Communication method and device
By using QUIC connection in distributed gateway networking to provide encryption protection between DHCP relay and DHCP server, the problems of complex encryption configuration and high performance consumption in the prior art are solved, and the effect of simplifying configuration and reducing operation and maintenance costs is achieved.
Patent Information
- Application Number
- CN202510447227.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-10
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2045-04-10
AI Technical Summary
In the existing distributed gateway networking, the packet encryption protection method between DHCP relay and DHCP server is complex, the configuration is difficult, and the performance consumption is high, and it needs to be reconfigured when the IP address of the network device changes, increasing the difficulty of operation and maintenance.
By introducing a QUIC connection into the distributed network, a QUIC connection is established between the DHCP management relay and the DHCP server, and each DHCP relay uses this connection to send an encrypted message to the DHCP server.
It simplifies the encryption configuration between DHCP relay and DHCP server, reduces operation and maintenance costs, avoids messages being listened to and tampered, and reduces the performance consumption of IPSec encryption.
Smart Images

Figure CN120151086A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technologies, and in particular, to a communication method and apparatus. Background Art
[0002] With the continuous expansion of the network scale and the increasing complexity of service requirements, the centralized gateway architecture has gradually exposed many problems, such as performance bottlenecks, insufficient scalability, single point of failure, and complex management. Thus, it has also promoted the development of distributed gateway networking.
[0003] Ethernet Virtual Private Network (EVPN) Virtual Extensible Local Area Network (VXLAN) is a layer 2 VPN technology. Its control plane uses MP-BGP to advertise EVPN routing information, and the data plane uses VXLAN encapsulation to forward packets. EVPN VXLAN identifies the VXLAN network through the VXLAN ID and maintains an independent MAC address table for each VXLAN network to achieve layer 2 intercommunication within the same VXLAN network and layer 2 isolation between different VXLAN networks. By deploying EVPN VXLAN gateways in the network, layer 3 intercommunication between different VXLAN networks and layer 3 communication between the VXLAN network and the external network can also be achieved.
[0004] EVPN VXLAN gateways include centralized gateways and distributed gateways. A centralized gateway means that there is one VTEP device in the network as the EVPN gateway, and all traffic between different VXLANs and traffic from VXLAN to access the external network are processed by the centralized gateway. A distributed gateway means that multiple VTEP devices act as EVPN gateways to perform layer 3 forwarding of local site traffic, relieving the pressure on the gateway. In a distributed gateway network, usually, a border gateway device also needs to be deployed for communication with the external network.
[0005] Dynamic Host Configuration Protocol (DHCP) adopts the client / server mode, and the server dynamically assigns network configuration parameters such as IP addresses to network devices. The Dynamic Host Configuration Protocol for IPv6 (DHCPv6) is designed for the IPv6 addressing scheme and is used to assign IPv6 prefixes, IPv6 addresses, and other network configuration parameters to hosts.
[0006] When the server and the client are not within the same link range, they cannot communicate directly, and DHCP Relay is needed to forward messages. Deploying DHCP Relay can avoid deploying DHCP servers in each link range, saving costs and facilitating centralized management.
[0007] Currently, network devices within a distributed gateway network can act as DHCP Relays. As Figure 1 shown, Figure 1 is a network diagram of an existing distributed gateway network supporting DHCP Relay. In Figure 1 , leaf (leaf1), leaf2, and leaf3 can all act as DHCP Relays, and the online message of the DHCP client can be processed by any one of the leaves.
[0008] At the same time, the distributed gateway network also supports the encryption requirements of DHCP Relays for DHCP messages. The existing RFC8213 protocol stipulates the optional requirements for implementing IPsec authentication and encryption between the relay and the server, and recommends that operators use IPsec to encrypt and protect the interaction messages between the relay and the server. However, the configuration of IPSec is relatively complex and requires defining content such as Security Policy, Security Association (abbreviation: SA), encryption algorithm, and authentication mechanism. Especially in a large network, configuring and managing multiple IPSec tunnels will increase the operation and maintenance difficulty; secondly, if the IP address of the network device changes, it is necessary to reconfigure or negotiate SA; finally, the IPSec encryption overhead is large, the performance consumption is large, resulting in a large delay. Summary of the Invention
[0009] In view of this, the present application provides a communication method and device, which provide a better protection method for message encryption between a DHCP Relay and a DHCP server, and between DHCP Relays in a distributed gateway network.
[0010] In a first aspect, the present application provides a communication method, which is applied to a first DHCP Relay within a distributed network. The first DHCP Relay is any DHCP Relay within the distributed network, and a QUIC connection is established between the DHCP management relay and the DHCP server in the distributed network. The method includes:
[0011] Receiving a first DHCP protocol message sent by a DHCP client;
[0012] Send a first QUIC packet to the DHCP server through the QUIC connection. The first QUIC packet includes a stream identifier, and the first QUIC packet is obtained by encrypting the first DHCP protocol packet with the key corresponding to the QUIC connection.
[0013] If a second QUIC packet including the stream identifier sent by the DHCP server is received and the second DHCP protocol packet generated by the DHCP server is encapsulated in the second QUIC packet, decrypt the second QUIC packet according to the key, and verify the decrypted second QUIC packet.
[0014] If the verification passes and there is a temporary entry corresponding to the DHCP client, generate a binding entry corresponding to the DHCP client according to the temporary entry, and send the second DHCP protocol packet to the DHCP client.
[0015] Wherein, the stream identifier is assigned by the DHCP management relay, and the stream identifiers assigned by each DHCP relay in the distributed network are different.
[0016] In a second aspect, the present application provides a communication method applied to a DHCP server. The DHCP server has established a QUIC connection with a DHCP management relay in a distributed network. The distributed network further includes a first DHCP relay, and the first DHCP relay is any DHCP relay in the distributed network. The method includes:
[0017] Receive a first QUIC packet sent by the first DHCP relay through the QUIC connection. The first QUIC packet includes a stream identifier.
[0018] If the first DHCP protocol packet is encapsulated in the first QUIC packet, decrypt the first QUIC packet according to the key corresponding to the QUIC connection, and verify the decrypted first QUIC packet.
[0019] If the verification passes and the first DHCP protocol packet is a first type of packet, generate a second QUIC packet. The second QUIC packet includes the stream identifier and a second DHCP protocol packet, and the second DHCP protocol packet is a response packet of the first DHCP protocol packet.
[0020] Send the second QUIC packet to the first DHCP relay through the QUIC connection.
[0021] Wherein, the stream identifier is assigned by the DHCP management relay, and the stream identifiers assigned by each DHCP relay in the distributed network are different.
[0022] In a third aspect, the present application provides a communication device, which is applied to a first DHCP relay within a distributed network. The first DHCP relay is any DHCP relay within the distributed network. A DHCP management relay in the distributed network establishes a QUIC connection with a DHCP server. The device includes:
[0023] A receiving unit, configured to receive a first DHCP protocol message sent by a DHCP client;
[0024] A sending unit, configured to send a first QUIC message to the DHCP server through the QUIC connection. The first QUIC message includes a stream identifier, and the first QUIC message is obtained by encrypting the first DHCP protocol message according to a key corresponding to the QUIC connection;
[0025] A verification unit, configured to, if the receiving unit receives a second QUIC message including the stream identifier sent by the DHCP server and a second DHCP protocol message generated by the DHCP server is encapsulated in the second QUIC message, decrypt the second QUIC message according to the key, and verify the decrypted second QUIC message;
[0026] A generating unit, configured to, if the verification is passed and there is a temporary entry corresponding to the DHCP client, generate a binding entry corresponding to the DHCP client according to the temporary entry;
[0027] The sending unit is further configured to send the second DHCP protocol message to the DHCP client;
[0028] Wherein, the stream identifier is assigned by the DHCP management relay, and the stream identifiers assigned by each DHCP relay within the distributed network are different from each other.
[0029] In a fourth aspect, the present application provides a communication device, which is applied to a DHCP server. The DHCP server has established a QUIC connection with a DHCP management relay in a distributed network. The distributed network further includes a first DHCP relay, and the first DHCP relay is any DHCP relay in the distributed network. The device includes:
[0030] A receiving unit, configured to receive a first QUIC message sent by the first DHCP relay through the QUIC connection. The first QUIC message includes a stream identifier;
[0031] A verification unit, configured to, if a first DHCP protocol packet is encapsulated in the first QUIC packet, decrypt the first QUIC packet according to the key corresponding to the QUIC connection, and verify the decrypted first QUIC packet;
[0032] A generation unit, configured to, if the verification is passed and the first DHCP protocol packet is a first type of packet, generate a second QUIC packet, where the second QUIC packet includes the flow identifier and a second DHCP protocol packet, and the second DHCP protocol packet is a response packet of the first DHCP protocol packet;
[0033] A sending unit, configured to send the second QUIC packet to the first DHCP relay through the QUIC connection;
[0034] Wherein, the flow identifier is allocated by the DHCP management relay, and the flow identifiers allocated by each DHCP relay in the distributed network are different from each other.
[0035] In a fifth aspect, the present application provides a network device, including a processor and a machine-readable storage medium, where the machine-readable storage medium stores machine-executable instructions that can be executed by the processor, and the processor is caused by the machine-executable instructions to execute the method provided in the first aspect of the present application.
[0036] In a sixth aspect, the present application provides a network device, including a processor and a machine-readable storage medium, where the machine-readable storage medium stores machine-executable instructions that can be executed by the processor, and the processor is caused by the machine-executable instructions to execute the method provided in the second aspect of the present application.
[0037] Therefore, by applying the communication method and device provided in the present application, the first DHCP relay receives a first DHCP protocol packet sent by a DHCP client; through a QUIC connection, the first DHCP relay sends a first QUIC packet to a DHCP server, where the first QUIC packet includes a flow identifier, and the first QUIC packet is obtained by encrypting the first DHCP protocol packet according to the key corresponding to the QUIC connection; if a second QUIC packet including the flow identifier sent by the DHCP server and a second DHCP protocol packet generated by the DHCP server is encapsulated in the second QUIC packet, the first DHCP relay decrypts the second QUIC packet according to the key, and verifies the decrypted second QUIC packet; if the verification is passed and there is a temporary entry corresponding to the DHCP client, the first DHCP relay generates a binding entry corresponding to the DHCP client according to the temporary entry, and sends a second DHCP protocol packet to the DHCP client; wherein, the flow identifier is allocated by the DHCP management relay, and the flow identifiers allocated by each DHCP relay in the distributed network are different from each other.
[0038] Thus, in a distributed network, a QUIC connection is established between the DHCP management relay and the DHCP server. Each DHCP relay can use this QUIC connection to send encrypted packets to the DHCP server. This avoids packet eavesdropping and tampering, reduces the configuration complexity of IPSec encryption, enables multiplexing for each DHCP relay using different flow identifiers to avoid congestion, and results in lower hardware and operation costs. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] Figure 1 FIG. is a schematic diagram of a network for an existing distributed gateway supporting DHCP relay;
[0040] Figure 2 FIG. is a flowchart of a communication method provided by an embodiment of the present application;
[0041] Figure 3 FIG. is a flowchart of another communication method provided by an embodiment of the present application;
[0042] Figure 4 FIG. is a structural diagram of a communication device provided by an embodiment of the present application;
[0043] Figure 5 FIG. is a structural diagram of another communication device provided by an embodiment of the present application;
[0044] Figure 6 FIG. is a hardware structure of a network device provided by an embodiment of the present application. DETAILED DESCRIPTION
[0045] Exemplary embodiments will be described in detail herein, and examples thereof are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application. Instead, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.
[0046] The terms used in the present application are for the purpose of describing specific embodiments only and are not intended to limit the present application. The singular forms "a", "the", and "said" used in the present application and the appended claims are also intended to include the plural forms unless the context clearly dictates otherwise. It should also be understood that the term "and / or" as used herein refers to and encompasses any and all possible combinations of one or more of the associated listed items.
[0047] It should be understood that although the terms first, second, third, etc. may be used in this application to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from each other. For example, without departing from the scope of this application, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, the word "if" as used herein may be interpreted as "when" or "while" or "in response to a determination".
[0048] The communication method provided by the embodiments of the present application will be described in detail below. Refer to Figure 2 , Figure 2 which is a flowchart of a communication method provided by an embodiment of the present application. This method is applied to a first DHCP relay, and the first DHCP relay is located between a DHCP client and a DHCP server. The communication method provided by the embodiments of the present application may include the following steps.
[0049] Step 210: Receive a first DHCP protocol packet sent by the DHCP client;
[0050] Specifically, the first DHCP relay receives the first DHCP protocol packet. The first DHCP protocol packet is sent by the DHCP client.
[0051] In the embodiments of the present application, the number of first DHCP relays is multiple, forming a distributed network. The DHCP client accesses any one of the first DHCP relays, and each first DHCP relay is connected to the DHCP server through a spine. For the DHCP server, all the first DHCP relays are regarded as one device.
[0052] As Figure 1 shown. leaf1, leaf2, and leaf3 are all first DHCP relays and form a distributed network. DHCP client 1 accesses leaf1, and DHCP client 2 accesses leaf3. Each leaf is connected to the DHCP server through a spine.
[0053] In the embodiments of the present application, the DHCP client may specifically be a client of the Dynamic Host Configuration Protocol for IPv4 (abbreviation: DHCPv4) that supports IPv4 or a DHCPv6 client.
[0054] When the DHCP client is a DHCPv4 client, the first DHCP relay is specifically a DHCPv4 relay, and the DHCP server is specifically a DHCPv4 server; when the DHCP client is a DHCPv6 client, the first DHCP relay is specifically a DHCPv6 relay, and the DHCP server is specifically a DHCPv6 server.
[0055] The communication schemes described in the embodiments of the present application below are applicable to both DHCPv4 (client, relay, server) and DHCPv6 (client, relay, server), and are hereinafter simply referred to as DHCP for convenience of description.
[0056] In the embodiments of the present application, the first DHCP relay in a distributed network is taken as an example for illustration. The first DHCP relay receives the first DHCP protocol packet sent by the DHCP client.
[0057] In the embodiments of the present application, multiple first DHCP relays within the distributed network will elect a DHCP management relay. The DHCP management relay can establish, maintain, and manage a connection based on the modern transport layer protocol (English: Quick UDP Internet Connections, abbreviated as: QUIC) of UDP with the DHCP server. Among them, when establishing a QUIC connection between the DHCP management relay and the DHCP server, the DHCP management relay acts as a QUIC client, and the DHCP server acts as a QUIC server. After the DHCP management relay completes the QUIC function configuration locally, it attempts to establish, maintain, and manage a QUIC connection with the DHCP server.
[0058] It can be understood that during the process of establishing a QUIC connection between the two end devices, in accordance with the provisions of the existing QUIC protocol, content such as verifying certificates, negotiating encryption algorithms, versions, keys, etc. will not be repeated here. In the embodiments of the present application, multiple first DHCP relays within the distributed network will elect a DHCP management relay, and the DHCP management relay will establish a QUIC connection with the DHCP server. Since each first DHCP relay is configured with the same IP address, each first DHCP relay can reuse this QUIC connection.
[0059] In the subsequent embodiments, the process of electing the DHCP management relay will be described and will not be repeated here.
[0060] It can be understood that the first DHCP relay in this step can be a DHCP management relay or a non-DHCP management relay.
[0061] Step 220: Send a first QUIC packet to the DHCP server through the QUIC connection. The first QUIC packet includes a stream identifier and is obtained by encrypting the first DHCP protocol packet with the key corresponding to the QUIC connection.
[0062] Specifically, according to the description in step 210, after receiving the first DHCP protocol packet, the first DHCP relay continues to forward it to the next-hop device.
[0063] In the embodiment of the present application, the next-hop device of the first DHCP relay is the DHCP server. As known from the foregoing, a QUIC connection has been established between the DHCP management relay and the DHCP server in accordance with the existing QUIC protocol regulations, and any first DHCP relay can reuse this QUIC connection. Therefore, in this step, whether the first DHCP relay is a DHCP management relay or a non-DHCP management relay, when sending a packet to the DHCP server, it can be sent through the QUIC connection.
[0064] Based on the first DHCP protocol packet, the first DHCP relay generates a first QUIC packet, which is obtained by encrypting the first DHCP protocol packet with the key corresponding to the QUIC connection by the first DHCP relay.
[0065] It can be understood that the first DHCP relay can first generate a new DHCP protocol packet according to the first DHCP protocol packet (for example, it can be called the third DHCP protocol packet, where "third" is used here to distinguish it from other DHCP protocol packets, and it can also be "second", "fourth"). The third DHCP protocol packet can be specifically obtained by the first DHCP relay processing according to the existing DHCP protocol (for example, adding an option field (option82) to the first DHCP protocol packet, etc.). Since the process of the first DHCP relay generating the third DHCP protocol packet is the same as the existing process, in the embodiment of the present application, this is not described in detail and is still referred to as the first DHCP protocol packet.
[0066] According to the existing QUIC protocol regulations, the first DHCP relay generates a first QUIC packet, which includes a stream identifier and the first DHCP protocol packet. After obtaining the first QUIC packet, the first DHCP relay sends the first QUIC packet to the DHCP server through the QUIC connection. It can be understood that in practical applications, QUIC packets are usually defaulted to encrypted packets.
[0067] The following briefly describes the QUIC packet.
[0068] A QUIC packet consists of two parts: a common header and a payload. The common header is further divided into a Long Header and a Short Header.
[0069] The Long Header is used in the connection establishment phase (such as initial handshake, version negotiation) and includes the following fields: Indicator bit field: Fixed at 1, indicating it is a Long Header. The length of the indicator bit is 1 bit; Type field: Represents the type of the packet. The length of the Type field is 4 bits; Version number (Ver) field: Represents the QUIC protocol version. The length of the Ver field is 4 bytes; Destination CID Length (DCID Len) field: Represents the length of the Destination Connection ID (DCID). The length of the DCID Len field is 1 byte; DCID field: Represents the receiver. The length of the DCID field is variable; Source CID Length (SCID Len) field: Represents the length of the Source Connection ID (SCID). The length of the SCID Len field is 1 byte; SCID field: Represents the sender. The length of the SCID field is variable; Packet Number field: Used for packet sequencing and loss detection. The length of the Packet Number field is variable, within the range of 1 to 4 bytes; Payload length field: Represents the length of the payload part. The length of the payload length field is 2 bytes.
[0070] The Short Header is used for regular data transmission after connection establishment and has a more compact format, including the following fields: Indicator bit field: Fixed value of 0, indicating it is a Short Header. The length of the indicator bit is 1 bit; Reserved bit field: Reserved for future use. The length of the reserved bit is 7 bits; DCID field: Represents the receiver. The length of the DCID field is variable; Packet Number field: Used for packet sequencing and loss detection. The length of the Packet Number field is variable, within the range of 1 to 4 bytes.
[0071] The payload part of a QUIC packet can contain one or more frames, and each frame represents a data transmission or control operation. The general structure of a frame includes two parts: type and frame data. Among them, the type represents the type of the frame and has a length of 1 byte; depending on the frame type, the structure of the frame data is different. Frame types include STREAM, ACK, CRYPTO, PADDING, and CONNECTION_CLOSE.
[0072] In the embodiments of the present application, the frame data includes a Stream ID field and a Stream Data field. The Stream ID field is used to carry the stream ID, and the Stream Data field is used to carry the actual application data, such as the first DHCP protocol packet.
[0073] In the QUIC protocol, the stream ID is self - allocated and managed by the end that initiates the stream (QUIC client or QUIC server). The stream ID is a unique identifier used in the QUIC protocol to identify different data streams; it is allocated sequentially by the end that initiates the stream, usually incrementally; it follows the parity rule, where the streams initiated by the QUIC client use even stream IDs, and the streams initiated by the QUIC server use odd stream IDs; the lowest two bits of the stream ID of a bidirectional stream are 0b00 or 0b01, and the lowest two bits of the stream ID of a unidirectional stream are 0b10 or 0b11.
[0074] For example, the QUIC client initiates a bidirectional stream and allocates a stream ID of 0 (even); the QUIC server initiates a unidirectional stream and allocates a stream ID of 1 (odd); the QUIC client then initiates another unidirectional stream and allocates a stream ID of 2 (even).
[0075] In the embodiments of the present application, the stream ID is allocated by the DHCP management relay so that the stream ID of each first DHCP relay is unique and corresponds to the Router ID of each first DHCP relay.
[0076] The frame data also includes an Offset field and a Length field. Among them, the Offset field represents the offset of the current data in the stream; the Length field represents the length of the subsequent stream data.
[0077] In the embodiments of the present application, the first DHCP relay fills the allocated stream ID in the Stream ID field and fills the first DHCP protocol packet in the Stream Data field. Then, the load part is encrypted through the key corresponding to the QUIC connection to obtain the first QUIC packet.
[0078] It should be noted that after the first DHCP relay obtains the first QUIC packet, a UDP header is encapsulated outside the first QUIC packet. The port number included in the UDP header is set to 50003 or 50004. Among them, 50003 represents DHCPv4 over QUIC, and 50004 represents DHCPv6 over QUIC.
[0079] Since the DHCP management relay in the distributed network has established a QUIC connection with the DHCP server, the QUIC connection can be reused by each DHCP relay in the distributed network. It is understandable that before the DHCP relay uses the QUIC connection, the DHCP management relay synchronizes the attribute information of the QUIC connection to other DHCP relays in the distributed network through the Border Gateway Protocol (BGP) Ethernet Virtual Private Network (EVPN) message, so that other DHCP relays can obtain the attribute information of the QUIC connection, including the QUIC session identifier, QUIC connection address, QUIC connection port, QUIC session key, QUIC session transmission parameters, and the correspondence between all router identifiers and flow identifiers in the network.
[0080] In subsequent embodiments, the attribute information of the DHCP management relay synchronization QUIC connection will be described in detail and will not be repeated here.
[0081] It is understandable that after receiving the first QUIC message, the DHCP server can first identify whether the first DHCP protocol message is encapsulated in the first QUIC message. If the first DHCP protocol message is not encapsulated in the first QUIC message, the DHCP server discards the first QUIC message. If the first DHCP protocol message is encapsulated in the first QUIC message, the first QUIC message is first decrypted using the key corresponding to the QUIC connection, and then the decrypted first QUIC message is verified. If the verification passes, the type of the first DHCP protocol message is identified. If it is a first type message, the protocol processing is performed in accordance with the provisions of DHCPv4 / DHCPv6, and the second QUIC message is fed back, and the second QUIC message is sent through the QUIC connection. If the verification fails, the first QUIC message is discarded.
[0082] When the DHCP server processes the first QUIC message, the DHCP server also obtains the flow identifier from the first QUIC message. When the DHCP server generates the second QUIC message, it continues to fill the flow identifier obtained from the first QUIC message into the flow identifier field included in the second QUIC message. The structure of the second QUIC message is the same as that of the first QUIC message, and will not be repeated here. For the specific processing process of the DHCP server on the first QUIC message and the second QUIC message, please refer to the description of the subsequent embodiments.
[0083] Step 230: If a second QUIC packet including the stream identifier sent by the DHCP server is received and the DHCP protocol packet generated by the DHCP server is encapsulated in the second QUIC packet, decrypt the second QUIC packet according to the key, and verify the decrypted second QUIC packet.
[0084] Specifically, according to the description in step 220, if the first DHCP relay receives a second QUIC packet including a stream identifier sent by the DHCP server, the first DHCP relay first identifies whether the second DHCP protocol packet generated by the DHCP server is encapsulated in the second QUIC packet.
[0085] Optionally, if the second DHCP protocol packet is not encapsulated in the second QUIC packet, the first DHCP relay discards the second QUIC packet.
[0086] If the second DHCP protocol packet is encapsulated in the second QUIC packet, the first DHCP relay first decrypts the second QUIC packet according to the key. Then, the first DHCP relay verifies the decrypted second QUIC packet.
[0087] It can be understood that the first DHCP relay can verify the second QUIC packet according to the existing QUIC protocol regulations. The verification process is briefly described below.
[0088] 1): Parse the packet header
[0089] Extract the unencrypted fields (such as connection ID, packet number, etc.) from the QUIC packet; determine the type of the QUIC packet (such as Initial, Handshake, Short Header, etc.).
[0090] 2): Determine the encryption key
[0091] The QUIC protocol stipulates that different types of packets are encrypted using different encryption keys: Initial packets are encrypted using the initial key; Handshake packets are encrypted using the handshake key; 1-RTT packets are encrypted using the application data key. The corresponding key can be selected according to the packet type.
[0092] 3): Decrypt the payload
[0093] Decrypt the payload using the selected key and encryption algorithm (e.g., AES-GCM or ChaCha20-Poly1305). The decryption process includes: extracting the ciphertext and the authentication tag; decrypting the ciphertext using the key and the initial vector (IV) to obtain the plaintext.
[0094] 4): Verify integrity
[0095] Perform integrity verification on the decrypted plaintext using the authentication tag. The verification process includes: recalculating the authentication tag using the key and the initial vector (IV). Compare the calculated authentication tag with the authentication tag in the QUIC packet. If they are the same, determine that the QUIC packet is complete and has not been tampered with; otherwise, discard the QUIC packet.
[0096] 5): Process the decrypted data
[0097] If decryption and verification are successful, upload the decrypted data to the upper-layer protocol (e.g., HTTP / 3) for processing. If decryption or verification fails, record the error and discard the QUIC packet.
[0098] According to the above verification process, the first DHCP relay verifies the decrypted second QUIC packet.
[0099] Optionally, if the verification fails, the first DHCP relay discards the second QUIC packet; if the verification passes, the first DHCP relay executes step 140.
[0100] Step 240: If the verification passes and there is a corresponding temporary entry for the DHCP client, generate a binding entry corresponding to the DHCP client according to the temporary entry, and send the second DHCP protocol packet to the DHCP client.
[0101] Specifically, according to the description of step 230, if the verification of the decrypted second QUIC packet passes, the first DHCP relay obtains the second DHCP protocol packet from the payload part included in the decrypted second QUIC packet, and obtains the media access control (abbreviation: MAC) address of the DHCP client from the second DHCP protocol packet. The second DHCP protocol packet is the feedback from the DHCP server according to the first DHCP protocol packet.
[0102] According to the MAC address, the first DHCP relay looks up in the locally stored temporary table to check if there is a temporary table entry that matches the MAC address. If there is a temporary table entry that matches the MAC address, the first DHCP relay determines the first DHCP protocol packet originally processed by itself for the DHCP client. The first DHCP relay generates a binding table entry corresponding to the DHCP client according to the temporary table entry.
[0103] Meanwhile, the first DHCP relay also sends a second DHCP protocol packet to the DHCP client.
[0104] Optionally, in the embodiment of the present application, if the verification of the decrypted second QUIC packet passes, but there is no temporary table entry that matches the MAC address, the first DHCP relay determines that the first DHCP protocol packet originally sent by the DHCP client was not processed by itself. The first DHCP relay can obtain the flow identifier from the second QUIC packet. According to the flow identifier, the first DHCP relay determines the fourth DHCP relay (here "fourth" is used to distinguish from other DHCP relays, and it can also be "second" or "third") that processes the decrypted second QUIC packet; the first DHCP relay sends the decrypted second QUIC packet to the fourth DHCP relay.
[0105] It can be understood that after receiving the decrypted second QUIC packet, the fourth DHCP relay does not need to perform verification processing on the decrypted second QUIC packet anymore. The fourth DHCP relay can look up in the locally stored temporary table to check if there is a temporary table entry that matches the MAC address. If there is a temporary table entry that matches the MAC address, the fourth DHCP relay determines the first DHCP protocol packet originally processed by itself for the DHCP client. The fourth DHCP relay generates a binding table entry corresponding to the DHCP client according to the temporary table entry.
[0106] Meanwhile, the fourth DHCP relay sends a second DHCP protocol packet to the DHCP client.
[0107] Optionally, in the embodiment of the present application, when the first DHCP relay is a DHCPv4 relay, the first DHCP relay includes a first interface, and this first interface is used to connect to the DHCPv4 client.
[0108] Under the above networking, according to the existing DHCPv4 protocol regulations, the first DHCP relay adds option82 to the first DHCP protocol packet. This option82 includes sub option 11, and this sub option 11 includes the first address of the first interface.
[0109] After the DHCP server obtains the first DHCP protocol message from the first QUIC message, it processes the first DHCP protocol message according to the provisions of DHCPv4.
[0110] During the process of the DHCP server processing the first DHCP protocol message according to the provisions of DHCPv4, if the first DHCP protocol message includes option54, the DHCP server verifies option54. The DHCP server continues to identify whether sub option11 is carried in option82 included in the first DHCP protocol message.
[0111] If sub option11 is carried, the DHCP server determines whether the address in sub option11 is the same as the address in option54, or the DHCP server determines whether the address in option54 is its own address. If the address in suboption11 is the same as the address in option54, or the address in option54 is its own address, the DHCP server determines that option54 passes the verification. Subsequently, the DHCP server continues to carry option54 in the feedback DHCP protocol message. The DHCP server encrypts the feedback DHCP protocol message according to the key corresponding to the QUIC connection and sends it through the QUIC connection.
[0112] If the address in sub option11 is different from the address in option54, or the address in option54 is not its own address, the DHCP server determines that option54 fails the verification. Subsequently, the DHCP server discards the first QUIC message.
[0113] If sub option11 is not carried, the DHCP server determines whether the address in option54 is its own address. If the address in option54 is its own address, the DHCP server determines that option54 passes the verification. Subsequently, the DHCP server continues to carry the option54 in the feedback DHCP protocol message. The DHCP server encrypts the feedback DHCP protocol message according to the key corresponding to the QUIC connection and sends it through the QUIC connection.
[0114] If the address in option54 is not its own address, the DHCP server determines that option54 fails the verification. Subsequently, the DHCP server discards the first QUIC message.
[0115] If the first QUIC packet does not include option 54, the DHCP server continues to identify whether sub option 11 is carried in option 82 included in the first QUIC packet.
[0116] If sub option 11 is carried, obtain an address from sub option 11 and fill the address in the newly added option 54. Subsequently, the DHCP server carries the newly added option 54 in the feedback DHCP protocol packet. The DHCP server encrypts the feedback DHCP protocol packet according to the key corresponding to the QUIC connection and sends it through the QUIC connection.
[0117] If sub option 11 is not carried, the DHCP server fills its own address in the address in the newly added option 54. Subsequently, the DHCP server carries the newly added option 54 in the feedback DHCP protocol packet. The DHCP server encrypts the feedback DHCP protocol packet according to the key corresponding to the QUIC connection and sends it through the QUIC connection.
[0118] In the embodiments of the present application, the addresses stored in option 54 are collectively referred to as the second addresses.
[0119] After the first DHCP relay passes the verification of the decrypted second QUIC packet, it obtains option 54 from the second DHCP protocol packet and obtains the second address from option 54. The first DHCP relay identifies whether the second address is the same as the first address; that is, the first DHCP relay identifies whether the second address is the interface address of its own first interface. If the second address is different from the first address, the first DHCP relay updates the second address to the first address. In this way, it can be ensured that the DHCP client sends subsequent DHCP protocol packets (such as renewal packets, release packets, etc.) to the first DHCP relay, and then the first DHCP relay encrypts and sends them to the DHCP server; if the second address is the same as the first address, the first DHCP relay keeps the second address.
[0120] Therefore, when applying the communication method provided by this application, the first DHCP relay receives the first DHCP protocol packet sent by the DHCP client; through the QUIC connection, the first DHCP relay sends a first QUIC packet to the DHCP server. The first QUIC packet includes a stream identifier, and the first QUIC packet is obtained by encrypting the first DHCP protocol packet according to the key corresponding to the QUIC connection. If the second QUIC packet including the stream identifier sent by the DHCP server and the second DHCP protocol packet generated by the DHCP server are encapsulated in the second QUIC packet, then according to the key, the first DHCP relay decrypts the second QUIC packet and verifies the decrypted second QUIC packet. If the verification passes and there is a temporary entry corresponding to the DHCP client, then according to the temporary entry, the first DHCP relay generates a binding entry corresponding to the DHCP client and sends the second DHCP protocol packet to the DHCP client. Among them, the stream identifier is allocated by the DHCP management relay, and the stream identifiers allocated by each DHCP relay in the distributed network are different from each other.
[0121] In this way, in the distributed network, through a QUIC connection established between the DHCP management relay and the DHCP server, each DHCP relay can use this QUIC connection to send encrypted packets to the DHCP server. This avoids the packets being eavesdropped and tampered with, reduces the configuration complexity of IPSec encryption, realizes multiplexing by each DHCP relay using different stream identifiers to avoid congestion, and has lower hardware and operation and maintenance costs.
[0122] Optionally, in the embodiments of this application, multiple first DHCP relays in the distributed network will also elect a DHCP management relay, so that the DHCP management relay will subsequently establish, manage, and maintain the QUIC connection with the DHCP server.
[0123] Specifically, before networking, the same BGP function is configured in each first DHCP relay. The router identifier (Router ID) of the BGP configured in each first DHCP relay is unique. The same QUIC function is also configured in the DHCP relay. For example: QUIC protocol version; TLS configuration; connection timeout and retry; flow control; congestion control; connection migration; 0-RTT and 1-RTT configuration.
[0124] After the first DHCP relays establish communication connections with each other, each first DHCP relay establishes a BGP neighbor with other first DHCP relays. Each first DHCP relay generates and sends a first BGP OPEN (OPEN) packet to other first DHCP relays. The first BGP OPEN packet includes the minimum Router identifier. The minimum Router identifier is the minimum value of the Router identifiers determined by each first DHCP relay itself.
[0125] In one implementation, in the initial stage of network formation, that is, just after the communication connection is established, when each first DHCP relay does not receive the first BGP OPEN message sent by other first DHCP relays (to distinguish the sender and the receiver, other first DHCP relays are referred to as second DHCP relays here), the minimum Router identifier determined by each first DHCP relay is its own Router identifier.
[0126] In the second implementation, if a first DHCP relay first receives the first BGP OPEN message sent by a second DHCP relay and has not sent the first BGP OPEN message itself, when determining the minimum Router identifier, the first DHCP relay needs to compare its own Router identifier with the minimum Router identifier included in the received first BGP OPEN message, and carry the minimum Router value after comparison in the first BGP OPEN message generated by itself.
[0127] For example, DHCP relay 1 and DHCP relay 2 form a distributed network. The Router identifier of DHCP relay 1 is 1, and the Router identifier of DHCP relay 2 is 2. In one implementation, neither DHCP relay 1 nor DHCP relay 2 receives the BGP OPEN message 1 sent by the peer. When generating the BGP OPEN message 1 itself, the minimum Router identifier determined by DHCP relay 1 is 1; the minimum Router identifier determined by DHCP relay 2 is 2.
[0128] In the second implementation, the BGP OPEN message 1 generated by DHCP relay 1 includes the minimum Router as 1. DHCP relay 1 sends the BGP OPEN message 1 to DHCP relay 2. DHCP relay 2 has not generated and sent the BGP OPEN message 2 yet. After receiving the BGP OPEN message 1, DHCP relay 2 obtains the minimum Router 1 from it. DHCP relay 2 compares its own Router identifier and the minimum Router identifier 1, and determines that the minimum Router identifier 1 is the minimum value. At this time, DHCP relay 2 generates the BGP OPEN message 2, and the minimum Router identifier included in this BGP OPEN message 2 is 1. DHCP relay 2 sends the BGP OPEN message 2 to DHCP relay 1.
[0129] In the embodiments of the present application, the first DHCP relay receives the first BGP OPEN messages sent by each second DHCP relay in the distributed network respectively, and obtains the minimum Router identifier from each first BGP OPEN message.
[0130] According to the existing BGP protocol regulations, during the process of each DHCP relay mutually exchanging BGP OPEN messages, the first DHCP relay establishes BGP neighbors with each second DHCP relay respectively. When the first DHCP relay successfully establishes a BGP neighbor with the first second DHCP relay, the first DHCP relay starts a timer, and the preset time of this timer is 10s. Within the preset time, the first DHCP relay determines whether there is a DHCP management relay in the distributed network.
[0131] It can be understood that during the initial network setup, each DHCP relay is mutually exchanging BGP OPEN messages, establishing BGP neighbors, and determining which DHCP relay in the network has the minimum Router identifier. Therefore, within the preset time, no DHCP management relay has been elected in the distributed network.
[0132] Therefore, if there is no DHCP management relay in the distributed network, the first DHCP relay determines whether each minimum Router identifier is less than its own first Router identifier. If each minimum Router identifier is not less than the first Router identifier, the first DHCP relay determines that the first Router identifier is the minimum Router identifier, that is, the minimum value of the Router identifiers in the distributed network.
[0133] If there is a minimum Router identifier that is less than the first Router identifier, the first DHCP relay waits for the BGP EVPN message sent by the second DHCP relay that subsequently becomes the DHCP management relay.
[0134] It should be noted that in the embodiments of the present application, the Router identifier of the DHCP management relay is the minimum value of the Router identifiers in the distributed network. Therefore, when there is a minimum Router identifier that is less than the first Router identifier, the first DHCP relay can determine that it cannot become the DHCP management relay.
[0135] Optionally, in the embodiments of the present application, the BGP OPEN message adds a first parameter Type Length Value (TLV) structure on the basis of the existing BGP OPEN message, and this first parameter TLV structure is used to carry the minimum Router identifier. Among them, the first parameter TLV structure includes a Type field, a Length field, and a Value field. The length of the Type field is 1 byte, and the value is set to 240; the length of the Length field is 1 byte, and the value is set to 1; the length of the Value field is variable and carries the minimum Router identifier.
[0136] Optionally, in the embodiments of the present application, when the duration of successfully establishing a BGP neighbor with the first second DHCP relay exceeds a preset time, the first DHCP relay determines that the distributed network has stabilized. The first DHCP relay then determines again whether there is a DHCP management relay in the distributed network (which can be determined by whether BGP EVPN packets are received).
[0137] If there is still no DHCP management relay in the distributed network, the first DHCP relay determines whether the first Router identifier is the current minimum Router identifier according to the minimum Router identifier included in each previously obtained first BGP OPEN packet. If the first Router identifier is the current minimum Router identifier, the first DHCP relay determines that it will be upgraded to a DHCP management relay and establishes a QUIC connection with the DHCP server.
[0138] It can be understood that the first DHCP relay will act as a QUIC client, and the DHCP server will act as a QUIC server. According to the existing QUIC protocol regulations, the first DHCP relay establishes a QUIC connection with the DHCP server, which will not be repeated here. At the same time, after becoming a DHCP management relay, the first DHCP relay also assigns corresponding flow identifiers to each Router identifier.
[0139] The first DHCP relay generates and sends a first BGP EVPN packet to each second DHCP relay respectively. The first BGP EVPN packet includes the attribute information of the QUIC connection, so that each second DHCP relay can reuse the QUIC connection according to the attribute information of the QUIC connection when forwarding DHCP protocol packets to the DHCP server.
[0140] If there is a DHCP management relay in the distributed network, the first DHCP relay waits for the BGP EVPN packet sent by the second DHCP relay that will become a DHCP management relay later.
[0141] Optionally, in the embodiments of the present application, a new type of BGP EVPN packet is added. The BGP EVPN packet includes a TLV structure. The TLV structure includes a type field, a length field, and a value field. The value field includes multiple sub-TLV (Sub-TLVs) structures, and each sub-TLV structure is used to carry one type of attribute information in the attribute information of the QUIC connection. The length of the type field is 1 byte, and the value is set to 254; the length of the length field is 2 bytes; the length of the value field is variable and carries at least one sub-TLV structure.
[0142] The sub-TLV structure includes a Sub-Type field, a Sub-Length field, and a Sub-Value field. The length of the Sub-Type field is 1 byte, and the value is set according to the carried attribute information (e.g., 1, 2, 3, etc.); the length of the Sub-Length field is 1 byte; the length of the Sub-Value field is variable and carries the attribute information.
[0143] The attribute information of the above QUIC connection includes the QUIC session identifier, the QUIC connection address, the QUIC connection port, the QUIC session key, the QUIC session transmission parameters, and the correspondence between all Router identifiers and flow identifiers within the network.
[0144] For example, in the sub-TLV structure carrying the QUIC session identifier, the Sub-Type field is set to 1; the Sub-Length field is variable and depends on the length of the QUIC session identifier; the Sub-Value field carries the unique identifier of the QUIC session, usually a randomly generated string or number. In the sub-TLV structure carrying the QUIC connection address, the Sub-Type field is set to 2; the Sub-Length field is set to 4 (IPv4) or 16 (IPv6); the Sub-Value field carries the IP address of the QUIC connection (the IP address of the DHCP relay or DHCP server). In the sub-TLV structure carrying the QUIC connection port, the Sub-Type field is set to 3; the Sub-Length field is set to 2; the Sub-Value field carries the port number of the QUIC connection (the port number of the DHCP relay or DHCP server). In the sub-TLV structure carrying the QUIC session key, the Sub-Type field is set to 4; the Sub-Length field is variable and depends on the length of the key; the Sub-Value field carries the encryption key of the QUIC session, which is used for other DHCP relays to verify the session. In the sub-TLV structure carrying the QUIC session transmission parameters, the Sub-Type field is set to 5; the Sub-Length field is variable and depends on the length of the transmission parameters; the Sub-Value field carries the transmission parameters of the QUIC session, such as the maximum packet size, flow control window, etc. In the sub-TLV structure carrying the correspondence between Router identifiers and flow identifiers, the Sub-Type field is set to 6; the Sub-Length field is variable and depends on the lengths of the Router identifier and the flow identifier; the Sub-Value field carries the correspondence between all Router identifiers and flow identifiers within the distributed network, where the Router identifier corresponds to a unique flow identifier.
[0145] Optionally, in the embodiment of the present application, when a new DHCP relay joins the distributed network, the new DHCP relay will also interact with each DHCP relay within the distributed network in processes such as sending BGP OPEN messages, establishing BGP, identifying whether there is a DHCP management relay, and obtaining the attribute information of QUIC.
[0146] Specifically, the first DHCP relay joins the distributed network as a new DHCP relay. After the first DHCP relay establishes communication connections with each second DHCP relay in the distributed network, each DHCP relay generates and sends BGP OPEN messages to each other. The first DHCP relay establishes BGP neighbors with each second DHCP relay respectively.
[0147] Each second DHCP relay generates a second BGP OPEN message, which includes the minimum Router identifier and the Router identifier of the DHCP management relay. Among them, the minimum Router identifier is the minimum value of the Router identifiers determined by the second DHCP relay.
[0148] It can be understood that when there is already a DHCP management relay in the distributed network, the minimum Router identifier determined by each second DHCP relay is the Router identifier of the DHCP management relay.
[0149] Each second DHCP relay sends the second BGP OPEN message to the first DHCP relay.
[0150] In one implementation, when the first DHCP relay does not receive the second BGP OPEN message sent by the second DHCP relay, the minimum Router identifier determined by the first DHCP relay is its own Router identifier and is carried in the second BGP OPEN message generated by itself. This second BGP OPEN message does not carry the Router identifier of the DHCP management relay. Moreover, the second BGP OPEN message has the same structure as the aforementioned first BGP OPEN message, and both include a first parameter TLV structure, which is used to carry the minimum Router identifier.
[0151] In the second implementation, if the first DHCP relay first receives the second BGP OPEN message sent by the second DHCP relay and has not sent the second BGP OPEN message itself, then when the first DHCP relay determines the minimum Router identifier, it needs to compare its own Router identifier with the minimum Router identifier included in the received second BGP OPEN message, and carry the minimum Router identifier after comparison in the second BGP OPEN message generated by itself. This second BGP OPEN message may also carry the Router identifier of the DHCP management relay (which can be determined according to the Router identifier of the DHCP management relay sent by the second DHCP relay).
[0152] Similarly, after the second DHCP relay receives the second BGP OPEN message sent by the first DHCP relay, if the Router identifier of the first DHCP relay is less than the Router identifier of the DHCP management relay, then after comparing the sizes of the identifiers, the second DHCP relay fills the Router identifier of the first DHCP relay at the minimum Router identifier, but the DHCP management relay remains unchanged.
[0153] The second BGP OPEN message generated by the second DHCP relay includes not only the first parameter TLV structure, but also the second parameter TLV structure, and this second parameter TLV structure is used to carry the Router identifier of the DHCP management relay. The second parameter TLV structure is the same as the first parameter TLV structure.
[0154] According to the existing BGP protocol regulations, the first DHCP relay establishes BGP neighbors with each second DHCP relay respectively. After successfully establishing a BGP neighbor with the first second DHCP relay, the first DHCP relay starts a timer, and the preset time of this timer is 10 s. Within the preset time, the first DHCP relay determines whether there is a DHCP management relay in the distributed network.
[0155] If there is a DHCP management relay in the distributed network (usually there is), then the first DHCP relay determines whether each minimum Router identifier is less than its own first Router identifier. If each first Router identifier is not less than the first Router identifier, then the first DHCP relay determines the first Router identifier as the minimum Router identifier. At the same time, the first DHCP relay waits for the BGP EVPN message sent by the DHCP management relay, for example, the third BGP EVPN message (only used to distinguish other BGP EVPN messages).
[0156] If there is no DHCP management relay in the distributed network (the DHCP management relay fails, the link fails and other abnormal situations cause the DHCP management relay to be out of contact), then the first DHCP relay determines whether each minimum Router identifier is less than its own first Router identifier. If each first Router identifier is not less than the first Router identifier, then the first DHCP relay determines the first Router identifier as the minimum Router identifier. If there is a minimum Router identifier that is less than the first Router identifier, then the first DHCP relay waits for the BGP EVPN message sent by the second DHCP relay that subsequently becomes the DHCP management relay, for example, the fourth BGP EVPN message (only used to distinguish other BGP EVPN messages).
[0157] Optionally, in the embodiment of the present application, when the duration of successfully establishing a BGP neighbor relationship with the first second DHCP relay exceeds the preset time, the first DHCP relay determines whether there is a DHCP management relay in the distributed network.
[0158] If there is no DHCP management relay in the distributed network (the DHCP management relay is lost due to abnormal conditions such as DHCP management relay failure and link failure), the first DHCP relay determines whether the first Router identifier is the current minimum Router identifier; if the first Router identifier is the current minimum Router identifier, the first DHCP relay establishes a QUIC connection with the DHCP server.
[0159] It is understandable that the first DHCP relay will act as a QUIC client and the DHCP server will act as a QUIC server. According to the existing QUIC protocol, the first DHCP relay establishes a QUIC connection with the DHCP server, which will not be repeated here.
[0160] The first DHCP relay sends a second BGP EVPN message to each second DHCP relay respectively, where the second BGP EVPN message includes the attribute information of the QUIC connection, so that each second DHCP relay multiplexes the QUIC connection according to the attribute information of the QUIC connection when forwarding the DHCP protocol message to the DHCP server.
[0161] It can be understood that the format of the second BGP EVPN message is the same as the format of the first BGP EVPN message, which will not be repeated here.
[0162] If a DHCP management relay exists in the distributed network (usually it exists), the first DHCP relay waits for a BGP EVPN message sent by the DHCP management relay, for example, a third BGP EVPN message (only used to distinguish other BGP EVPN messages).
[0163] For example, DHCP relay 1 and DHCP relay 2 have formed a distributed network. The Router ID of DHCP relay 1 is 4, and the Router ID of DHCP relay 2 is 5. According to the above embodiment, in the distributed network, DHCP relay 1 is the DHCP management relay. At this time, DHCP relay 3 joins the distributed network, and the Router ID of DHCP relay 3 is 1.
[0164] In the first implementation method, after the DHCP relay 3 establishes communication connections with the DHCP relay 1 and the DHCP relay 2, the DHCP relay 3 does not receive other BGP OPEN messages. At this time, the DHCP relay 3 determines that the minimum Router identifier is 1 and carries it in the BGP OPEN message 1. The DHCP relay 3 sends the BGP OPEN message 1 to the DHCP relay 1 and the DHCP relay 2.
[0165] After receiving the BGP OPEN message 1, the DHCP relay 1 and the DHCP relay 2 obtain the Router value 1 of the DHCP relay 3 from it. The DHCP relay 1 compares the Router value of the DHCP relay 3 with the current minimum Router value 4, and determines that the Router value 1 of the DHCP relay 3 is the current minimum Router value. The DHCP relay 1 refreshes the current minimum Router identifier to 1. Similarly, the DHCP relay 2 also refreshes the current minimum Router identifier to 1.
[0166] At the same time, the DHCP relay 1 and the DHCP relay 2 also generate the BGP OPEN message 2. If it is generated before receiving the BGP OPEN message 1, the BGP OPEN message 2 includes the minimum Router identifier 4 and the Router identifier 4 of the DHCP management relay; if it is generated after receiving the BGP OPEN message 1, the BGP OPEN message 1 includes the minimum Router identifier 1 and the Router identifier 4 of the DHCP management relay.
[0167] After receiving multiple BGP OPEN messages 2, the DHCP relay 3 establishes BGP neighbors with the DHCP relay 1 and the DHCP relay 2 respectively according to the existing BGP protocol regulations. If the DHCP relay 3 first establishes a BGP neighbor with the DHCP relay 1, the DHCP relay 3 starts a timer, and the preset time of this timer is 10s. Within the preset time, the DHCP relay 3 determines whether there is a DHCP management relay in the distributed network. The DHCP relay 3 determines that there is a DHCP management relay in the distributed network according to the Router identifier of the DHCP management relay included in each BGP OPEN message 2, that is, the DHCP relay 1 is the DHCP management relay. And the DHCP relay 3 uses its own Router identifier as the minimum Router identifier. The DHCP relay 3 waits for the BGP EVPN message sent by the DHCP relay 1.
[0168] When the duration of successfully establishing a BGP neighbor with DHCP Relay 1 exceeds the preset time, DHCP Relay 3 determines again whether there is a DHCP management relay in the distributed network. At this time, there is a DHCP management relay in the distributed network, that is, DHCP Relay 1 is still the DHCP management relay. DHCP Relay 3 waits for the BGP EVPN packets sent by DHCP Relay 1.
[0169] In the second implementation, after DHCP Relay 1, DHCP Relay 2, and DHCP Relay 3 establish a communication connection, DHCP Relay 1 generates a BGP OPEN packet 2. When BGP OPEN packet 1 is not received, DHCP Relay 1 generates and sends BGP OPEN packet 2 to DHCP Relay 3. The minimum Router ID and the Router ID of the DHCP management relay included in this BGP OPEN packet 2 are both 4, that is, the Router ID of DHCP Relay 1. Similarly, DHCP Relay 2 also generates the same BGP OPEN packet 2.
[0170] After receiving multiple BGP OPEN packets 2, DHCP Relay 3 obtains the minimum Router ID 4 and the Router ID 4 of the DHCP management relay from them. DHCP Relay 3 determines that DHCP Relay 1 is the DHCP management relay. DHCP Relay 3 compares its own Router ID 1 with the minimum Router ID 4 and determines that its own Router ID 1 is the current minimum Router ID.
[0171] At the same time, DHCP Relay 3 also generates a BGP OPEN packet 1. If it is generated before receiving BGP OPEN packet 2, then BGP OPEN packet 1 includes the minimum Router ID 1; if it is generated after receiving BGP OPEN packet 2, then BGP OPEN packet 1 includes the minimum Router ID 1 and the Router ID 4 of the DHCP management relay.
[0172] It can be understood that after DHCP Relay 1 and DHCP Relay 2 receive BGP OPEN packet 1, they refresh the current minimum Router ID to 1 according to the included minimum Router ID 1.
[0173] After the DHCP relay 3 receives the BGP OPEN message 2, according to the existing BGP protocol regulations, it establishes BGP neighbors with the DHCP relay 1 and the DHCP relay 2 respectively. If the DHCP relay 3 first establishes a BGP neighbor with the DHCP relay 1, the DHCP relay 3 starts a timer, and the preset time of this timer is 10s. Within the preset time, the DHCP relay 3 determines whether there is a DHCP management relay in the distributed network. The DHCP relay 3 determines that there is a DHCP management relay in the distributed network according to the Router identifier of the DHCP management relay included in each BGP OPEN message 2, that is, the DHCP relay 1 is the DHCP management relay. And the DHCP relay 3 takes its own Router identifier as the minimum Router identifier. The DHCP relay 3 waits for the BGP EVPN message sent by the DHCP relay 1.
[0174] When the duration of successfully establishing a BGP neighbor with the DHCP relay 1 exceeds the preset time, the DHCP relay 3 determines again whether there is a DHCP management relay in the distributed network. At this time, there is a DHCP management relay in the distributed network, that is, the DHCP relay 1 is still the DHCP management relay. The DHCP relay 3 waits for the BGP EVPN message sent by the DHCP relay 1. Subsequently, when forwarding the DHCP protocol message to the DHCP server, the QUIC connection is multiplexed according to the attribute information of the QUIC connection included in the BGP EVPN message.
[0175] During the process of the DHCP relay 3 joining the distributed network, if the DHCP relay 1 fails or the link fails and causes disconnection when the DHCP relay 3 first determines whether there is a DHCP management relay in the distributed network, the DHCP relay 3 determines that there is no DHCP management relay in the distributed network. At this time, after the DHCP relay 3 determines that its own Router identifier is the minimum Router identifier, it refreshes the current minimum Router identifier to its own Router identifier.
[0176] Then, when the DHCP relay 3 determines again whether there is a DHCP management relay in the distributed network after the duration of successfully establishing a BGP neighbor with the DHCP relay 1 exceeds the preset time, the DHCP relay 3 still determines that there is no DHCP management relay in the distributed network. At this time, after the DHCP relay 3 determines again that its own Router identifier is the minimum Router identifier, the DHCP relay 3 establishes a QUIC connection with the DHCP server.
[0177] It can be understood that the DHCP relay 3 will act as a QUIC client, and the DHCP server will act as a QUIC server. According to the existing QUIC protocol regulations, the DHCP relay 3 establishes a QUIC connection with the DHCP server, which will not be repeated here.
[0178] DHCP relay agent 3 sends a BGP EVPN message to DHCP relay agent 2.
[0179] Optionally, in an embodiment of the present application, when the first DHCP relay has not become a DHCP management relay, it will also receive a BGP EVPN message sent by a DHCP relay that becomes a DHCP management relay to obtain attribute information of the QUIC connection.
[0180] Specifically, if there is a DHCP management relay in the distributed network, the first DHCP relay receives a third BGP EVPN message (only used to distinguish other BGP EVPN messages) sent by the DHCP management relay, and the third BGP EVPN message includes attribute information of the QUIC connection.
[0181] or;
[0182] If there is no DHCP management relay in the distributed network and the first Router identifier of the first DHCP relay is not the minimum value of the Router identifiers of all DHCP relays included in the distributed network, the first DHCP relay receives the fourth BGP EVPN message (only used to distinguish other BGP EVPN messages) sent by the second DHCP relay that becomes the DHCP management relay, and the fourth BGP EVPN message includes attribute information of the QUIC connection.
[0183] It can be understood that the formats of the third BGP EVPN message and the fourth BGP EVPN message are the same as the formats of the first BGP EVPN message and the second BGP EVPN message, which will not be repeated here.
[0184] Optionally, in an embodiment of the present application, if a DHCP management relay fails or a link fails, causing the DHCP management relay to lose connection with the first DHCP relay in the distributed network, the other first DHCP relays elect a DHCP management relay again to manage and maintain the QUIC connection.
[0185] Specifically, if the first DHCP relay is disconnected from the DHCP management relay, the first DHCP relay locally obtains the Router identifier of each third DHCP relay except the DHCP management relay in the distributed network.
[0186] It is understandable that, through the BGP EVPN message sent by the DHCP management relay, each first DHCP relay can store the correspondence between the Router identifiers and the flow identifiers of all the DHCP relays in the network.
[0187] The first DHCP relay selects the minimum value of the Router identifiers from among the Router identifiers of multiple third DHCP relays. The first DHCP relay determines whether the minimum value of the selected Router identifier is its own first Router identifier.
[0188] If the minimum value of the Router identifier selected by the first DHCP relay is its own first Router identifier, the first DHCP relay maintains the QUIC connection as the new DHCP management relay (e.g., interacts with the DHCP server, keeps the QUIC connection alive, etc.), and sends a fifth BGP EVPN message to each third DHCP relay. The fifth BGP EVPN message includes the attribute information of the QUIC connection, so that each third DHCP relay can reuse the QUIC connection according to the attribute information of the QUIC connection when forwarding DHCP protocol messages to the DHCP server.
[0189] If the minimum value of the Router identifier selected by the first DHCP relay is not its own first Router identifier, the first DHCP relay waits for the sixth BGP EVPN message sent by the third DHCP relay that becomes the new DHCP management relay, and after receiving the sixth BGP EVPN message, obtains the attribute information of the QUIC connection from the sixth BGP EVPN message. Subsequently, when forwarding DHCP protocol messages to the DHCP server, the QUIC connection is reused according to the attribute information of the QUIC connection.
[0190] Optionally, in the embodiments of this application, during the process of establishing a QUIC connection between the DHCP management relay and the DHCP server, QUIC connection request and QUIC connection response messages are communicated with each other. During the interaction process, since the IP addresses of the DHCP relays in the distributed network are the same, when the DHCP server sends back the QUIC connection response message, the QUIC connection response message will be sent to a non-DHCP management relay. At this time, the non-DHCP management relay should forward the QUIC connection response message to the DHCP management relay.
[0191] Specifically, if the first DHCP relay receives the QUIC connection response message sent by the DHCP server and the first DHCP relay is not the DHCP management relay, then according to the minimum value of the Router identifiers among all the DHCP relays included in the distributed network, the first DHCP relay sends the QUIC connection response message to the DHCP relay indicated by the minimum value of the Router identifier.
[0192] It can be understood that the DHCP relay indicated by the minimum value of the Router identifier is the DHCP management relay.
[0193] The communication method provided by the embodiments of the present application will be described in detail below. Refer to Figure 3 , Figure 3 which is a flowchart of another communication method provided by the embodiments of the present application. This method is applied to a DHCP server that has established a QUIC connection with a DHCP management relay in a distributed network. The communication method provided by the embodiments of the present application may include the following steps.
[0194] Step 310: Receive a first QUIC packet sent by the first DHCP relay through the QUIC connection, where the first QUIC packet includes a stream identifier;
[0195] Specifically, according to the foregoing embodiments, the DHCP server may specifically be a DHCPv4 server or a DHCPv6 server. In a distributed network, the DHCP server establishes a QUIC connection with the DHCP management relay and acts as a QUIC server.
[0196] According to the foregoing embodiments, after the first DHCP relay in the distributed network receives the first DHCP protocol packet, it encrypts the first DHCP protocol packet according to the key corresponding to the QUIC connection, and then multiplexes the QUIC connection to send it to the DHCP server.
[0197] In this step, the DHCP server receives the first QUIC packet through the QUIC connection.
[0198] Step 320: If the first DHCP protocol packet is encapsulated in the first QUIC packet, decrypt the first QUIC packet according to the key corresponding to the QUIC connection, and verify the decrypted first QUIC packet;
[0199] Specifically, according to the description in step 310, after receiving the first QUIC packet, the DHCP server first identifies whether the first DHCP protocol packet is encapsulated in the first QUIC packet.
[0200] If the first DHCP protocol packet is encapsulated in the first QUIC packet, the DHCP server decrypts the first QUIC packet according to the key corresponding to the QUIC connection. Then, the DHCP server verifies the decrypted first QUIC packet.
[0201] If the verification of the decrypted first QUIC packet passes, the DHCP server executes step 230.
[0202] Optionally, in the embodiments of the present application, if the verification of the decrypted first QUIC packet fails, the DHCP server discards the first QUIC packet.
[0203] Optionally, in the embodiments of the present application, if the first DHCP protocol message is not encapsulated in the first QUIC message, the DHCP server discards the first QUIC message.
[0204] It should be noted that the process of the DHCP server verifying the QUIC message is the same as the process of the DHCP relay verifying the QUIC message in the foregoing embodiments, and will not be repeated here.
[0205] Step 330: If the verification passes and the first DHCP protocol message is a first type of message, generate a second QUIC message, where the second QUIC message includes the flow identifier and a second DHCP protocol message, and the second DHCP protocol message is a response message of the first DHCP protocol message;
[0206] Specifically, according to the description of step 320, if the decrypted first QUIC message passes the verification, the DHCP server identifies the type of the first DHCP protocol message included in the payload part of the first QUIC message.
[0207] If the first DHCP protocol message is a first type of message, then according to the existing DHCP protocol regulations, the DHCP server generates a second DHCP protocol message. This second DHCP protocol message is the response message of the first DHCP protocol message.
[0208] In the embodiments of the present application, the first type of message specifically refers to a message that requires the DHCP server to reply to the DHCP protocol message.
[0209] Optionally, in the embodiments of the present application, when the DHCP server is a DHCPv4 server, it can identify whether the first DHCP protocol message is encapsulated in the first QUIC message, decrypt the first QUIC message, verify the decrypted first QUIC message, and identify the type of the first DHCP protocol message according to the foregoing description.
[0210] During the process of generating the second DHCP protocol message, the DHCP server performs protocol processing on the first DHCP protocol message according to the regulations of DHCPv4.
[0211] During the process of the DHCP server performing protocol processing on the first DHCP protocol message according to the regulations of DHCPv4, if the first DHCP protocol message includes option54, the DHCP server verifies option54.
[0212] The DHCP server continues to identify whether suboption11 is carried in option82 included in the first DHCP protocol message.
[0213] If sub option11 is carried, the DHCP server determines whether the address in sub option11 is the same as the address in option54, or the DHCP server determines whether the address in option54 is its own address. If the address in sub option11 is the same as the address in option54, or the address in option54 is its own address, the DHCP server determines that the option54 verification passes. Subsequently, the DHCP server continues to carry option54 in the second DHCP protocol message. The DHCP server fills the flow identifier included in the first QUIC message and the second DHCP protocol message in the payload part to generate a second QUIC message.
[0214] If the address in sub option11 is different from the address in option54, or the address in option54 is not its own address, the DHCP server determines that the option54 verification fails. Subsequently, the DHCP server discards the first QUIC message.
[0215] If sub option11 is not carried, the DHCP server determines whether the address in option54 is its own address. If the address in option54 is its own address, the DHCP server determines that the option54 verification passes. Subsequently, the DHCP server continues to carry the option54 in the second DHCP protocol message. The DHCP server fills the flow identifier included in the first QUIC message and the second DHCP protocol message in the payload part to generate a second QUIC message.
[0216] If the address in option54 is not its own address, the DHCP server determines that the option54 verification fails. Subsequently, the DHCP server discards the first QUIC message.
[0217] If the first DHCP protocol message does not include option54, the DHCP server continues to identify whether sub option11 is carried in option82 included in the first DHCP protocol message.
[0218] If sub option11 is carried, an address is obtained from sub option11 and filled in the newly added option54. Subsequently, the DHCP server carries the newly added option54 in the second DHCP protocol message. The DHCP server fills the flow identifier included in the first QUIC message and the second DHCP protocol message in the payload part to generate a second QUIC message.
[0219] If the sub option11 is not carried, the DHCP server fills its own address in the address within the newly added option54. Subsequently, the DHCP server carries the newly added option54 in the second DHCP protocol message. The DHCP server fills the stream identifier included in the first QUIC message and the second DHCP protocol message in the payload part to generate a second QUIC message.
[0220] Step 340: Send the second QUIC message to the first DHCP relay through the QUIC connection.
[0221] Specifically, according to the description of step 330, after generating the second QUIC message, the DHCP server also encrypts the second QUIC message according to the key.
[0222] It should be noted that when the DHCP server encrypts the QUIC message, it encrypts the complete QUIC message, and does not encrypt the outer IP header and UDP header.
[0223] Through the QUIC connection, the DHCP server sends the second QUIC message to the first DHCP relay.
[0224] Therefore, by applying the communication method provided in this application, through the QUIC connection, the DHCP server receives the first QUIC message sent by the first DHCP relay, and the first QUIC message includes a stream identifier; if the first DHCP protocol message is encapsulated in the first QUIC message, the DHCP server decrypts the first QUIC message according to the key corresponding to the QUIC connection, and verifies the decrypted first QUIC message; if the verification passes and the first DHCP protocol message is a first type message, the DHCP server generates a second QUIC message, and the second QUIC message includes a stream identifier and a second DHCP protocol message, and the second DHCP protocol message is a response message of the first DHCP protocol message; through the QUIC connection, the DHCP server sends the second QUIC message to the first DHCP relay; wherein, the stream identifier is allocated by the DHCP management relay and the stream identifiers allocated by each DHCP relay in the distributed network are different.
[0225] In this way, in the distributed network, through a QUIC connection established between the DHCP management relay and the DHCP server, each DHCP relay can use this QUIC connection to send encrypted messages to the DHCP server. It avoids the messages being eavesdropped and tampered with; reduces the configuration complexity of IPSec encryption; each DHCP relay uses different stream identifiers to achieve multiplexing and avoid congestion; the hardware and operation and maintenance costs are lower.
[0226] Based on the same inventive concept, embodiments of the present application further provide a communication device corresponding to the communication method. Refer to Figure 4 , Figure 4 A communication device provided in an embodiment of the present application. The device is applied to a first DHCP relay in a distributed network. The first DHCP relay is any DHCP relay in the distributed network. A DHCP management relay in the distributed network establishes a QUIC connection with a DHCP server. The device includes:
[0227] A receiving unit 410, configured to receive a first DHCP protocol message sent by a DHCP client;
[0228] A sending unit 420, configured to send a first QUIC message to the DHCP server through the QUIC connection. The first QUIC message includes a stream identifier. The first QUIC message is obtained by encrypting the first DHCP protocol message according to a key corresponding to the QUIC connection;
[0229] A verification unit 430, configured to, if the receiving unit receives a second QUIC message including the stream identifier sent by the DHCP server and a second DHCP protocol message generated by the DHCP server is encapsulated in the second QUIC message, decrypt the second QUIC message according to the key, and verify the decrypted second QUIC message;
[0230] A generating unit 440, configured to, if the verification is passed and there is a temporary entry corresponding to the DHCP client, generate a binding entry corresponding to the DHCP client according to the temporary entry;
[0231] The sending unit 420 is further configured to send the second DHCP protocol message to the DHCP client;
[0232] Wherein, the stream identifier is allocated by the DHCP management relay, and the stream identifiers allocated by each DHCP relay in the distributed network are different from each other
[0233] Optionally, the receiving unit 410 is further configured to receive first BGP OPEN messages respectively sent by each second DHCP relay in the distributed network. Each first BGP OPEN message includes a minimum Router identifier, and the minimum Router identifier is the minimum value of the Router identifiers determined by the second DHCP relay;
[0234] The device further includes: a first determination unit (not shown in the figure), configured to determine whether there is a DHCP management relay in the distributed network within a preset time after successfully establishing a BGP neighbor with the first second DHCP relay;
[0235] A second determination unit (not shown in the figure) for determining whether each minimum Router identifier is less than the first Router identifier of the first DHCP relay if it does not exist;
[0236] A processing unit (not shown in the figure) for, if not, using the first Router identifier as the minimum Router identifier.
[0237] Optionally, the first determination unit (not shown in the figure) is further configured to determine whether the DHCP management relay exists in the distributed network when the duration of successfully establishing a BGP neighbor with the first second DHCP relay exceeds the preset time;
[0238] The second determination unit (not shown in the figure) is further configured to determine whether the first Router identifier is the current minimum Router identifier if it does not exist;
[0239] An establishment unit (not shown in the figure) for, if so, establishing the QUIC connection with the DHCP server;
[0240] The sending unit 420 is further configured to send a first BGP EVPN message to each of the second DHCP relays, where the first BGP EVPN message includes attribute information of the QUIC connection, so that each of the second DHCP relays multiplexes the QUIC connection according to the attribute information of the QUIC connection when forwarding DHCP protocol messages to the DHCP server.
[0241] Optionally, the receiving unit 410 is further configured to receive second BGP OPEN messages respectively sent by each second DHCP relay in the distributed network, where each second BGP OPEN message includes a minimum Router identifier and the Router identifier of the DHCP management relay, and the minimum Router identifier is the minimum value of the Router identifiers determined by the second DHCP relay;
[0242] The first determination unit (not shown in the figure) is further configured to determine whether the DHCP management relay exists in the distributed network within a preset time after successfully establishing a BGP neighbor with the first second DHCP relay;
[0243] The second determination unit (not shown in the figure) is further configured to determine whether each minimum Router identifier is less than the first Router identifier of the first DHCP relay if it exists;
[0244] The processing unit (not shown in the figure) is further configured to, if not, use the first Router identifier as the minimum Router identifier.
[0245] Optionally, the first determination unit (not shown in the figure) is further configured to, when the duration of successfully establishing a BGP neighbor with the first second DHCP relay exceeds the preset time, determine whether there is a DHCP management relay in the distributed network;
[0246] The second determination unit (not shown in the figure) is further configured to, if not, determine whether the first Router identifier is the current minimum Router identifier;
[0247] The establishment unit (not shown in the figure) is further configured to, if so, establish the QUIC connection with the DHCP server;
[0248] The sending unit 420 is further configured to send a second BGP EVPN message to each of the second DHCP relays, where the second BGP EVPN message includes attribute information of the QUIC connection, so that each of the second DHCP relays multiplexes the QUIC connection according to the attribute information of the QUIC connection when forwarding a DHCP protocol message to the DHCP server.
[0249] Optionally, the receiving unit 410 is further configured to, if there is a DHCP management relay in the distributed network, receive a third BGP EVPN message sent by the DHCP management relay, where the third BGP EVPN message includes attribute information of the QUIC connection;
[0250] Or;
[0251] The receiving unit 410 is further configured to, if there is no DHCP management relay in the distributed network and the first Router identifier of the first DHCP relay is not the minimum among the Router identifiers of all DHCP relays included in the distributed network, receive a fourth BGP EVPN message sent by the second DHCP relay that becomes the DHCP management relay, where the fourth BGP EVPN message includes attribute information of the QUIC connection.
[0252] Optionally, the device further includes:
[0253] An obtaining unit (not shown in the figure), configured to, if disconnected from the DHCP management relay, obtain the Router identifier of each third DHCP relay in the distributed network except the DHCP management relay;
[0254] A selection unit (not shown in the figure) for selecting the minimum value of the Router identifiers from among the Router identifiers of multiple third DHCP relays;
[0255] The second determination unit (not shown in the figure) is further configured to determine whether the minimum value of the selected Router identifier is the first Router identifier of the first DHCP relay;
[0256] The sending unit 420 is further configured to, if so, maintain the QUIC connection as a new DHCP management relay and send a fifth BGP EVPN message to each of the third DHCP relays, the fifth BGP EVPN message including the attribute information of the QUIC connection, so that each of the third DHCP relays multiplexes the QUIC connection according to the attribute information of the QUIC connection when forwarding DHCP protocol messages to the DHCP server;
[0257] The receiving unit 410 is further configured to, if not, receive a sixth BGP EVPN message sent by a third DHCP relay that becomes a new DHCP management relay, the sixth BGP EVPN message including the attribute information of the QUIC connection.
[0258] Optionally, when the first DHCP relay is a DHCPv4 relay, the first DHCP relay includes a first interface;
[0259] The first QUIC message further includes option82, option82 includes sub option11, and suboption11 includes the first address of the first interface; the second QUIC message further includes option54, and option54 includes a second address;
[0260] The apparatus further includes:
[0261] An identification unit (not shown in the figure) for identifying whether the second address is the same as the first address;
[0262] An update unit (not shown in the figure) for updating the second address to the first address if they are different;
[0263] A holding unit (not shown in the figure) for holding the second address if they are the same.
[0264] Optionally, the apparatus further includes:
[0265] A determination unit (not shown in the figure) is configured to, if the verification is passed and there is no temporary table entry corresponding to the DHCP client, determine a fourth DHCP relay for processing the decrypted second QUIC packet according to the MAC address of the DHCP client.
[0266] The sending unit 420 is further configured to send the decrypted second QUIC packet to the fourth DHCP relay.
[0267] Optionally, the sending unit 420 is further configured to, if the receiving unit 410 receives a QUIC connection response packet sent by the DHCP server and the first DHCP relay is not the DHCP management relay, send the QUIC connection response packet to the DHCP relay indicated by the minimum Router identifier among all the DHCP relays included in the distributed network.
[0268] Optionally, the BGP OPEN packet includes a first parameter TLV structure for carrying the first minimum Router identifier.
[0269] Or;
[0270] The BGP OPEN packet includes a first parameter TLV structure and a second parameter TLV structure. The first parameter TLV structure is used to carry the first minimum Router identifier, and the second parameter TLV structure is used to carry the Router identifier of the DHCP management relay.
[0271] Optionally, the BGP EVPN packet includes a TLV structure. The TLV structure includes a value field, and the value field includes a plurality of sub-TLV structures. Each sub-TLV structure is used to carry one piece of attribute information in the attribute information of the QUIC connection.
[0272] The attribute information of the QUIC connection includes a QUIC session identifier, a QUIC connection address, a QUIC connection port, a QUIC session key, QUIC session transmission parameters, and a correspondence between a Router identifier and a flow identifier.
[0273] Optionally, the apparatus further includes:
[0274] A discard unit (not shown in the figure) is configured to discard the second QUIC packet if the second DHCP protocol packet is not encapsulated in the second QUIC packet.
[0275] The discard unit (not shown in the figure) is further configured to discard the second QUIC packet if the verification fails.
[0276] Therefore, when applying the communication method provided by this application, the first DHCP relay receives the first DHCP protocol packet sent by the DHCP client; through the QUIC connection, the first DHCP relay sends a first QUIC packet to the DHCP server. The first QUIC packet includes a stream identifier, and the first QUIC packet is obtained by encrypting the first DHCP protocol packet according to the key corresponding to the QUIC connection; if the second QUIC packet including the stream identifier sent by the DHCP server and the second DHCP protocol packet generated by the DHCP server are encapsulated in the second QUIC packet, then according to the key, the first DHCP relay decrypts the second QUIC packet and verifies the decrypted second QUIC packet; if the verification passes and there is a temporary entry corresponding to the DHCP client, then according to the temporary entry, the first DHCP relay generates a binding entry corresponding to the DHCP client and sends a second DHCP protocol packet to the DHCP client; wherein, the stream identifier is assigned by the DHCP management relay and the stream identifiers assigned by each DHCP relay in the distributed network are different from each other.
[0277] In this way, in a distributed network, through a QUIC connection established between the DHCP management relay and the DHCP server, each DHCP relay can use this QUIC connection to send encrypted packets to the DHCP server. This avoids packet eavesdropping and tampering; reduces the configuration complexity of IPSec encryption; each DHCP relay uses different stream identifiers to achieve multiplexing and avoid congestion; the hardware and operation and maintenance costs are lower.
[0278] Based on the same inventive concept, an embodiment of this application also provides a communication device corresponding to the communication method. See Figure 5 , Figure 5 which is another communication device provided by an embodiment of this application. The device is applied to a DHCP server. The DHCP server has established a QUIC connection with the DHCP management relay in the distributed network. The distributed network further includes a first DHCP relay, and the first DHCP relay is any DHCP relay in the distributed network. The device includes:
[0279] A receiving unit 510, configured to receive, through the QUIC connection, a first QUIC packet sent by the first DHCP relay, where the first QUIC packet includes a stream identifier;
[0280] A verification unit 520, configured to, if a first DHCP protocol packet is encapsulated in the first QUIC packet, decrypt the first QUIC packet according to the key corresponding to the QUIC connection, and verify the decrypted first QUIC packet;
[0281] A generating unit 530, configured to generate a second QUIC packet if the verification passes and the first DHCP protocol packet is a first-type packet, where the second QUIC packet includes the flow identifier and a second DHCP protocol packet, and the second DHCP protocol packet is a response packet of the first DHCP protocol packet;
[0282] A sending unit 540, configured to send the second QUIC packet to the first DHCP relay through the QUIC connection;
[0283] Wherein, the flow identifier is allocated by the DHCP management relay, and the flow identifiers allocated by each DHCP relay in the distributed network are different from each other.
[0284] Optionally, the QUIC packet includes a flow identifier field for carrying the flow identifier.
[0285] Optionally, the apparatus further includes:
[0286] A discarding unit (not shown in the figure), configured to discard the first QUIC packet if the first DHCP protocol packet is not encapsulated in the first QUIC packet;
[0287] The discarding unit (not shown in the figure) is further configured to discard the first QUIC packet if the verification fails.
[0288] Therefore, by applying the communication method provided in this application, through the QUIC connection, the DHCP server receives the first QUIC packet sent by the first DHCP relay, and the first QUIC packet includes a flow identifier; if the first DHCP protocol packet is encapsulated in the first QUIC packet, the DHCP server decrypts the first QUIC packet according to the key corresponding to the QUIC connection, and verifies the decrypted first QUIC packet; if the verification passes and the first DHCP protocol packet is a first-type packet, the DHCP server generates a second QUIC packet, and the second QUIC packet includes a flow identifier and a second DHCP protocol packet, and the second DHCP protocol packet is a response packet of the first DHCP protocol packet; through the QUIC connection, the DHCP server sends the second QUIC packet to the first DHCP relay; wherein, the flow identifier is allocated by the DHCP management relay, and the flow identifiers allocated by each DHCP relay in the distributed network are different from each other.
[0289] Thus, in a distributed network, a QUIC connection is established between the DHCP management relay and the DHCP server. Each DHCP relay can use this QUIC connection to send encrypted packets to the DHCP server, avoiding packet eavesdropping and tampering, reducing the configuration complexity of IPSec encryption, achieving multiplexing using different flow identifiers for each DHCP relay to avoid congestion, and having lower hardware and operation costs.
[0290] Based on the same inventive concept, an embodiment of the present application also provides a network device, as Figure 6 shown, including a processor 610, a transceiver 620, and a machine-readable storage medium 630. The machine-readable storage medium 630 stores machine-executable instructions that can be executed by the processor 610. The processor 610 is prompted by the machine-executable instructions to execute the communication method provided by the embodiment of the present application. The foregoing Figure 4 、 Figure 5 shown communication device can be implemented using the hardware structure of the network device as Figure 6 shown.
[0291] The above-mentioned computer-readable storage medium 630 may include a random access memory (English: Random Access Memory, abbreviated as: RAM), and may also include a non-volatile memory (English: Non-volatile Memory, abbreviated as: NVM), such as at least one disk memory. Optionally, the computer-readable storage medium 630 may also be at least one storage device located far from the foregoing processor 610.
[0292] The above-mentioned processor 610 may be a general-purpose processor, including a central processing unit (English: Central Processing Unit, abbreviated as: CPU), a network processor (English: Network Processor, abbreviated as: NP), etc.; it may also be a digital signal processor (English: Digital Signal Processor, abbreviated as: DSP), an application-specific integrated circuit (English: Application Specific Integrated Circuit, abbreviated as: ASIC), a field-programmable gate array (English: Field-Programmable Gate Array, abbreviated as: FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.
[0293] In the embodiment of the present application, the processor 610 reads the machine-executable instructions stored in the machine-readable storage medium 630 and is prompted by the machine-executable instructions to enable the processor 610 itself and call the transceiver 620 to execute the communication method described in the foregoing embodiment of the present application.
[0294] In addition, an embodiment of the present application provides a machine-readable storage medium 630. The machine-readable storage medium 630 stores machine-executable instructions, which, when called and executed by the processor 610, cause the processor 610 itself and the transceiver 620 to execute the communication method described in the foregoing embodiments of the present application.
[0295] For the specific implementation process of the functions and roles of each unit in the above device, please refer to the implementation process of the corresponding steps in the above method, which will not be elaborated here.
[0296] For the device embodiment, since it basically corresponds to the method embodiment, the relevant parts can be referred to the partial description of the method embodiment. The device embodiment described above is only illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of the present application. Those of ordinary skill in the art can understand and implement it without creative efforts.
[0297] For the embodiments of the communication device and the machine-readable storage medium, since the method content involved is basically similar to the foregoing method embodiments, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiments.
[0298] The above are only the preferred embodiments of the present application and are not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application shall be included in the scope of protection of the present application.
Claims
1. A communication method, characterized in that: Applied to a first DHCP relay in a distributed network, the first DHCP relay is any DHCP relay in the distributed network, a DHCP management relay in the distributed network establishes a QUIC connection with a DHCP server, the method comprising: Receiving a first DHCP protocol message sent by a DHCP client; Sending a first QUIC message to the DHCP server through the QUIC connection, where the first QUIC message includes a flow identifier, and the first QUIC message is obtained by encrypting the first DHCP protocol message according to a key corresponding to the QUIC connection; If a second QUIC message including the flow identifier sent by the DHCP server is received and the second DHCP protocol message generated by the DHCP server is encapsulated in the second QUIC message, decrypting the second QUIC message according to the key, and verifying the decrypted second QUIC message; If the check passes and there is a temporary entry corresponding to the DHCP client, generating a binding entry corresponding to the DHCP client according to the temporary entry, and sending the second DHCP protocol message to the DHCP client; The flow identifier is allocated by the DHCP management relay and the flow identifiers allocated by each DHCP relay in the distributed network are different.
2. The method according to claim 1, characterized in that Before receiving the first DHCP protocol message sent by the DHCP client, the method further includes: receiving first BGP OPEN messages respectively sent by each second DHCP relay in the distributed network, each first BGP OPEN message including a minimum Router identifier, where the minimum Router identifier is a minimum value of the Router identifiers determined by the second DHCP relay; After successfully establishing a BGP neighbor relationship with the first second DHCP relay, determining whether the DHCP management relay exists in the distributed network within a preset time; If not, determine whether each minimum Router ID is smaller than the first Router ID of the first DHCP relay agent; If not, the first Router ID is used as the minimum Router ID.
3. The method according to claim 2, characterized in that The method further comprises: When the duration of successfully establishing a BGP neighbor relationship with the first second DHCP relay exceeds the preset time, determining whether the DHCP management relay exists in the distributed network; If not, determine whether the first Router ID is the current smallest Router ID; If yes, establishing the QUIC connection with the DHCP server; A first BGP EVPN message is sent to each of the second DHCP relay agents respectively, where the first BGP EVPN message includes attribute information of the QUIC connection, so that each of the second DHCP relay agents multiplexes the QUIC connection according to the attribute information of the QUIC connection when forwarding the DHCP protocol message to the DHCP server.
4. The method according to claim 1, characterized in that Before receiving the first DHCP protocol message sent by the DHCP client, the method further includes: receiving a second BGP OPEN message respectively sent by each second DHCP relay in the distributed network, each second BGP OPEN message including a minimum Router ID and a Router ID of the DHCP management relay, the minimum Router ID being a minimum value of the Router IDs determined by the second DHCP relay; After successfully establishing a BGP neighbor relationship with the first second DHCP relay, determining whether the DHCP management relay exists in the distributed network within a preset time; If so, determine whether each minimum Router ID is smaller than the first Router ID of the first DHCP relay agent; If not, the first Router ID is used as the minimum Router ID.
5. The method according to claim 4, characterized in that The method further comprises: When the duration of successfully establishing a BGP neighbor relationship with the first second DHCP relay exceeds the preset time, determining whether the DHCP management relay exists in the distributed network; If not, determine whether the first Router ID is the current smallest Router ID; If yes, establishing the QUIC connection with the DHCP server; A second BGP EVPN message is sent to each of the second DHCP relay agents respectively, where the second BGP EVPN message includes attribute information of the QUIC connection, so that each of the second DHCP relay agents multiplexes the QUIC connection according to the attribute information of the QUIC connection when forwarding the DHCP protocol message to the DHCP server.
6. The method according to any one of claims 2 to 5, characterized in that: The method further comprises: If the DHCP management relay exists in the distributed networking, receiving a third BGP EVPN message sent by the DHCP management relay, wherein the third BGP EVPN message includes attribute information of the QUIC connection; or; If the DHCP management relay does not exist in the distributed networking and the first Router identifier of the first DHCP relay is not the minimum value of the Router identifiers of all DHCP relays included in the distributed networking, a fourth BGP EVPN message sent by the second DHCP relay that becomes the DHCP management relay is received, and the fourth BGP EVPN message includes attribute information of the QUIC connection.
7. The method according to claim 1, characterized in that The method further comprises: If the connection with the DHCP management relay is disconnected, obtaining the Router identifier of each third DHCP relay in the distributed network except the DHCP management relay; Selecting a minimum value of the Router IDs from among the Router IDs of the plurality of third DHCP relay agents; Determine whether the minimum value of the selected Router identifier is the first Router identifier of the first DHCP relay agent; If so, maintain the QUIC connection as a new DHCP management relay, and send a fifth BGP EVPN message to each of the third DHCP relays respectively, wherein the fifth BGP EVPN message includes the attribute information of the QUIC connection, so that each of the third DHCP relays reuses the QUIC connection according to the attribute information of the QUIC connection when forwarding the DHCP protocol message to the DHCP server; If not, receive the sixth BGP EVPN message sent by the third DHCP relay that becomes the new DHCP management relay, where the sixth BGP EVPN message includes the attribute information of the QUIC connection.
8. The method according to claim 1, characterized in that When the first DHCP relay is a DHCPv4 relay, the first DHCP relay includes a first interface; The first QUIC message further includes option 82, wherein option 82 includes sub option 11, wherein sub option 11 includes the first address of the first interface; the second QUIC message further includes option 54, wherein option 54 includes the second address; Before sending the second DHCP protocol message to the DHCP client, the method further includes: identifying whether the second address is the same as the first address; If they are different, updating the second address to the first address; If they are the same, the second address is maintained.
9. The method according to claim 1, characterized in that: The method further comprises: If the check passes and there is no temporary table entry corresponding to the DHCP client, determining, according to the MAC address of the DHCP client, a fourth DHCP relay that processes the decrypted second QUIC message; Send the decrypted second QUIC message to the fourth DHCP relay agent.
10. The method according to claim 1, characterized in that The method further comprises: If a QUIC connection response message sent by the DHCP server is received and the first DHCP relay is not the DHCP management relay, the QUIC connection response message is sent to the DHCP relay indicated by the minimum value of the Router identifier among all the DHCP relays included in the distributed networking.
11. The method according to claim 2 or 4, characterized in that: The BGP OPEN message includes a first parameter TLV structure, where the first parameter TLV structure is used to carry the first minimum Router identifier; or; The BGP OPEN message includes a first parameter TLV structure and a second parameter TLV structure, the first parameter TLV structure is used to carry the first minimum Router identifier, and the second parameter TLV structure is used to carry the Router identifier of the DHCP management relay.
12. The method according to any one of claims 3, 5-7, characterized in that: The BGP EVPN message includes a TLV structure, the TLV structure includes a value field, the value field includes multiple sub-TLV structures, each sub-TLV structure is used to carry one attribute information of the attribute information of the QUIC connection; The attribute information of the QUIC connection includes the QUIC session identifier, the QUIC connection address, the QUIC connection port, the QUIC session key, the QUIC session transmission parameters, and the correspondence between the Router identifier and the stream identifier.
13. The method according to claim 1, characterized in that The method further comprises: If the second DHCP protocol message is not encapsulated in the second QUIC message, discarding the second QUIC message; If the verification fails, the second QUIC message is discarded.
14. A communication method, characterized in that: Applied to a DHCP server, the DHCP server has established a QUIC connection with a DHCP management relay in a distributed network, the distributed network further includes a first DHCP relay, and the first DHCP relay is any DHCP relay in the distributed network, the method includes: Receiving, through the QUIC connection, a first QUIC message sent by the first DHCP relay, where the first QUIC message includes a flow identifier; If the first DHCP protocol message is encapsulated in the first QUIC message, decrypting the first QUIC message according to the key corresponding to the QUIC connection, and verifying the decrypted first QUIC message; If the verification passes and the first DHCP protocol message is a first type message, a second QUIC message is generated, where the second QUIC message includes the flow identifier and a second DHCP protocol message, and the second DHCP protocol message is a response message to the first DHCP protocol message; Sending the second QUIC message to the first DHCP relay agent through the QUIC connection; The flow identifier is allocated by the DHCP management relay and the flow identifiers allocated by each DHCP relay in the distributed network are different.
15. The method according to claim 14, characterized in that The QUIC message includes a flow identification field, and the flow identification field is used to carry the flow identification.
16. The method according to claim 14, characterized in that The method further comprises: If the first DHCP protocol message is not encapsulated in the first QUIC message, discarding the first QUIC message; If the verification fails, the first QUIC message is discarded.
17. A communication device, characterized in that: Applied to a first DHCP relay in a distributed network, the first DHCP relay is any DHCP relay in the distributed network, a DHCP management relay in the distributed network establishes a QUIC connection with a DHCP server, and the device includes: A receiving unit, configured to receive a first DHCP protocol message sent by a DHCP client; a sending unit, configured to send a first QUIC message to the DHCP server through the QUIC connection, where the first QUIC message includes a flow identifier, and the first QUIC message is obtained by encrypting the first DHCP protocol message according to a key corresponding to the QUIC connection; a verification unit, configured to decrypt the second QUIC message according to the key and verify the decrypted second QUIC message if the receiving unit receives the second QUIC message including the flow identifier sent by the DHCP server and the second DHCP protocol message generated by the DHCP server is encapsulated in the second QUIC message; a generating unit, configured to generate a binding entry corresponding to the DHCP client according to the temporary entry if the verification passes and there is a temporary entry corresponding to the DHCP client; The sending unit is further used to send the second DHCP protocol message to the DHCP client; The flow identifier is allocated by the DHCP management relay and the flow identifiers allocated by each DHCP relay in the distributed network are different.
18. A communication device, characterized in that: Applied to a DHCP server, the DHCP server has established a QUIC connection with a DHCP management relay in a distributed network, the distributed network further includes a first DHCP relay, the first DHCP relay is any DHCP relay in the distributed network, the device includes: a receiving unit, configured to receive, through the QUIC connection, a first QUIC message sent by the first DHCP relay, where the first QUIC message includes a flow identifier; a verification unit, configured to decrypt the first QUIC message according to a key corresponding to the QUIC connection, and verify the decrypted first QUIC message if the first DHCP protocol message is encapsulated in the first QUIC message; a generating unit, configured to generate a second QUIC message if the verification passes and the first DHCP protocol message is a first type message, wherein the second QUIC message includes the flow identifier and a second DHCP protocol message, and the second DHCP protocol message is a response message to the first DHCP protocol message; a sending unit, configured to send the second QUIC message to the first DHCP relay agent through the QUIC connection; The flow identifier is allocated by the DHCP management relay and the flow identifiers allocated by each DHCP relay in the distributed network are different.
Citation Information
Patent Citations
Method and apparatus for implementing multi-host multi-path secure transmission using QUIC
CN115244897A
Method and apparatus for user equipment-to-network relay communication in wireless communications
CN115379591A
Signaling communication method, service communication agent node, electronic equipment and storage medium
CN117596563A
Host access control method and device and storage medium
CN119690573A
Methods and apparatuses for enabling multi-host multipath secure transport with quic
US20230074838A1