Heartbeat packet sending method and device and storage medium

By using SRv6 data packets to carry heartbeat packets and perform anti-replay verification in the SASE architecture, the effective time of heartbeat packets is dynamically adjusted, and the traffic overhead problem caused by heartbeat packet transmission is solved, achieving more efficient network access and stronger security.

CN120151253APending Publication Date: 2025-06-13CHINA TELECOM NETWORK SECURITY TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510297049.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-13
Publication Date
2025-06-13

AI Technical Summary

Technical Problem

In a Secure Access Service Edge (SASE) architecture, user devices need to regularly send large amounts of heartbeat packets to maintain real-time and validity of access, which adds additional traffic overhead.

Method used

By carrying the heartbeat packet in the segmented routing extension header of the SRv6 data packet and forwarding it to the controller after performing anti-replay verification at the edge node, the effective time of the heartbeat packet is dynamically adjusted to reduce the transmission frequency of the heartbeat packet.

Benefits of technology

Reduces the additional traffic overhead of processing heartbeat packets, reduces the complexity of processing processes, and ensures real-time and security of access rights.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120151253A_ABST
    Figure CN120151253A_ABST
Patent Text Reader

Abstract

The invention discloses a heartbeat packet sending method and device and a storage medium, and relates to the technical field of network security. The method comprises the following steps: receiving an SRv6 data packet from a terminal; wherein a heartbeat packet is carried in a segment routing extension head (SRH) of the SRv6 data packet; performing anti-replay verification on the heartbeat packet, and when it is determined that the anti-replay verification result of the heartbeat packet is passed, forwarding the SRv6 data packet to a controller; receiving heartbeat packet target effective time from the controller; wherein the heartbeat packet target effective time is determined by the controller at least based on the SRv6 data packet sending frequency and the heartbeat packet sending frequency, and the heartbeat packet target effective time is used for the terminal to adjust the next heartbeat packet sending time based on the heartbeat packet target effective time so as to reduce the extra traffic overhead for processing the heartbeat packets.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and in particular, to a method, device, and storage medium for sending heartbeat packets. Background Art

[0002] In a Secure Access Service Edge (SASE) architecture, when a user device accesses network resources, it generally needs to perform identity authentication, which usually involves providing valid authentication information, such as a username and password, fingerprint recognition, verification code, etc., to ensure that the identity of the visitor is authentic and trustworthy. After the identity authentication passes, the access permissions of the user of the device will be determined, and corresponding access authorization will be performed.

[0003] In the above architecture, in order to maintain the real-time and effectiveness of user access permissions, the user device also needs to periodically send a large number of heartbeat packets to the management system additionally to prove that it is still active and request to maintain access permissions, which undoubtedly increases the additional traffic overhead. Summary of the Invention

[0004] This application provides a method, device, and storage medium for sending heartbeat packets to reduce the additional traffic overhead for processing heartbeat packets.

[0005] In a first aspect, a method for sending a heartbeat packet is provided, which is applied to an edge node. The method includes:

[0006] Receiving an SRv6 data packet from a terminal; wherein, a heartbeat packet is carried in a Segment Routing Header (SRH) of the SRv6 data packet;

[0007] Performing anti-replay verification on the heartbeat packet. When it is determined that the anti-replay verification result of the heartbeat packet passes, forwarding the SRv6 data packet to a controller;

[0008] Receiving a heartbeat packet target valid time from the controller; wherein, the heartbeat packet target valid time is determined by the controller based on at least the number of SRv6 data packet transmissions and the number of heartbeat packet transmissions, and is used for the terminal to adjust the sending time of the next heartbeat packet based on the heartbeat packet target valid time.

[0009] In some embodiments, the performing anti-replay verification on the heartbeat packet includes:

[0010] Performing anti-replay verification on the heartbeat packet according to a random number in the heartbeat packet;

[0011] If the random number is different from all the random numbers included in the database, it is determined that the anti-replay verification result of the heartbeat packet passes;

[0012] If the random number is the same as the random number included in the database, it is determined that the anti-replay check result of the heartbeat packet fails, and an interception operation is performed on the SRv6 data packet.

[0013] In some embodiments, the heartbeat packet further includes the account information of the terminal, and the account information is generated by the terminal encrypting the user account name and user password using an encryption algorithm.

[0014] In some embodiments, the heartbeat packet further includes the access information of the terminal, and the access information at least includes the user access permission level; wherein, the user access permission level is associated with a preset heartbeat packet valid time.

[0015] In the embodiments of the present application, first, since the heartbeat packet is carried in the SRH of the SRv6 data packet sent by the terminal, making it have both the functions of a heartbeat packet and a data packet, the edge node can authenticate and verify it together when forwarding the SRv6 data packet, while ensuring security, reducing the additional traffic overhead of heartbeat packet verification, and reducing the processing process; second, it can also interact with the controller for heartbeat packet valid time regulation to dynamically adjust the frequency of the terminal sending heartbeat packets, thereby reducing the traffic overhead of processing heartbeat packets.

[0016] In a second aspect, a method for sending a heartbeat packet is provided, which is applied to a controller, and the method includes:

[0017] Receiving an SRv6 data packet from an edge node; wherein, the heartbeat packet is carried in the SRH of the SRv6 data packet, and is forwarded by the edge node after determining that the anti-replay check result of the heartbeat packet passes;

[0018] Based on the number of times the SRv6 data packet is sent and the number of times the heartbeat packet is sent, determining the target valid time of the heartbeat packet; wherein, the target valid time of the heartbeat packet is used for the terminal to adjust the sending time of the next heartbeat packet based on the target valid time of the heartbeat packet.

[0019] In some embodiments, the heartbeat packet further includes the account information of the terminal, and the account information is generated by the terminal encrypting the user account name and user password using an encryption algorithm.

[0020] In some embodiments, the heartbeat packet further includes the access information of the terminal, and the access information includes the user access permission level; wherein, the user access permission level is associated with a preset heartbeat packet valid time.

[0021] In some embodiments, the determining the target valid time of the heartbeat packet based on the number of times the SRv6 data packet is sent and the number of times the heartbeat packet is sent includes:

[0022] If within the number of times of sending the SRv6 packet, among the number of times of sending the heartbeat packet, there are N heartbeat packets carried that do not exceed the current heartbeat packet valid time, then based on the current heartbeat packet valid time, increase the target valid time of the heartbeat packet;

[0023] If within the number of times of sending the SRv6 packet, among the number of times of sending the heartbeat packet, there are M heartbeat packets carried that exceed the current heartbeat packet valid time, then based on the current heartbeat packet valid time, decrease the target valid time of the heartbeat packet; where the N and the M are the same or different, and are both preset times.

[0024] In a third aspect, there is provided an edge node, including:

[0025] A first receiving module, configured to receive an SRv6 packet from a terminal; where a heartbeat packet is carried in the SRH of the SRv6 packet;

[0026] A verification module, configured to perform anti-replay verification on the heartbeat packet, and when it is determined that the anti-replay verification result of the heartbeat packet passes, forward the SRv6 packet to a controller;

[0027] A second receiving module, configured to receive the target valid time of the heartbeat packet from the controller; where the target valid time of the heartbeat packet is determined by the controller based on at least the number of times of sending the SRv6 packet and the number of times of sending the heartbeat packet, and is used for the terminal to adjust the sending time of the next heartbeat packet based on the target valid time of the heartbeat packet.

[0028] In a fourth aspect, there is provided a controller, including:

[0029] A receiving module, configured to receive an SRv6 packet from an edge node; where a heartbeat packet is carried in the SRH of the SRv6 packet, and it is the SRv6 packet forwarded by the edge node after determining that the anti-replay verification result of the heartbeat packet passes;

[0030] A determining module, configured to determine the target valid time of the heartbeat packet based on the number of times of sending the SRv6 packet and the number of times of sending the heartbeat packet; where the target valid time of the heartbeat packet is used for the terminal to adjust the sending time of the next heartbeat packet based on the target valid time of the heartbeat packet.

[0031] In a fifth aspect, there is provided a communication device, including:

[0032] A memory, configured to store a computer program; a processor, when executing the computer program stored on the memory, implements the method steps described in any item of the first aspect.

[0033] In a sixth aspect, there is provided a computer-readable storage medium storing a computer program, which when executed by a processor, implements the method steps described in any one of the first aspect.

[0034] For the technical effects that can be achieved by each of the above second to sixth aspects and each aspect, reference may be made to the technical effects that can be achieved by the first aspect or various possible solutions in the first aspect described above, and details will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] Figure 1 Schematic diagram of an application scenario applicable to the embodiments of the present application;

[0036] Figure 2 Flowchart of a heartbeat packet sending method applied to an edge node provided by an embodiment of the present application;

[0037] Figure 3 Flowchart of a heartbeat packet sending method applied to a controller provided by an embodiment of the present application;

[0038] Figure 4 Schematic diagram of signaling interaction for heartbeat packet sending provided by an embodiment of the present application;

[0039] Figure 5 Schematic diagram of the structure of an edge node provided by an embodiment of the present application;

[0040] Figure 6 Schematic diagram of the structure of a controller provided by an embodiment of the present application;

[0041] Figure 7 Schematic diagram of the structure of a communication device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0042] To make the objectives, technical solutions, and advantages of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the scope of protection of the present application. Without conflict, the embodiments in the present application and the features in the embodiments may be combined with each other arbitrarily. And although the logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than here.

[0043] In the description and claims of this application and the above-mentioned drawings, the terms "first" and "second" are used to distinguish different objects, rather than to describe a specific order. In addition, the term "comprising" and any variations thereof are intended to cover non-exclusive protection. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally further include steps or units not listed, or may optionally further include other steps or units inherent to these processes, methods, products or devices. "Multiple" in this application may mean at least two, for example, it may be two, three or more, and the embodiments of this application do not make limitations.

[0044] The following describes exemplary embodiments of this application with reference to the accompanying drawings. Various details of the embodiments of this application are included to facilitate understanding, and they should be considered merely exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope of the disclosure of this application. Similarly, for the sake of clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description. It should be noted that in the embodiments of this application, some industry-existing solutions such as certain software, components, models, etc. may be mentioned, and they should be considered exemplary. The purpose is only to illustrate the feasibility in the implementation of the technical solution of this application, but it does not mean that the applicant has already or necessarily used this solution.

[0045] To better understand the embodiments of this application, the following first explains the technical terms involved in the embodiments of this application.

[0046] (1) Segment Routing IPv6 (SRv6) is the application of SR technology in IPv6 networks. SRv6 explicitly specifies the destination address of the packet by inserting a Segment Routing Header (SRH) into the IPv6 packet and adding the identifiers (Segment IDs, SIDs) of all segments that the path should pass through, that is, the SID List, in the SRH.

[0047] (2) Secure Access Service Edge (SASE) is a service based on the identity of entities, real-time context, enterprise security or compliance policies, and continuously evaluating risks and trust throughout the session.

[0048] The following briefly introduces the application scenarios to which the technical solutions of the embodiments of this application can be applied. It should be noted that the application scenarios introduced below are only for illustrating the embodiments of this application and not for limitation. In specific implementation, the technical solutions provided by the embodiments of this application can be flexibly applied according to actual needs.

[0049] Figure 1 This is a schematic diagram of the application scenario applicable to the embodiments of the present application. As shown in the figure, this application scenario mainly includes: a terminal 10, an edge node 11, and a controller 12. Among them, the edge node 11 can interact information with the terminal 10 and the controller 11 respectively through a communication network. The communication methods adopted by this communication network can include: wireless communication methods and wired communication methods.

[0050] In some scenarios, the terminal 10 can access the network through cellular mobile communication technology and communicate with the edge node 11. This cellular mobile communication technology can include the fifth-generation mobile communication (5th Generation Mobile Networks, 5G) technology, as well as future sixth-generation mobile communication technologies, etc.

[0051] In some scenarios, the terminal 10 can access the network through short-range wireless communication methods and communicate with the server 11. This short-range wireless communication method can include wireless fidelity (Wireless Fidelity, Wi-Fi) technology.

[0052] The embodiments of the present application do not impose any restrictions on the quantity of the above devices. As Figure 1 shown, only the terminal 10, the edge node 11, and the controller 12 are taken as examples for description. Next, a brief introduction to the above devices and their respective functions will be given.

[0053] The terminal 10 is a device that can provide voice and / or data connectivity to users, including: handheld terminal devices with wireless connection functions, in-vehicle terminal devices, etc. For example, the terminal 10 includes but is not limited to: mobile phones, tablet computers, laptop computers, palm computers, mobile Internet devices (Mobile Internet Device, MID), wearable devices, virtual reality (Virtual Reality, VR) devices, augmented reality (Augmented Reality, AR) devices, wireless terminal devices in industrial control, wireless terminal devices in unmanned driving, wireless terminal devices in smart grids, wireless terminal devices in transportation safety, wireless terminal devices in smart cities, or wireless terminal devices in smart homes, etc.

[0054] In the embodiments of the present application, the terminal 10 can be used to modify SRv6 data packets, encapsulate heartbeat information, random numbers for anti-replay attacks, as well as the user's account information and access information, etc. into a heartbeat packet, and place the heartbeat packet in the SRH of the SRv6 data packet, and forward it to the accessed edge node 11, facilitating subsequent anti-replay verification by the edge node 11 and dynamic adjustment of the heartbeat packet validity time set for the terminal 10 by the controller 12.

[0055] The edge node 11 is deployed with multiple security capabilities, which can forward the SRv6 data packets (or traffic) sent by the terminal 10 to the destination server. Further, it can also perform anti-replay verification on the heartbeat packets carried in the SRv6 data packets to prevent anti-replay attacks. And when the anti-replay verification result of the heartbeat packet passes, the SRv6 data packet is forwarded to the controller 12.

[0056] After receiving the SRv6 data packet sent by the edge node 11, the controller 12 can dynamically increase or decrease the valid time of the heartbeat packet corresponding to the terminal 10 based on the number of times the SRv6 data packet is sent, the number of times the heartbeat packet is sent, etc., and forward the adjusted valid time of the heartbeat packet to the terminal 10 via the edge node 11, so that the terminal 10 can adaptively adjust the sending time of the next heartbeat packet based on the new valid time of the heartbeat packet, which can not only ensure the access permission of the terminal 10, but also achieve the purpose of reducing the sending of keep-alive heartbeat packets, thereby solving the additional overhead caused by sending heartbeat packets.

[0057] To further illustrate the technical solutions provided by the embodiments of the present application, the following will be described in detail in combination with the accompanying drawings and specific implementation manners. Although the embodiments of the present application provide the method operation steps as shown in the following embodiments or drawings, based on routine or non-creative labor, more or fewer operation steps may be included in the method. In steps where there is no necessary causal relationship logically, the execution order of these steps is not limited to the execution order provided by the embodiments of the present application. When the method is actually processed or the device executes, it can be executed in the method order shown in the embodiments or drawings or executed concurrently.

[0058] Figure 2 It is a flowchart of a method for sending heartbeat packets applied to an edge node provided by an embodiment of the present application, which is used to reduce the additional traffic overhead for processing heartbeat packets. As Figure 2 shown, the process includes the following steps:

[0059] 201: Receive an SRv6 data packet from a terminal, and a heartbeat packet is carried in the SRH of the SRv6 data packet.

[0060] In some embodiments, the heartbeat packet includes a random number for anti-replay verification, and may also include the account information, access information, and other verification information of the terminal (for example, whether large bandwidth is required for video data transmission, whether there are special requirements for link delay, etc.); further, the account information may be generated by the terminal encrypting information such as the user account name, user password, and user fingerprint using an encryption algorithm (for example, a hash algorithm, a key pair encryption algorithm, etc.) to prevent the leakage of the user's privacy information; the access information may include the user access permission level, and may also include service information requested by the user to access, etc.

[0061] In some embodiments, the user access permission level is associated with a preset heartbeat packet valid time. For example, the user access permission level is divided into 4 levels. The heartbeat packet valid time corresponding to user access permission level 1 is 30 seconds, the heartbeat packet valid time corresponding to user access permission level 2 is 45 seconds, and the heartbeat packet valid time corresponding to user access permission level 3 is 1 minute. For another example, the user access permission level is divided into 4 levels, and each user access permission level corresponds to multiple heartbeat packet valid time levels, and each heartbeat packet valid time level corresponds to its own heartbeat packet valid time. Suppose user access permission level 1 corresponds to 3 heartbeat packet valid time levels, and the corresponding heartbeat packet valid times are 20 seconds, 30 seconds, and 40 seconds respectively. Suppose user access permission level 2 corresponds to 3 heartbeat packet valid time levels, and the corresponding heartbeat packet valid times are 30 seconds, 40 seconds, and 50 seconds respectively.

[0062] The interaction process of this step can be: After the terminal (such as the terminal 10 shown in Figure 1 ) adds a heartbeat packet to the SRH of the SRv6 packet, it sends the SRv6 packet carrying the heartbeat packet to the edge node (such as the edge node 11 shown in Figure 1 ). The edge node 11 can perform parsing, verification and other processing on the SRv6 packet after receiving it.

[0063] 202: Perform anti-replay verification on the heartbeat packet. When it is determined that the anti-replay verification result of the heartbeat packet passes, forward the SRv6 packet to the controller.

[0064] In some embodiments, performing anti-replay verification on the heartbeat packet can be: According to the random number in the heartbeat packet, perform anti-replay verification on the heartbeat packet. If the random number is different from all the random numbers contained in the database, it indicates that the heartbeat packet is unique and trustworthy, and it can be determined that the anti-replay verification result of the heartbeat packet passes. If the random number is the same as the random numbers contained in the database, it indicates that the heartbeat packet contains attack data and is untrustworthy, and it can be determined that the anti-replay verification result of the heartbeat packet fails, and an interception operation is performed on the SRv6 packet to prevent a replay attack on the edge node, timely block the sending of abnormal packets, and improve data transmission security.

[0065] In some other embodiments, after it is determined that the anti-replay verification result of the heartbeat packet passes, the SRv6 packet can also be forwarded to the server where the next node indicated in the SRH is located for subsequent access service requests.

[0066] 203: Receive the heartbeat packet target valid time from the controller. The heartbeat packet target valid time is determined by the controller based on at least the number of SRv6 packet transmissions and the number of heartbeat packet transmissions, and is used for the terminal to adjust the transmission time of the next heartbeat packet based on the heartbeat packet target valid time.

[0067] In some embodiments, after receiving the heartbeat packet target valid time from the controller (such as the controller 102 shown Figure 1 ), the indication information carrying the heartbeat packet target valid time can be sent to the terminal, so that the terminal can adjust the time of sending the next heartbeat packet (which can refer to an additional heartbeat packet or a heartbeat packet placed in the SRv6 packet) based on the heartbeat packet target valid time and information such as its own user access privilege level.

[0068] In the embodiments of the present application, first, since the SRH of the SRv6 packet sent by the terminal carries a heartbeat packet, making it have the functions of both a heartbeat packet and a data packet, the edge node can perform joint authentication and verification on it when forwarding the SRv6 packet, while ensuring security, reducing the additional traffic overhead of heartbeat packet verification, and reducing the processing process; second, it can also interact with the controller for heartbeat packet valid time regulation to dynamically adjust the frequency of the terminal sending heartbeat packets, thereby reducing the traffic overhead of processing heartbeat packets.

[0069] Figure 3 It is a flowchart of a heartbeat packet sending method applied to a controller provided by the embodiments of the present application, used to reduce the additional traffic overhead of processing heartbeat packets. As Figure 3 shown, the process includes the following steps:

[0070] 301: Receive the SRv6 packet from the edge node. The SRH of the SRv6 packet carries a heartbeat packet, and it is forwarded by the edge node after determining that the anti-replay verification result of the heartbeat packet passes.

[0071] In some embodiments, the heartbeat packet includes a random number for anti-replay verification, and may also include the terminal's account information, access information, and other verification information (for example, whether large bandwidth is required for video data transmission, whether there are special requirements for link delay, etc.); further, the account information can be generated by the terminal using an encryption algorithm (such as a hash algorithm, a key pair encryption algorithm, etc.) to encrypt information such as the user account name, user password, and user fingerprint to prevent the leakage of user privacy information; the access information may include the user access privilege level and may also include service information requested by the user to access, etc.

[0072] In some embodiments, the user access privilege level is associated with a preset heartbeat packet valid time, and specific reference can be made to the relevant description above, which will not be repeated here.

[0073] 302: Determine the heartbeat target valid time based on the number of SRv6 data packet transmissions and the number of heartbeat packet transmissions. The heartbeat target valid time is used for the terminal to adjust the transmission time of the next heartbeat packet based on the heartbeat target valid time.

[0074] In some embodiments, determining the heartbeat target valid time based on the number of SRv6 data packet transmissions and the number of heartbeat packet transmissions may be:

[0075] If within the number of SRv6 data packet transmissions, among the number of heartbeat packet transmissions, there are N heartbeat packets that do not exceed the current heartbeat packet valid time, then based on the current heartbeat packet valid time, increase the heartbeat target valid time;

[0076] If within the number of SRv6 data packet transmissions, among the number of heartbeat packet transmissions, there are M heartbeat packets that exceed the current heartbeat packet valid time, then based on the current heartbeat packet valid time, decrease the heartbeat target valid time; where N and M are the same or different and are both preset numbers.

[0077] For example, assume that the number of SRv6 data packet transmissions is 8 times and the number of heartbeat packet transmissions is 5 times, and N is preset to 3 times and M is preset to 3 times; if the controller determines that among these 5 times, 3 heartbeat packets do not exceed the current heartbeat packet valid time configured for the terminal (for example, 30 seconds), then based on the current heartbeat packet valid time, increase the heartbeat target valid time to 45 seconds, or 1 minute, etc., and can reasonably increase it from the heartbeat packet valid time associated with the user access privilege level of the terminal, thereby reducing the frequency of subsequent heartbeat packet transmissions by the terminal and reducing the traffic overhead. If the controller determines that among these 5 times, 3 heartbeat packets exceed the current heartbeat packet valid time (for example, 30 seconds), then based on the current heartbeat packet valid time, decrease the heartbeat target valid time to 20 seconds, or 25 seconds, etc., and can reasonably decrease it from the heartbeat packet valid time associated with the user access privilege level of the terminal, thereby maintaining the subsequent access privilege of the user terminal. By adopting this mechanism of dynamically adjusting the heartbeat valid time, reduce the frequency of heartbeat packet transmissions and reduce the traffic overhead.

[0078] In some embodiments, after determining the heartbeat target valid time, the controller can forward it to the edge node, facilitating the edge node to send indication information carrying the heartbeat target valid time to the terminal. Subsequently, the terminal can adjust the time of the next heartbeat packet (which can refer to an additional heartbeat packet or a heartbeat packet placed in the SRv6 data packet) based on the heartbeat target valid time and information such as its own user access privilege level.

[0079] In the embodiments of the present application, since the SRH of the SRv6 data packet sent by the terminal carries a heartbeat packet, it has two functions of a heartbeat packet and a data packet. Therefore, when the edge node forwards the SRv6 data packet, it can authenticate and verify them together, reducing the additional traffic overhead of heartbeat packet verification and the processing flow while ensuring security. Secondly, it can also interact with the controller for heartbeat packet validity time regulation to dynamically adjust the frequency of the terminal sending heartbeat packets, thereby reducing the traffic overhead of processing heartbeat packets.

[0080] Based on the above Figure 2 and Figure 3 shown method, Figure 4 is a signaling interaction diagram for heartbeat packet sending provided by the embodiments of the present application. As Figure 4 shown, it may include the following steps:

[0081] 401: The terminal sends an SRv6 data packet carrying a heartbeat packet to the edge node.

[0082] 402: The edge node performs anti-replay verification based on the random number in the heartbeat packet. If the anti-replay verification result of the heartbeat packet is passed, the SRv6 data packet is sent to the controller.

[0083] 403: The controller counts the number of SRv6 data packet transmissions and the number of heartbeat packet transmissions, and determines the target valid time of the heartbeat packet based on the number of SRv6 data packet transmissions and the number of heartbeat packet transmissions.

[0084] This step is similar to 302 in the above Figure 3 and will not be described again here.

[0085] 404: The controller sends the target valid time of the heartbeat packet to the terminal via the edge node.

[0086] Based on the same technical concept, an edge node is also provided in the embodiments of the present application. The edge node can implement the heartbeat packet sending method flow applied to the edge node side in the embodiments of the present application.

[0087] Figure 5 is a structural schematic diagram of an edge node provided by the embodiments of the present application. The edge node includes a first receiving module 501, a verification module 502, and a second receiving module 503.

[0088] The first receiving module 501 is configured to receive an SRv6 data packet from the terminal; wherein, the SRH of the SRv6 data packet carries a heartbeat packet;

[0089] The verification module 502 is used to perform anti-replay verification on the heartbeat packet. When it is determined that the anti-replay verification result of the heartbeat packet passes, the SRv6 data packet is forwarded to the controller;

[0090] The second receiving module 503 is used to receive the target valid time of the heartbeat packet from the controller; wherein, the target valid time of the heartbeat packet is determined by the controller based on at least the number of SRv6 data packet transmissions and the number of heartbeat packet transmissions, and is used for the terminal to adjust the transmission time of the next heartbeat packet based on the target valid time of the heartbeat packet.

[0091] In some embodiments, the verification module 502 is specifically configured to:

[0092] Perform anti-replay verification on the heartbeat packet according to the random number in the heartbeat packet;

[0093] If the random number is different from all the random numbers included in the database, it is determined that the anti-replay verification result of the heartbeat packet passes;

[0094] If the random number is the same as any of the random numbers included in the database, it is determined that the anti-replay verification result of the heartbeat packet fails, and an interception operation is performed on the SRv6 data packet.

[0095] Based on the same technical concept, an embodiment of the present application also provides a controller, which can implement the above-mentioned heartbeat packet sending method flow applied to the controller side in the embodiment of the present application.

[0096] Figure 6 A schematic structural diagram of a controller provided in an embodiment of the present application, the controller includes a receiving module 601 and a determining module 602.

[0097] The receiving module 601 is used to receive the SRv6 data packet from the edge node; wherein, a heartbeat packet is carried in the SRH of the SRv6 data packet, and it is forwarded after the edge node determines that the anti-replay verification result of the heartbeat packet passes;

[0098] The determining module 602 is used to determine the target valid time of the heartbeat packet based on the number of SRv6 data packet transmissions and the number of heartbeat packet transmissions; wherein, the target valid time of the heartbeat packet is used for the terminal to adjust the transmission time of the next heartbeat packet based on the target valid time of the heartbeat packet.

[0099] In some embodiments, the determining module 602 is specifically configured to:

[0100] If within the number of SRv6 packet transmissions, among the number of heartbeat packet transmissions, there are N heartbeat packets carried that do not exceed the current heartbeat packet valid time, then based on the current heartbeat packet valid time, increase the heartbeat packet target valid time;

[0101] If within the number of SRv6 packet transmissions, among the number of heartbeat packet transmissions, there are M heartbeat packets carried that exceed the current heartbeat packet valid time, then based on the current heartbeat packet valid time, decrease the heartbeat packet target valid time; where N and M are the same or different and are both preset numbers.

[0102] It should be noted here that the above device provided in the embodiments of the present application can implement all the method steps in the above method embodiments and can achieve the same technical effects. The same parts and beneficial effects as in the method embodiments will not be specifically described in this embodiment.

[0103] Based on the same technical concept, an embodiment of the present application also provides a communication device, and the communication device can implement the functions of the foregoing edge node or controller.

[0104] Figure 7 It is a schematic structural diagram of a communication device provided in an embodiment of the present application.

[0105] At least one processor 701, and a memory 702 connected to at least one processor 701. In the embodiments of the present application, the specific connection medium between the processor 701 and the memory 702 is not limited. Figure 7 Here, it is taken as an example that the processor 701 and the memory 702 are connected through a bus 700. The bus 700 is represented by a thick line in Figure 7 For the connection manners between other components, only a schematic illustration is made and is not limited thereto. The bus 700 can be divided into an address bus, a data bus, a control bus, etc. For the sake of easy representation, Figure 7 only a thick line is used to represent it in, but it does not mean that there is only one bus or one type of bus. Or, the processor 701 can also be called a controller, and the name is not limited.

[0106] In the embodiments of the present application, the memory 702 stores instructions executable by at least one processor 701. By executing the instructions stored in the memory 702, at least one processor 701 can execute a data processing method described above. The processor 701 can implement Figure 5 or Figure 6 the functions of each module in the device shown.

[0107] Among them, the processor 701 is the control center of the device. It can connect various parts of the entire control device through various interfaces and lines. By running or executing instructions stored in the memory 702 and invoking data stored in the memory 702, various functions of the device and data processing are carried out, thereby monitoring the device as a whole.

[0108] In the embodiment of the present application, the processor 701 may include one or more processing units. The processor 701 may integrate an application processor and a modem processor. Among them, the application processor mainly processes the operating system, user interface, application programs, etc., and the modem processor mainly processes wireless communication. It can be understood that the above-mentioned modem processor may not be integrated into the processor 701. In some embodiments, the processor 701 and the memory 702 may be implemented on the same chip. In some embodiments, they may also be separately implemented on independent chips.

[0109] The processor 701 may be a general-purpose processor, such as a central processing unit (CPU), a digital signal processor, an application-specific integrated circuit, a field-programmable gate array, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, which can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of a heartbeat packet sending method disclosed in combination with the embodiments of the present application can be directly embodied as being executed by a hardware processor, or executed by a combination of hardware and software modules in the processor.

[0110] The memory 702 serves as a non-volatile computer-readable storage medium and can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. The memory 702 can include at least one type of storage medium. For example, it can include flash memory, hard disks, multimedia cards, card-type memories, random access memory (RAM), static random access memory (SRAM), programmable read-only memory (PROM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic memories, magnetic disks, optical discs, and so on. The memory 702 is any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 702 in the embodiments of the present application can also be a circuit or any other device capable of implementing a storage function, for storing program instructions and / or data.

[0111] By programming the design of the processor 701, the code corresponding to the heartbeat packet sending method introduced in the foregoing embodiments can be solidified into the chip, so that the chip can execute Figure 2 or Figure 3 the heartbeat packet sending method of the embodiment shown. How to program the design of the processor 701 is a well-known technology to those skilled in the art and will not be elaborated here.

[0112] It should be noted here that the above communication device provided in the embodiments of the present application can implement all the method steps implemented in the above method embodiments and can achieve the same technical effects. The same parts and beneficial effects as those in the method embodiments will not be specifically elaborated in this embodiment.

[0113] Based on the same technical concept, the embodiments of the present application provide a computer storage medium. The computer storage medium includes: computer program code, which when run on a computer, causes the computer to execute a heartbeat packet sending method as described in any of the foregoing discussions. Since the principle of the above computer storage medium for solving problems is similar to that of a heartbeat packet sending method, the implementation of the above computer storage medium can refer to the implementation of the method, and the repeated parts will not be elaborated.

[0114] In a specific implementation process, the computer storage medium may include: various storage media that can store program codes, such as a Universal Serial Bus Flash Drive (USB), a mobile hard disk, a Read-Only Memory (ROM), a Random Access Memory (RAM), a magnetic disk, or an optical disc.

[0115] Based on the same technical concept, an embodiment of the present application further provides a computer program product, which includes: computer program code. When the computer program code runs on a computer, it causes the computer to execute a method for sending a heartbeat packet as described in any of the foregoing discussions. Since the principle of the computer program product for solving problems is similar to that of a method for sending a heartbeat packet, the implementation of the computer program product can refer to the implementation of the method, and the repeated parts will not be described again.

[0116] The computer program product can adopt any combination of one or more readable media. The readable media can be a readable signal medium or a readable storage medium. The readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or component, or any combination of the above. More specific examples (a non-exhaustive list) of the readable storage medium include: an electrical connection with one or more wires, a portable disk, a hard disk, a Random Access Memory (RAM), a Read-Only Memory (ROM), an Erasable Programmable Read-Only Memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0117] The method in the present application can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in the form of a computer program product in whole or in part. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in the present application are executed in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device, a core network device, an OAM, or other programmable devices.

[0118] The computer program or instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another. For example, the computer program or instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired or wireless manner. The computer-readable storage medium can be any available medium that can be accessed by a computer, or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium, such as a floppy disk, hard disk, or magnetic tape; it can also be an optical medium, such as a digital video disc; or it can be a semiconductor medium, such as a solid-state drive. The computer-readable storage medium can be a volatile or non-volatile storage medium, or can include both volatile and non-volatile types of storage media.

[0119] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, system, or computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage and optical storage, etc.) that contain computer-usable program code.

[0120] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing device generate a device for implementing the specified functions in Figure 1 one or more of the processes or multiple processes and / or blocks Figure 1 one or more of the blocks or multiple blocks. These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device that implements the specified functions in Figure 1 one or more of the processes or multiple processes and / or blocks Figure 1 one or more of the blocks or multiple blocks.

[0121] These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus, so that a series of operation steps are performed on the computer or other programmable apparatus to produce a computer-implemented process, thereby the instructions executed on the computer or other programmable apparatus provide steps for realizing the processing in the process Figure 1 one process or a plurality of processes and / or blocks Figure 1 steps for realizing the functions specified in one block or a plurality of blocks.

[0122] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these changes and modifications.

Claims

1. A heartbeat packet sending method, characterized in that: Applied to an edge node, the method comprises: Receiving an IPv6 segment routing SRv6 data packet from a terminal; wherein a segment routing extension header SRH of the SRv6 data packet carries a heartbeat packet; Performing an anti-replay check on the heartbeat packet, and when it is determined that the anti-replay check result of the heartbeat packet is passed, forwarding the SRv6 data packet to the controller; Receive a heartbeat packet target validity time from the controller; wherein the heartbeat packet target validity time is determined by the controller based at least on the number of SRv6 data packet transmissions and the number of heartbeat packet transmissions, and is used by the terminal to adjust the transmission time of the next heartbeat packet based on the heartbeat packet target validity time.

2. The method according to claim 1, characterized in that The anti-replay verification of the heartbeat packet includes: Performing anti-replay verification on the heartbeat packet according to the random number in the heartbeat packet; If the random number is different from the random number contained in the database, determining that the anti-replay verification result of the heartbeat packet is passed; If the random number is the same as the random number contained in the database, it is determined that the anti-replay check result of the heartbeat packet is failed, and an interception operation is performed on the SRv6 data packet.

3. The method according to claim 1, characterized in that The heartbeat packet also includes the account information of the terminal, and the account information is generated by the terminal encrypting the user account name and user password using an encryption algorithm.

4. The method according to claim 1 or 3, characterized in that The heartbeat packet also includes access information of the terminal, and the access information includes at least the user access permission level; wherein the user access permission level is associated with a preset heartbeat packet validity period.

5. A heartbeat packet sending method, characterized in that: Applied to a controller, the method comprises: Receiving an IPv6 segment routing SRv6 data packet from an edge node; wherein the segment routing extension header SRH of the SRv6 data packet carries a heartbeat packet, which is forwarded after the edge node determines that the anti-replay check result of the heartbeat packet is passed; Based on the number of SRv6 data packet transmissions and the number of heartbeat packet transmissions, the heartbeat packet target validity period is determined; wherein the heartbeat packet target validity period is used by the terminal to adjust the transmission time of the next heartbeat packet based on the heartbeat packet target validity period.

6. The method according to claim 5, characterized in that The heartbeat packet also includes the account information of the terminal, and the account information is generated by the terminal encrypting the user account name and user password using an encryption algorithm.

7. The method according to claim 5 or 6, characterized in that The heartbeat packet also includes access information of the terminal, and the access information includes the user access permission level; wherein the user access permission level is associated with a preset heartbeat packet validity period.

8. The method according to claim 5, characterized in that The determining of the target effective time of the heartbeat packet based on the number of times the SRv6 data packet is sent and the number of times the heartbeat packet is sent includes: If, within the number of times the SRv6 data packet is sent, the heartbeat packets carried in N times of the heartbeat packet sending times do not exceed the current heartbeat packet validity period, then based on the current heartbeat packet validity period, the heartbeat packet target validity period is increased; If, within the number of times the SRv6 data packet is sent, the heartbeat packets carried in M ​​of the heartbeat packet transmission times exceed the current heartbeat packet validity period, then based on the current heartbeat packet validity period, the heartbeat packet target validity period is reduced; wherein, N and M are the same or different, and are both preset numbers.

9. An edge node, characterized in that: include: A first receiving module is used to receive an IPv6 segment routing SRv6 data packet from a terminal; wherein a segment routing extension header SRH of the SRv6 data packet carries a heartbeat packet; A verification module, configured to perform an anti-replay verification on the heartbeat packet, and when it is determined that the anti-replay verification result of the heartbeat packet is passed, forwarding the SRv6 data packet to the controller; The second receiving module is used to receive the target effective time of the heartbeat packet from the controller; wherein the target effective time of the heartbeat packet is determined by the controller based on at least the number of SRv6 data packet transmissions and the number of heartbeat packet transmissions, and is used by the terminal to adjust the transmission time of the next heartbeat packet based on the target effective time of the heartbeat packet.

10. A controller, characterized in that: include: A receiving module, used to receive an IPv6 segment routing SRv6 data packet from an edge node; wherein the segment routing extension header SRH of the SRv6 data packet carries a heartbeat packet, which is forwarded after the edge node determines that the anti-replay check result of the heartbeat packet is passed; A determination module is used to determine the target effective time of the heartbeat packet based on the number of SRv6 data packet transmissions and the number of heartbeat packet transmissions; wherein the target effective time of the heartbeat packet is used by the terminal to adjust the transmission time of the next heartbeat packet based on the target effective time of the heartbeat packet.

11. A communication device, characterized in that: include: Memory, used to store computer programs; A processor, for implementing the method described in any one of claims 1 to 4, or implementing the method described in any one of claims 5 to 8, when executing the computer program stored in the memory.

12. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 5 is implemented, or the method according to any one of claims 5 to 8 is implemented.