Border gateway protocol VPN routing source verification device and method
By designing a boundary gateway protocol VPN routing source verification device in the VPN network environment, and using the expansion of VPN routing attributes in the RTR protocol and ROA, the problem that existing RPKI technology is difficult to prevent routing prefix hijacking in the VPN network is solved, and effective checksum routing security risks are achieved for VPN routing information.
Patent Information
- Application Number
- CN202510366797.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-26
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2045-03-26
AI Technical Summary
Existing RPKI technologies are difficult to prevent the risk of routing prefix hijacking in VPN network environments.
A border gateway protocol VPN routing source verification device is designed, including MP-BGP protocol module, RTR protocol module and VPN routing source verification module. By expanding the VPN routing attributes in the RTR protocol and ROA, verification of VPN routing information is realized.
This device can effectively verify the routing source in the VPN network environment, prevent routing prefix hijacking, and significantly improve the routing security risk resistance of VPN users.
Smart Images

Figure CN120151264A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical fields of network management and routing security protection, and in particular, to a border gateway protocol VPN routing source verification device and method. Background Art
[0002] RPKI (Resource Public Key Infrastructure) is an architecture for enhancing the security of BGP (Border Gateway Protocol) routing on the Internet. By defining the legitimate IP prefixes and ASNs (Autonomous System Numbers) held by entities and providing cryptographic guarantees for route origin verification, it avoids malicious attackers from spreading false routing information, ensuring the security of inter-domain routing in the autonomous system AS (Autonomous System) and the correct transmission of data.
[0003] The working principle of RPKI is as follows: The resource holder creates a route origin authorization object (ROA, Route Origin Authorisations), which includes elements such as the IP address prefixes owned by the holder, the maximum prefix length, and the ASN for which the prefix is announced for routing. The ROA is signed with a digital certificate, and the relevant certificates and ROAs are stored in the RPKI repository. The network management department of an operator or other organization deploys an RP (Relying Party), periodically synchronizes the certificates and ROAs from the RPKI repository, and transmits the verified ROA information to the BGP router at the AS boundary through the RTR protocol (Resource Public Key Infrastructure to Router Protocol). When receiving a route advertisement message, the BGP router performs route origin verification (ROV, Route Origin Validation), that is, checks whether the IP address prefix length and the origin ASN match the ROA information, and generates one of the three verification results: Valid, Invalid, or Unknown. Then, according to the set policy, it receives or discards the route, thereby preventing incorrect route advertisements and enhancing network security.
[0004] Currently, the RPKI technology system performs routing origin verification through the binding relationship between IP address prefixes and origin ASNs, which can effectively prevent security risks such as eBGP routing prefix hijacking between different AS domains on the Internet. However, in a large number of large internal private networks of the military, operators, financial institutions or other organizations, due to security considerations, a large number of network users are located within MPLS BGP VPNs. The IP address prefixes are published through BGP VPNv4 / VPNv6 or EVPN address families, and the risk of routing prefix hijacking between different users within the VPN cannot be prevented by the existing RPKI technology. Summary of the Invention
[0005] An object of the present invention is to solve at least one technical problem in the background art and provide a Border Gateway Protocol VPN routing source verification device and method.
[0006] To achieve the above object, the present invention provides a Border Gateway Protocol VPN routing source verification device, including: an MP-BGP protocol module, an RTR protocol module, and a VPN routing source verification module;
[0007] The MP-BGP protocol module runs the MP-BGP routing protocol, establishes an MP-BGP neighbor relationship with the PE router in the network system, receives intra-domain and cross-domain VPN routing information, and sends it to the VPN routing source verification module for verification according to the routing type;
[0008] The RTR protocol module obtains the verified VPN extended ROA from the RP dependent party in the network system through the RTR protocol and caches it;
[0009] The VPN routing source verification module combines the VPN routing information received by the MP-BGP protocol module and the VPN extended ROA cached by the RTR protocol module, and performs routing source verification according to the IP address prefix, maximum prefix length, ASN, and additional VPN attribute values to determine whether the routing is valid.
[0010] According to one aspect of the present invention, the VPN routing is VPNv4 or VPNv6 address family routing, and the VPN routing source verification module verifies by comparing the corresponding fields of the VPN extended ROA according to the IP address prefix, maximum prefix length, ASN, RD, and RT in the VPN routing information.
[0011] According to one aspect of the present invention, the RTR protocol module extends the PDU type of the RTR protocol, defines VPNv4 prefix PDU and VPNv6 prefix PDU, and realizes the VPN extension of the ROA.
[0012] According to one aspect of the present invention, the VPN route is an EVPN address family type 5 route, and the VPN route source verification module verifies by comparing the corresponding fields of the VPN extended ROA based on the IP address prefix, maximum prefix length, ASN, RD, RT, and L3VNI in the VPN route information.
[0013] According to one aspect of the present invention, the RTR protocol module extends the PDU type of the RTR protocol, defines an IP address prefix PDU of EVPN address family type 5, and realizes the VPN extension of the ROA.
[0014] According to one aspect of the present invention, the length of the VPNv4 prefix PDU is 36 bytes, and the format is that an 8-byte RD field and an 8-byte RT field are added to the standard 20-byte IPv4 prefix PDU, and the added RD field and RT field are located after the IPv4 prefix field;
[0015] The length of the VPNv6 prefix PDU is 48 bytes, and the format is that an 8-byte RD field and an 8-byte RT field are added to the standard 32-byte IPv6 prefix PDU, and the added RD field and RT field are located after the IPv6 prefix field.
[0016] According to one aspect of the present invention, the IP address prefix PDU of EVPN address family type 5 includes an EVPN address family type 5 IPv4 prefix PDU and an EVPN address family type 5 IPv6 prefix PDU. The length of the EVPN address family type 5 IPv4 prefix PDU is 39 bytes, and the format is that an 8-byte RD field, an 8-byte RT field, and a 3-byte L3VNI field are added to the standard 20-byte IPv4 prefix PDU, and the added RD field, RT field, and L3VNI field are located after the IPv4 prefix field; the length of the EVPN address family type 5 IPv6 prefix PDU is 51 bytes, and the format is that an 8-byte RD field, an 8-byte RT field, and a 3-byte L3VNI field are added to the standard 32-byte IPv6 prefix PDU, and the added RD field, RT field, and L3VNI field are located after the IPv6 prefix field.
[0017] To achieve the above object, the present invention also provides a method for verifying the source of a border gateway protocol VPN route implemented by the above border gateway protocol VPN route source verification device, including:
[0018] The MP-BGP protocol module establishes an MP-BGP peer with the PE router, receives and stores VPN route information, and sends the VPN route information to the VPN route source verification module;
[0019] The RTR protocol module establishes a logical connection with the RP dependent party, obtains the verified VPN extended ROA and caches it.
[0020] The VPN route source verification module performs route source verification based on the VPN route information and the VPN extended ROA, and outputs a verification result.
[0021] According to one aspect of the present invention, when the VPN route source verification module performs route source verification based on the VPN route information and the VPN extended ROA, the output verification result is:
[0022] Taking the RD value as a reference value, when the VPN route source verification module verifies the VPN route information, it first compares whether the RD value in the VPN route information can match the RD value in the VPN extended ROA. If they do not match, the route source verification result is unknown. If they match, it continues to verify the route according to the IPv4 or IPv6 route source verification rules in the VPN route information and the VPN extended ROA with the same RD value, and obtains one of the three verification results: valid, invalid, or unknown.
[0023] According to one aspect of the present invention, when the VPN route source verification module performs route source verification based on the VPN route information and the VPN extended ROA, the output verification result is:
[0024] Taking the RT value as a reference value, when the VPN route source verification module verifies the VPN route information, it first compares whether the RT value in the VPN route information can match the RT value in the VPN extended ROA. If they do not match, the route source verification result is unknown. If they match, it continues to verify the route according to the IPv4 or IPv6 route source verification rules in the VPN route information and the VPN extended ROA with the same RT value, and obtains one of the three verification results: valid, invalid, or unknown.
[0025] According to one aspect of the present invention, when the VPN route source verification module performs route source verification based on the VPN route information and the VPN extended ROA, the output verification result is:
[0026] For EVPN address family type 5 routes, taking the L3VNI value as a reference value, when the VPN route source verification module verifies the VPN route information, it first compares whether the L3VNI value in the VPN route information can match the L3VNI value in the VPN extended ROA. If they do not match, the route source verification result is unknown. If they match, it continues to verify the route according to the IPv4 or IPv6 route source verification rules in the VPN route information and the VPN extended ROA with the same L3VNI value, and obtains one of the three verification results: valid, invalid, or unknown.
[0027] To achieve the above object, the present invention further provides an electronic device, including a processor, a memory, and a computer program stored on the memory and executable on the processor. When the computer program is executed by the processor, it implements the above-mentioned method for verifying the source of BGP VPN routes.
[0028] To achieve the above object, the present invention further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the above-mentioned method for verifying the source of BGP VPN routes.
[0029] According to the solution of the present invention, the BGP VPN route source verification device and method provided by the present invention break through the limitation that the existing RPKI technology system can only verify the origin of ordinary public network routes by expanding the VPN route attributes in the RTR protocol and ROA, and designing a calculation method for verifying the origin of VPN routes, enabling it to be applied to the VPN network environment, greatly expanding the applicable scenarios, application scope and use value of the RPKI technology, and greatly enhancing the ability of VPN users to resist routing security risks. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] Figure 1 Schematically shows the functional structure and connection relationship diagram of a BGP VPN route source verification device according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0031] Now, the content of the present invention will be described with reference to exemplary embodiments. It should be understood that the described embodiments are only for enabling those of ordinary skill in the art to better understand and thus implement the content of the present invention, rather than implying any limitation to the scope of the present invention.
[0032] As used herein, the term "comprising" and its variants are to be construed as open-ended terms meaning "including but not limited to". The term "based on" is to be construed as "at least partially based on". The terms "one embodiment" and "an embodiment" are to be construed as "at least one embodiment".
[0033] Figure 1 Schematically shows the functional structure and connection relationship diagram of a BGP VPN route source verification device according to an embodiment of the present invention. As Figure 1 shown, in this embodiment, a Border Gateway Protocol (BGP) VPN route source verification device, which is applied to a network system, includes: an MP-BGP protocol module, an RTR protocol module, and a VPN route source verification module;
[0034] The MP-BGP protocol module runs the MP-BGP routing protocol, establishes an MP-BGP neighbor relationship with the PE routers in the network system, receives intra-domain and inter-domain VPN routing entries, and sends them to the VPN routing source verification module for verification according to the routing type.
[0035] The RTR protocol module obtains the verified VPN extended ROA from the RP (Relying Party) in the network system through the RTR protocol and caches it.
[0036] The VPN routing source verification module combines the VPN routing information received by the MP-BGP protocol module and the VPN extended ROA cached by the RTR protocol module, and performs routing source verification according to the IP address prefix, maximum prefix length, ASN, and additional VPN attribute values to determine whether the route is valid.
[0037] Furthermore, according to an embodiment of the present invention, in the corresponding network scenario, the VPN route is a VPNv4 or VPNv6 address family route, and the VPN routing source verification module verifies by comparing the corresponding fields of the VPN extended ROA based on the IP address prefix, maximum prefix length, ASN, RD (Route Distinguisher), and RT (Route Target) in the VPN routing information.
[0038] In this embodiment, the RTR protocol module extends the PDU type of the RTR protocol, defines the VPNv4 prefix PDU (PDUType 14) and the VPNv6 prefix PDU (PDU Type 16), and realizes the VPN extension of the ROA.
[0039] In this embodiment, the length of the VPNv4 prefix PDU (PDU Type 14) is 36 bytes, and the format is that an 8-byte RD field and an 8-byte RT field are added to the standard 20-byte IPv4 prefix PDU, and the added RD field and RT field are located after the IPv4 prefix field.
[0040] In this embodiment, the length of the VPNv6 prefix PDU (PDU Type 16) is 48 bytes, and the format is that an 8-byte RD field and an 8-byte RT field are added to the standard 32-byte IPv6 prefix PDU, and the added RD field and RT field are located after the IPv6 prefix field.
[0041] Furthermore, according to another embodiment of the present invention, in the corresponding network scenario, the VPN route is an EVPN address family type 5 route, and the VPN routing source verification module verifies by comparing the corresponding fields of the VPN extended ROA based on the IP address prefix, maximum prefix length, ASN, RD, RT, and L3VNI in the VPN routing information.
[0042] In this embodiment, the RTR protocol module extends the PDU types of the RTR protocol, defines the IPv4 prefix PDU (PDU Type 17) of EVPN address family type 5 and the IPv6 prefix PDU (PDU Type 18) of EVPN address family type 5, and realizes the VPN extension of ROA.
[0043] In this embodiment, the length of the EVPN address family type 5 IPv4 prefix PDU (PDU Type 17) is 39 bytes, and the format is that an 8-byte RD field, an 8-byte RT field, and a 3-byte L3VNI field are added to the standard 20-byte IPv4 prefix PDU, and the added RD field, RT field, and L3VNI field are located after the IPv4 prefix field; the length of the EVPN address family type 5 IPv6 prefix PDU (PDU Type 18) is 51 bytes, and the format is that an 8-byte RD field, an 8-byte RT field, and a 3-byte L3VNI field are added to the standard 32-byte IPv6 prefix PDU, and the added RD field, RT field, and L3VNI field are located after the IPv6 prefix field.
[0044] According to the solution of the present invention, the BGP VPN route origin verification device and method provided by the present invention break through the limitation that the existing RPKI technology system can only perform origin verification on ordinary public network routes by expanding the VPN route attributes in the RTR protocol and ROA and designing a VPN route origin verification calculation method, enabling it to be applied to the VPN network environment, greatly expanding the applicable scenarios, application scope, and usage value of the RPKI technology, and greatly enhancing the ability of VPN users to resist routing security risks.
[0045] Further, to achieve the above object, the present invention also provides a border gateway protocol VPN route origin verification method implemented by the above border gateway protocol VPN route origin verification device, including:
[0046] The MP-BGP protocol module establishes an MP-BGP peer with the PE router, receives and stores VPN route information, and sends the VPN route information to the VPN route origin verification module;
[0047] The RTR protocol module establishes a logical connection with the RP dependent party, obtains the verified VPN extended ROA and caches it;
[0048] The VPN route origin verification module performs route origin verification according to the VPN route information and the VPN extended ROA, and outputs a verification result.
[0049] Further, according to an embodiment of the present invention, the VPN route origin verification module performs route origin verification according to the VPN route information and the VPN extended ROA, and the output verification result is:
[0050] Taking the RD value as a reference value, when the VPN route source verification module verifies the VPN route information, it first compares whether the RD value in the VPN route information can match the RD value in the VPN extended ROA. If they do not match, the route source verification result is unknown. If they match, it continues to verify the route according to the IPv4 or IPv6 route source verification rules in the VPN route information and the VPN extended ROA with the same RD value, and obtains one of the three verification results: valid, invalid, or unknown.
[0051] Among them, verifying the route according to the IPv4 or IPv6 route source verification rules and obtaining one of the three verification results: valid, invalid, or unknown is:
[0052] According to the general rules for verifying the origin of BGP routes for ordinary IPv4 or IPv6, compare the IP address prefix, mask length, and origin AS number to obtain one of the three verification results: valid, invalid, or unknown. In this embodiment, the general verification rule is the ordinary RPKI route verification rule.
[0053] Furthermore, according to another embodiment of the present invention, the VPN route source verification module performs route source verification based on the VPN route information and the VPN extended ROA, and the output verification result is:
[0054] Taking the RT value as a reference value, when the VPN route source verification module verifies the VPN route information, it first compares whether the RT value in the VPN route information can match the RT value in the VPN extended ROA. If they do not match, the route source verification result is unknown. If they match, it continues to verify the route according to the IPv4 or IPv6 route source verification rules in the VPN route information and the VPN extended ROA with the same RT value, and obtains one of the three verification results: valid, invalid, or unknown. In this embodiment, the IPv4 or IPv6 route source verification rules also use the ordinary RPKI route verification rule.
[0055] Furthermore, according to the third embodiment of the present invention, the VPN route source verification module performs route source verification based on the VPN route information and the VPN extended ROA, and the output verification result is:
[0056] For EVPN address family type 5 routes, with the L3VNI value as the reference value, when the VPN route source verification module verifies the VPN route information, it first compares whether the L3VNI value in the VPN route information can match the L3VNI value in the VPN extended ROA. If they do not match, the route source verification result is unknown. If they match, the route is further verified according to the IPv4 or IPv6 route source verification rules in the VPN route information and the VPN extended ROA with the same L3VNI, and one of the three verification results of valid, invalid, or unknown is obtained. In this embodiment, the IPv4 or IPv6 route source verification rules also use the ordinary RPKI route verification rules.
[0057] According to the solution of the present invention, the BGP VPN route source verification device and method provided by the present invention break through the limitation that the existing RPKI technology system can only perform origin verification on ordinary public network routes by expanding the VPN route attributes in the RTR protocol and ROA and designing a VPN route origin verification calculation method, enabling it to be applied in the VPN network environment, greatly expanding the applicable scenarios, application scope, and usage value of the RPKI technology, and greatly enhancing the ability of VPN users to resist routing security risks.
[0058] Further, to achieve the above object, the present invention also provides an electronic device, including a processor, a memory, and a computer program stored on the memory and executable on the processor. When the computer program is executed by the processor, the border gateway protocol VPN route source verification method as described above is implemented.
[0059] Further, to achieve the above object, the present invention also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by the processor, the border gateway protocol VPN route source verification method as described above is implemented.
[0060] Those of ordinary skill in the art can realize that the modules and algorithm steps described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.
[0061] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the above-described devices and equipment can refer to the corresponding processes in the foregoing method embodiments and will not be repeated herein.
[0062] In the embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the modules is only a logical function division. In actual implementation, there may be other division methods. For example, multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of the devices or modules can be in electrical, mechanical or other forms.
[0063] The modules described as separate components may or may not be physically separated. The components shown as modules may or may not be physical modules, that is, they can be located in one place or distributed to multiple network modules. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of the embodiments of the present invention.
[0064] In addition, each functional module in the embodiments of the present invention can be integrated in a processing module, or each module can exist physically alone, or two or more modules can be integrated in one module.
[0065] If the functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method for sending / receiving energy-saving signals in various embodiments of the present invention. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, ROM, RAM, magnetic disks, or optical discs that can store program codes.
[0066] The above description is only the preferred embodiment of the present application and the explanation of the applied technical principles. Those skilled in the art should understand that the scope of the invention involved in the present application is not limited to the technical solution formed by the specific combination of the above technical features, but should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the inventive concept. For example, the technical solutions formed by mutually replacing the above features with the (but not limited to) technical features with similar functions disclosed in the present application.
[0067] It should be understood that the magnitudes of the sequence numbers of the steps in the summary of the invention and the embodiments of the present invention do not absolutely mean the sequence of execution. The execution sequence of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present invention.
Claims
1. A border gateway protocol VPN routing source verification device, characterized in that: include: MP-BGP protocol module, RTR protocol module and VPN routing source verification module; The MP-BGP protocol module runs the MP-BGP routing protocol, establishes an MP-BGP neighbor relationship with a PE router in the network system, receives intra-domain and inter-domain VPN routing information, and sends it to the VPN routing source verification module for verification according to the routing type; The RTR protocol module obtains the verified VPN extended ROA from the RP relying party in the network system through the RTR protocol and caches it; The VPN route source verification module combines the VPN route information received by the MP-BGP protocol module and the VPN extended ROA cached by the RTR protocol module, and performs route source verification according to the IP address prefix, maximum prefix length, ASN and additional VPN attribute value to determine whether the route is valid.
2. The border gateway protocol VPN routing source verification device according to claim 1, characterized in that: The VPN route is a VPNv4 or VPNv6 address cluster route, and the VPN route source verification module verifies the corresponding fields of the VPN extended ROA according to the IP address prefix, maximum prefix length, ASN, RD and RT in the VPN route information.
3. The border gateway protocol VPN routing source verification device according to claim 2, characterized in that: The RTR protocol module extends the PDU type of the RTR protocol, defines the VPNv4 prefix PDU and the VPNv6 prefix PDU, and implements VPN extension of the ROA.
4. The border gateway protocol VPN routing source verification device according to claim 1, characterized in that: The VPN route is an EVPN address cluster type 5 route, and the VPN route source verification module verifies the corresponding fields of the VPN extended ROA according to the IP address prefix, maximum prefix length, ASN, RD, RT and L3VNI in the VPN route information.
5. The border gateway protocol VPN routing source verification device according to claim 4, characterized in that: The RTR protocol module extends the PDU type of the RTR protocol, defines the IP address prefix PDU of the EVPN address cluster type 5, and implements VPN extension of the ROA.
6. The border gateway protocol VPN routing source verification device according to claim 3, characterized in that: The VPNv4 prefix PDU has a length of 36 bytes and a format of adding an 8-byte RD field and an 8-byte RT field to a standard 20-byte IPv4 prefix PDU, and the added RD field and RT field are located after the IPv4 prefix field; The VPNv6 prefix PDU has a length of 48 bytes and a format of adding an 8-byte RD field and an 8-byte RT field to a standard 32-byte IPv6 prefix PDU. The added RD field and RT field are located after the IPv6 prefix field.
7. The border gateway protocol VPN routing source verification device according to claim 5, characterized in that: The IP address prefix PDU of the EVPN address cluster type 5 includes an EVPN address cluster type 5 IPv4 prefix PDU and an EVPN address cluster type 5 IPv6 prefix PDU. The length of the EVPN address cluster type 5 IPv4 prefix PDU is 39 bytes, and the format is that an 8-byte RD field, an 8-byte RT field, and a 3-byte L3VNI field are added to the standard 20-byte IPv4 prefix PDU, and the added RD field, RT field, and L3VNI field are located after the IPv4 prefix field; the length of the EVPN address cluster type 5 IPv6 prefix PDU is 51 bytes, and the format is that an 8-byte RD field, an 8-byte RT field, and a 3-byte L3VNI field are added to the standard 32-byte IPv6 prefix PDU, and the added RD field, RT field, and L3VNI field are located after the IPv6 prefix field.
8. A method for verifying the routing source of a Border Gateway Protocol VPN implemented by the Border Gateway Protocol VPN routing source verification device according to any one of claims 1 to 7, characterized in that: include: The MP-BGP protocol module establishes an MP-BGP peer with the PE router, receives and stores VPN routing information, and sends the VPN routing information to the VPN routing source verification module; The RTR protocol module establishes a logical connection with the RP relying party, obtains the verified VPN extended ROA and caches it; The VPN route source verification module performs route source verification according to VPN route information and VPN extended ROA, and outputs the verification result.
9. The Border Gateway Protocol VPN routing source verification method according to claim 8, characterized in that: The VPN route source verification module performs route source verification according to the VPN route information and the VPN extended ROA, and outputs the verification result as follows: Taking the RD value as a reference value, when the VPN routing source verification module verifies the VPN routing information, it first compares whether the RD value in the VPN routing information can match the RD value in the VPN extended ROA. If they do not match, the routing source verification result is unknown. If they match, the routing is verified according to the IPv4 or IPv6 routing source verification rules in the VPN routing information and the VPN extended ROA with the same RD value, and one of the three verification results of valid, invalid or unknown is obtained.
10. The border gateway protocol VPN routing source verification method according to claim 8, characterized in that: The VPN route source verification module performs route source verification according to the VPN route information and the VPN extended ROA, and outputs the verification result as follows: Taking the RT value as a reference value, when the VPN routing source verification module verifies the VPN routing information, it first compares whether the RT value in the VPN routing information can match the RT value in the VPN extended ROA. If they do not match, the routing source verification result is unknown. If they match, the routing is verified according to the IPv4 or IPv6 routing source verification rules in the VPN routing information and the VPN extended ROA with the same RT value, and one of the three verification results of valid, invalid or unknown is obtained.
11. The border gateway protocol VPN routing source verification method according to claim 8, characterized in that: The VPN route source verification module performs route source verification according to the VPN route information and the VPN extended ROA, and outputs the verification result as follows: For EVPN address cluster type 5 routing, the L3VNI value is used as a reference value. When the VPN routing source verification module verifies the VPN routing information, it first compares whether the L3VNI value in the VPN routing information can match the L3VNI value in the VPN extended ROA. If there is no match, the routing source verification result is unknown. If there is a match, the routing is verified according to the IPv4 or IPv6 routing source verification rules in the VPN routing information and VPN extended ROA of the same L3VNI, and one of the three verification results of valid, invalid or unknown is obtained.
12. An electronic device, characterized in that The invention comprises a processor, a memory and a computer program stored in the memory and executable on the processor, wherein when the computer program is executed by the processor, the border gateway protocol VPN routing source verification method as described in any one of claims 8 to 11 is implemented.
13. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the border gateway protocol VPN routing source verification method according to any one of claims 8 to 11 is implemented.
Citation Information
Patent Citations
Quality detection method and device for routing origin authorization
CN112003822A
Effective routing origin synchronization method and system based on fact ownership
CN113055288A
Route verification method and device, data sending method and device, equipment and storage medium
CN115208600A
Routing resource configuration method and device, electronic equipment and storage medium
CN117221202A
Source address verification method and device of SRv6 network
CN117997625A