Network layer routing encryption communication method and system based on destination address
By adopting multi-agent reinforcement learning and Paillier homomorphic encryption technology in anonymous network, a network layer routing encryption communication method is designed based on the destination address, which solves the problems of high latency and insufficient scalability of the anonymous network, and realizes efficient and flexible anonymous communication.
Patent Information
- Application Number
- CN202510434111.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-08
- Publication Date
- 2025-06-13
AI Technical Summary
Existing anonymous networks have problems of high latency and insufficient scalability during application deployment.
A network layer routing encryption communication method and system based on destination address is proposed. Multiple paths are calculated through multi-agent reinforcement learning technology, and Paillier homomorphic encryption and differential privacy blind network instructions are used to design a dense routing table matching and forwarding mechanism to reduce the delay caused by dense routing matching.
It improves the system throughput and resilience, ensures communication anonymity, and implements normal routing and forwarding functions without directly decrypting routing information, reducing the computing operations of switching nodes.
Smart Images

Figure CN120151077A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security and information communication technologies, and in particular, to a network layer routing encryption communication method and system based on a destination address. Background Art
[0002] With the exposure of more and more privacy leakage incidents, privacy protection technologies in network communication have received increasing attention. Traditional end-to-end encryption can effectively guarantee data privacy. Typical secure communication protocols in the Internet, such as Transport Layer Security (TLS), have been widely deployed, and most Internet traffic uses HTTPS for encryption protection. However, although end-to-end encryption protects data privacy, metadata such as the five-tuple and packet length during the communication process can be easily obtained by attackers, and then traffic analysis attacks can be carried out, and the identity privacy of users cannot be effectively guaranteed.
[0003] To solve this problem, anonymous networks emerged. While protecting data privacy, anonymous networks usually use technologies such as data encryption, traffic obfuscation, and protocol disguise to protect communication metadata. The essence of an anonymous network is an overlay network that provides anonymous communication services, which can provide ordinary users with Internet anonymous access functions to conceal the source and destination of network communication and hide the service mechanism from service providers, effectively protecting identity privacy during the communication process.
[0004] However, there are many problems in the application and deployment process of current anonymous networks. Taking the currently most widely used onion routing as an example, its main defects are as follows: (1) High latency. Even low-latency anonymous networks often receive criticism for their performance. On the one hand, most current anonymous networks are designed as overlay networks, which inevitably bring higher latency compared to network layer protocols; on the other hand, during the packet forwarding process, encryption and decryption operations need to be performed at each node. (2) Insufficient scalability. In anonymous networks, it is usually required that all participants share a globally consistent view of all relays, and at the same time, users are given full control over the relay selection on their paths to resist cognitive attacks and routing capture attacks by attackers. However, as the number of clients grows, the network bandwidth demand grows quadratically, which greatly limits the scalability of anonymous networks. Summary of the Invention
[0005] Aiming at the problems of high latency and insufficient scalability existing in the anonymous networks of the prior art, the present invention proposes a network layer routing encryption communication method and system based on a destination address. The routing encryption communication protocol is involved based on the destination address addressing mechanism, and encryption is carried out from four parts: traffic obfuscation, encryption, blinding, and covert routing, which can solve the problems of high latency and insufficient scalability in encrypted communication.
[0006] In a first aspect, the present invention provides a network layer routing encryption communication method based on a destination address, including:
[0007] Step 1: The SDN controller collects network topology information with SR segment identifiers, calculates multiple paths based on security requirements, selects one path as the communication path, and encodes the communication path into a routing list; wherein the routing list is used to generate a flow table.
[0008] Step 2: The SDN controller assists the two communication parties to generate keys. After the sender encrypts and blinds the key content of the data packet using a two-layer encryption method based on the key, an encrypted data packet is obtained and the encrypted data packet is sent; wherein the key content of the data packet includes communication payload, destination address, and part of the metadata.
[0009] Step 3: The SDN controller issues the flow table according to the types of switching nodes in the communication path. After receiving the flow table, the switching node constructs a confidential routing table locally. After receiving the encrypted data packet, the switching node looks up the table according to the confidential routing table and the SR segment identifier in the encrypted data packet, and forwards the encrypted data packet to the next switching node according to the lookup result. The next switching node re-looks up the table and forwards it until the encrypted data packet is forwarded to the receiver. After receiving the encrypted data packet, the receiver decrypts the encrypted data packet based on the pre-generated key to restore the original data content.
[0010] Wherein, the confidential routing table is a data structure improved based on the B+ tree, used for random query, sequential query, or range query of path information, and includes encrypted routing information and corresponding forwarding rules.
[0011] Further, the calculation of multiple paths based on security requirements specifically includes:
[0012] Using multi-agent reinforcement learning technology, multiple agents, according to the local information observed currently and their respective policy functions, and through sharing part of the information and a graph neural network to achieve cooperation between agents, continuously select the next-hop node, so that each agent cooperates with each other to generate a path with the maximum path entropy, and multiple agents generate multiple paths.
[0013] Further, the single agent selects the next-hop node based on delay and bandwidth.
[0014] Further, Step 2 specifically includes:
[0015] Step 2.1: The SDN controller assists the two communication parties to generate internal keys, session keys, and blinding keys; wherein the internal key is used for the communication entity to maintain and update itself; the session key and the blinding key are generated before each anonymous session starts.
[0016] Step 2.2: Use the session key to perform end-to-end encryption on the communication payload and part of the metadata;
[0017] Step 2.3: Use the blinding key to perform homomorphic encryption and differential privacy on the destination address to complete the blinding of the destination address, the part of the metadata, and the flow table.
[0018] Further, the step 2.2 further includes: during the encryption process, first match the header information of the data packet with the matching keyword. If not hit, discard the encrypted data packet; if hit, perform the encryption operation;
[0019] After the encryption is completed, use the HMAC hash algorithm to perform integrity verification on the encrypted data packet. If the length of the encrypted data packet is less than the length corresponding to the network layer address, padding is performed at the end of the encrypted data packet payload.
[0020] Further, the step 2.3 specifically includes: using the Paillier cryptosystem to encrypt the destination address, with the encryption key being the blinding key, and introducing a random factor at the same time.
[0021] Further, the encrypted state routing table includes leaf nodes and internal nodes. The leaf nodes are used to store all keywords and data structures, and the internal nodes are used to store keywords and pointers; wherein, the keywords include the destination address information encrypted by the blinding key, the pointers are used to point to other nodes to help construct the structure of the encrypted state routing table, and the data structures are used to record the switching node information related to the storage and the communication path; wherein the keywords are arranged in non-decreasing order using the HEComparison operation and are linked by a doubly linked list.
[0022] Further, during the table lookup process, perform a homomorphic subtraction operation on the encrypted data packet header and the header information of the encrypted state routing table, and determine whether a matching routing entry is found according to the operation result.
[0023] Further, after receiving the encrypted data packet, the receiving party decrypts the encrypted data packet based on the key, specifically including: the receiving party uses the session key to decrypt the data packet, and after decryption, removes the differential privacy noise.
[0024] In a second aspect, the present invention provides a network layer routing encryption communication system based on a destination address, including:
[0025] A path establishment module, which is used to collect network topology information with SR segment identifiers, calculate multiple paths based on security requirements, select one path as the communication path, and encode the communication path into a routing list; wherein the routing list is used to generate a flow table.
[0026] An encryption and blinding module, which is used to assist both communication parties to generate keys. After the sender encrypts and blinds the key content of the data packet using a two-layer encryption method based on the key, an encrypted data packet is obtained and the encrypted data packet is sent; wherein the key content of the data packet includes communication payload, destination address, and part of the metadata.
[0027] A covert routing and forwarding module, which is used to issue the flow table according to the type of switching node in the communication path. After receiving the flow table, the switching node constructs a confidential routing table locally. After receiving the encrypted data packet, the switching node looks up the table according to the confidential routing table and the SR segment identifier in the encrypted data packet, and forwards the encrypted data packet to the next switching node according to the lookup result. The next switching node re-looks up the table and forwards it until the encrypted data packet is forwarded to the receiver. After receiving the encrypted data packet, the receiver decrypts the encrypted data packet based on the pre-generated key to restore the original data content.
[0028] Wherein, the confidential routing table is a data structure improved based on the B+ tree, which is used to perform random query, sequential query, or range query of path information, and includes encrypted routing information and corresponding forwarding rules.
[0029] Advantages of the present invention:
[0030] The present invention performs multi-path selection based on multi-agent reinforcement learning, which not only plays the role of traffic confusion and service hiding in the anonymous network, but also improves the throughput and resilience of the system; the present invention encrypts network instructions based on Paillier homomorphic encryption and differential privacy to hide routing information without affecting the routing forwarding of intermediate nodes, and can ensure communication anonymity even if there are malicious nodes on the path. The present invention designs a confidential routing table matching and forwarding mechanism, which can realize normal routing forwarding functions without directly decrypting routing information. And it improves a confidential routing table BSIDTree, and the design of this data structure can support efficient random query, sequential query, range query, and reduce the delay caused by confidential routing matching. Description of the Drawings
[0031] Figure 1 It is a schematic flowchart of a network layer routing encryption communication method based on the destination address provided by an embodiment of the present invention.
[0032] Figure 2Schematic diagram of the communication process of a network layer routing encryption communication method based on the destination address provided by an embodiment of the present invention. Detailed implementation manners
[0033] To make the objectives, technical solutions, and advantages of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0034] As Figure 1 shown, a network layer routing encryption communication system based on the destination address provided by an embodiment of the present invention includes:
[0035] Step 1: The SDN controller collects network topology information with SR segment identifiers, calculates multiple paths based on security requirements, selects one path as the communication path, and encodes the communication path into a routing list. The routing list is used to generate a flow table. Among them, one path can be selected as the communication path according to the shortest path algorithm.
[0036] Specifically, the multi-agent reinforcement learning technology is adopted. Multiple agents, according to the local information observed currently and their respective policy functions, and through sharing partial information and a graph neural network to realize the cooperation between agents, continuously select the next-hop node, so that each agent cooperates with each other to generate a path with the maximum path entropy, and multiple agents generate multiple paths. Moreover, a single agent selects the next-hop node based on delay and bandwidth to generate a path as efficient as possible. The agent in the embodiment of the present invention refers to a switching node.
[0037] In the embodiment of the present invention, the SR segment identifier is uploaded to the controller by the device itself when the SDN controller connects to the network device by uploading device information.
[0038] Step 2: The SDN controller assists the communication parties to generate keys. After the sender encrypts and blinds the key content of the data packet by using a two-layer encryption method based on the keys, an encrypted data packet is obtained and the encrypted data packet is sent; the key content of the data packet includes communication payload, destination address, and part of the metadata. Among them, part of the metadata is the original address information about the communication parties.
[0039] Step 3: The SDN controller issues a flow table according to the types of switching nodes in the communication path. After receiving the flow table, the switching node constructs a confidential routing table locally. After receiving an encrypted data packet, the switching node looks up the table according to the confidential routing table and the SR segment identifier in the encrypted data packet, and forwards the encrypted data packet to the next switching node according to the lookup result. The next switching node re-looks up the table and forwards it until the encrypted data packet is forwarded to the receiver. After receiving the encrypted data packet, the receiver decrypts the encrypted data packet based on the pre-generated key to restore the original data content.
[0040] Among them, the confidential routing table is a data structure improved based on the B+ tree, which is used for random query, sequential query or range query of path information, and can reduce the delay caused by matching in the confidential routing table; the confidential routing table contains encrypted routing information and corresponding forwarding rules.
[0041] The confidential routing table includes leaf nodes and internal nodes. The leaf nodes are used to store all keywords and data structures, and the internal nodes are used to store keywords and pointers; among them, the keywords contain the destination address information encrypted by the blinding key, the pointers are used to point to other nodes to help construct the structure of the confidential routing table, and the data structures are used to record the switching node information related to storage and communication paths; among them, the keywords are arranged in non-decreasing order using the HEComparison operation and are linked by a doubly linked list.
[0042] During the table lookup process, a homomorphic subtraction operation is performed on the encrypted data packet header and the header information of the confidential routing table, and it is judged whether a matching routing entry is found according to the operation result. After receiving the encrypted data packet, the receiver decrypts the data packet using the session key, and removes the differential privacy noise after decryption.
[0043] Specifically, a homomorphic subtraction operation is performed on the encrypted data packet header and the header information of the confidential routing table to obtain the size relationship between the two, and thus it is judged whether the routing entry is hit. According to the principle of differential privacy, introducing a random factor ensures the freshness of the ciphertext but does not affect the correctness of the matching result. And since the switching node decrypts the difference between the two, even if the switching node obtains the key, it cannot obtain the plaintext routing information, which can prevent the malicious behavior of traitor nodes.
[0044] Such as Figure 2As shown in the figure, it shows a schematic diagram of the communication process of the method provided by the embodiments of the present invention. The method provided by the embodiments of the present invention first performs definable symmetric encryption on the communication payload and metadata, and can flexibly select the encryption range; in order to protect the network layer header segment list information from being routed and forwarded, the present invention proposes to use the methods of homomorphic encryption and differential privacy to blind it, ensuring the "usable but invisible" of network instructions; finally, in order to prevent anonymous sessions from being connected by attackers, the present invention proposes to use multi-path routing for traffic confusion and solve the path based on the multi-agent graph reinforcement learning algorithm method. The present invention designs a ciphertext state routing table matching and forwarding mechanism, which can realize normal routing and forwarding functions without directly decrypting routing information. And it improves a ciphertext state routing table BSID Tree. The design of this data structure can support efficient random query, sequential query, and range query, reducing the delay caused by ciphertext state routing matching. Compared with the traditional routing encryption communication system, the present invention reduces the computational operations required by the switching nodes while taking into account anonymity, effectively improving flexibility and scalability.
[0045] On the basis of the above embodiments, a specific implementation method for step 2 is further provided, including:
[0046] Step 2.1: The SDN controller assists the communication parties to generate internal keys, session keys, and blinding keys; where the internal keys are used for the communication entity to maintain and update itself; the session keys and blinding keys are generated before each anonymous session. When the key life cycle is exceeded, the SDN controller will trigger the key update mechanism to regenerate the session keys and blinding keys.
[0047] Step 2.2: Use the session key to perform end-to-end encryption on the communication payload and part of the metadata.
[0048] Furthermore, during the encryption process, first match the header information of the data packet with the matching keyword. If it fails to match, discard the encrypted data packet; if it matches, perform the encryption operation. After the encryption is completed, use the HMAC hash algorithm to perform integrity verification on the encrypted data packet. If the length of the encrypted data packet is less than the length corresponding to the network layer address, padding is performed at the end of the encrypted data packet payload.
[0049] Specifically, the first layer of encryption is to protect the communication payload by the communication parties using the end-to-end encryption (AES algorithm) method, and the key uses the session key, and only the communication parties can decrypt it.
[0050] Step 2.3: Use the blinding key to perform homomorphic encryption and differential privacy on the destination address to complete the blinding of the destination address, part of the metadata, and the flow table.
[0051] Specifically, the second - layer encryption is performed by the SDN controller using the Paillier cryptosystem and differential privacy to blind the path information. Specifically, the Paillier cryptosystem is used to encrypt the destination address, and the encryption key is the blinding key. At the same time, a random factor is introduced to prevent adversaries from replaying.
[0052] Furthermore, for the flow tables on the data plane, the same method is also used for blinding. It can ensure that the path information is invisible to adversaries, and using the homomorphism of homomorphic encryption, the essential attributes of the path information can be restored under the ciphertext condition.
[0053] The forwarding and matching logic of the data plane can be programmed according to network programming languages and distributed to devices to achieve efficient orchestration of paths, services, and applications, improving the flexibility and scalability of anonymous communication.
[0054] The embodiment of the present invention also provides a network - layer routing encryption communication system based on the destination address, including:
[0055] A path - establishment module, configured to collect network topology information with SR segment identifiers, calculate multiple paths based on security requirements, select one path as the communication path, and encode the communication path into a routing list; where the routing list is used to generate flow tables
[0056] An encryption and blinding module, configured to assist the communication parties in generating keys. After the sender encrypts and blinds the key content of the data packet using a two - layer encryption method based on the key, an encrypted data packet is obtained and the encrypted data packet is sent; where the key content of the data packet includes communication payloads, destination addresses, and some metadata.
[0057] A covert routing module, configured to distribute flow tables according to the types of switching nodes in the communication path. After receiving the flow tables, the switching nodes locally construct a cipher - state routing table. After receiving the encrypted data packet, the switching nodes look up the table according to the cipher - state routing table and the SR segment identifier in the encrypted data packet, and forward the encrypted data packet to the next switching node according to the lookup result. The next switching node re - looks up the table and forwards it until the encrypted data packet is forwarded to the receiver. After receiving the encrypted data packet, the receiver decrypts the encrypted data packet based on the pre - generated key to restore the original data content.
[0058] Among them, the cipher - state routing table is a data structure improved based on the B + tree, used for random query, sequential query, or range query of path information.
[0059] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the various embodiments of the present invention.
Claims
1. A network layer routing encryption communication method based on destination address, characterized in that: include: Step 1: The SDN controller collects network topology information with SR segment identifiers, calculates multiple paths based on security requirements, selects one path as a communication path, and encodes the communication path into a routing list; The routing list is used to generate a flow table; Step 2: The SDN controller assists the communicating parties to generate a key. The sender encrypts and blinds the key content of the data packet using a two-layer encryption method based on the key, obtains an encrypted data packet, and sends the encrypted data packet. The key content of the data packet includes the communication payload, the destination address, and some metadata. Step 3: The SDN controller sends the flow table according to the type of switching node in the communication path. After receiving the flow table, the switching node constructs a secret routing table locally. After receiving the encrypted data packet, the switching node performs a table lookup according to the secret routing table and the SR segment identifier in the encrypted data packet, and forwards the encrypted data packet to the next switching node according to the table lookup result. The next switching node performs table lookup and forwarding again until the encrypted data packet is forwarded to the receiver. After receiving the encrypted data packet, the receiver decrypts the encrypted data packet based on the pre-generated key to restore the original data content. The encrypted routing table is a data structure based on an improved B+ tree, which is used for performing random query, sequential query or range query of path information, and contains encrypted routing information and corresponding forwarding rules.
2. According to the network layer routing encryption communication method based on the destination address according to claim 1, it is characterized in that: The calculating of multiple paths based on security requirements specifically includes: Using multi-agent reinforcement learning technology, multiple agents, based on the currently observed local information and their respective strategy functions, realize collaboration between agents by sharing partial information with graph neural networks, continuously select the next hop node, and enable each agent to collaborate with each other to generate a path with the largest path entropy. Multiple agents generate multiple paths.
3. A network layer routing encryption communication method based on destination address according to claim 2, characterized in that: The single agent selects the next hop node based on latency and bandwidth.
4. According to the network layer routing encryption communication method based on the destination address according to claim 1, it is characterized in that: The step 2 specifically includes: Step 2.1: The SDN controller assists both communicating parties in generating internal keys, session keys and blinding keys; wherein the internal keys are used for the communication entities to maintain and update themselves; the session keys and the blinding keys are generated before each anonymous session starts; Step 2.2: Using the session key to perform end-to-end encryption on the communication payload and part of the metadata; Step 2.3: Use the blinding key to perform homomorphic encryption and differential privacy on the destination address to complete the blinding of the destination address, the partial metadata and the flow table.
5. A network layer routing encryption communication method based on destination address according to claim 4, characterized in that: The step 2.2 also includes: in the encryption process, firstly matching the header information of the data packet with the matching keyword, if there is no match, discarding the encrypted data packet; if there is a match, performing the encryption operation; After encryption is completed, the HMAC hash algorithm is used to perform integrity check on the encrypted data packet. If the length of the encrypted data packet is less than the length corresponding to the network layer address, padding is performed at the end of the encrypted data packet payload.
6. A network layer routing encryption communication method based on destination address according to claim 4, characterized in that: The step 2.3 specifically includes: encrypting the destination address using the Paillier system, the encryption key is a blinded key, and a random factor is introduced.
7. A network layer routing encryption communication method based on destination address according to claim 1, characterized in that: The secret routing table includes leaf nodes and internal nodes, wherein the leaf nodes are used to store all keywords and data structures, and the internal nodes are used to store keywords and pointers; wherein the keywords include destination address information encrypted by a blinding key, the pointers are used to point to other nodes to help construct the structure of the secret routing table, and the data structure is used to record and store switching node information related to the communication path; wherein the keywords are arranged in non-descending order using a HEComparison operation and are linked through a bidirectional linked list.
8. A network layer routing encryption communication method based on destination address according to claim 1, characterized in that: During the table lookup process, a homomorphic subtraction operation is performed on the encrypted data packet header and the header information of the encrypted routing table, and it is determined whether a matching routing entry is found based on the operation result.
9. A network layer routing encryption communication method based on destination address according to claim 1, characterized in that: After receiving the encrypted data packet, the receiver decrypts the encrypted data packet based on the key, specifically including: the receiver uses the session key to decrypt the data packet, and removes differential privacy noise after decryption.
10. A network layer routing encryption communication system based on destination address, characterized in that: include: A path establishment module, used to collect network topology information with SR segment identifiers, calculate multiple paths based on security requirements, select a path as a communication path, and encode the communication path into a routing list; The routing list is used to generate a flow table; The encryption and blinding module is used to assist the communicating parties in generating a key. The sender encrypts and blinds the key content of the data packet using a two-layer encryption method based on the key, obtains an encrypted data packet, and sends the encrypted data packet; wherein the key content of the data packet includes the communication payload, the destination address, and some metadata; A concealed routing and forwarding module, used for issuing the flow table according to the type of switching node in the communication path, the switching node constructing a secret state routing table locally after receiving the flow table, the switching node performing a table lookup according to the secret state routing table and the SR segment identifier in the encrypted data packet after receiving the encrypted data packet, forwarding the encrypted data packet to the next switching node according to the table lookup result, the next switching node re-performs table lookup and forwarding until the encrypted data packet is forwarded to the receiving party, and the receiving party decrypts the encrypted data packet based on a pre-generated key after receiving the encrypted data packet to restore the original data content; The encrypted routing table is a data structure based on an improved B+ tree, which is used for performing random query, sequential query or range query of path information, and contains encrypted routing information and corresponding forwarding rules.