; when the IBC system parameter certificate is invalid, determining that the routing in the routing verification information is an invalid routing; when the IBC system parameter certificate is valid, generating an identification public key according to the IBC system parameters in the IBC system parameter certificate, the system identifier of the AS in the routing verification information, and the routing prefix information published by the AS, and verifying the authorization signature information in the routing verification information according to the identification public key; when the signature verification passes, determining that the routing in the routing verification information is a valid routing; when the signature verification fails, determining that the routing in the routing verification information is an invalid routing.
[0013] In some embodiments, after generating the routing verification information according to the authorization signature information, the identifier of the generation institution, the system identifier of the AS, and the routing prefix information published by the AS, the method further includes: obtaining a revocation identifier, the system identifier of the routing autonomous system AS, and the routing prefix information published by the AS; using the identification private key of the IBC system to sign the revocation identifier, the system identifier of the AS, and the routing prefix information published by the AS to obtain a first revocation signature information; generating a first revocation information of the routing verification information according to the first revocation signature information, the identifier of the generation institution, the system identifier of the AS, and the routing prefix information published by the AS.
[0014] In some embodiments, the method further includes: determining, according to the identifier of the generation institution in the first revocation information, the IBC system parameter certificate corresponding to the identifier of the generation institution and the public key corresponding to the digital certificate of the generation institution; determining whether the IBC system parameter certificate is valid according to the public key corresponding to the digital certificate; when the IBC system parameter certificate is invalid, rejecting the first revocation information; when the IBC system parameter certificate is valid, generating an identification public key according to the IBC system parameters in the IBC system parameter certificate, the system identifier of the AS in the routing verification information, and the routing prefix information published by the AS, and verifying the first revocation signature information in the first revocation information according to the identification public key; when the signature verification passes, revoking the routing verification information; when the signature verification fails, rejecting the first revocation information.
[0015] In some embodiments, after generating the routing verification information based on the authorized signature information, the identifier of the generating institution, the system identifier of the AS, and the routing prefix information published by the AS, the method further includes: obtaining a revocation identifier, the system identifier of the routing autonomous system AS, and the routing prefix information published by the AS; using the private key corresponding to the digital certificate to sign the revocation identifier, the system identifier of the AS, and the routing prefix information published by the AS to obtain a second revocation signature information; generating a second revocation information of the routing verification information based on the second revocation signature information, the identifier of the generating institution, the system identifier of the AS, and the routing prefix information published by the AS.
[0016] In some embodiments, the method further includes: determining a digital certificate corresponding to the identifier of the generating institution according to the identifier of the generating institution in the second revocation information, wherein there is a one-to-one correspondence between the identifier of the generating institution and the digital certificate; determining whether the digital certificate is valid; when the digital certificate is invalid, rejecting the second revocation information; when the digital certificate is valid, verifying the second revocation signature information in the second revocation information using the public key corresponding to the digital certificate; when the verification passes, revoking the routing verification information; when the verification fails, rejecting the second revocation information.
[0017] According to another aspect of the present disclosure, there is also provided a routing verification information generation device, the device includes: an obtaining module, configured to obtain the system identifier of the routing autonomous system AS and the routing prefix information published by the AS; a first generation module, configured to use the private key of the identifier of the IBC system to sign the system identifier of the AS and the routing prefix information published by the AS to generate authorized signature information, wherein the private key of the identifier is generated by the IBC system according to the system identifier of the AS and the routing prefix information published by the AS; a second generation module, configured to generate routing verification information according to the authorized signature information, the identifier of the generating institution, the system identifier of the AS, and the routing prefix information published by the AS.
[0018] According to another aspect of the present disclosure, there is also provided an electronic device, the electronic device includes: a processor; and a memory, configured to store executable instructions of the processor; wherein the processor is configured to execute the verification information generation method described in any one of the above via executing the executable instructions.
[0019] According to another aspect of the present disclosure, there is also provided a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the verification information generation method described in any one of the above is implemented.
[0020] According to another aspect of the present disclosure, there is also provided a computer program product, including: a computer program or instruction, which, when executed by a processor, implements the verification information generation method of any one of the above.
[0021] A method, apparatus and related device for generating routing verification information provided in an embodiment of the present disclosure. The method includes: obtaining the system identifier of a routing autonomous system (AS) and the routing prefix information published by the AS; using the identity private key of the IBC system to sign the system identifier of the AS and the routing prefix information published by the AS to generate authorized signature information, where the identity private key is generated by the IBC system according to the system identifier of the AS and the routing prefix information published by the AS; generating routing verification information according to the authorized signature information, the identifier of the generating institution, the system identifier of the AS, and the routing prefix information published by the AS. By introducing the identity-based cryptography (IBC) system, the method of the present disclosure can directly generate the identity private key for signature by using the system identifier of the AS and the published routing prefix information, thereby avoiding storing the complete EE certificate in the ROA, reducing the data volume of the ROA, and thus saving storage space.
[0022] Furthermore, due to the reduction in the ROA data volume, the time and resources required for storing and transmitting the ROA will also be correspondingly reduced. The overall efficiency of the network is improved. Especially in a large-scale network environment, it can respond more quickly to routing changes, enhancing the stability and reliability of the network.
[0023] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] The drawings herein are incorporated into the specification and constitute a part of this specification, showing embodiments consistent with the present disclosure, and are used together with the specification to explain the principles of the present disclosure. Obviously, the drawings in the following description are only some embodiments of the present disclosure, and those of ordinary skill in the art can obtain other drawings based on these drawings without creative efforts.
[0025] Figure 1 A schematic diagram showing an overall RPKI architecture in an embodiment of the present disclosure;
[0026] Figure 2 A schematic diagram showing the issuance of resource certificates in RPKI in a related art in an embodiment of the present disclosure;
[0027] Figure 3 A schematic diagram showing the system architecture of a method for generating routing verification information in an embodiment of the present disclosure;
[0028] Figure 4Shows a flowchart of a method for generating verification information in an embodiment of the present disclosure;
[0029] Figure 5 Shows a schematic structural diagram of an RPKI system based on an IBC system in an embodiment of the present disclosure;
[0030] Figure 6 Shows a flowchart of a method for implementing an IBC system in an embodiment of the present disclosure;
[0031] Figure 7 Shows a flowchart of a method for generating an IBC system parameter certificate in an embodiment of the present disclosure;
[0032] Figure 8 Shows a flowchart of a method for verifying routing verification information in an embodiment of the present disclosure;
[0033] Figure 9 Shows a flowchart of a method for verifying routing verification information in an embodiment of the present disclosure;
[0034] Figure 10 Shows a flowchart of a method for generating a routing verification information revocation message in an embodiment of the present disclosure;
[0035] Figure 11 Shows a flowchart of a method for revoking routing verification information in an embodiment of the present disclosure;
[0036] Figure 12 Shows a flowchart of another method for generating a routing verification information revocation message in an embodiment of the present disclosure;
[0037] Figure 13 Shows a flowchart of another method for revoking routing verification information in an embodiment of the present disclosure;
[0038] Figure 14 Shows a specific implementation flowchart of a method for generating routing verification information in an embodiment of the present disclosure;
[0039] Figure 15 Shows a schematic diagram of a device for generating routing verification information in an embodiment of the present disclosure;
[0040] Figure 16 Shows a structural block diagram of an electronic device in an embodiment of the present disclosure. Detailed implementation manners
[0041] Example embodiments will now be described more fully with reference to the accompanying drawings. However, the example embodiments can be implemented in various forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the concept of example embodiments to those skilled in the art. The described features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.
[0042] In addition, the accompanying drawings are only schematic illustrations of the present disclosure and are not necessarily drawn to scale. The same reference numerals in the drawings denote the same or similar parts, and thus repeated descriptions thereof will be omitted. Some of the block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities may be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.
[0043] For ease of understanding, before introducing the embodiments of the present disclosure, first, in combination with Figure 1 the schematic diagram of the RPKI architecture shown, several terms involved in the embodiments of the present disclosure are explained as follows:
[0044] Resource Public Key Infrastructure (RPKI): A technical framework based on Public Key Infrastructure (PKI), specifically designed to enhance the security of the Internet routing infrastructure. RPKI, also known as resource authentication, aims to ensure the authenticity and legality of Internet routing information by providing cryptographically verifiable guarantees, thereby preventing network security issues such as route hijacking. It establishes an architecture that defines the IP addresses and / or autonomous system numbers (ASNs) legally held by entities and provides cryptographic guarantees for authorizing one or more autonomous systems (ASs) to originate routes for the IP prefixes they hold. RPKI does not attach signatures to BGP (Border Gateway Protocol) announcements but stores the signatures independently in an out-of-band manner in the RPKI repository. These signatures are retrieved and verified by specialized RPKI servers, and the verified results are provided to routers to guide their route selection. RPKI extends X.509 certificates to authenticate the allocation relationships of Internet number resources such as IP addresses and AS numbers, and further authenticates the IP address authorization relationships by issuing a series of Route Origin Authorization (ROA) data objects, thereby ensuring the legality of the originating AS in BGP route announcements.
[0045] Autonomous System (AS): It is a collection of a group of IP networks managed by one or more network operators in the Internet. From a technical perspective, it has a unified routing policy. For example, the network within a large enterprise or all the networks of an Internet Service Provider (ISP) can form an autonomous system. In terms of routing protocols, the Interior Gateway Protocol (IGP), such as OSPF (Open Shortest Path First), is used within an autonomous system to manage the routing of the internal network; while between different autonomous systems, the Exterior Gateway Protocol (EGP), such as BGP (Border Gateway Protocol), is used to exchange routing information, thus achieving the interconnection and interoperability of the entire Internet.
[0046] Route Origin Authorization (ROA): ROA is a mechanism used to verify the authenticity and legality of Internet routing information. It is mainly used to ensure that the source of the routing prefixes propagated through the Border Gateway Protocol (BGP) is authorized. Simply put, ROA is like an "ID card" for a route. It specifies the legitimate owner and the originating autonomous system (AS) of a certain IP address prefix, and only the route announcements that comply with the ROA regulations are considered trustworthy.
[0047] Certification Authority (CA): When the Internet Assigned Numbers Authority (such as the five major RIRs) assigns resources to the holders of Internet number resources, it will issue a CA certificate with its own private key. The certificate includes the public key of the resource holder and the corresponding Internet number resources, indicating that the resource holder has obtained the legal authorization to use this part of the number resources.
[0048] End-Entity (EE) Certificate: When the resource owner wishes to authorize an AS to announce the IP address prefix it owns, it will first issue an EE certificate with its own private key, and then use the private key of the EE certificate to issue a ROA to complete the binding of the IP address prefix and this AS.
[0049] Digital Signature: Digital signature is a method used to verify the authenticity and integrity of electronic documents using asymmetric encryption technology. It is usually used to ensure that a message or document has not been tampered with and to verify the identity of the sender. Digital signature is a very important part of the information security field and is widely used in fields such as e-commerce, legal documents, and software release.
[0050] RPKI Repository (Resource Public Key Infrastructure Repository): All certificates involved in RPKI are stored in the RPKI repository. The RPKI repository adopts a distributed storage structure and consists of many databases. Multiple RPKI repositories constitute a certificate storage system.
[0051] RPKI Relying Party (RP): RPKI sets up the relying party as an agent for BGP routers, responsible for some repetitive and offline-processable transactions, including synchronous downloading of data objects, construction and verification of certificate chains, generation and transmission of INR authorization relationship information, and cache management, etc. It is one of the executors of the certificate synchronization verification mechanism.
[0052] Internet Assigned Numbers Authority (IANA): It is an organization responsible for managing global Internet number resources and belongs to the certificate issuance system, including IP addresses, AS numbers, domain names, etc. Its main responsibility is to formulate the allocation rules and standards for global Internet number resources to ensure the stability and security of the Internet.
[0053] Regional Internet Registry (RIR): It is an organization responsible for allocating and managing Internet number resources (such as IP addresses and autonomous system numbers) within a specific geographical area and belongs to the certificate issuance system. These organizations play a key role in the global Internet resource allocation system to ensure the reasonable allocation and effective utilization of Internet addresses within the region. For example, African Internet Data Information Center, RIPE NCC (for Europe), APNIC (for Asia-Pacific), ARIN (for the United States), LACNIC (for Latin America and the Caribbean), etc.
[0054] National Internet Registry (NIR): It is an institution that manages and allocates Internet number resources within a country. It coordinates and manages Internet resources at the national level and is an intermediate link between the Regional Internet Registry (RIR) and the Local Internet Registry (LIR). It should be noted that in some scenarios, the registration institutions at the same level as the national Internet registry may also include regional Internet registries.
[0055] Local Internet Registry (LIR): It is an institution that directly faces end-users or smaller network units and uses and manages Internet number resources. It is the most basic unit of Internet resource allocation and directly participates in the provision of Internet services.
[0056] Internet Service Provider (ISP): An Internet Service Provider (ISP) is a telecommunications operator that comprehensively provides Internet access services, information services, and value-added services to a large number of users. Its main role is to provide users with a way to access the Internet. For example, home broadband is achieved through an ISP. The ISP owns network infrastructure such as servers and communication lines. After users pay the ISP, they can use the network connection service provided by it to access various resources on the Internet, such as websites and email services. ISPs are also divided into different levels. There are backbone ISPs that connect major regional networks, and regional ISPs that provide services to local users. In addition, some large enterprises may also build their own network facilities to become their own ISPs to meet special needs such as internal office work.
[0057] Combined with Figure 1 As shown, the overall RPKI architecture consists of three parts: Certificate Issuance System: Composed of RPKI certification centers distributed globally, used for issuing RPKI resource certificates; Certificate Storage System: All certificates involved in RPKI are stored in the RPKI repository. The RPKI repository is a distributed storage structure composed of many databases; Certificate Synchronization and Verification Mechanism: The RPKI repository can be synchronized by relying parties. The RP synchronizes and verifies RPKI certificates and signature objects. After the RP synchronizes and verifies, it provides the verification result (the binding relationship between IP address prefixes and ASNs) to the border routers in the Internet inter-domain routing system to guide routing filtering. This system is composed of BGP routers deployed in different network autonomous domains. Among them, the square represents the RPKI certificate, and the circle represents the ROA.
[0058] Figure 2 Shows a schematic diagram of the RPKI issuing a resource certificate. Combined with Figure 2 As shown, the following exemplarily gives the process of the RPKI issuing resource certificates level by level from top to bottom. It should be noted that the certificate format in the following process is a simplified certificate format, not the actual certificate format. Among them, the square represents the RPKI certificate, and the circle represents the ROA.
[0059] 1. Asia-Pacific Network Information Center (APNIC) issues a self-signed root certificate ①: {Issuer: APNIC, Receiver: APNIC, Number Resources: 10.1.0.0 / 16, 10.2.0.0 / 16, AS1 - AS99}. After the certificate is generated, APNIC will store the root certificate in its own repository.
[0060] 2. APNIC issues a resource certificate ② for ISP1 using the root certificate ①: {Issuer: APNIC, Receiver: ISP1, Number resources: 10.1.0.0 / 18, 10.2.0.0 / 20, AS1-AS9}. After the certificate is generated, ISP1 will also store the issued certificate in its own database;
[0061] 3. ISP1 issues a ROA ③ using its own certificate ②: {Issuer: ISP1, Binding relationship: 10.1.1.0 / 24 & AS1}. By issuing a ROA signature, it authorizes a certain autonomous network to initiate a route origin announcement for a certain IP address prefix. The ROA binds the AS number of the autonomous network to the IP prefix.
[0062] Identity-Based Cryptography (IBC): IBC is an identity-based cryptographic system. In the traditional public-key cryptographic system, the user's public key is a string of random numbers, and the corresponding relationship between the public key and the user's identity needs to be verified through methods such as digital certificates. In IBC, the user's public key can be directly generated from the user's identity (such as email address, ID number, etc.), and the private key is generated by the Private Key Generator (PKG) according to the system master key and the user's identity and securely distributed to the user. Common identity-based cryptographic algorithms such as the domestic cryptographic algorithm SM9. In addition, there are other identity-based cryptographic algorithms, such as identity-based cryptographic algorithms based on elliptic curves. The elliptic curve algorithm uses the elliptic curve discrete logarithm problem to ensure security and has good performance on resource-constrained devices. In addition, there are identity-based cryptographic algorithms based on lattices. Lattice cryptography is constructed based on difficult problems on lattices, and its security is based on the difficulty in the quantum computing environment and is considered a potential candidate algorithm for resisting quantum computing.
[0063] The following will describe in detail the specific implementation manners of the embodiments of the present disclosure with reference to the accompanying drawings.
[0064] Figure 3 Shows an exemplary application system architecture diagram to which the routing verification information generation method in the embodiments of the present disclosure can be applied. As Figure 3 shown, the system architecture may include a terminal device 301, a network 302, and a server 303.
[0065] The network 302 is used to provide a medium for the communication link between the terminal device 301 and the server 303, which can be a wired network or a wireless network.
[0066] Optionally, the above-mentioned wireless network or wired network uses standard communication technologies and / or protocols. The network is usually the Internet, but can also be any network, including but not limited to any combination of a local area network (LAN), a metropolitan area network (MAN), a wide area network (WAN), a mobile, wired or wireless network, a private network or a virtual private network). In some embodiments, technologies and / or formats including Hyper Text Mark-up Language (HTML), Extensible Markup Language (XML), etc. are used to represent data exchanged through the network. In addition, conventional encryption technologies such as Secure Socket Layer (SSL), Transport Layer Security (TLS), Virtual Private Network (VPN), Internet Protocol Security (IPSec), etc. can be used to encrypt all or some of the links. In other embodiments, customized and / or dedicated data communication technologies can also be used to replace or supplement the above data communication technologies.
[0067] The terminal device 301 can be various electronic devices, including but not limited to smart phones, tablet computers, laptop portable computers, desktop computers, smart speakers, smart watches, wearable devices, augmented reality devices, virtual reality devices, etc.
[0068] Optionally, the clients of the application programs installed in different terminal devices 301 are the same, or clients of the same type of application programs based on different operating systems. Depending on the different terminal platforms, the specific form of the client of the application program can also be different. For example, the client of the application program can be a mobile client, a PC client, etc.
[0069] The server 303 can be a server that provides various services, such as a background management server that supports the operations performed by the user using the terminal device 301. The background management server can analyze and process data such as requests received, and feedback the processing results to the terminal device.
[0070] Optionally, the server can be an independent physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms.
[0071] Those skilled in the art can know that Figure 3 the number of terminal devices, networks, and servers in [[ ]] is only illustrative. According to actual needs, there can be any number of terminal devices, networks, and servers. The embodiments of the present disclosure do not limit this.
[0072] Under the above system architecture, an embodiment of the present disclosure provides a method for generating routing verification information, and this method can be executed by any electronic device with computing and processing capabilities.
[0073] In some embodiments, the method for generating routing verification information provided in the embodiments of the present disclosure can be executed by the terminal device of the above system architecture; in other embodiments, the method for generating routing verification information provided in the embodiments of the present disclosure can be executed by the server in the above system architecture; in other embodiments, the method for generating routing verification information provided in the embodiments of the present disclosure can be implemented by the terminal device and the server in the above system architecture through interaction.
[0074] Figure 4 Shows a flowchart of a method for generating verification information in an embodiment of the present disclosure. As Figure 4 shown, the method for generating routing verification information provided in the embodiments of the present disclosure includes the following steps:
[0075] S402, obtain the system identifier of the routing autonomous system AS and the routing prefix information published by the AS.
[0076] In this embodiment, a routing autonomous system (AS) is a collection of a group of IP networks managed by one or more Internet service providers (ISPs) or other network operators. These networks adopt a unified routing policy internally. The system identifier (ASN) is a globally unique identifier used to distinguish different autonomous systems. Just like each household has a house number, the ASN enables network devices such as routers to identify different ASs, such as AS1 and AS2. Routing prefix information refers to an IP address block and its associated mask information. For example, 192.168.1.0 / 24 is a routing prefix, indicating the IP address range from 192.168.1.0 to 192.168.1.255. An AS will publish the routing prefix information it manages, so that other network devices know how to reach the networks within this AS when performing routing selection. The system identifier of the routing autonomous system AS and the routing prefix information published by the AS are the content of the routing verification information that the ISP hopes to publish, that is, the binding relationship between the routing IP address prefix and the autonomous system AS.
[0077] S404, use the identity private key of the IBC system to sign the system identifier of the AS and the routing prefix information published by the AS to generate authorized signature information.
[0078] Among them, the identity private key is generated by the IBC system according to the system identifier of the AS and the routing prefix information published by the AS. IBC (Identity-Based Cryptography) is an identity-based cryptosystem. Unlike traditional cryptography that is based on the public key in the public key infrastructure, it directly uses the user's identity identifier (such as name, email, etc.) as the public key, avoiding the process of saving the public key through EE certificates in the traditional RPKI system during subsequent verification processes, and the private key corresponding to the public key is generated by the key generation center according to a specific algorithm.
[0079] In this embodiment, first, the IBC system generates an identity private key according to the system identifier of the AS and the routing prefix information it publishes. Then, use this identity private key to perform a signature operation on the system identifier of the AS and the routing prefix information. Finally, authorized signature information is generated, and this signature can be used for related purposes such as verifying the legitimacy of the information source.
[0080] Specifically, the ISP uses the identity private key to perform a signature operation on the system identifier of the AS and the routing prefix information published by the AS, binding the system identifier of the AS and the routing prefix information published by the AS.
[0081] In the traditional RPKI system, the issuance and management of EE certificates involve multiple steps and participants, increasing the complexity of management. In this embodiment, by directly generating a private key based on the IBC system using the routing verification information content, the certificate management process is simplified and the management cost is reduced.
[0082] S406. Generate routing verification information according to the authorized signature information, the identifier of the generating institution, the system identifier of the AS, and the routing prefix information published by the AS.
[0083] In this embodiment, the authorized signature information is an identifier information for verifying the legitimacy of the source, indicating the binding relationship between the system identifier of the AS and the routing prefix information. The identifier of the generating institution is used to represent the institution that issues the routing-related information data, which is unique and convenient for tracing and management, such as ISP1, ISP2, etc. In the following text, the relevant methods of the present disclosure will be exemplarily described with the ISP as the institution responsible for the issuance and maintenance of the routing verification information data object. However, it should be noted that within the scope of RPKI, in addition to the ISP, any Internet number resource holder can be responsible for the issuance and maintenance of data objects such as routing verification information, and the present disclosure does not limit this. The routing verification information is the ROA.
[0084] Specifically, the authorized signature information and the ISP identifier are used as additional fields of the ROA to verify the authenticity, integrity of the ROA content, and confirm the association relationship between the ISP and the ROA, etc. It should be noted that in the RPKI architecture, the ISP needs to upload the routing verification information to the RPKI repository for subsequent verification operations.
[0085] In this embodiment, by introducing the identity-based cryptography (IBC) system, the method of the present disclosure can directly generate an identity private key for signature using the system identifier of the AS and the published routing prefix information, thus avoiding storing the complete EE certificate for saving the public key in the ROA, reducing the data volume of the ROA, and further saving storage space. In addition, compared with the existing process of the RPKI resource owner issuing the ROA, where issuing the EE certificate and issuing the ROA require two signature operations, this method only requires one signature operation. The one signature operation for issuing the IBC system parameter certificate is regarded as amortized in multiple ROA issuance processes and can be ignored, thus reducing the computing resource consumption of the RPKI resource owner.
[0086] In some embodiments, Figure 5 is a schematic structural diagram of an RPKI system based on the IBC system. Combining Figure 5As shown, the RPKI resource owner (such as an ISP) adds the functions of the IBC key generation center of the IBC system, which can realize the generation of IBC system parameters, the master key, and the identity private key, as well as the functions of the IBC cryptographic operation unit of the IBC system, including signature operation using the identity private key; the RPKI repository adds the functions of the IBC cryptographic operation unit, including identity public key generation and signature verification operation using the public key; the ROA verifier (such as an RPKI relying party) adds the functions of the IBC cryptographic operation unit, including identity public key generation and signature verification operation using the public key.
[0087] In this embodiment, the RPKI resource owner adds support for IBC and the functions of the key generation center, and the ROA verifier only needs to add corresponding modifications for IBC signature verification, and the modification is relatively small.
[0088] Figure 6 It is a flowchart of a method for implementing an IBC system according to an embodiment of the present disclosure. Combining Figure 5 and Figure 6 As shown, the IBC system includes an IBC key generation center. Before signing the system identifier of the AS and the routing prefix information published by the AS using the identity private key of the IBC system to generate authorized signature information, the method provided by the embodiment of the present disclosure further includes:
[0089] S602, generating IBC system basic parameters and an IBC system master key using the IBC key generation center, where the IBC system master key is used to calculate the system identifier of the AS and the routing prefix information published by the AS to generate an identity private key and an identity private key.
[0090] In this embodiment, the IBC system basic parameters are data related to the basic framework for the operation of the entire IBC system. For example, it includes curve parameters (if based on elliptic curve cryptography), coding rules, etc. These parameters define the mathematical rules and format requirements for operations such as encryption, decryption, and signature verification. It enables different participating parties (such as senders, receivers, verifiers, etc.) to operate under the same standard, ensuring the security and accuracy of communication. The master key is generated through a specific algorithm, and the master key has confidentiality and uniqueness. Based on the master key, the identity private keys of each user can be derived, which are used to sign messages to prove the authenticity and integrity of the message source. The IBC system basic parameters and the IBC system master key together constitute the IBC system parameters.
[0091] Taking SM9 as an example, the IBC system basic parameter Mpub = {P 1 , P 2 , sP 1 or sP 2 , e……}, where e is a mapping relationship: G 1 *G2 →G 3 , such that e(aP 1 , bP 2 ) = e(abP 1 , P 2 ) = e(P 1 , abP 2 ) = e(P 1 , P 2 ) ab , where P is a base point on the elliptic curve, G 1 represents the public key group identifier, G 2 represents the private key group identifier, and a and b are randomly generated private keys. e(aP 1 , bP 2 ) = e(abP 1 , P 2 ) = e(P 1 , abP 2 ) = e(P 1 , P 2 ) ab is the verification formula. In this formula, aP1 represents a public key in the public key group G1, obtained by multiplying the base point P1 by the private key a; bP2 represents a private key in the private key group G2, obtained by multiplying the base point P2 by the private key b. e is a bilinear mapping that maps elements in G1 and G2 to G3 and maintains specific algebraic properties. Through this mapping relationship, secure identity authentication and encryption functions can be achieved.
[0092] The identification key generation can specifically include:
[0093] Public key generation for identification: Identification Q ID = H 1 (ID)P 1 + sP 1 ∈ G 1
[0094] Private key generation for identification: Identification d ID = s / (H 1 (ID)P 1 + s)P 2 ∈ G 2
[0095] Verification of the correctness of the private key: e(Q ID , d ID ) = e(H 1 (ID)P 1 + s)P 1 , s / (H 1 (ID)P 1 + s)P 2 ) = e(P 1, sP 2 ) = e(P 1 , P 2 ) s Among them, H 1 is a hash function.
[0096] It should be noted that the identification private key and the identification public key can be interchanged groups: Q ID ∈G 2 , d ID ∈G 1 .
[0097] In this embodiment, the IBC key generation center can generate the IBC system basic parameters and the IBC system master key to calculate the system identification of the AS and the published routing prefix information to obtain the identification private key, and then sign the system identification of the AS and the published routing prefix information, thereby ensuring the authenticity and integrity of the network information and improving the security of the network.
[0098] Figure 7 It is a flowchart of a method for generating an IBC system parameter certificate according to an embodiment of the present disclosure. Combining Figure 7 as shown, the method provided by the embodiment of the present disclosure further includes:
[0099] S702, obtain the private key corresponding to the digital certificate of the generation institution, where the digital certificate of the generation institution is issued by a trusted digital certificate issuing authority.
[0100] In this embodiment, the digital certificate is an electronic file containing information such as a public key, which is used to prove the identity of an entity in a network environment. Here, it is issued by a trusted digital certificate issuing authority (CA), and the CA issues it only after strictly verifying that the applicant's identity is legal. Generally speaking, the digital certificate of the generation institution is issued by its corresponding superior registration institution. For example, the digital certificate of an ISP is issued by its corresponding national Internet registration institution and / or regional Internet registration institution, etc. It should be noted that within the scope of RPKI, in addition to the national Internet registration institution and the regional Internet registration institution, any Internet number resource holder can be responsible for the CA certificate issuance and maintenance work. The private key exists in pairs with the public key in the asymmetric encryption system. The private key corresponding to the digital certificate of the generation institution is secretly stored by the certificate owner, that is, the generation institution, and is used to decrypt the data encrypted with the corresponding public key or sign the data.
[0101] S704, sign the IBC system parameters according to the private key corresponding to the digital certificate to generate an IBC system parameter certificate.
[0102] In this embodiment, the private key in the digital certificate is unique and confidential. Signing the IBC system parameters with the private key in the digital certificate of the generating institution to generate the IBC system parameter certificate can ensure the security of the IBC system. Among them, the generating institution identifier corresponds one-to-one with the IBC system parameter certificate to identify the source of the certificate. Each generating institution has a unique identifier. When managing and verifying the IBC system parameter certificate, the corresponding certificate can be quickly located according to the identifier to ensure accuracy and traceability.
[0103] Taking ISP as an example, first, the IBC system parameter certificate contains the IBC (Identity-Based Cryptography) system parameters. Then, the ISP signs the certificate content containing the IBC system parameters with its own private key. This private key is the private key corresponding to the CA certificate issued by the upper-level distributing institution for the ISP. The purpose of doing this is to verify the authenticity and integrity of the certificate source. Through the private key signature, the receiving party can use the corresponding public key to verify the signature to ensure that the IBC system parameter certificate has not been tampered with during the transmission process and indeed comes from a legitimate ISP, thereby guaranteeing communication security and other related application scenarios based on the IBC system. It should be noted that in the RPKI architecture, the ISP needs to upload the IBC system parameter certificate to the RPKI repository for subsequent verification operations.
[0104] In this embodiment, signing with the private key corresponding to the digital certificate of the generating institution guarantees the integrity of the IBC system parameters, prevents the parameters from being tampered with or stolen, and also facilitates subsequent verification. In addition, the corresponding relationship also facilitates operations such as verifying and querying the IBC system parameter certificate in a complex system.
[0105] In some embodiments, Figure 8 The flowchart of a method for verifying routing verification information in an embodiment of the present disclosure is shown.
[0106] Combined with Figure 8 As shown, the method provided in the embodiment of the present disclosure further includes:
[0107] S802, verifying the routing verification information according to the identifier of the generating institution, the IBC system parameter certificate, and the routing verification information ROA.
[0108] In this embodiment, the reliability of the source is determined by using the generating institution identifier, and in combination with the rules in the IBC system parameter certificate, the routing verification information in the ROA is checked to determine whether it meets the requirements.
[0109] In some embodiments, Figure 9 The flowchart of a method for verifying routing verification information in an embodiment of the present disclosure is shown. It can be understood that, combined with Figure 5 As shown, the method provided in this embodiment can be executed by the RPKI relying party. Combined withFigure 5 and Figure 9 As shown in Figure 9 , the routing verification information is verified according to the identifier of the generation institution, the IBC system parameter certificate, and the routing verification information, including:
[0110] S902, determine the IBC system parameter certificate corresponding to the identifier of the generation institution and the public key corresponding to the digital certificate of the generation institution according to the identifier of the generation institution in the routing verification information.
[0111] In this embodiment, the routing verification information contains the identifier of the generation institution. The IBC system parameter certificate is a kind of authentication of configuration and other information related to a specific institution. Through the identifier of the generation institution in the ROA, the corresponding IBC system parameter certificate can be found because each institution has its unique settings and parameters. And the digital certificate contains important information such as the public key. Similarly, according to the identifier of the generation institution, the corresponding digital certificate can be determined, and then the public key therein can be obtained. The public key plays a key role in encrypted communication, etc., such as for verifying digital signatures or encrypting data.
[0112] Specifically, the RPKI relying party can obtain the IBC system parameter certificate and the digital certificate of the corresponding ISP according to the ISP identifier in the ROA.
[0113] S904, determine whether the IBC system parameter certificate is valid according to the public key corresponding to the digital certificate.
[0114] In this embodiment, since the IBC system parameter certificate is signed according to the private key corresponding to the digital certificate, when verifying the validity of the IBC system parameter certificate, the public key in the digital certificate can be used. If the signature of the IBC system parameter certificate can be successfully verified with the public key of the digital certificate, it indicates that the certificate comes from a reliable source; otherwise, if the verification fails, the certificate is invalid.
[0115] S906, when the IBC system parameter certificate is invalid, determine that the route in the routing verification information is an invalid route.
[0116] In this embodiment, the RPKI relying party confirms the validity of the IBC system parameter certificate. If it is valid, continue; if it is invalid, it is an invalid route.
[0117] S908, when the IBC system parameter certificate is valid, generate an identification public key according to the IBC system parameters in the IBC system parameter certificate, the system identifier of the AS in the routing verification information, and the route prefix information published by the AS, and verify the authorization signature information in the routing verification information according to the identification public key.
[0118] In this embodiment, when the IBC system parameter certificate is valid, it means that the IBC system parameter certificate is in a usable state. Further, since the authorized signature information is obtained by signing with the identification private key, and the identification private key is generated from the IBC system parameters, the system identification of the AS in the routing verification information, and the routing prefix information published by the AS. To verify the validity of the authorized signature information, an identification public key can be generated according to the IBC system parameters in the IBC system parameter certificate, the system identification of the AS in the routing verification information, and the routing prefix information published by the AS for subsequent verification operations. The authorized signature information is verified with the identification public key. If successful, it indicates that the source of the signature information is reliable because only the corresponding identification private key can generate a signature that can be verified by the identification public key.
[0119] S910, when the signature verification passes, determine that the route in the routing verification information is a valid route.
[0120] S912, when the signature verification fails, determine that the route in the routing verification information is an invalid route.
[0121] In this embodiment, although the method of the present disclosure reduces the number of certificate storages, it still relies on the security of identity cryptography to ensure the validity and immutability of the signature. Therefore, while reducing the storage space, this method also ensures security.
[0122] In some embodiments, it may be necessary to revoke the routing verification information in certain cases. Revocation means canceling or abolishing a previously set state or operation. In routing-related operations, revoking the routing verification information means canceling operations such as the validity of a certain route. For example, on the one hand, if the network topology changes significantly, such as adding or removing a large number of network devices, re-planning the route after a link is interrupted, etc., the original routing verification information may no longer be applicable and needs to be revoked to reconfigure accurate verification information. On the other hand, when it is found that there are security vulnerabilities in the routing verification information, which are maliciously exploited or there is a risk of misjudgment, the relevant verification information must be revoked to prevent the network from being attacked or routing errors from occurring. In addition, if the relevant network services stop or are replaced, the associated routing verification information no longer needs to exist, and at this time, a revocation operation is also required.
[0123] Taking the ISP as an example, the revocation of the routing verification information can be achieved through the following process: The ISP finds the ROA record corresponding to the RPKI, usually located through relevant identifiers such as IP address prefixes. Initiate a revocation operation request, and it may be necessary to fill in information such as the revocation reason. The platform will verify the revocation request, including permission checks, etc. After the verification passes, the platform will update the ROA status to revoked and synchronize the relevant information to other relevant RPKI participants, such as network devices like routers, so that they can update their routing policies.
[0124] In some embodiments, Figure 10 The flowchart of a method for generating a revocation message of routing verification information provided by an embodiment of the present disclosure is shown. In combination with Figure 5 and Figure 10 As shown, after generating routing verification information according to the authorized signature information, the identifier of the generating institution, the system identifier of the AS, and the routing prefix information published by the AS, the method provided by the embodiment of the present disclosure further includes:
[0125] S1002, obtain a revocation identifier, the system identifier of the routing autonomous system AS, and the routing prefix information published by the AS.
[0126] In this embodiment, the revocation identifier is a special mark used to identify that a certain routing verification information needs to be revoked. The revocation identifier can be a piece of code or a specific combination of symbols, etc. By obtaining these information, it can prepare for the subsequent revocation operation of the routing verification information, and the system identifier of the AS and the routing prefix information help to accurately locate the specific routing-related part where the verification information is to be revoked.
[0127] S1004, use the identity private key of the IBC system to sign the revocation identifier, the system identifier of the AS, and the routing prefix information published by the AS to obtain the first revocation signature information.
[0128] In this embodiment, the IBC key generation center of the ISP generates an identity private key with the system identifier of the AS and the routing prefix information published by the AS as the identifier. The IBC cryptographic operation unit of the ISP uses this identity private key to perform a signature operation on {revocation identifier|ROA content} to obtain the first revocation signature information, where the ROA content includes the system identifier of the AS and the routing prefix information published by the AS.
[0129] S1006, generate the first revocation information of the routing verification information according to the first revocation signature information, the identifier of the generating institution, the system identifier of the AS, and the routing prefix information published by the AS.
[0130] In this embodiment, the first revocation signature information is used to indicate that the routing verification information is to be revoked. It is generated based on the first revocation signature information, the generating institution identifier, the AS system identifier, and the routing prefix information, aiming to inform relevant systems that a certain routing verification information should no longer be used. Specifically, the IBC cryptographic operation unit of the ISP uses the first revocation signature information, the identifier of the generating institution, the system identifier of the AS, and the routing prefix information published by the AS to form the first revocation information of the routing verification information. Further, the ISP uploads the first revocation information to the RPKI repository.
[0131] In some embodiments, Figure 11 The flowchart of a method for revoking routing verification information provided by an embodiment of the present disclosure is shown. It can be understood that in combination withFigure 5 As shown, the method provided in this embodiment can be executed by the RPKI repository. Combining Figure 5 and Figure 11 As shown, the method provided in the embodiments of the present disclosure further includes:
[0132] S1008, determining, according to the identifier of the generating institution in the first revocation information, the IBC system parameter certificate corresponding to the identifier of the generating institution and the public key corresponding to the digital certificate of the generating institution.
[0133] In this embodiment, the RPKI repository obtains the IBC system parameter certificate according to the ISP identifier in the ROA revocation information.
[0134] S1010, determining whether the IBC system parameter certificate is valid according to the public key corresponding to the digital certificate.
[0135] In this embodiment, the RPKI repository confirms the validity of the IBC system parameter certificate. If it is valid, continue; if it is invalid, reject the first revocation information of the routing verification information.
[0136] S1012, when the IBC system parameter certificate is invalid, rejecting the first revocation information.
[0137] In this embodiment, in the IBC system, when it is detected that the system parameter certificate is invalid, the subsequent execution link related to the first revocation information will be blocked, preventing it from triggering revocation operations such as modifying the data status and deleting relevant records.
[0138] S1014, when the IBC system parameter certificate is valid, generating an identification public key according to the IBC system parameters in the IBC system parameter certificate, the system identifier of the AS in the routing verification information, and the routing prefix information published by the AS, and verifying the signature of the first revocation signature information in the first revocation information according to the identification public key.
[0139] In this embodiment, the IBC cryptographic operation unit of the RPKI repository uses the IBC system parameters, and uses the content of the routing verification information, that is, the system identifier of the AS in the routing verification information and the routing prefix information published by the AS as the identifier to generate an identification public key. The IBC cryptographic operation unit of the RPKI repository uses the identification public key to verify the signature in the ROA revocation information.
[0140] S1016, when the signature verification passes, revoking the routing verification information.
[0141] In this embodiment, the routing verification information may be used to verify the validity and legality of a route during network communication or data transmission. Revoking the routing verification information means that after the first revocation signature information is successfully verified, the information related to routing verification in the first revocation signature information is cancelled. For example, the information originally marked as a valid route (indicating that the route can be used normally) is changed to an invalid route (indicating that this route is no longer recognized), or the relevant information of the valid route is directly deleted.
[0142] S1018. When the signature verification fails, reject the first revocation information.
[0143] In this embodiment, by using the key system and cryptographic operations of IBC, operations are performed based on identities to ensure that only legitimate ISPs can correctly revoke the routing verification information.
[0144] In some embodiments, Figure 12 shows a flowchart of another method for generating a message for revoking routing verification information provided by an embodiment of the present disclosure. Combining Figure 5 and Figure 12 as shown, after generating the routing verification information according to the authorized signature information, the identifier of the generating institution, the system identifier of the AS, and the routing prefix information published by the AS, the method provided by the embodiment of the present disclosure further includes:
[0145] S1202. Obtain the revocation identifier, the system identifier of the routing autonomous system AS, and the routing prefix information published by the AS.
[0146] S1204. Use the private key corresponding to the digital certificate to sign the revocation identifier, the system identifier of the AS, and the routing prefix information published by the AS to obtain the second revocation signature information.
[0147] In this embodiment, the digital certificate refers to the digital certificate issued by the superior registration institution to the generating institution. Specifically, taking an ISP as an example, the ISP uses the private key corresponding to its own CA certificate to perform a signature operation on {revocation identifier|ROA content} to obtain the second revocation signature information. Similarly, the ROA content includes the system identifier of the AS and the routing prefix information published by the AS.
[0148] S1206. Generate the second revocation information of the routing verification information according to the second revocation signature information, the identifier of the generating institution, the system identifier of the AS, and the routing prefix information published by the AS.
[0149] In this embodiment, the second revocation signature information is also used to indicate the revocation of routing verification information. It is generated based on the second revocation signature information, the identity of the issuing agency, the AS system identifier, and the routing prefix information, with the aim of informing relevant systems that a certain routing verification information should no longer be used. Specifically, the ISP uses the second revocation signature information, the identity of the issuing agency, the AS system identifier, and the routing prefix information published by the AS to form the second revocation information of the routing verification information. Further, the ISP uploads this second revocation information to the RPKI repository.
[0150] In some embodiments, Figure 13 The flowchart of a method for revoking routing verification information provided by an embodiment of the present disclosure is shown. It can be understood that, in combination with Figure 5 as shown, the method provided in this embodiment can be executed by the RPKI repository. In combination with Figure 5 and Figure 13 as shown, the method provided by the embodiment of the present disclosure further includes:
[0151] S1208, determine the digital certificate corresponding to the identity of the issuing agency in the second revocation information.
[0152] In this embodiment, there is a one-to-one correspondence between the identity of the issuing agency and the digital certificate.
[0153] S1210, determine whether the digital certificate is valid.
[0154] In this embodiment, to determine whether the digital certificate is valid, on the one hand, it can be checked whether the certificate is within the validity period, that is, whether it is between the start date and the end date; on the other hand, since the digital certificate corresponding to the identity of the issuing agency is issued by the superior registration agency of the issuing agency, it can also be verified whether the issuing agency is trustworthy, such as checking whether the root certificate of the issuing agency is in the local trust list; it can also be verified by checking the status of the digital certificate, such as whether it has been revoked, which can be checked by querying the Certificate Revocation List (CRL) or using the Online Certificate Status Protocol (OCSP).
[0155] S1212, when the digital certificate is invalid, reject the second revocation information.
[0156] In this embodiment, the RPKI repository confirms the validity of the digital certificate. If it is valid, continue; if it is invalid, reject the second revocation information.
[0157] S1214, when the digital certificate is valid, verify the second revocation signature information in the second revocation information using the public key corresponding to the digital certificate.
[0158] In this embodiment, the RPKI repository uses the ISP public key in the CA certificate to verify the second revocation signature information in the second revocation signature information. If the verification is passed, the corresponding route verification information is removed from the RPKI repository. If the verification fails, the second revocation information is rejected.
[0159] S1216. When the verification is passed, revoke the route verification information.
[0160] S1218. When the verification fails, reject the second revocation information.
[0161] In this embodiment, by using the digital certificate and cryptographic operations of the generating authority, it is ensured that only legitimate ISPs can correctly revoke the route verification information.
[0162] Figure 14 The figure shows a specific implementation flowchart of a method for generating route verification information provided by an embodiment of the present disclosure. Combining Figure 14 As shown, the upper-level registration authority APNIC issues CA certificates for ISP1 and ISP2 respectively (the boxes in the figure represent CA certificates), and uploads the corresponding CA certificates to the corresponding repositories. ISP1 uses the private key corresponding to its own CA certificate to sign the IBC system parameter certificate (the triangles in the figure represent IBC system parameter certificates), and uploads the corresponding IBC system parameter certificates to the corresponding repositories. ISP1 uses the identity private key generated by the IBC system to sign the ROAs of AS1 and AS2 respectively, and does not need to store the certificates.
[0163] Based on the same inventive concept, an embodiment of the present disclosure also provides a device for generating route verification information, as described in the following embodiment. Since the principle of solving problems in this device embodiment is similar to that of the above method embodiment, the implementation of this device embodiment can refer to the implementation of the above method embodiment, and the repeated parts will not be elaborated.
[0164] Figure 15 The figure shows a schematic diagram of a wireless resource reservation device in an embodiment of the present disclosure, as Figure 15 shown. The device includes: an acquisition module 151, a first generation module 152, and a second generation module 153;
[0165] The acquisition module 151 is configured to acquire the system identifier of the routing autonomous system AS and the route prefix information published by the AS;
[0166] The first generation module 152 is configured to use the identity private key of the IBC system to sign the system identifier of the AS and the route prefix information published by the AS to generate authorized signature information, where the identity private key is generated by the IBC system according to the system identifier of the AS and the route prefix information published by the AS;
[0167] A second generation module 153, configured to generate routing verification information according to the authorized signature information, the identifier of the generating institution, the system identifier of the AS, and the routing prefix information published by the AS.
[0168] In some embodiments, the IBC system includes an IBC key generation center. Before using the private key of the IBC system identifier to sign the system identifier of the AS and the routing prefix information published by the AS to generate authorized signature information, the apparatus further includes: a third generation module, configured to use the IBC key generation center to generate IBC system basic parameters and an IBC system master key, where the IBC system master key is used to calculate the system identifier of the AS and the routing prefix information published by the AS to generate the identifier private key and the identifier public key.
[0169] In some embodiments, the third generation module is further configured to: obtain the private key corresponding to the digital certificate of the generating institution, where the digital certificate of the generating institution is issued by a trusted digital certificate issuing authority; sign the IBC system parameters according to the private key corresponding to the digital certificate to generate an IBC system parameter certificate; where there is a one-to-one correspondence between the identifier of the generating institution and the IBC system parameter certificate.
[0170] In some embodiments, the apparatus further includes: a verification module, configured to verify the routing verification information according to the identifier of the generating institution, the IBC system parameter certificate, and the routing verification information.
[0171] In some embodiments, the verification module is specifically configured to: determine the IBC system parameter certificate corresponding to the identifier of the generating institution and the public key corresponding to the digital certificate of the generating institution according to the identifier of the generating institution in the routing verification information; determine whether the IBC system parameter certificate is valid according to the public key corresponding to the digital certificate; when the IBC system parameter certificate is invalid, determine that the routing in the routing verification information is an invalid routing; when the IBC system parameter certificate is valid, generate an identifier public key according to the IBC system parameters in the IBC system parameter certificate, the system identifier of the AS, and the routing prefix information in the routing verification information, and verify the authorized signature information in the routing verification information according to the identifier public key; when the signature verification passes, determine that the routing in the routing verification information is a valid routing; when the signature verification fails, determine that the routing in the routing verification information is an invalid routing.
[0172] In some embodiments, after generating the routing verification information based on the authorized signature information, the identifier of the generating institution, the system identifier of the AS, and the routing prefix information published by the AS, the apparatus further includes: a first revocation module, configured to obtain a revocation identifier, the system identifier of the routing autonomous system AS, and the routing prefix information published by the AS; use the identity private key of the IBC system to sign the revocation identifier, the system identifier of the AS, and the routing prefix information published by the AS to obtain a first revocation signature information; generate a first revocation information of the routing verification information based on the first revocation signature information, the identifier of the generating institution, the system identifier of the AS, and the routing prefix information published by the AS.
[0173] In some embodiments, the first revocation module is further configured to: determine, according to the identifier of the generating institution in the first revocation information, the IBC system parameter certificate corresponding to the identifier of the generating institution and the public key corresponding to the digital certificate of the generating institution; determine whether the IBC system parameter certificate is valid according to the public key corresponding to the digital certificate; when the IBC system parameter certificate is invalid, reject the first revocation information; when the IBC system parameter certificate is valid, generate an identity public key according to the IBC system parameters in the IBC system parameter certificate, the system identifier of the AS, and the routing prefix information in the routing verification information, and verify the first revocation signature information in the first revocation information according to the identity public key; when the verification passes, revoke the routing verification information; when the verification fails, reject the first revocation information.
[0174] In some embodiments, after generating the routing verification information based on the authorized signature information, the identifier of the generating institution, the system identifier of the AS, and the routing prefix information published by the AS, the apparatus further includes: a second revocation module, configured to obtain a revocation identifier, the system identifier of the routing autonomous system AS, and the routing prefix information published by the AS; use the private key corresponding to the digital certificate to sign the revocation identifier, the system identifier of the AS, and the routing prefix information published by the AS to obtain a second revocation signature information; generate a second revocation information of the routing verification information based on the second revocation signature information, the identifier of the generating institution, the system identifier of the AS, and the routing prefix information published by the AS.
[0175] In some embodiments, the second revocation module is further configured to: determine a digital certificate corresponding to the identifier of the generation institution according to the identifier of the generation institution in the second revocation information, where there is a one-to-one correspondence between the identifier of the generation institution and the digital certificate; determine whether the digital certificate is valid; when the digital certificate is invalid, reject the second revocation information; when the digital certificate is valid, verify the second revocation signature information in the second revocation information using the public key corresponding to the digital certificate; when the verification passes, revoke the routing verification information; when the verification fails, reject the second revocation information.
[0176] It should be noted here that the examples and application scenarios implemented by each module in the above device embodiments are the same as the corresponding steps in the method embodiments, but are not limited to the content disclosed in the above method embodiments. It should be noted that the above modules, as part of the device, can be executed in a computer system such as a set of computer-executable instructions.
[0177] Those skilled in the art can understand that various aspects of the present disclosure can be specifically implemented in the following forms, namely: a complete hardware implementation, a complete software implementation (including firmware, microcode, etc.), or an implementation combining hardware and software aspects, which can be collectively referred to as "circuit", "module" or "system" here.
[0178] Based on the same inventive concept, an electronic device is also provided in the embodiments of the present disclosure. The electronic device includes: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to execute the routing verification information generation method of any one of the above via executing the executable instructions. Since the principle of solving problems in this electronic device embodiment is similar to that of the above method embodiment, the implementation of this electronic device embodiment can refer to the implementation of the above method embodiment, and the repeated parts will not be described again.
[0179] The following refers to Figure 16 to describe the electronic device 1600 according to this embodiment of the present disclosure. Figure 16 The shown electronic device 1600 is only an example and should not bring any limitation to the functions and usage scope of the embodiments of the present disclosure.
[0180] As Figure 16 shown, the electronic device 1600 is presented in the form of a general-purpose computing device. The components of the electronic device 1600 may include but are not limited to: the at least one processing unit 1610, the at least one storage unit 1620, and a bus 1630 connecting different system components (including the storage unit 1620 and the processing unit 1610).
[0181] Among them, the storage unit stores program code, which can be executed by the processing unit 1610, so that the processing unit 1610 executes the steps according to various exemplary embodiments of the present disclosure described in the "Exemplary Method" section above of this specification. For example, the processing unit 1610 may execute the following steps of the above method embodiment: obtaining wireless resource reservation requirement information of the service system; generating a service process of the service system according to the wireless resource reservation requirement information; obtaining at least one functional component from the low-code environment platform according to the service process and the wireless resource reservation requirement information to obtain wireless resource reservation, so that the low-code environment platform executes wireless resource reservation.
[0182] The storage unit 1620 may include a readable medium in the form of a volatile storage unit, such as a random access storage unit (RAM) 16201 and / or a cache storage unit 16202, and may further include a read-only storage unit (ROM) 16203.
[0183] The storage unit 1620 may further include a program / utilities 16204 having a set (at least one) of program modules 16205. Such program modules 16205 include, but are not limited to: an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include an implementation of a network environment.
[0184] The bus 1630 may represent one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, a graphics acceleration port, a processing unit, or a local bus using any of a variety of bus structures.
[0185] The electronic device 1600 may also communicate with one or more external devices 1640 (such as a keyboard, a pointing device, a Bluetooth device, etc.), may also communicate with one or more devices that enable a user to interact with the electronic device 1600, and / or communicate with any device that enables the electronic device 1600 to communicate with one or more other computing devices (such as a router, a modem, etc.). Such communication may be carried out through an input / output (I / O) interface 1650. And, the electronic device 1600 may also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through a network adapter 1660. As shown in the figure, the network adapter 1660 communicates with other modules of the electronic device 1600 through the bus 1630. It should be understood that, although not shown in the figure, other hardware and / or software modules may be used in conjunction with the electronic device 1600, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.
[0186] From the description of the above embodiments, those skilled in the art can easily understand that the exemplary embodiments described herein can be implemented by software, or by a combination of software and necessary hardware. Therefore, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (which can be a personal computer, a server, a terminal device, or a network device, etc.) to execute the method according to the embodiments of the present disclosure.
[0187] Based on the same inventive concept, an embodiment of the present disclosure also provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the routing verification information generation method according to any one of the above. Since the principle of solving the problem in this embodiment of the computer-readable storage medium is similar to that of the above method embodiment, the implementation of this embodiment of the computer-readable storage medium can refer to the implementation of the above method embodiment, and the repeated parts will not be described again.
[0188] More specific examples of the computer-readable storage medium in the present disclosure may include, but are not limited to: electrical connections with one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above.
[0189] In the present disclosure, the computer-readable storage medium may include a data signal propagated in a baseband or as part of a carrier wave, on which the readable program code is carried. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The readable signal medium may also be any readable medium other than the readable storage medium, and this readable medium can send, propagate, or transmit a program used by or in combination with an instruction execution system, apparatus, or device.
[0190] Optionally, the program code included on the computer-readable storage medium can be transmitted by any appropriate medium, including but not limited to wireless, wired, optical cable, RF, etc., or any suitable combination of the above.
[0191] In specific implementation, program code for performing the operations of the present disclosure can be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, etc., and also including conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computing device, partially on the user's device, executed as an independent software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device can be connected to the user's computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (e.g., by connecting through the Internet using an Internet service provider).
[0192] Based on the same inventive concept, an embodiment of the present disclosure also provides a computer program product, including: a computer program or instruction, which when executed by a processor implements the routing verification information generation method in any one of the above method embodiments. Since the principle of solving problems in this computer program product embodiment is similar to that of the above method embodiments, the implementation of this computer program product embodiment can refer to the implementation of the above method embodiments, and the repeated parts will not be described again.
[0193] It should be noted that although several modules or units of devices for action execution are mentioned in the above detailed description, this division is not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of two or more of the above-described modules or units can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.
[0194] In addition, although the steps of the methods in the present disclosure are described in a specific order in the drawings, this does not require or imply that these steps must be executed in that specific order, or that all the steps shown must be executed to achieve the desired result. Additionally or alternatively, some steps can be omitted, multiple steps can be combined into one step for execution, and / or one step can be decomposed into multiple steps for execution, etc.
[0195] From the description of the above embodiments, those skilled in the art can easily understand that the example embodiments described herein can be implemented by software or by a combination of software and necessary hardware. Therefore, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, and includes several instructions to enable a computing device (such as a personal computer, a server, a mobile terminal, or a network device, etc.) to execute the method according to the embodiments of the present disclosure.
[0196] After considering the specification and practicing the invention disclosed herein, those skilled in the art will readily conceive of other embodiments of the present disclosure. The present disclosure is intended to cover any variations, uses, or adaptations of the present disclosure, which follow the general principles of the present disclosure and include well-known common general knowledge or conventional technical means in the technical field not disclosed by the present disclosure. The specification and the embodiments are only regarded as exemplary, and the true scope and spirit of the present disclosure are pointed out by the appended claims.
Claims
1. A method for generating routing verification information, characterized in that: The method comprises: Obtaining the system identifier of the routing autonomous system AS and the routing prefix information published by the AS; Using the identification private key of the IBC system, the system identification of the AS and the routing prefix information published by the AS are signed to generate authorization signature information, wherein the identification private key is generated by the IBC system according to the system identification of the AS and the routing prefix information published by the AS; The routing verification information is generated according to the authorization signature information, the identifier of the generating organization, the system identifier of the AS, and the routing prefix information published by the AS.
2. The method for generating routing verification information according to claim 1, characterized in that: The IBC system includes an IBC key generation center. Before using the identification private key of the IBC system to sign the system identification of the AS and the routing prefix information published by the AS to generate the authorization signature information, the method further includes: The IBC key generation center is used to generate IBC system basic parameters and an IBC system master key, wherein the IBC system master key is used to calculate the system identification of the AS and the routing prefix information published by the AS to generate the identification private key and the identification public key.
3. The method for generating routing verification information according to claim 2, characterized in that: The method further comprises: Obtaining a private key corresponding to the digital certificate of the generating organization, wherein the digital certificate of the generating organization is issued by a trusted digital certificate issuing authority; The IBC system parameters are signed according to the private key corresponding to the digital certificate to generate an IBC system parameter certificate; wherein there is a one-to-one correspondence between the identifier of the generating organization and the IBC system parameter certificate.
4. The method for generating routing verification information according to claim 3, characterized in that: The method further comprises: The routing verification information is verified according to the identification of the generating organization, the IBC system parameter certificate and the routing verification information.
5. The method for generating routing verification information according to claim 4, characterized in that: The verifying the routing verification information according to the identifier of the generating organization, the IBC system parameter certificate and the routing verification information includes: Determine, according to the identifier of the generating organization in the routing verification information, the IBC system parameter certificate corresponding to the identifier of the generating organization and the public key corresponding to the digital certificate of the generating organization; Determine whether the IBC system parameter certificate is valid according to the public key corresponding to the digital certificate; When the IBC system parameter certificate is invalid, determining that the route in the route verification information is an invalid route; When the IBC system parameter certificate is valid, an identification public key is generated according to the IBC system parameters in the IBC system parameter certificate, the system identifier of the AS in the routing verification information, and the routing prefix information published by the AS, and the authorization signature information in the routing verification information is verified according to the identification public key; When the signature verification passes, determining that the route in the route verification information is a valid route; When the signature verification fails, it is determined that the route in the route verification information is an invalid route.
6. The method for generating routing verification information according to claim 1, characterized in that: After generating the routing verification information according to the authorization signature information, the identifier of the generating organization, the system identifier of the AS, and the routing prefix information published by the AS, the method further includes: Obtaining a revocation identifier, a system identifier of the routing autonomous system AS, and routing prefix information published by the AS; Using the identification private key of the IBC system, the revocation identification, the system identification of the AS, and the routing prefix information published by the AS are signed to obtain first revocation signature information; The first revocation information of the routing verification information is generated according to the first revocation signature information, the identifier of the generating organization, the system identifier of the AS, and the routing prefix information published by the AS.
7. The method for generating routing verification information according to claim 6, characterized in that: The method further comprises: Determine, according to the identifier of the generating organization in the first revocation information, the IBC system parameter certificate corresponding to the identifier of the generating organization and the public key corresponding to the digital certificate of the generating organization; Determine whether the IBC system parameter certificate is valid according to the public key corresponding to the digital certificate; When the IBC system parameter certificate is invalid, rejecting the first revocation information; When the IBC system parameter certificate is valid, generating an identification public key according to the IBC system parameters in the IBC system parameter certificate, the system identifier of the AS in the routing verification information, and the routing prefix information published by the AS, and verifying the first revocation signature information in the first revocation information according to the identification public key; When the signature verification is passed, the routing verification information is revoked; When the signature verification fails, the first revocation information is rejected.
8. The method for generating routing verification information according to claim 3, characterized in that: After generating the routing verification information according to the authorization signature information, the identifier of the generating organization, the system identifier of the AS, and the routing prefix information published by the AS, the method further includes: Obtaining a revocation identifier, a system identifier of the routing autonomous system AS, and routing prefix information published by the AS; Using the private key corresponding to the digital certificate, the revocation identifier, the system identifier of the AS, and the routing prefix information published by the AS are signed to obtain second revocation signature information; The second revocation information of the routing verification information is generated according to the second revocation signature information, the identifier of the generating organization, the system identifier of the AS, and the routing prefix information published by the AS.
9. The method for generating routing verification information according to claim 8, characterized in that: The method further comprises: Determining, according to the identifier of the generating organization in the second revocation information, a digital certificate corresponding to the identifier of the generating organization, wherein there is a one-to-one correspondence between the identifier of the generating organization and the digital certificate; Determining whether the digital certificate is valid; When the digital certificate is invalid, rejecting the second revocation information; When the digital certificate is valid, verifying the second revocation signature information in the second revocation information according to the public key corresponding to the digital certificate; When the signature verification is passed, the routing verification information is revoked; When the signature verification fails, the second revocation information is rejected.
10. A routing verification information generating device, characterized in that: The device comprises: An acquisition module, used to acquire a system identifier of a routing autonomous system AS and routing prefix information published by the AS; A first generating module is used to use the identification private key of the IBC system to sign the system identification of the AS and the routing prefix information published by the AS to generate authorization signature information, wherein the identification private key is generated by the IBC system according to the system identification of the AS and the routing prefix information published by the AS; The second generating module is used to generate routing verification information according to the authorization signature information, the identifier of the generating organization, the system identifier of the AS, and the routing prefix information published by the AS.
11. An electronic device, characterized in that: include: processor; as well as A memory, configured to store executable instructions of the processor; The processor is configured to execute the routing verification information generating method according to any one of claims 1 to 9 by executing the executable instructions.
12. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method for generating routing verification information according to any one of claims 1 to 9 is implemented.
13. A computer program product comprising: A computer program or instruction, characterized in that when the computer program or instruction is executed by a processor, it implements the routing verification information generating method described in any one of claims 1 to 9.