Method, device and system for sharing IPsec tunnel
By establishing an IPsec tunnel sharing method between base stations, the problem of limited number of IPsec tunnels is solved, and the utilization rate of tunnels and the efficiency of service data transmission is improved.
Patent Information
- Application Number
- CN202311650506.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-04
- Publication Date
- 2025-06-06
AI Technical Summary
In the scenario where the base station provides services to multi-operators or multi-service instances, the number of IPsec tunnels is limited, resulting in insufficient number of encrypted data streams and unable to meet service needs.
By establishing an IPsec tunnel sharing method between the first network device and the second network device, multiple target objects (operators or service instances) are allowed to share one or more IPsec tunnels, thereby improving the utilization of the tunnel.
It realizes that when the base station provides services to multi-operators or multi-service instances, the utilization rate of IPsec tunnel is improved, and the efficiency and reliability of service data transmission is enhanced.
Smart Images

Figure CN120111495A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology, and in particular to a method, device and system for sharing an IPsec tunnel. Background Art
[0002] With the current 3rd generation partnership project (3GPP) already supporting the X2 / Xn interface for secure self-establishment, such as supporting the direct establishment of an IPsec tunnel (hereinafter referred to as "IPsec tunnel") between two base stations, such as an Internet Protocol Security (IPsec) tunnel. Among them, in a multi-service instance base station scenario, such as a base station serving multiple operators or multiple service instances at the same time, since transmission isolation and data isolation are required between service instances, different service instances usually use different virtual routing domains (virtual routing and forwarding, VRF), and different VRFs require separate IPsec tunnels.
[0003] However, due to the resource limitations of IPsec, the number of IPsec tunnels that a base station can establish is usually limited. Based on this, when the number of base station IPsec tunnels is limited, how to increase the number of encrypted data flows in the IPsec tunnel when the base station provides services for multiple operators or multiple business instances is a problem that needs to be solved. Summary of the invention
[0004] The present application provides a method, device and system for sharing an IPsec tunnel, which can improve the utilization rate of the IPsec tunnel while ensuring that the business runs more reliably and efficiently.
[0005] In order to achieve the above objectives, this application adopts the following technical solutions:
[0006] In a first aspect, a method for sharing an IPsec tunnel is provided, which is applied to a first network device, where the first network device provides services for multiple target objects, where the target objects are operators or service instances, where the multiple target objects include a first target object and a second target object, and where one or more IPsec tunnels are established between the first network device and the second network device. The method may include:
[0007] A first data packet and a second data packet are sent to the second network device through a first IPsec tunnel, the first data packet belongs to the first target object, the second data packet belongs to a second different target object, the first data packet includes first service data and first information, the first information is used to indicate the first target object, the second data packet includes second service data and second information, the second information is used to indicate the second target object; wherein the first IPsec tunnel is one of the one or more IPsec tunnels. Based on this, one or more IPsec tunnels are established between the first network device and the second network device, the one or more IPsec tunnels are used for the transmission of service data between the first network device and the second network device, the first network device and the second network device both provide services for multiple target objects, the first data packet and the second data packet can come from the same or different target objects, the first data packet includes first service data and first information, the first service data is the service data of the first target object, the first information is used to indicate that the first service data comes from the first target object, the second data packet includes second service data and second information, the second service data is the service data of the second target object, and the second information is used to indicate that the second service data comes from the second target object. The target object may be an operator or a service instance. In some examples, it may also be other dedicated networks. No limitation is made herein. The service data of multiple target objects served by the first network and the second network may use any one of the one or more IPsec tunnels as the first IPsec tunnel to transmit the service data. In this way, the IPsec tunnel between the first network device and the second network device is shared among multiple target objects, thereby improving the IPsec tunnel specifications available to the target object when transmitting service data, and at the same time improving the utilization rate of the IPsec tunnel between the first network device and the second network device, so as to improve the transmission efficiency of service data between the first network device and the second network device.
[0008] As a possible implementation method, sending the first data packet and the second data packet to the second network device through the first IPsec tunnel includes: transmitting the first business data and the second business data to the tunnel interface of the first IPsec tunnel respectively; encrypting the first business data and the second business data at the tunnel interface to obtain the first data packet and the second data packet respectively; and sending the first data packet and the second data packet to the second network device through the first IPsec tunnel. Based on this, when using the first IPsec tunnel to transmit business data, the first business data and the second business data are first transmitted to the tunnel interface of the first IPsec tunnel. The first IPsec tunnel can be any one of multiple IPsec tunnels, and the first business data and the second business data can come from the same or different target objects. At the tunnel interface, the first business data and the second business data are respectively encapsulated and encrypted according to the security protocol policy corresponding to the first IPsec tunnel to obtain the first data packet and the second data packet, and then the first data packet and the second data packet are sent through the first IPsec tunnel. In this way, by controlling the transmission method of the first business data and the second business data, the sharing of the first IPsec tunnel when business data from the same or different target objects are transmitted is achieved. It can be understood that the first IPsec tunnel is any one of the one or more IPsec tunnels between the first network device and the second network device, and the first business data and the second business data can be business data of any different target objects served by the first network device.
[0009] As a possible implementation, the transmitting of the first service data and the second service data to the tunnel interface of the first IPsec tunnel respectively includes: transmitting the first service data and the second service data to the tunnel interface according to a preset routing method of an inner address. Based on this, when transmitting the first service data and the second service data to the tunnel interface of the first IPsec tunnel, the first service data and the second service data from the same or different target objects can be transmitted to the tunnel interface of the first IPsec tunnel by routing, and the data transmission path of the first service data and the second service data can be controlled to realize the sharing of IPsec tunnels by different target objects.
[0010] As a possible implementation method, the preset routing method of the inner address includes one or more of the following: destination address routing, source address routing, and policy routing. Based on this, the first service data and the second service data are transmitted from their respective inner addresses to the tunnel interface of the first IPsec tunnel by means of preset routing. Exemplarily, the routing method of destination address routing, the routing method of source address routing, and the routing method of policy routing can be adopted. Policy routing can self-establish and learn the address of the other end, and transmit the service data to the tunnel interface of the IPsec tunnel by means of source address + destination address. In some examples, other routing methods that can realize the transmission of service data to the tunnel interface can also be adopted, and no limitation is made here.
[0011] As a possible implementation, both the first service data and the second service data pass the traffic selection of the tunnel interface. Based on this, after the first service data and the second service data are transmitted to the tunnel interface, the first service data and the second service data can be subjected to traffic selection at the tunnel interface, so that both the first service data and the second service data pass the traffic selection of the tunnel interface at the tunnel interface, and the first service data and the second service data are subjected to encapsulation processing or encryption processing at the tunnel interface.
[0012] As a possible implementation, the tunnel interface includes a traffic selector, and the encryption of the first service data and the second service data at the tunnel interface includes: selecting the first service data and the second service data at the tunnel interface through the traffic selector, and encrypting the first service data and the second service data respectively when the traffic selection passes. Based on this, when the tunnel interface performs traffic selection, the traffic selector can be used to select the service data. Exemplarily, the traffic selector can be used to select the first service data and the second service data. When the inner layer address of the first service data meets the preset address range of the traffic selector, the first service data and the second service data pass through the traffic selector, and the first service data and the second service data are encrypted.
[0013] As a possible implementation, the flow selection of the first business data and the second business data includes: judging that the inner addresses corresponding to the first business data and the second business data meet the preset address range of the flow selector, and determining that the flow selection is passed. Based on this, the preset address range of the flow selector can be set according to the transmission requirements of the business data, and when the inner addresses corresponding to the first business data and the second business data are within the preset address range of the flow selector, it is determined that the first business data and the second business data meet the flow selection rules of the flow selector, and the flow selection of the first business data and the second business data is determined to be passed.
[0014] As a possible implementation method, the traffic selection of the first business data and the second business data by the traffic selector includes: the traffic selector selects the first business data and the second business data based on the any~any selection strategy, wherein the IPv4 address range corresponding to the traffic selector is 0.0.0.0 / 0~0.0.0.0 / 0, and the corresponding IPv6 address range is ::0 / 0~::0 / 0. Based on this, in some examples, the selection strategy of the traffic selector can be any~any, that is, after the first business data and the second business data are transmitted to the tunnel interface through the preset route, the traffic selector can allow the first business data and the second business data to pass the traffic selection, wherein the first business data and the second business data both belong to the preset address range of the traffic selector, the address range of the traffic selector in the ipv4 scenario is 0.0.0.0 / 0~0.0.0.0 / 0, and the address range of the traffic selector in the ipv6 scenario is ::0 / 0~::0 / 0. When the first business data and the second business data belong to the address range, it is determined that the first business data and the second business data traffic are selected to pass, that is, the traffic selector at the tunnel interface allows all data transmitted to the tunnel interface through the preset route to pass the traffic selection. The traffic selector and the preset route cooperate with each other to control the transmission process of the business data, and transmit the business data to the corresponding tunnel interface, thereby realizing the sharing of the IPsec tunnel between the first network device and the second network device, and improving the transmission efficiency of the business data.
[0015] As a possible implementation, the first service data and the second service data are encrypted at the tunnel interface, including: after writing the first virtual routing domain identifier corresponding to the first target object in the first information, the first service data is encrypted; and after writing the second virtual routing domain identifier corresponding to the second target object in the second information, the second service data is encrypted. Based on this, in the process of encrypting the first service data and the second service data, the first service data comes from the first target object, and the first virtual routing domain identifier corresponding to the first target object is written into the first information, and the second service data comes from the second target object, and the second virtual routing domain identifier corresponding to the second target object is written into the second information, wherein the first virtual routing domain identifier is used to indicate the first target object, and the second virtual routing domain identifier is used to indicate the second target object.
[0016] As a possible implementation manner, writing the first virtual routing domain identifier corresponding to the first target object in the first information includes: writing the first virtual routing domain identifier corresponding to the first target object into the first information based on a first mapping mechanism; writing the second virtual routing domain identifier corresponding to the second target object in the second information includes: writing the second virtual routing domain identifier corresponding to the second target object into the second information based on the second mapping mechanism; wherein the first mapping mechanism and the second mapping mechanism may be different.
[0017] As a possible implementation, the first data message includes a field for carrying the first information, and the second data message includes a field for carrying the second information, and the field includes one or more of the following: an extended header field, a special field, a reserved field, a TTL field, a flowlable field, and a dh header field. Based on this, when the first virtual routing domain identifier is written into the first information, and the second virtual routing domain identifier is written into the second information, the first virtual routing domain identifier and the second virtual routing domain identifier can be mapped to the extended header field, the special field, the reserved field, the TTL field, the flowlable field, and the dh header field, or other available fields in the data message, without any limitation here.
[0018] As a possible implementation, the first business data includes first address information, and the first address information is used to indicate the first target object. The second business data includes second address information, and the second address information is used to indicate the second target object. Based on this, when the target object sends business data, the business data carries address information that can indicate the corresponding target object. In some examples, the first business data may include first address information, and the first address information may indicate source address information and target address information corresponding to the first business data. The second business data may include second address information, and the second address information may indicate source address information and target address information corresponding to the second business data, so as to determine the first target object and the second target object corresponding to the first business data and the second business data.
[0019] In a second aspect, a method for sharing an IPsec tunnel is provided, which is applied to a second network device, where the second network device provides services for multiple target objects, where the target objects are operators or service instances, where the multiple target objects include a first target object and a second target object, and where one or more IPsec tunnels are established between the second network device and the first network device. The method may include:
[0020] First, a first data packet and a second data packet sent by a first network device through a first IPsec tunnel are received, wherein the first data packet includes first service data and first information, and the first information is used to indicate the first target object, and the second data packet includes second service data and second information, and the second information is used to indicate the second target object. Based on this, one or more IPsec tunnels are established between the first network device and the second network device, and the one or more IPsec tunnels are used for the transmission of service data between the first network device and the second network device. The first network device and the second network device both provide services for multiple target objects. The second network device receives the first data packet and the second data packet from the first network device, and the first data packet and the second data packet can come from the same or different target objects. The target object can be an operator or a service instance. In some examples, it can also be other dedicated networks, and no limitation is made here.
[0021] Then, the first service data and the first information are obtained from the first data message, and the second service data and the second information are obtained from the second data message. Based on this, the first service data and the first information are obtained from the first data message, and the first information is used to indicate that the first service data belongs to the first target object, and the second service data and the second information are obtained from the second data message, and the second information is used to indicate that the second service data comes from the second target object. In this way, the target object to which the data message belongs can be determined through the first information or the second information carried in the data message, and the second network device can receive and identify the first service data and the second service data, and receive the first service data and the second service data.
[0022] As a possible implementation, the obtaining of the first business data and the first information from the first data packet includes: parsing the first data packet according to the security protocol policy corresponding to the first IPsec tunnel to obtain the first business data and the first information. The obtaining of the second business data and the second information from the second data packet includes: parsing the second data packet according to the security protocol policy corresponding to the first IPsec tunnel to obtain the second business data and the second information. Based on this, the first data packet and the second data packet received by the second network device from the first IPsec tunnel are both decrypted according to the security protocol policy corresponding to the first IPsec tunnel to obtain the corresponding first business data and the first information, as well as the second business data and the second information, wherein the IPsec tunnel can be configured to set the corresponding security protocol policy for use when encrypting the business data transmitted through the IPsec tunnel.
[0023] As a possible implementation, the method may further include: obtaining a first virtual routing domain identifier corresponding to the first information based on a third mapping mechanism, the first information being encapsulated in the first data message by the first network device based on the first mapping mechanism; obtaining a second virtual routing domain identifier corresponding to the second information based on the fourth mapping mechanism, the second information being encapsulated in the second data message by the first network device based on the first mapping mechanism. Wherein, the third mapping mechanism and the fourth mapping mechanism may be the same or different. Based on this, when obtaining the corresponding first virtual routing domain identifier according to the first information, the third mapping mechanism may be used to obtain the first virtual routing domain identifier from the field used to carry the first information, and when obtaining the corresponding second virtual routing domain identifier according to the second information, the fourth mapping mechanism may be used to obtain the second virtual routing domain identifier from the field used to carry the second information, wherein the third mapping mechanism and the fourth mapping mechanism may be the same or different, and at the same time, the third mapping mechanism and the first mapping mechanism may be the same or different, and the fourth mapping mechanism and the second mapping mechanism may be the same or different, and the specific mapping rules may be determined by negotiation between the first network device and the second network device.
[0024] As a possible implementation method, the first data message and the second data message include one or more of the following fields: an extended header field, a special field, a reserved field, a TTL field, a flowlable field, and a dh header field, and the first information is located in the field. Based on this, when obtaining the corresponding first virtual routing domain identifier according to the first information, and obtaining the corresponding second virtual routing domain identifier according to the second information, the first virtual routing domain identifier carried by the first information and the second virtual routing domain identifier carried by the second information can be obtained from the extended header field, the special field, the reserved field, the TTL field, the flowlable field, the dh header field, etc., or they can be obtained from other available fields in the data message, without any limitation here.
[0025] As a possible implementation, the method may also include: transmitting the first service data to the first target object served by the second network device according to the first virtual routing domain identifier, and the first virtual routing domain identifier is associated with the first target object; transmitting the second service data to the second target object served by the second network device according to the second virtual routing domain identifier, and the second virtual routing domain identifier is associated with the second target object. Based on this, it can be understood that the first virtual routing domain identifier is associated with the first target object, and the second virtual routing domain identifier is associated with the second target object. Therefore, the first service data can be sent to the first target object served by the second network device according to the first virtual routing domain identifier and the association relationship between the first virtual routing domain identifier and the first target object, and the second service data can be sent to the second target object served by the second network device according to the second virtual routing domain identifier and the association relationship between the second virtual routing domain identifier and the second target object, so as to complete the reception of the first service data and the second service data.
[0026] As a possible implementation, the first business data includes first address information, and the first address information is used to indicate the first target object. The second business data includes second address information, and the second address information is used to indicate the second target object. Based on this, after acquiring the business data, the business data carries address information that can indicate the corresponding target object. In some examples, the first business data may include first address information, and the first address information may indicate the target address information corresponding to the first business data. The second business data may include second address information, and the second address information may indicate the target address information corresponding to the second business data. The first target object and the second target object corresponding to the first business data and the second business data can be determined based on the target address information.
[0027] As a possible implementation, the method further includes: transmitting the first business data to the first target object served by the second network device according to the first address information; transmitting the second business data to the second target object served by the second network device according to the second address information. Based on this, the address information may include source address information and target address information. In some examples, the target object corresponding to the business data may be determined by obtaining the target address information in the address information. Exemplarily, the first target object corresponding to the first business data may be determined according to the target address information in the first address information, and the first business data may be sent to the first target object. The second target object corresponding to the second business data may be determined according to the target address information in the second address information, and the second business data may be sent to the second target object, so as to complete the reception of the first business data and the second business data.
[0028] According to a third aspect, a communication system is provided, which may include a first network device and a second network device, wherein the first network device is used to implement the method described in any one of the first aspect, and the second network device is used to implement the method described in any one of the second aspect.
[0029] In a fourth aspect, an electronic device is provided, which may include: a transceiver for sending and receiving signals; a memory for storing computer program instructions; and a processor for executing computer program instructions to support the electronic device to implement a method in any possible implementation of the first aspect or the second aspect.
[0030] In a fifth aspect, a computer-readable storage medium is provided, on which computer program instructions are stored. When the computer program instructions are executed by a processing circuit, the method in any possible implementation of the first aspect or the second aspect is implemented.
[0031] In a sixth aspect, a computer program product comprising instructions is provided, which, when executed on a computer, enables the computer to execute a method in any possible implementation of the first aspect or the second aspect.
[0032] In the seventh aspect, a chip system is provided, which includes a processing circuit and a storage medium, in which computer program instructions are stored; when the computer program instructions are executed by the processing circuit, a method in any possible implementation manner of the first aspect or the second aspect is implemented. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] Figure 1 A schematic diagram of data transmission based on IPsec tunnel provided for related technologies;
[0034] Figure 2 A schematic diagram of a system architecture provided for related technologies;
[0035] Figure 3 Another system architecture diagram provided for related technologies;
[0036] Figure 4 A schematic diagram of data transmission based on an IPsec tunnel provided in an embodiment of the present application;
[0037] Figure 5 A schematic diagram of the hardware results of a network device provided in an embodiment of the present application;
[0038] Figure 6 A schematic diagram of a system architecture provided for an embodiment of the present application;
[0039] Figure 7Another schematic diagram of a system architecture provided for an embodiment of the present application;
[0040] Figure 8 A flowchart of a method for sharing an IPsec tunnel provided in an embodiment of the present application;
[0041] Fig. 9 A schematic diagram of data transmission based on policy routing provided in an embodiment of the present application;
[0042] Fig.10 A schematic diagram of a data message in a data transmission process of an IPsec tunnel provided in an embodiment of the present application;
[0043] Fig.11 A schematic diagram of a virtual routing domain indication method provided in an embodiment of the present application;
[0044] Fig.12 A schematic diagram of another virtual routing domain indication method provided in an embodiment of the present application;
[0045] Fig.13 A detailed flowchart of a method for sharing an IPsec tunnel provided in an embodiment of the present application. DETAILED DESCRIPTION
[0046] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application. In the description of the embodiments of the present application, unless otherwise specified, " / " means or, for example, A / B can mean A or B; "and / or" in this article is only a description of the association relationship of associated objects, indicating that there can be three relationships, for example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In addition, in the description of the embodiments of the present application, "multiple" means two or more than two.
[0047] In the following, the terms "first", "second", etc. are only used to distinguish different description objects, and have no limiting effect on the position, order, priority, quantity or content of the described objects. For example, if the described object is a "field", the ordinal number before the "field" in the "first field" and the "second field" does not limit the position or order between the "fields", and the "first" and "second" do not limit whether the "fields" they modify are in the same message, nor do they limit the order of the "first field" and the "second field". For another example, if the described object is a "level", the ordinal number before the "level" in the "first level" and the "second level" does not limit the priority between the "levels". For another example, the number of described objects is not limited by the ordinal number, and can be one or more. Taking the "first device" as an example, the number of "devices" can be one or more. In addition, the objects modified by different prefixes can be the same or different. For example, if the described object is a "device", the "first device" and the "second device" can be the same type of device or different types of devices. For another example, if the described object is "information", the "first information" and the "second information" can be information of the same content or information of different contents. In summary, the use of prefixes such as ordinal numbers to distinguish the described objects in the embodiments of the present application does not constitute a limitation on the described objects. For the statement of the described objects, please refer to the description in the context of the claims or embodiments, and no unnecessary limitation should be constituted due to the use of such prefixes.
[0048] Furthermore, in the embodiments of the present application, "connection" may be a direct connection or an indirect connection; in addition, it may refer to an electrical connection or a communication connection; for example, the connection between two electrical components A and B may refer to a direct connection between A and B, or may refer to an indirect connection between A and B through other electrical components or connecting media, or may refer to an indirect connection between A and B through other communication devices or communication media, as long as communication between A and B can be achieved.
[0049] Currently, in wireless base station application scenarios, the X2 / Xn interface is supported for secure self-establishment (such as two base stations directly establishing an X2 / XnIPsec tunnel), where X2 is the interface between LTE stations and Xn is the interface between NR stations. This method is referred to as the direct connection security protocol (Direct IPsec). The above direct connection security protocol does not support the sharing of IPsec tunnels between base stations. Therefore, in order to avoid the problem of being unable to isolate and distinguish multiple operators or multiple service instances when there are address conflicts between multiple operators or multiple service instances (address conflicts are a common scenario), different operators or service instances require independent Direct IPsec to support them, that is, one Direct IPsec cannot provide multiplexing and sharing for multiple operators or service instances. In this case, Figure 1As shown in FIG. 1 , if there are N (N is a positive integer greater than 1) inner VRFs, N local Internet Key Exchange (IKE) addresses and N Direct IPsec addresses need to be provided between base station 1 and base station 2. The operator can be Figure 1 The virtual routing domain (virtual routing and forwarding, VRF) shown in the figure is exemplary and may include VRF 1, VRF2 and VRF3. In some cases, an operator or service instance may also be referred to as a "VRF instance". Among them, VRF is an instance created on a physical device and obtained by logically dividing the physical device. Each instance is isolated at the routing level, based on which data or service isolation can be achieved. Each VRF has an independent interface, routing table and routing protocol process, etc. In other words, the current protocol cannot support the sharing of IPsec tunnels between base stations in terms of both protocol functions and the prescribed communication process.
[0050] Furthermore, due to the resource limitation of IPsec, each base station generally has a specification limit, such as 512 DirectIPsec. However, in a multi-operator scenario, since transmission isolation is required between operators (such as independent planning of transmission IP, routing, etc., and data isolation between operators), different VRFs are generally adopted. Each operator's VRF requires a separate directIPsec tunnel. While the total specification of base station Direct IPsec remains unchanged, the directIPsec available to each operator is reduced by N times, where N is the number of operators. In a multi-operator scenario, if the number of operators is 3 and each operator requires 500+ direct IPsec, the total specification of direct IPsec required is 1500+, while the base station Direct IPsec specification is 512, which cannot meet the needs of operators.
[0051] On the other hand, in mixed scenarios of to business (2B) and to customer (2C), 2B and 2C also need to independently plan transmission and data isolation, and use different VRF methods, which requires the Direct IPsec specifications between stations to be expanded N times, where N is the number of slices, resulting in the base station being unable to meet the requirements of the scenario.
[0052] In wireless base station application scenarios, such as Figure 2 As shown, secure communication between the base station and the core network can be achieved by establishing a secure protocol channel between the base station and a security gateway (SeGW) to carry collaborative services between the base stations, wherein the core network may include Figure 2The local area network (LAN), SeGW, mobility management entity (MME) / authentication management function (AMF), signaling gateway (SGW) / user plane function (UPF), etc. are shown.
[0053] In order to reduce the traffic load on the security gateway and reduce the delay between base stations, an IPsec tunnel can be directly established between base stations, such as a Direct IPsec tunnel (hereinafter referred to as "IPsec tunnel"). Figure 2 As shown, the secure transmission between base station 1 and base station 2 can be achieved by using the secure protocol channel between the base station and the security gateway (SeGW) of the core network, as well as the IPsec tunnel between base station 1 and base station 2. Specifically, as Figure 3 As shown, in some scenarios, when the IPsec tunnel exceeds the specification, X2 / Xn of the remaining data transmission except IPsec transmission is forwarded through the security gateway, which reduces the data transmission speed.
[0054] In the scenario of multi-operator base stations, such as a scenario where a base station serves multiple operators at the same time, that is, in the RAN Sharing scenario where multiple operators share the same base station, since transmission isolation and data isolation are required between operators, different operators usually use different VRFs, where different VRFs require separate IPsec tunnels. In order to perform transmission isolation and data isolation between operators, taking the example of base station 1 and base station 2 providing services for four operators, four inter-station IPsec tunnels need to be established between base station 1 and base station 2 according to the operator granularity. Similarly, multiple IPsec tunnels need to be established between base station 1 and other base stations, and multiple IPsec tunnels need to be established between base station 2 and other base stations to meet the isolation between different operators.
[0055] We know that IPsec resources are limited. For example, IPsec single-board hardware is limited. For example, in some examples, the IPsec tunnel specification of the entire single board is 512, that is, a base station can have 512 neighboring stations. If based on the conventional inter-station IPsec tunnel establishment mechanism, taking base station 1 with 4 operators, and 4 IPsec tunnels are established between base station 1 and others as an example, base station 1 needs to establish 512*4=2048 IPsec tunnels with other base stations. Therefore, based on the conventional inter-station IPsec tunnel establishment mechanism, the inter-station IPsec tunnel specification will increase dramatically. The essence of this problem is that the IPsec tunnel cannot be shared as a public channel for all operators, which greatly wastes base station resources. In other words, the key to solving the problem of the above-mentioned sharp increase in IPsec tunnel specifications is to improve the utilization rate of IPsec tunnels through IPsec tunnel sharing when the number of base station IPsec tunnel specifications is limited. Among them, the key to establishing IPsec tunnels is to negotiate security parameters for protecting IPsec tunnels and security parameters for protecting business data.
[0056] In order to solve the problem of the sharp increase in the specifications of IPsec tunnels between stations in the network in conventional technologies, an embodiment of the present application provides a method for sharing IPsec tunnels, which can support multiple operators to share one or more IPsec tunnels between network devices. The multiple IPsec tunnels are available to any operator served by the first network device and the second network device. Figure 4 As shown, data of any operator between base station 1 and base station 2 can be transmitted through IPsec tunnel 1, where IPsec tunnel 1 is provided with encryption and other security protection by IKE1. In other words, no matter any operator served by the first network device and the second network device has data transmission needs, the first network device can complete data transmission through any IPsec tunnel between the first network device and the second network device. Based on this, the problem of the sharp increase in the specifications of IPsec tunnels between stations can be solved, system computing, storage, IP address and other resources can be saved, customer operation and maintenance costs can be reduced, and the utilization rate of IPsec tunnels can be improved, and the business can be guaranteed to run more reliably and efficiently.
[0057] It should be noted that in some scenarios, an operator or service instance may also be a VPN instance.
[0058] Among them, the network device described in the embodiment of the present application can be the base station in the above example, such as: a macro base station, a micro base station (also called a "small station"), a distributed unit-control unit (distributed unit-control unit, DU-CU), etc., wherein the DU-CU is a device deployed in a wireless access network that enables terminal devices to perform wireless communications. In addition, the above base station can also be a wireless controller in a cloud radio access network (cloud radio access network, CRAN) scenario, or a relay station, access point, vehicle-mounted equipment, wearable device, or a network device in a future evolved public land mobile network (public landmobile network, PLMN) network, etc.
[0059] In some examples, the base station may be a gNB or a transmission / reception point (TRP). It may also be a base station defined by the 3rd Generation Partnership Project (3GPP), such as an eNB or an e-NodeB.
[0060] In addition, when the eNB is connected to the core network of NR or the next generation core network (NGC) or the 5th generation core network (5GC), the eNB can also be called eLTE eNB. Specifically, the eLTE eNB is an LTE base station device evolved on the basis of the eNB, which can be directly connected to the 5G CN. The eLTE eNB also belongs to the base station equipment in NR.
[0061] In some examples, the network device described in the embodiments of the present application may also include network devices of other types, functions and structures, such as wireless terminals (WT), access points (AP), access controllers (AC), or other network devices capable of communicating with terminal devices and core networks. The embodiments of the present application are not specifically limited.
[0062] Please refer to Figure 5 , Figure 5 A schematic diagram of the hardware results of a network device is shown. Figure 5 As shown, the network device may include a processor 501, a communication line 502, a memory 503, and at least one communication interface ( Figure 5 The communication interface 504 is used as an example for illustration only).
[0063] The processor 501 may be a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits for controlling the execution of the program of the present application.
[0064] Communication link 502 may include a pathway for transmitting information between the above-mentioned components.
[0065] The communication interface 504 uses any transceiver or other device for communicating with other devices or communication networks, such as Ethernet, RAN, WLAN, etc.
[0066] In the embodiment of the present application, the communication line 502 and the communication interface 504 can be used to support the transmission of business data corresponding to an operator or a business instance between a network device and other network devices (such as a first network device and a second network device).
[0067] The memory 503 may be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory may exist independently and be connected to the processor via a communication line 502. The memory may also be integrated with the processor.
[0068] The memory 503 is used to store computer-executable instructions for executing the solution of the present application, wherein the memory 503 can store instructions for implementing two modular functions: sending instructions, receiving instructions, and processing instructions, and the execution is controlled by the processor 501. The processor 501 is used to execute the computer-executable instructions stored in the memory 503, thereby implementing the method provided in the following embodiments of the present application. Figure 5 The memory 503 shown in the figure is only a schematic diagram, and the memory may also include other functional instructions, which is not limited by the present invention.
[0069] Optionally, the computer-executable instructions in the present application may also be referred to as application code, which is not specifically limited in the present application.
[0070] In a specific implementation, as an embodiment, the processor 501 may include one or more CPUs, such as Figure 5 CPU0 and CPU1 in.
[0071] It should be noted that Figure 5 This is only an example of a network device, and does not limit the specific structure of the network device. For example, the network device may also include other functional modules.
[0072] The following will specifically introduce the IPsec tunnel sharing method provided in the embodiment of the present application in conjunction with the accompanying drawings.
[0073] The embodiment of the present application achieves the situation where the physical hardware remains unchanged by sharing an IPsec tunnel through the inner layer data of multiple operators or multiple service instances and using the same IPsec SA. In the scenario of multiple operators or multiple service instances, the IPsec tunnel specifications of each operator or service instance are not reduced.
[0074] For some examples, see Figure 6 , which shows a schematic diagram of a system architecture provided by an embodiment of the present application, such as Figure 6 As shown, in the wireless base station application scenario, secure communication between the base station and the core network can be achieved by establishing a secure protocol channel between the base station and the security gateway to carry collaborative services between base stations, where the core network may include MME / AMF, SGW / UPF, etc.
[0075] In order to reduce the traffic load of the security gateway and reduce the delay between base stations, an IPsec tunnel can be directly established between base stations, such as Figure 6 As shown, the secure transmission between base station 1 and base station 2 can be achieved by using the secure protocol channel between the base station and the security gateway (SGW) of the core network. Figure 7 As shown, base station 1 and base station 2 can directly transmit data through an IPsec tunnel.
[0076] In some embodiments, the present application provides a method for sharing an IPsec tunnel, which is applied to a first network device, where the first network device provides services for multiple target objects, where the target objects are operators or service instances, where the multiple target objects include a first target object and a second target object, and where one or more IPsec tunnels are established between the first network device and the second network device. When the first network device is used as a sending end, the method may include:
[0077] A first data packet and a second data packet are sent to the second network device through a first IPsec tunnel, wherein the first data packet belongs to the first target object, and the second data packet belongs to a second different target object, the first data packet includes first business data and first information, and the first information is used to indicate the first target object, and the second data packet includes second business data and second information, and the second information is used to indicate the second target object; wherein the first IPsec tunnel is one of the one or more IPsec tunnels.
[0078] It should be noted that one or more IPsec tunnels are established between the first network device and the second network device, and the one or more IPsec tunnels are used for transmitting business data between the first network device and the second network device. The first network device and the second network device both provide services for multiple target objects. The first data packet and the second data packet may come from the same or different target objects. The first data packet includes first business data and first information, and the first business data is the business data of the first target object. The first information is used to indicate that the first business data comes from the first target object. The second data packet includes second business data and second information, and the second business data is the business data of the second target object. The second information is used to indicate that the second business data comes from the second target object. The target object may be an operator or a service instance. In some examples, it may also be other dedicated networks. No limitation is made herein. The service data of multiple target objects served by the first network and the second network may use any one of the one or more IPsec tunnels as the first IPsec tunnel to transmit the service data. In this way, the IPsec tunnel between the first network device and the second network device is shared among multiple target objects, thereby improving the IPsec tunnel specifications available to the target object when transmitting service data, and at the same time improving the utilization rate of the IPsec tunnel between the first network device and the second network device, so as to improve the transmission efficiency of service data between the first network device and the second network device.
[0079] In some examples, sending the first data packet and the second data packet to the second network device through the first IPsec tunnel includes: transmitting the first business data and the second business data to the tunnel interface of the first IPsec tunnel, respectively; encrypting the first business data and the second business data at the tunnel interface to obtain the first data packet and the second data packet; and sending the first data packet and the second data packet to the second network device through the first IPsec tunnel.
[0080] In some examples, when a first IPsec tunnel is used for business data transmission, the first business data and the second business data are first transmitted to the tunnel interface of the first IPsec tunnel. The first IPsec tunnel can be any one of a plurality of IPsec tunnels. The first business data and the second business data can come from the same or different target objects. At the tunnel interface, the first business data and the second business data are respectively encapsulated and encrypted according to the security protocol policy corresponding to the first IPsec tunnel to obtain a first data packet and a second data packet. The first data packet and the second data packet are then sent through the first IPsec tunnel. In this way, by controlling the transmission mode of the first business data and the second business data, the sharing of the first IPsec tunnel when business data from the same or different target objects are transmitted is achieved. It can be understood that the first IPsec tunnel is any one of one or more IPsec tunnels between the first network device and the second network device. The first business data and the second business data can be business data of any different target objects served by the first network device.
[0081] For some examples, see Figure 8 , which shows a flow chart of a method for sharing an IPsec tunnel provided in an embodiment of the present application, such as Figure 8 As shown, based on the first network device, the method may include:
[0082] S801: Transmit first service data and second service data to the tunnel interface of the first IPsec tunnel.
[0083] It should be noted that transmitting the first service data and the second service data to the tunnel interface of the first IPsec tunnel respectively may include: transmitting the first service data and the second service data to the tunnel interface according to the preset routing method of the inner address. When transmitting the first service data and the second service data to the tunnel interface of the first IPsec tunnel, the first service data and the second service data from the same or different target objects may be transmitted to the tunnel interface of the first IPsec tunnel by routing, and the data transmission path of the first service data and the second service data may be controlled to realize the sharing of the IPsec tunnel by different target objects.
[0084] In some examples, the preset routing method of the inner address includes one or more of the following: destination address routing, source address routing, and policy routing. The first service data and the second service data are transmitted from their respective inner addresses to the tunnel interface of the first IPsec tunnel by means of preset routing. Exemplarily, the routing method of destination address routing, the routing method of source address routing, and the routing method of policy routing can be adopted. In some examples, other routing methods that can realize the transmission of service data to the tunnel interface can also be adopted, and no limitation is made here. Among them, the destination address routing can be based on the address of the second network device to which the service data needs to be transmitted to route the service data, the source address routing can be based on the address of the first network device that sends the service data to route the service data, and the policy routing can be based on the source address + destination routing method to transmit the service data. The router matches the source address and destination address of the service data to route the service data, and controls the transmission path of the service data through one or more of the above-mentioned routing methods to realize the transmission of the service data to the tunnel interface of the corresponding first IPsec tunnel.
[0085] For some examples, see Fig. 9 It shows a schematic diagram of data transmission based on policy routing provided by an embodiment of the present application, such as Fig. 9 As shown, the first network device may include multiple operators or multiple service instances. For example, it may include operator 1 (VRF1), operator 2 (VRF2) and operator 3 (VRF3). Multiple operators correspond to their own policy routing methods. For example, operator 1 corresponds to policy routing 1, operator 2 corresponds to policy routing 2, and operator 3 corresponds to policy routing 3. For the three operators in the first network device, all service data can pass through the traffic selector (traffic selector, TS). Accordingly, when the service data arrives at the IPsec tunnel interface, it is also necessary to encrypt and process it according to the security policy protocol corresponding to the IPsec tunnel to obtain the corresponding data packet, and finally send it to the second network device through the IPsec tunnel in the form of a data packet. There can be one or more IPsec tunnels between the first network device and the second network device.
[0086] For some examples, see Fig.10 , which shows a schematic diagram of a data message in a data transmission process of an IPsec tunnel provided in an embodiment of the present application, such as Fig.10As shown, a layer of IPsec tunnel header is encapsulated before the original IP packet, and AH or ESP can be used. For example, the ESP method can be used. The inner layer data is the original IP message, which can include IP header, TCP header, data, TCP tail, etc. The outer layer is the tunnel header added by IPsec, which can include IP header and ESP header.
[0087] In some examples, after sending the first business data and the second business data to the tunnel interface of the IPsec tunnel, the method may also include: encrypting the first business data and the second business data at the tunnel interface to obtain the first data packet and the second data packet.
[0088] In some examples, the first service data and the second service data both pass the traffic selection of the tunnel interface. After the first service data and the second service data are transmitted to the tunnel interface, traffic selection can be performed on the first service data and the second service data at the tunnel interface, so that the first service data and the second service data both pass the traffic selection of the tunnel interface at the tunnel interface, and the first service data and the second service data are encapsulated or encrypted at the tunnel interface.
[0089] In some examples, the tunnel interface includes a traffic selector, and the encryption of the first service data and the second service data at the tunnel interface includes: selecting the first service data and the second service data at the tunnel interface by the traffic selector, and encrypting the first service data and the second service data when the traffic selection passes. When the tunnel interface performs traffic selection, the traffic selector can be used to select the service data. Exemplarily, the traffic selector can be used to select the first service data and the second service data. When the inner layer address of the first service data meets the preset address range of the traffic selector, the first service data and the second service data pass through the traffic selector, and the first service data and the second service data are encrypted.
[0090] In some examples, the flow selection of the first business data and the second business data includes: determining that the inner addresses corresponding to the first business data and the second business data meet the preset address range of the flow selector, and determining that the flow selection is passed. The preset address range of the flow selector can be set according to the transmission requirements of the business data. When the inner addresses corresponding to the first business data and the second business data are within the preset address range of the flow selector, it is determined that the first business data and the second business data meet the flow selection rules of the flow selector, and the flow selection of the first business data and the second business data is determined to be passed.
[0091] In some examples, the traffic selection of the first business data and the second business data by the traffic selector includes: the traffic selector selects the first business data and the second business data based on the any~any selection strategy, wherein the ipv4 address range corresponding to the traffic selector is 0.0.0.0 / 0~0.0.0.0 / 0, and the corresponding ipv6 address range is ::0 / 0~::0 / 0. In some examples, the selection strategy of the traffic selector can be any~any, that is, after the first business data and the second business data are transmitted to the tunnel interface through a preset route, the traffic selector can allow the first business data and the second business data to pass through the traffic selection, wherein the first business data and the second business data both belong to the preset address range of the traffic selector, the address range of the traffic selector in the ipv4 scenario is 0.0.0.0 / 0~0.0.0.0 / 0, and the address range of the traffic selector in the ipv6 scenario is ::0 / 0~::0 / 0. When the first business data and the second business data belong to the address range, it is determined that the first business data and the second business data traffic are selected to pass, that is, the traffic selector at the tunnel interface allows all data transmitted to the tunnel interface through the preset route to pass through the traffic selection. The traffic selector and the preset route cooperate with each other to control the transmission process of the business data, and transmit the business data to the corresponding tunnel interface, thereby realizing the sharing of the IPsec tunnel between the first network device and the second network device and improving the transmission efficiency of the business data.
[0092] In some examples, the encryption processing of the first service data and the second service data at the tunnel interface includes: after writing the first virtual routing domain identifier corresponding to the first target object in the first information, encrypting the first service data; and after writing the second virtual routing domain identifier corresponding to the second target object in the second information, encrypting the second service data. In the process of encrypting the first service data and the second service data, the first service data comes from the first target object, and the first virtual routing domain identifier corresponding to the first target object is written into the first information, and the second service data comes from the second target object, and the second virtual routing domain identifier corresponding to the second target object is written into the second information, wherein the first virtual routing domain identifier is used to indicate the first target object, and the second virtual routing domain identifier is used to indicate the second target object.
[0093] In some examples, the step of writing the first virtual routing domain identifier corresponding to the first target object in the first information includes: writing the first virtual routing domain identifier corresponding to the first target object into the first information based on a first mapping mechanism; the step of writing the second virtual routing domain identifier corresponding to the second target object in the second information includes: writing the second virtual routing domain identifier corresponding to the second target object into the second information based on the second mapping mechanism; wherein the first mapping mechanism and the second mapping mechanism may be the same or different. When writing the first virtual routing domain identifier into the first information, the first mapping mechanism may be used to map the first virtual routing domain identifier to a field for carrying the first information, and the second mapping mechanism may be used to map the second virtual routing domain identifier to a field for carrying the second information. The specific mapping rule may be negotiated between the first network device and the second network device. In some examples, the first mapping mechanism and the second mapping mechanism may be the same, and in other examples, the first mapping mechanism and the second mapping mechanism may be different.
[0094] In some examples, the first data message includes a field for carrying the first information, and the second data message includes a field for carrying the second information, and the field includes one or more of the following: an extended header field, a special field, a reserved field, a TTL field, a flowlable field, and a dh header field. When the first virtual routing domain identifier is written into the first information, and the second virtual routing domain identifier is written into the second information, the first virtual routing domain identifier and the second virtual routing domain identifier can be mapped to the extended header field, the special field, the reserved field, the TTL field, the flowlable field, and the dh header field, or other available fields in the data message, without any limitation here.
[0095] In some examples, the first business data includes first address information, which is used to indicate the first target object, and the second business data includes second address information, which is used to indicate the second target object. When the target object sends business data, the business data carries address information that can indicate the corresponding target object. In some examples, the first business data may include first address information, which can indicate source address information and target address information corresponding to the first business data, and the second business data may include second address information, which can indicate source address information and target address information corresponding to the second business data, so as to determine the first target object and the second target object corresponding to the first business data and the second business data.
[0096] S802: Send a first data packet and a second data packet through a first IPsec tunnel (the first data packet includes first service data and first information, and the second data packet includes second service data and second information).
[0097] It should be noted that the first IPsec tunnel is any one of the one or more IPsec tunnels between the first network device and the second network device, the first data packet includes first business data and first information, and the second data packet includes second business data and second information, wherein the first business data and the second business data can come from any one of the target objects served by the first network device, that is, multiple target objects served by the first network device can use any IPsec tunnel between the first network device and the second network device to transmit business data, thereby realizing the sharing of IPsec tunnels between different target objects.
[0098] In some examples, such as Figure 8 As shown, the method is applied to a second network device, the second network device provides services for multiple target objects, the target objects are operators or service instances, the multiple target objects include a first target object and a second target object, one or more IPsec tunnels are established between the second network device and the first network device, and when the second network device serves as a receiving end, the method may include:
[0099] S803: Acquire first service data and first information from the first data packet, and acquire second service data and second information from the second data packet.
[0100] It should be noted that a first data packet and a second data packet sent by a first network device through a first IPsec tunnel are received, wherein the first data packet includes first service data and first information, and the first information is used to indicate the first target object, and the second data packet includes second service data and second information, and the second information is used to indicate the second target object. One or more IPsec tunnels are established between the first network device and the second network device, and the one or more IPsec tunnels are used for the transmission of service data between the first network device and the second network device. The first network device and the second network device both provide services for multiple target objects. The second network device receives the first data packet and the second data packet from the first network device, and the first data packet and the second data packet may come from the same or different target objects. The target object may be an operator or a service instance, and in some examples, it may also be other dedicated networks, without any limitation here.
[0101] In some examples, the first service data and the first information are obtained from the first data packet, and the second service data and the second information are obtained from the second data packet. The first service data and the first information are obtained from the first data packet, and the first information is used to indicate that the first service data belongs to the first target object. The second service data and the second information are obtained from the second data packet, and the second information is used to indicate that the second service data comes from the second target object. In this way, the target object to which the data packet belongs can be determined through the first information or the second information carried in the data packet, and the second network device can receive and identify the first service data and the second service data, thereby receiving the first service data and the second service data.
[0102] In some examples, the obtaining of the first business data and the first information from the first data packet includes: parsing the first data packet according to the security protocol policy corresponding to the first IPsec tunnel to obtain the first business data and the first information. The obtaining of the second business data and the second information from the second data packet includes: parsing the second data packet according to the security protocol policy corresponding to the first IPsec tunnel to obtain the second business data and the second information. The first data packet and the second data packet received by the second network device from the first IPsec tunnel are both decrypted according to the security protocol policy corresponding to the first IPsec tunnel to obtain the corresponding first business data and the first information, as well as the second business data and the second information, wherein the IPsec tunnel can be configured to set the corresponding security protocol policy for use when encrypting business data transmitted through the IPsec tunnel.
[0103] S804: Send the first service data to the first target object indicated by the first information, and send the second service data to the second target object indicated by the second information.
[0104] It should be noted that the first information is used to indicate that the first business data belongs to the first target object, and the second information is used to indicate that the second business data comes from the second target object. In this way, the target object to which the data packet belongs can be judged by the first information or the second information carried in the data packet, so that the second network device can judge the target objects corresponding to the first business data and the second business data. According to the result of the judgment, the first business data is sent to the target object indicated by the first information, and the second business data is sent to the target object indicated by the second information, wherein the target object may include an operator or a business instance.
[0105] In some examples, the method may further include: obtaining a first virtual routing domain identifier corresponding to the first information based on a third mapping mechanism, the first information being encapsulated in the first data message by the first network device based on the first mapping mechanism; obtaining a second virtual routing domain identifier corresponding to the second information based on the fourth mapping mechanism, the second information being encapsulated in the second data message by the first network device based on the first mapping mechanism. Wherein, the third mapping mechanism and the fourth mapping mechanism may be the same or different. When obtaining the corresponding first virtual routing domain identifier according to the first information, the third mapping mechanism may be used to obtain the first virtual routing domain identifier from the field used to carry the first information, and when obtaining the corresponding second virtual routing domain identifier according to the second information, the fourth mapping mechanism may be used to obtain the second virtual routing domain identifier from the field used to carry the second information, wherein the third mapping mechanism and the fourth mapping mechanism may be the same or different, and at the same time, the third mapping mechanism and the first mapping mechanism may be the same or different, and the fourth mapping mechanism and the second mapping mechanism may be the same or different, and the specific mapping rules may be determined by negotiation between the first network device and the second network device.
[0106] In some examples, the first data message and the second data message include one or more of the following fields: an extended header field, a special field, a reserved field, a TTL field, a flowlable field, and a dh header field, and the first information is located in the field. When obtaining the corresponding first virtual routing domain identifier according to the first information, and obtaining the corresponding second virtual routing domain identifier according to the second information, the first virtual routing domain identifier carried by the first information and the second virtual routing domain identifier carried by the second information can be obtained from the extended header field, the special field, the reserved field, the TTL field, the flowlable field, the dh header field, etc., or can be obtained from other available fields in the data message, without any limitation here.
[0107] In some examples, the method may also include: transmitting the first service data to the first target object served by the second network device according to the first virtual routing domain identifier, and the first virtual routing domain identifier is associated with the first target object; transmitting the second service data to the second target object served by the second network device according to the second virtual routing domain identifier, and the second virtual routing domain identifier is associated with the second target object. It can be understood that the first virtual routing domain identifier is associated with the first target object, and the second virtual routing domain identifier is associated with the second target object. Therefore, the first service data can be sent to the first target object served by the second network device according to the first virtual routing domain identifier and the association relationship between the first virtual routing domain identifier and the first target object, and the second service data can be sent to the second target object served by the second network device according to the second virtual routing domain identifier and the association relationship between the second virtual routing domain identifier and the second target object, so as to complete the reception of the first service data and the second service data.
[0108] For some examples, see Fig.11 , which shows a schematic diagram of the principle of indicating a virtual routing domain provided by an embodiment of the present application, such as Fig.11 As shown, the virtual routing domain identifier corresponding to the target object is mapped to generate a virtual local area network identifier (VID) parameter, and an association relationship between the virtual routing domain and the VID parameter is established. In this way, the VID parameter can be written into the available field as a virtual routing domain identifier to indicate the operator or service instance corresponding to the service data. In some examples, the corresponding VID parameter can be carried through the inner or outer layer through the extension header, special field, and optional field. Since the VID parameter is bound to the virtual routing forwarding domain VRF, and the VID corresponding to the same operator or service instance between base station 1 and base station 2 needs to be consistent. Exemplarily, it can also be mapped through the next hop extension header of Internet Protocol Version 6 (IPv6).
[0109] Exemplarily, between base station 1 and base station 2, the vid value corresponding to VRF1 in base station 1 and the vid value corresponding to VRF3 in base station 2 remain the same, so that after the service data is transmitted to base station 2, it can be determined by the vid value that the service data belongs to VRF3. In some examples, the mapping mechanism between VRF1 and vid in base station 1 and the mapping mechanism between VRF3 and vid in base station 2 can be the same or different, and the mapping mechanism between different VRFs and vid in the same base station can be the same or different. It can be understood that based on the same principle, it is also possible to choose to use existing fields for mapping. Exemplarily, the existing fields may include one or more of the following: the TTL field of the message represents vid, the option field of Internet Protocol Version 4 (IPv4), the flowlable of IPv6, the DH header of IPv6, etc., and other optional existing fields, which are not limited here.
[0110] In some examples, the first business data includes first address information, which is used to indicate the first target object, and the second business data includes second address information, which is used to indicate the second target object. After acquiring the business data, the business data carries address information that can indicate the corresponding target object. In some examples, the first business data may include first address information, which can indicate the target address information corresponding to the first business data, and the second business data may include second address information, which can indicate the target address information corresponding to the second business data. The first target object and the second target object corresponding to the first business data and the second business data can be determined based on the target address information.
[0111] In some examples, the method further includes: transmitting the first business data to a first target object served by the second network device according to the first address information; transmitting the second business data to a second target object served by the second network device according to the second address information. The address information may include source address information and target address information. In some examples, the target object corresponding to the business data may be determined by obtaining the target address information in the address information. Exemplarily, the first target object corresponding to the first business data may be determined according to the target address information in the first address information, and the first business data may be sent to the first target object. The second target object corresponding to the second business data may be determined according to the target address information in the second address information, and the second business data may be sent to the second target object, so as to complete the reception of the first business data and the second business data.
[0112] In some embodiments, see Fig.12, which shows a schematic diagram of the principle of indicating a virtual routing domain provided by an embodiment of the present application, such as Fig.12 As shown, the service data sent by VRF1 includes the inner address ip1 corresponding to VRF1, and the service data sent by VRF2 includes the inner address ip2 corresponding to VRF2. After the service data is sent from base station 1 to base station 2, the corresponding VRF domain can be determined by different inner IP addresses. There is an association relationship between different target objects and different VRFs, and the inner addresses of different target objects are different. The corresponding VRF domain can be determined by the inner IP address.
[0113] In some embodiments, an IPsec tunnel is a data transmission path, and other similar data transmission paths are also applicable to the concept of the IPsec tunnel sharing method provided in this application, and no limitation is made here.
[0114] It is understandable that an IPsec tunnel header is encapsulated before the original IP packet, and AH or ESP can be used. When the commonly used ESP method is used, the inner layer data is the original IP message, and the outer layer is the tunnel header added by IPsec.
[0115] In some embodiments, the inner layer data of multiple operators share one IPsec tunnel and use the same IPsecSA, which is the sharing of the IPsec tunnel in the above embodiments.
[0116] In some examples, the network device can establish an outer IKE local address through an IPsec tunnel, which is shared by multiple operators. The IPsec tunnel generation rule is any to any, and traffic is directed to the IPsec tunnel through policy routing. One of the security protocol policies (IPsec policies) established by multiple operators is determined and bound to the tunnel interface of the IPsec tunnel.
[0117] The principles of the sending process and the receiving process in this embodiment include:
[0118] Sending processing: The plaintext (before encryption) of the sender modifies the message content and maps the id of the internal VRF to field x.
[0119] Receiving processing: After decryption based on IPsec SA matching, the id in the inner message field x is mapped to the inner VRF.
[0120] It should be noted that field x can be the first information in the aforementioned embodiment, the sending end can be the first network device in the aforementioned embodiment, and the receiving end can be the second network device in the aforementioned embodiment. Similarly, the first network device can also be used as the receiving end, and the second network device can also be used as the sending end. Furthermore, the IDs of the sending end and the receiving end must be uniformly mapped with the VRF.
[0121] For other examples, see Fig.13 , which shows a detailed flow chart of a method for sharing an IPsec tunnel provided in an embodiment of the present application, such as Fig.13 As shown, the method may include:
[0122] S1: specifies the tunnel for the outer IKE negotiation and the local and remote addresses of IKE.
[0123] In some examples, IKE is first created between network devices, that is, the parameters of the first phase of IPsec tunnel negotiation are established based on one or more IPsec tunnels, and the local address and the remote address of the outer layer of the IPsec tunnel are determined through negotiation between the first network device and the second network device.
[0124] S2: Create an IPsec tunnel interface based on the IPsec tunnel.
[0125] Specifically, a corresponding interface is created according to the IPsec tunnel. Different IPsec tunnels correspond to their own tunnel interfaces, which are used for traffic matching of business data and encryption of business data (specifically, business data can be directed to the tunnel interface through routing, and then the IPsec policy is bound to the tunnel interface to determine the encryption method of the business data).
[0126] S3: Bind the IPsec policy to the IPsec tunnel interface.
[0127] The IPsec policy is bound to the IPsec tunnel interface (for encapsulating or encrypting the business data according to the IPsec policy corresponding to the IPsec tunnel when the business data is transmitted to the IPsec tunnel interface).
[0128] Based on this, the negotiation and creation process based on IPsec tunnels between network devices is realized, so that IPsec tunnels can serve multiple business instances and improve the data transmission efficiency between network devices.
[0129] S4: Service data from the operator or service instance selects the IPsec tunnel interface through policy routing.
[0130] The sender will guide the business data that needs to be encrypted to the IPsec tunnel interface through routing, which can adopt destination address routing, source address routing and policy routing.
[0131] It should be noted that during the transmission of service data, in the process of transmitting service data to the tunnel interface of the first IPsec tunnel, destination address routing may be used, source address routing may be used, and further, policy routing may be used. Wherein, destination address routing may be based on the address of the second network device to which the service data needs to be transmitted to route the service data, source address routing may be based on the address of the first network device that sends the service data to route the service data, and policy routing may be based on the source address + destination address, and the router determines whether the service data is sent through the route, and the purpose of transmitting the service data to the corresponding first IPsec tunnel is achieved by controlling the sending path of the service data through policy routing.
[0132] In some embodiments, the inner layer of the network device can divert the service data of the operator or service instance through policy routing. The policy routing can divert the service data to the IPsec tunnel interface for the user plane or signaling plane of X2 / Xn through the source IP address + destination IP address (SRC IP + DST IP), so as to facilitate IPsec encryption of the user plane or signaling plane of X2 / Xn between stations. When it is the signaling plane, the SRC IP is the local address of the signaling plane of X2 / Xn, and the DST IP is the address carried by the MME / AMF to the base station through the signaling interface of S1 / NG; when it is the user plane, the SRC ip is the local address of the user plane of X2 / Xn, and the DST IP is the address carried to the base station through the signaling interface of X2 / Xn, and the outbound interface of the policy routing is the tunnel interface of the direct IPsec between stations, so as to ensure that only the service data of X2 / Xn between stations is encrypted by direct IPsec.
[0133] In some embodiments, X2 / Xn between network device stations may first establish a control plane (CP), and then establish a user plane (UP) through the CP.
[0134] S5. Select matching service data based on the traffic selector, and encrypt the matching service data according to the IPsec policy.
[0135] Configure the TS for the second phase of IPsec negotiation. This is used to match service data after it reaches the IPsec tunnel interface.
[0136] It should be noted that the selection mode of the traffic selector setting is any~any, that is, the service data transmitted to the tunnel interface through the preset route can be encrypted and encapsulated to obtain the corresponding data message.
[0137] It can be understood that the key step in business data encryption is to first transmit the business data to the ispec tunnel interface through the preset route, and then bind the IPsec interface to the traffic selector TS corresponding to the IPsec policy. If the business data matches the preset rules of TS, it will be encrypted and encapsulated to obtain the data packet corresponding to the business data.
[0138] In some embodiments, during the direct IPsec self-establishment process between network devices, TS uses the any~any selection rule. The address range corresponding to IPv4 is 0.0.0.0~0.0.0.0, and the address range corresponding to IPv6 is ::0~::0, so that one IPsec tunnel uses one IPsec SA, saving IPsec SA resources and improving data transmission efficiency.
[0139] S6: After encrypting the service data based on the above security protocol policy, an IPsec tunnel transmission request is made.
[0140] In some embodiments, after receiving the data message at the receiving end, the method for sharing the iSpec tunnel with the inner layer message data may include:
[0141] In the mapping process, the corresponding VRF domain can be obtained through the inner or outer extension header, special field, optional field, etc. The specific method is as follows: the vid parameter of the IPSec security proposal is carried through the extension header, special field, and optional field. The vid parameter is bound to the virtual routing forwarding domain VRF. The vid between the base station BTS1 and the base station BTS2 needs to be consistent. For details, please refer to the above embodiment for Fig.11 The relevant details will not be elaborated here.
[0142] In some examples, different VRF domains can also be determined by the inner IP addresses carried by different service data. Fig.12 The relevant details will not be elaborated here.
[0143] The embodiment of the present application provides a method for sharing an IPsec tunnel, where the outer layer of directIPsec tunnels established by multiple operators is shared, that is, multiple IPsec share an IKE and IPsec tunnel; first, the direct IPsec established by the network device is directed through policy routing, using the VRF+srcIP+DST IP method; secondly, the direct IPsec SA established by the network device is any~any; finally, the mapping of the inner message VRF uses the existing field or IP address or extended field method to distinguish the data messages of different service instances within the same network device. In this way, the specifications of direct IPsec shared by multiple operators are increased by N times, and there is no need to expand the capacity of the security gateway.
[0144] It is understandable that direct IPsec shared by multiple operators between network devices changes the IP / routing specification from N to 1, reducing network planning and construction costs; the direct IPsec specification shared by multiple operators changes from 1 / N to N, meeting the demands of CA services, and the specification shared by multiple operators does not decrease; operators independently plan IP networks, and there is no need for communication between operators to verify IP planning.
[0145] It can be understood that by supporting the deletion of IPsec tunnels and the modification of the association between IPsec tunnels and service instances (such as adding or deleting, etc.) between network devices in the embodiments of the present application, more flexible IPsec tunnel sharing can be achieved. For example, network devices can negotiate with other network devices at any time about the management of IPsec tunnels according to actual needs, including adding or deleting IPsec tunnels on demand, adding / deleting the association between IPsec tunnels and service instances on demand, and supporting on-demand allocation of system computing, storage, IP address and other resources through on-demand adjustment, so as to achieve more scientific resource allocation.
[0146] It should be understood that the various schemes of the embodiments of the present application can be used in reasonable combination, and the explanations or descriptions of the various terms appearing in the embodiments can be mutually referenced or explained in the various embodiments, without limitation.
[0147] It should also be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0148] It is understandable that, in order to implement the functions of any of the above-mentioned embodiments, the network device (such as the first network device or the second network device) includes a hardware structure and / or software module corresponding to the execution of each function. Those skilled in the art should easily realize that, in combination with the units and algorithm steps of each example described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0149] The embodiment of the present application can divide the network device into functional modules. For example, each functional module can be divided according to each function, or two or more functions can be integrated into one processing module. The above integrated module can be implemented in the form of hardware or in the form of software functional modules. It should be noted that the division of modules in the embodiment of the present application is schematic and is only a logical function division. There may be other division methods in actual implementation.
[0150] It should also be understood that each module in the network device can be implemented in software and / or hardware form, and there is no specific limitation on this. In other words, the network device is presented in the form of functional modules. The "module" here can refer to a specific application integrated circuit ASIC, a circuit, a processor and a memory that executes one or more software or firmware programs, an integrated logic circuit, and / or other devices that can provide the above functions.
[0151] In an optional manner, when data transmission is implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present application is implemented in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions may be transmitted from a website site, computer, server or data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) mode to another website site, computer, server or data center. The computer-readable storage medium may be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrated. The available medium may be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a digital video disk (DVD)), or a semiconductor medium (e.g., a solid state disk (SSD)), etc.
[0152] The steps of the method or algorithm described in conjunction with the embodiments of the present application can be implemented in hardware or by executing software instructions by a processor. The software instructions can be composed of corresponding software modules, which can be stored in random access memory (RAM), flash memory, read-only memory (ROM), erasable programmable read-only memory (EPROM), electrically erasable read-only memory (EEPROM) memory, register, hard disk, mobile hard disk, compact disc read-only memory (CD-ROM) or any other form of storage medium known in the art. An exemplary storage medium is coupled to a processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and the storage medium can be located in an application specific integrated circuit (ASIC). In addition, the ASIC can be located in a network device. Of course, the processor and the storage medium can also exist as discrete components.
[0153] Through the description of the above implementation methods, technical personnel in the relevant field can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional modules is used as an example. In actual applications, the above-mentioned functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.
Claims
1. A method for sharing an IPsec tunnel, It is characterized in that Applied to a first network device, the first network device provides services for multiple target objects, the target objects are operators or service instances, the multiple target objects include a first target object and a second target object, one or more IPsec tunnels are established between the first network device and the second network device, and the method includes: Sending a first data packet and a second data packet to the second network device through the first IPsec tunnel, where the first data packet belongs to the first target object, and the second data packet belongs to a second different target object, the first data packet includes first service data and first information, and the first information is used to indicate the first target object, and the second data packet includes second service data and second information, and the second information is used to indicate the second target object; The first IPsec tunnel is one of the one or more IPsec tunnels.
2. The method according to claim 1, It is characterized in that The sending the first data packet and the second data packet to the second network device through the first IPsec tunnel includes: Transmitting the first service data and the second service data to the tunnel interface of the first IPsec tunnel respectively; The first service data and the second service data are encrypted at the tunnel interface to obtain the first data message and the second data message; The first data packet and the second data packet are sent to the second network device through the first IPsec tunnel.
3. The method according to claim 2, It is characterized in that The transmitting the first service data and the second service data to the tunnel interface of the first IPsec tunnel respectively includes: The first service data and the second service data are transmitted to the tunnel interface according to a preset routing mode of the inner address.
4. The method according to claim 3, It is characterized in that The preset routing mode of the inner address includes one or more of the following: destination address routing, source address routing, and policy routing.
5. The method according to any one of claims 2 to 4, It is characterized in that Both the first service data and the second service data pass the traffic selection of the tunnel interface.
6. The method according to any one of claims 2 to 5, It is characterized in that The tunnel interface includes a traffic selector, and the encrypting the first service data and the second service data at the tunnel interface respectively includes: The traffic selector is used to select the first service data and the second service data at the tunnel interface, and the first service data and the second service data are encrypted respectively when the traffic selection is passed.
7. The method according to claim 6, It is characterized in that The performing flow selection on the first service data and the second service data includes: It is determined that the inner addresses corresponding to the first business data and the second business data meet the preset address range of the traffic selector, and it is determined that the traffic is selected to pass.
8. The method according to claim 6 or 7, It is characterized in that The performing flow selection on the first service data and the second service data by the flow selector includes: The traffic selector performs traffic selection on the first service data and the second service data based on the any-any selection strategy, Among them, the IPv4 address range corresponding to the traffic selector is 0.0.0.0 / 0~0.0.0.0 / 0, and the corresponding IPv6 address range is ::0 / 0~::0 / 0.
9. The method according to any one of claims 2 to 8, It is characterized in that The encrypting the first service data and the second service data at the tunnel interface respectively includes: After writing the first virtual routing domain identifier corresponding to the first target object into the first information, encrypting the first service data; And after writing the second virtual routing domain identifier corresponding to the second target object into the second information, the second service data is encrypted.
10. The method according to claim 9, It is characterized in that The step of writing the virtual routing domain identifier corresponding to the first target object into the first information includes: Writing a first virtual routing domain identifier corresponding to the first target object into the first information based on a first mapping mechanism; The step of writing the virtual routing domain identifier corresponding to the second target object into the second information includes: Writing the second virtual routing domain identifier corresponding to the second target object into the second information based on the second mapping mechanism; The first mapping mechanism and the second mapping mechanism may be the same or different.
11. The method according to claim 10, It is characterized in that The first data packet includes a field for carrying first information, and the second data packet includes a field for carrying second information, and the field includes one or more of the following: an extended header field, a special field, a reserved field, a TTL field, a flowlable field, and a dh header field.
12. The method according to claim 1, It is characterized in that The first business data includes first address information, and the first address information is used to indicate the first target object. The second business data includes second address information, and the second address information is used to indicate the second target object.
13. A method for sharing an IPsec tunnel, It is characterized in that Applied to a second network device, the second network device provides services for multiple target objects, the target objects are operators or service instances, the multiple target objects include a first target object and a second target object, one or more IPsec tunnels are established between the second network device and the first network device, and the method includes: Receive a first data packet and a second data packet sent by a first network device through a first IPsec tunnel, wherein the first data packet includes first service data and first information, and the first information is used to indicate the first target object, and the second data packet includes second service data and second information, and the second information is used to indicate the second target object; The first service data and the first information are obtained from the first data packet, and the second service data and the second information are obtained from the second data packet.
14. The method according to claim 13, It is characterized in that The acquiring the first service data and the first information from the first data message includes: Parsing the first data message according to the security protocol policy corresponding to the first IPsec tunnel to obtain the first service data and the first information; The acquiring the second service data and the second information from the second data message includes: The second data packet is parsed according to the security protocol policy corresponding to the first IPsec tunnel to obtain the second business data and the second information.
15. The method according to claim 13 or 14, It is characterized in that The method further comprises: Acquire a first virtual routing domain identifier corresponding to the first information based on a third mapping mechanism, where the first information is encapsulated in the first data message by the first network device based on the first mapping mechanism; The second virtual routing domain identifier corresponding to the second information is obtained based on the fourth mapping mechanism, and the second information is encapsulated in the second data message by the first network device based on the first mapping mechanism. The third mapping mechanism and the fourth mapping mechanism may be the same or different.
16. The method according to claim 15, It is characterized in that The first data message and the second data message include one or more of the following fields: an extended header field, a special field, a reserved field, a TTL field, a flowlable field, and a dh header field, and the first information is located in the field.
17. The method according to any one of claims 13 to 16, It is characterized in that The method further comprises: According to the first virtual routing domain identifier, the first service data is transmitted to a first target object served by the second network device, and the first virtual routing domain identifier is associated with the first target object; According to the second virtual routing domain identifier, the second service data is transmitted to a second target object served by the second network device, and the second virtual routing domain identifier is associated with the second target object.
18. The method according to claim 13, It is characterized in that The first business data includes first address information, and the first address information is used to indicate the first target object. The second business data includes second address information, and the second address information is used to indicate the second target object.
19. The method according to claim 18, It is characterized in that The method further comprises: transmitting the first service data to a first target object served by the second network device according to the first address information; The second service data is transmitted to a second target object served by the second network device according to the second address information.
20. A communication system, It is characterized in that The communication system comprises a first network device and a second network device, wherein the first network device is used to implement the method according to any one of claims 1 to 12, and the second network device is used to implement the method according to any one of claims 13 to 19.
21. A network device, It is characterized in that The network equipment includes: A transceiver, used for sending and receiving signals; a memory for storing computer program instructions; A processor, configured to execute the computer program instructions to support the network device to implement the method as described in any one of claims 1-12 or 13-19.
22. A computer-readable storage medium, It is characterized in that The computer-readable storage medium stores computer program instructions, and when the computer program instructions are executed by the processing circuit, the method according to any one of claims 1-12 or 13-19 is implemented.
23. A computer program product comprising instructions, It is characterized in that When the computer program product is run on a computer, the computer is caused to perform the method according to any one of claims 1 to 12 or 13 to 19.
24. A chip system, It is characterized in that The chip system includes a processing circuit and a storage medium, wherein the storage medium stores computer program instructions; when the computer program instructions are executed by the processing circuit, the method as described in any one of claims 1-12 or 13-19 is implemented.
Citation Information
Cited By
Ipsec tunnel sharing method, and device and system
WO2025118965A1