Constraint authentication method and device for routing outbound rule
By introducing tag (TAG) attributes and signature authentication mechanisms into the routing and outbound policy of the autonomous system, the problem that the autonomous system outbound policy fails to effectively follow the Gao-Rexford extension principle, and the secure dissemination of routing information and the improvement of network security is achieved.
Patent Information
- Application Number
- CN202510275491.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-10
- Publication Date
- 2025-06-20
AI Technical Summary
In the prior art, the autonomous system fails to effectively follow the Gao-Rexford extension principle in outbound strategy, resulting in illegal dissemination of routing information and network security risks.
By introducing tag (TAG) attributes and signature authentication mechanisms, detection and prevention of violations of route outbound constraints. Specific steps include generating and signing tags when the packet leaves the router, verifying tag attribute values when entering the router, and updating tags when leaving the router again.
It effectively improves the security of inter-domain routing propagation, ensures the authenticity, integrity and source traceability of routing information, prevents malicious nodes from covering up, and maintains the overall security of the network.
Smart Images

Figure CN120185871A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of computer network information security, and particularly to a constraint authentication method and device for routing outbound rules. Background Art
[0002] Inter-domain routing refers to the process of exchanging routing information between different autonomous systems (AS). An autonomous system is a basic organizational unit of the Internet, usually managed by one or more network operators. The following are the common relationships between autonomous systems and their roles in inter-domain routing:
[0003] Customer-Provider relationship: In this relationship, one AS (customer) establishes a connection with another AS (provider) by paying a fee to send its traffic to other parts of the Internet. The customer AS usually sends its traffic to the provider AS, and the provider AS is responsible for forwarding the traffic to other ASes.
[0004] Peering relationship: Peering means that two different ASes directly exchange routing information without going through a third-party AS. This relationship is usually based on the principle of reciprocity, where both sides exchange traffic for free, but it can also be based on a commercial contract, in which one or both sides may need to pay a fee.
[0005] Transit relationship: A transit relationship is formed when one AS (transit provider) allows another AS (customer) to send traffic through its network to other parts of the Internet. This is similar to the customer-provider relationship, but the transit provider usually has a wider network coverage and can provide traffic transmission services across multiple ASes.
[0006] Under normal circumstances, routing policies include inbound policies and outbound policies. An inbound policy specifies whether to reject or permit received routes and assigns a local preference to indicate the degree of preference for that route. An outbound policy allows an autonomous system to determine whether to propagate its best routes to its neighbors. Based on commercial interests, most autonomous systems follow the Gao-Rexford extension principle in their outbound policy settings: when exporting to a provider or peer network, an autonomous system can export its own routes and customer routes, but generally does not export the routes of its providers or peer networks; when exporting to a customer or peer autonomous system, an autonomous system can export its own routes and customer routes, as well as the routes of its providers or peer networks. These outbound rules indicate that the AS path should be valley-free, that is, after experiencing a provider-to-customer edge or a peer-to-peer edge, the AS path cannot cross a customer-to-provider edge or another peer-to-peer edge. In other words, a provider-to-customer or peer-to-peer-to-peer edge can only be followed by a provider-to-customer or peer-to-peer edge. However, it has been observed that some announced AS paths do not conform to the valley-free property, which means that the common policy is not followed in these cases.
[0007] In inter-domain routing of the Internet, autonomous systems (ASes) are the basic organizational units, and their relationships mainly include forms such as customer-provider, adjacency, and transit. These relationships have an important impact on the exchange and dissemination of routing information. In the prior art, autonomous systems generally follow the Gao-Rexford extension principle in their outbound policies to ensure network stability and security. However, in actual operation, some AS paths do not follow this principle, resulting in the illegal dissemination of routing information and posing risks to network security.
[0008] Therefore, there is an urgent need to specify a set of verifiable routing outbound constraint detection mechanisms to ensure that routing announcements conform to the Gao-Rexford principle and guarantee the legitimate interests among ASes. Summary of the Invention
[0009] The present invention aims to solve at least one of the technical problems in the related art to some extent.
[0010] The present invention proposes a constraint authentication method for routing outbound rules, aiming to solve the problem that BGP routes violate the outbound principle. By introducing the label (TAG) attribute and signature authentication mechanism, it can effectively detect and prevent the occurrence of violations of routing outbound constraints.
[0011] Another object of the present invention is to propose a constraint authentication device for routing outbound rules.
[0012] The third object of the present invention is to provide a computer device.
[0013] The fourth object of the present invention is to provide a non - transitory computer - readable storage medium.
[0014] To achieve the above object, on the one hand, the present invention provides a constraint authentication method for routing outbound rules, including:
[0015] When a data packet leaves the router, perform label generation and signature operations according to predefined router export rules;
[0016] When a data packet enters the router, verify the label attribute value according to predefined router import rules;
[0017] When the data packet leaves the router again, perform an update operation on the TAG according to predefined router export rules.
[0018] The constraint authentication method for routing outbound rules according to the embodiments of the present invention may further have the following additional technical features:
[0019] In an embodiment of the present invention, when a data packet leaves the router, performing label generation and signature operations according to predefined router export rules includes:
[0020] When the router sends a routing announcement to a customer or a peer, if it is determined that there is no TAG attribute in the BGP Path Attribute, add the TAG attribute thereto;
[0021] The value of the TAG attribute is equal to the autonomous system number ASN of the local AS, and the local AS uses its own private key to sign the generated TAG to obtain TAG sigX (X).
[0022] In an embodiment of the present invention, the BGP Path Attribute is a field in the Update message.
[0023] In an embodiment of the present invention, if a route is received from a provider or a peer and the TAG attribute does not exist, the current route also adds the TAG attribute.
[0024] In an embodiment of the present invention, when a data packet enters the router, verifying the label attribute value according to predefined router import rules includes:
[0025] The routing announcement received by the local AS Y from the upstream AS X contains the TAG attribute, and AS Y decrypts the TAG sigX (X) to obtain the attribute value of the TAG;
[0026] If the attribute value obtained by decryption is equal to the autonomous system number X of the upstream AS and the upstream AS is not a customer of the local AS, the current TAG attribute value is legal; otherwise,
[0027] it is a routing leak or a violation of the Gao-Rexford principle, and the propagation of the current route is stopped.
[0028] In an embodiment of the present invention, when the data packet leaves the router again, the TAG is updated according to the predefined router egress rules, including:
[0029] After the local AS Y receives a route with a TAG attribute, this route will not be forwarded to the provider or peer, but only to the customer; and the TAG attribute is updated to TAG sigY (Y).
[0030] To achieve the above object, another aspect of the present invention proposes a constraint authentication device for routing egress rules, including:
[0031] A label generation module, configured to perform label generation and signature operations according to the predefined router egress rules when the data packet leaves the router;
[0032] A label verification module, configured to verify the label attribute value according to the predefined router ingress rules when the data packet enters the router;
[0033] A label propagation module, configured to update the TAG according to the predefined router egress rules when the data packet leaves the router again.
[0034] The constraint authentication method and device for routing egress rules according to the embodiments of the present invention effectively improve the security of inter-domain routing propagation, and ensure the authenticity, integrity and traceability of routing information. This mechanism can not only detect the occurrence of routing egress events, but also prevent the covering-up behavior of malicious nodes, thereby maintaining the overall security of the network. Especially in the face of an increasingly complex network environment and potential security threats, the present invention provides a practical solution to ensure the legitimate interests between autonomous systems.
[0035] To achieve the above object, a third aspect embodiment of the present application proposes a computer device, including: a processor and a memory; wherein, the processor runs a program corresponding to the executable program code by reading the executable program code stored in the memory, so as to implement the method described in the first aspect embodiment.
[0036] To achieve the above object, an embodiment of the fourth aspect of the present application proposes a non-transitory computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, the method described in the embodiment of the first aspect is implemented.
[0037] Additional aspects and advantages of the present invention will be given in part in the following description, become apparent in part from the following description, or be understood through the practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] The above and / or additional aspects and advantages of the present invention will become apparent and be readily understood from the following description of the embodiments in conjunction with the accompanying drawings, in which:
[0039] Figure 1 is a flowchart of a constraint authentication method for routing outbound rules according to an embodiment of the present invention;
[0040] Figure 2 is an example diagram of TAG announcement verification according to an embodiment of the present invention;
[0041] Figure 3 is a structural diagram of a constraint authentication device for routing outbound rules according to an embodiment of the present invention;
[0042] Figure 4 is a computer device according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0043] It should be noted that, without conflict, the embodiments in the present invention and the features in the embodiments may be combined with each other. The present invention will be described in detail below with reference to the accompanying drawings and in conjunction with the embodiments.
[0044] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without making creative efforts shall fall within the protection scope of the present invention.
[0045] The constraint authentication method, device, computer device, and storage medium for routing outbound rules according to an embodiment of the present invention will be described below with reference to the accompanying drawings.
[0046] It is understandable that the main purpose of the present invention is to promptly detect the occurrence of events violating routing outbound rules during inter-domain routing propagation and prevent the covering-up behavior of malicious nodes, thereby ensuring that routing propagation follows established rules. This solution can strictly verify the authenticity, integrity, and source of routing information, thus effectively enhancing the overall security of inter-domain routing propagation.
[0047] To achieve the above object, the present invention proposes a constraint authentication method for routing outbound rules, defines an optional and transitive BGP Path Attribute (a field belonging to the Update message), and ensures the legal propagation of routes by adding a label (TAG) attribute and performing signature during path propagation.
[0048] Figure 1 It is a flowchart of the constraint authentication method for routing outbound rules according to an embodiment of the present invention, as Figure 1 shown. The method includes:
[0049] S1, when a data packet leaves the router, perform label generation and signature operations according to predefined router exit rules.
[0050] Specifically, if a routing announcement is to be sent to a customer or peer and the TAG attribute does not exist, a TAG attribute must be added to the BGP Path Attribute, and its attribute value is equal to the autonomous system number (ASN) of the local AS. Then the local AS X uses its own private key to sign the generated TAG to obtain TAG sigX (X).
[0051] If a route is received from a provider or peer and the TAG attribute does not exist, then the route must also add a TAG attribute according to the above rules.
[0052] S2, when a data packet enters the router, verify the label attribute value according to predefined router entry rules.
[0053] Specifically, when the local AS Y receives an announcement containing the TAG attribute from the upstream AS X, AS Y will decrypt TAG sigX (X) to obtain the attribute value of TAG. If the attribute value is equal to the autonomous system number X of the upstream AS and the upstream AS is not a customer of the local AS, then the TAG value is legal. Otherwise, if any one of the conditions is violated, this violates the routing outbound Gao-Rexford Yushu, and this route must be unqualified, and the propagation of this route is stopped.
[0054] S3. When the data packet leaves the router again, perform an update operation on the TAG according to the predefined router egress rules.
[0055] After the local AS Y receives a route with TAG attributes, this route will definitely not be forwarded to the provider or peer, and can only be sent to the customer. At the same time, update the TAG attribute to TAG sigY (Y) according to step S1.
[0056] The above routing rules can provide routing egress constraint detection for the local AS. On the premise that the above rules are deployed in the local AS, the existence of the TAG attribute can indicate to the egress router that this route is learned from the provider or peer, and it can only be sent to the customer. If a route from the Customer or Peer is received, the TAG attribute set locally also provides a method to detect the egress behavior of the AS beyond multiple hops. For example, if an AS sets the TAG attribute on the route sent to the peer, and this route is subsequently received by an AS on the path from its customer, then the receiving AS will detect that this route violates the reasonable egress principle due to the existence of the TAG, which is mainly determined by the transitivity of the TAG attribute.
[0057] It can be understood that the present invention defines an optional and transitive BGP path attribute by introducing the TAG attribute, aiming to improve the security of inter-domain routing. This mechanism includes three main steps: Label generation phase: When the router needs to send a route announcement to the customer or peer, if there is no TAG attribute in the BGP Path Attribute, a TAG attribute needs to be added, and its attribute value is equal to the ASN of the local AS. Then, the local AS signs the generated TAG with its own private key to obtain the signed TAG. Label verification phase: When the router receives a route announcement containing the TAG attribute from the upstream AS, it will decrypt the signed TAG with the public key of the upstream AS to obtain the attribute value of the TAG. If the attribute value is equal to the autonomous system number of the upstream AS and the upstream AS is not a customer of the local AS, it means that the TAG value is legal; otherwise, it is a route leak or violates the Gao-Rexford principle, and the propagation of this route will be stopped. Label propagation phase: When the router receives a route with the TAG attribute, this route will not be forwarded to the provider or peer, and can only be sent to the customer. At the same time, update the TAG attribute to the new signed TAG according to the generation phase.
[0058] Furthermore, a security verification example of the present invention is as Figure 2 shown, and the field interpretations are as follows:
[0059] Three ASes, AS A, AS B, AS C, and ASD, which exhibit normal behavior. Among them, AS B is the provider of AS A, AS B and AS C are in a peer relationship, and AS C is the provider of ASD. There is an abnormal AS M, which is a customer of AS B and AS C.
[0060] First, as the legal owner of the prefix 192.168.8.0 / 24, AS A normally announces it to AS B.
[0061] In step S1, AS B has only two announcement objects, namely AS C and AS M. That is, AS B is about to send announcements to its customers and peers. Since the BGP Path Attribute does not contain the TAG attribute at this time, AS B needs to generate a TAG according to step S1 and sign it with its private key to obtain TAG sigB (B). Then this TAG attribute is announced to AS C and AS M respectively as part of the Path Attribute.
[0062] In step S2, AS C receives this announcement at the router entry and obtains the TAG sigB (B). Subsequently, it decrypts it using the public key of ASB to obtain the TAG attribute value B. After verification, it is consistent with the autonomous system number of the upstream AS B, and AS B is not a local customer, so the verification passes and the route is valid. At the same time, AS C also receives an announcement from the malicious AS M. For AS M, there are two ways to act maliciously. One is to forge the role of AS B to generate TAG sigM (B) or modify it to TAG using its own private key sigM (M). For the first method, after AS C decrypts it using the public key of M, the obtained TAG value is B, which is not equal to M, so this route is illegal. For the second method, although the TAG value is consistent with the autonomous system number of AS M, but it is a customer of AS C, so it is also illegal. Therefore, AS C can detect the route leakage behavior of AS M and reject this announcement.
[0063] In step S3, after verifying the legal announcement of AS B, AS C updates the TAG attribute to TAG sigC (C) at the route exit. This route will no longer be passed to its provider or peer, and can only be propagated to its customer ASD.
[0064] The constraint authentication method for routing outbound rules according to an embodiment of the present invention solves the problem that BGP routes violate the outbound principle. By introducing the label (TAG) attribute and the signature authentication mechanism, it effectively detects and prevents the occurrence of violations of routing outbound constraints. It effectively improves the security of inter-domain routing propagation, ensuring the authenticity, integrity, and traceability of routing information. This mechanism can not only detect the occurrence of routing outbound events but also prevent the covering-up behavior of malicious nodes, thereby maintaining the overall security of the network.
[0065] To implement the above embodiment, as Figure 3 shown, in this embodiment, a constraint authentication device 10 for routing outbound rules is further provided, including:
[0066] A label generation module 100, configured to perform label generation and signature operations according to predefined router exit rules when a data packet leaves the router;
[0067] A label verification module 200, configured to verify the label attribute value according to predefined router entry rules when a data packet enters the router;
[0068] A label propagation module 300, configured to update the TAG according to predefined router exit rules when the data packet leaves the router again.
[0069] The constraint authentication device for routing outbound rules according to an embodiment of the present invention solves the problem that BGP routes violate the outbound principle. By introducing the label (TAG) attribute and the signature authentication mechanism, it effectively detects and prevents the occurrence of violations of routing outbound constraints. It effectively improves the security of inter-domain routing propagation, ensuring the authenticity, integrity, and traceability of routing information. This mechanism can not only detect the occurrence of routing outbound events but also prevent the covering-up behavior of malicious nodes, thereby maintaining the overall security of the network.
[0070] To implement the method of the above embodiment, the present invention further provides a computer device, as Figure 4 shown, the computer device 600 includes a memory 601 and a processor 602; wherein, the processor 602 runs a program corresponding to the executable program code by reading the executable program code stored in the memory 601 to implement the respective steps of the method described above.
[0071] To implement the above embodiment, the present application further proposes a non-transitory computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the method described in the foregoing embodiment.
[0072] In the description of this specification, the descriptions referring to terms such as "one embodiment", "some embodiments", "examples", "specific examples", or "some examples", etc. mean that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic expressions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples. In addition, without contradiction, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.
[0073] In addition, the terms "first" and "second" are only used for descriptive purposes and cannot be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include at least one of such features. In the description of the present invention, "a plurality of" means at least two, such as two, three, etc., unless otherwise specifically and clearly defined.
Claims
1. A constraint authentication method for routing outbound rules, characterized in that: include: When the data packet leaves the router, label generation and signature operations are performed according to the predefined router egress rules; When a data packet enters a router, the label attribute value is verified according to the predefined router entry rules; When the data packet leaves the router again, the TAG is updated according to the predefined router exit rule.
2. The method according to claim 1, characterized in that When a data packet leaves the router, label generation and signature operations are performed according to the predefined router egress rules, including: When the router sends a routing advertisement to a customer or peer, if it determines that there is no TAG attribute in the BGP Path Attribute, it adds the TAG attribute to it; The TAG attribute value is equal to the autonomous system number ASN of the local AS. The local AS uses its own private key to sign the generated TAG to obtain the TAG. sigX (X).
3. The method according to claim 2, characterized in that BGP Path Attribute is a field in the Update message.
4. The method according to claim 1, characterized in that If a route is received from a provider or peer and the TAG attribute does not exist, the TAG attribute is also added to the current route.
5. The method according to claim 2, characterized in that: When a data packet enters a router, the label attribute value is verified according to the predefined router entry rules, including: The routing advertisement received by local AS Y from upstream AS X contains the TAG attribute. AS Y decrypts the TAG using X's public key. sigX (X) Get the attribute value of TAG; If the decrypted attribute value is equal to the autonomous system number X of the upstream AS and the upstream AS is not a customer of the local AS, the current TAG attribute value is legal; otherwise, That is, the route is leaked or violates the Gao-Rexford principle, and the propagation of the current route is stopped.
6. The method according to claim 3, characterized in that When the data packet leaves the router again, the TAG is updated according to the predefined router egress rules, including: When local AS Y receives a route with the TAG attribute, it will not forward the route to the provider or peer, but only to the customer; and will update the TAG attribute to TAG sigY (Y).
7. A constraint authentication device for routing outbound rules, characterized in that: include: A label generation module, used to generate labels and perform signature operations according to predefined router egress rules when a data packet leaves the router; The label verification module is used to verify the label attribute value according to the predefined router entry rules when the data packet enters the router; The label propagation module is used to update the TAG according to the predefined router egress rule when the data packet leaves the router again.
8. A computer device, characterized in that: including a processor and a memory; The processor runs a program corresponding to the executable program code by reading the executable program code stored in the memory, so as to implement the constraint authentication method for routing outbound rules as described in any one of claims 1 to 6.
9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the constraint authentication method for routing outbound rules as described in any one of claims 1 to 6 is implemented.