Embedded router security authentication method and system

By sending detection data packets in router security authentication for IP authentication and forwarding path similarity calculation, combining standard transmission paths and transmission paths to be verified, the problems of insufficient security authentication accuracy and large path detection work in the prior art are solved, and more efficient and accurate security authentication is achieved.

CN120200842AActive Publication Date: 2025-06-24SHENZHEN HUAXUN OPTICAL COMM CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510574759.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-06
Publication Date
2025-06-24
Estimated Expiration
2045-05-06

AI Technical Summary

Technical Problem

The prior art cannot effectively detect multiple accessible paths in router security authentication, resulting in insufficient accuracy of security authentication and huge path detection work.

Method used

By sending the detection data packet and the data to be authenticated from the party to be authenticated to the destination router, performing IP authentication and forwarding path similarity calculation, combining the standard transmission path and the transmission path to be authenticated, the security authentication result is determined, and the path detection workload is reduced.

Benefits of technology

It improves the accuracy of router security authentication, reduces the workload of path detection, and enhances the verification ability of router intranet data transmission paths.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200842A_ABST
    Figure CN120200842A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of router authentication, and discloses an embedded router security authentication method and system, and the method comprises the steps: transmitting a detection data packet and to-be-authenticated data to a target router from a to-be-authenticated party, and carrying out the IP authentication of the to-be-authenticated data through the detection data packet; when the IP authentication fails, determining a first security authentication result of the target router about the to-be-authenticated data; when the IP authentication succeeds, calculating the forwarding path similarity between the detection data packet and the to-be-authenticated data; determining a second security authentication result of the target router about the to-be-authenticated data by using the detection data packet; and when the forwarding path similarity does not accord with a preset similarity threshold, querying a normal data packet sent to the target router by the to-be-authenticated party, and determining a third security authentication result of the target router about the to-be-authenticated data by using a data query result. According to the invention, the accuracy of security authentication can be improved on the premise of reducing the path detection workload.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an embedded router security authentication method and system, belonging to the technical field of router authentication. Background Art

[0002] Currently, a router is network hardware responsible for the work of the network layer in the OSI reference model and forwarding IP packets between different networks according to the routing table. Here, the network mainly refers to an IP subnet. During the routing transmission process, the source IP address and the destination IP address do not change, only the MAC address changes. The next-hop MAC address is used to find the next router to be forwarded. The MAC address is a physical address operating at the data link layer.

[0003] When the IP address prefix match is successful, it does not mean that the data received by the router is legal data. This is because an illegal user may use IP spoofing to imitate the correct IP address. Therefore, the accuracy rate of verifying whether the data is safe and legal only by the IP address prefix matching method is insufficient. Secondly, the prior art performs matching of the routing path (the path composed of the routers passed by the data) (matching with the standard routing path). If the path match is successful, it means that the data received by the router is legal. This process is implemented by Dublin Traceroute. However, Dublin Traceroute can only find one of the paths. There may be multiple communicable paths between the source and the destination. Even by using the multi-path detection method to solve the defect that Dublin Traceroute can only find one of the paths, all reachable paths cannot be completely detected. This is because at each router node, there are multiple branches of the next-hop router, and Dublin Traceroute can only detect the path by sending detection data packets based on different destination IP addresses. Since it is necessary to detect each router and the next-hop path of each router, this workload is undoubtedly huge. Finally, as is well known, a router links a subnet (network). When the routing network match is successful, there are two cases. One is that the routing network where the illegal user is located (the network managed and linked by a router. Devices in this network need to be forwarded by the manager of this network (i.e., the router) if they want to communicate with other networks) is actually the same as the network of the correct and legal user. The other is that the illegal user uses network number spoofing to be in the same network as the normal user. In either case, the prior art can only detect the routing path and cannot detect whether the path composed of multiple MAC addresses is abnormal. This makes the accuracy rate of verifying whether the data is safe and legal only by matching the routing path insufficient.

[0004] Therefore, there is an urgent need for a solution that can improve the accuracy of security authentication while reducing the workload of path detection. Summary of the Invention

[0005] The present invention provides an embedded router security authentication method and system, and its main purpose is to improve the accuracy of security authentication while reducing the workload of path detection.

[0006] To achieve the above object, an embedded router security authentication method provided by the present invention includes:

[0007] Sending a detection data packet and authentication data from the party to be authenticated to the destination router, and in the destination router, using the detection data packet to perform IP authentication on the authentication data;

[0008] When the IP authentication fails, determining a first security authentication result of the destination router regarding the authentication data;

[0009] When the IP authentication is successful, calculating the forwarding path similarity between the detection data packet and the authentication data;

[0010] When the forwarding path similarity meets a preset similarity threshold, using the detection data packet to determine a second security authentication result of the destination router regarding the authentication data;

[0011] When the forwarding path similarity does not meet the preset similarity threshold, querying normal data packets sent by the party to be authenticated to the destination router to obtain a data query result, and using the data query result to determine a third security authentication result of the destination router regarding the authentication data;

[0012] Taking the first security authentication result, the second security authentication result, and the third security authentication result as the final security authentication result.

[0013] Optionally, the step of sending a detection data packet and authentication data from the party to be authenticated to the destination router includes:

[0014] Sending the detection data packet from the party to be authenticated to the destination router;

[0015] Finding the destination host corresponding to the detection data packet through the Address Resolution Protocol in the destination router;

[0016] Obtaining the destination switch corresponding to the destination host;

[0017] Sending the detection data packet to the destination host via the destination switch;

[0018] Determine whether a response packet from the destination host regarding the probe packet is received in the destination router;

[0019] When a response packet from the destination host regarding the probe packet is received in the destination router, send authentication data to be authenticated from the party to be authenticated to the destination router.

[0020] Optionally, in the destination router, using the probe packet to perform IP authentication on the authentication data to be authenticated includes:

[0021] Extract the standard source IP address and the source IP address to be verified from the probe packet and the authentication data to be authenticated respectively;

[0022] Calculate the address Hamming distance between the standard source IP address and the source IP address to be verified;

[0023] Calculate the Hamming distance standard corresponding to the standard source IP address;

[0024] When the address Hamming distance is inconsistent with the Hamming distance standard, determine that the IP authentication fails;

[0025] When the address Hamming distance is consistent with the Hamming distance standard, determine that the IP authentication is successful.

[0026] Optionally, calculating the forwarding path similarity between the probe packet and the authentication data to be authenticated includes:

[0027] Trace the standard forwarding path of the probe packet from the party to be authenticated to the destination router;

[0028] Trace the forwarding path to be verified of the authentication data to be authenticated from the party to be authenticated to the destination router;

[0029] Calculate the sequence Hamming distance between the router address sequence on the standard forwarding path and the router address sequence on the forwarding path to be verified to obtain the forwarding path similarity.

[0030] Optionally, tracing the standard forwarding path of the probe packet from the party to be authenticated to the destination router includes:

[0031] Obtain a path tracing tool from the party to be authenticated to the destination router;

[0032] Use the path tracing tool to trace the first routing path of the probe packet;

[0033] According to the first routing path, select the next-hop MAC address of the probe packet;

[0034] Generate a transmission address sequence of the detection data packet through the next-hop MAC address;

[0035] Based on the transmission address sequence, send the detection data packet from the party to be authenticated to the destination router;

[0036] Use the path tracing tool to trace the second routing path of the detection data packet;

[0037] Use the first routing path and the second routing path as the standard forwarding path of the detection data packet from the party to be authenticated to the destination router.

[0038] Optionally, the using the detection data packet to determine a second security authentication result of the destination router for the data to be authenticated includes:

[0039] Obtain the standard source IP address corresponding to the detection data packet;

[0040] Identify the standard transmission path of the standard source IP address in the router network corresponding to the party to be authenticated;

[0041] Identify the to-be-verified transmission path corresponding to the to-be-verified source IP address corresponding to the data to be authenticated;

[0042] Extract the standard MAC address on the standard transmission path;

[0043] Extract the to-be-verified MAC address on the to-be-verified transmission path;

[0044] Generate a standard MAC sequence of the standard MAC address and a to-be-verified MAC sequence of the to-be-verified MAC address;

[0045] Send the standard MAC sequence and the to-be-verified MAC sequence to the destination router;

[0046] In the destination router, calculate the MAC Hamming distance and the MAC distance standard between the standard MAC sequence and the to-be-verified MAC sequence;

[0047] When the MAC Hamming distance is consistent with the MAC distance standard, regard the security authentication as successful as the second security authentication result;

[0048] When the MAC Hamming distance is inconsistent with the MAC distance standard, regard the security authentication as failed as the second security authentication result.

[0049] Optionally, the identifying the standard transmission path of the standard source IP address in the router network corresponding to the party to be authenticated includes:

[0050] Obtain the router network corresponding to the standard source IP address at the party to be authenticated;

[0051] Query the first-level switch connected to the source host corresponding to the standard source IP address through the link tracing tool in the router network;

[0052] Query the second-level switch from the first-level switch to the source router corresponding to the standard forwarding path through the link tracing tool;

[0053] Generate the standard transmission path using the source host, the first-level switch, the second-level switch, and the source router.

[0054] Optionally, the querying the normal data packets sent by the party to be authenticated to the destination router to obtain a data query result includes:

[0055] Obtain the forwarding path to be verified;

[0056] Based on the forwarding path to be verified, select the path to be traced of the normal data packet;

[0057] Query whether there is ICMP timeout information of the normal data packet on the path to be traced;

[0058] When there is ICMP timeout information of the normal data packet, taking that the normal data packets sent by the party to be authenticated to the destination router can be queried as the data query result;

[0059] When there is no ICMP timeout information of the normal data packet, taking that the normal data packets sent by the party to be authenticated to the destination router cannot be queried as the data query result.

[0060] Optionally, the using the data query result to determine the third security authentication result of the destination router for the data to be authenticated includes:

[0061] Query whether the starting point to be verified of the forwarding path to be verified is consistent with the standard starting point of the standard forwarding path;

[0062] When the starting point to be verified of the forwarding path to be verified is inconsistent with the standard starting point, taking security authentication failure as the third security authentication result;

[0063] When the starting point to be verified of the forwarding path to be verified is consistent with the standard starting point, if the data query result is a data query failure, return the previous step of tracing the standard forwarding path of the probe data packet from the party to be authenticated to the destination router;

[0064] When the starting point to be verified of the forwarding path to be verified is consistent with the standard starting point, if the data query result is successful data query, it is determined that the security authentication is successful as the third security authentication result.

[0065] To solve the above problems, the present invention also provides an embedded router security authentication system, and the system includes:

[0066] An IP authentication module, configured to send a probe data packet and data to be authenticated from the party to be authenticated to the destination router, and in the destination router, perform IP authentication on the data to be authenticated by using the probe data packet;

[0067] A first authentication module, configured to determine a first security authentication result of the destination router with respect to the data to be authenticated when the IP authentication fails.

[0068] A similarity calculation module, configured to calculate a forwarding path similarity between the probe data packet and the data to be authenticated when the IP authentication is successful;

[0069] A second authentication module, configured to determine a second security authentication result of the destination router with respect to the data to be authenticated by using the probe data packet when the forwarding path similarity meets a preset similarity threshold;

[0070] A third authentication module, configured to query normal data packets sent by the party to be authenticated to the destination router when the forwarding path similarity does not meet the preset similarity threshold, obtain a data query result, and determine a third security authentication result of the destination router with respect to the data to be authenticated by using the data query result;

[0071] A final authentication module, configured to use the first security authentication result, the second security authentication result, and the third security authentication result as the final security authentication result.

[0072] Compared with the problem described in the background technology, the embodiment of the present invention sends a detection data packet and the data to be authenticated from the party to be authenticated to the destination router to confirm which router the destination IP address belongs to, so as to use this router as the destination router. Furthermore, the embodiment of the present invention performs IP authentication on the data to be authenticated in the destination router using the detection data packet to determine whether the standard source IP address is consistent with the source IP address to be verified. Furthermore, the embodiment of the present invention calculates the forwarding path similarity between the detection data packet and the data to be authenticated to match the path structure formed by the routers through which the data passes. At the same time, it can design which paths should be detected subsequently based on only the first path detected initially, thereby reducing the huge workload of detecting all paths. Furthermore, the embodiment of the present invention determines the second security authentication result of the destination router regarding the data to be authenticated by using the standard transmission path and the transmission path to be verified, so as to introduce the MAC address to verify the data in the router intranet. The transmission path is determined by the authentication party, thereby improving the accuracy of security authentication. Further, the embodiment of the present invention obtains the data query result by querying the normal data packet sent by the authentication party to the destination router, so that when the forwarding path to be verified is matched to be illegal, it indicates that the authentication data packet that should be transmitted has been modified by the illegal user, thereby being transmitted to other error router networks. Since the error router network cannot find the destination IP address of the authentication data packet, when the forwarding hop count times out, an ICMP timeout protocol data will be sent back to the source host to inform the source host that a data transmission error has occurred. The principle of the ICMP timeout protocol data can be used to detect whether the ICMP timeout protocol data can be received on other paths except the error forwarding path to be verified. If received, it indicates that the authentication data packet is indeed transmitted to other routers by mistake, thereby verifying that the forwarding path to be verified is illegal, rather than a new path appears and the new path is not updated to the standard forwarding path in time, and finally extracting the accuracy of security authentication. Therefore, the embedded router security authentication method and system provided by the embodiment of the present invention can improve the accuracy of security authentication under the premise of reducing the workload of path detection. BRIEF DESCRIPTION OF THE DRAWINGS

[0073] Figure 1 A schematic diagram of a flow chart of an embedded router security authentication method provided by an embodiment of the present invention;

[0074] Figure 2 A schematic diagram of a module for implementing the embedded router security authentication method provided by an embodiment of the present invention.

[0075] The purpose, features and advantages of the present invention will be further described with reference to the accompanying drawings in conjunction with the embodiments. DETAILED DESCRIPTION

[0076] It should be understood that the specific embodiments described herein are merely used to explain the present invention and are not intended to limit the present invention.

[0077] An embodiment of the present application provides an embedded router security authentication method. The execution subject of the embedded router security authentication method includes, but is not limited to, at least one of electronic devices such as a server, a terminal, etc. that can be configured to execute the method provided by the embodiment of the present application. In other words, the embedded router security authentication method can be executed by software or hardware installed on a terminal device or a server device. The server includes, but is not limited to: a single server, a server cluster, a cloud server, or a cloud server cluster, etc.

[0078] Embodiment 1:

[0079] Refer to Figure 1 As shown, it is a flowchart of an embedded router security authentication method provided by an embodiment of the present invention. In this embodiment, the embedded router security authentication method includes:

[0080] S1. Send a probe packet and authentication data to the destination router from the party to be authenticated. In the destination router, use the probe packet to perform IP authentication on the authentication data.

[0081] In an embodiment of the present invention, the party to be authenticated refers to the source host that produces and sends the probe packet and the authentication data. The probe packet refers to a packet used in combination with a path tracing tool to probe the routing path from the source host to the destination router. The destination router refers to the router to which the destination host that receives the probe packet and the authentication data belongs.

[0082] Furthermore, in an embodiment of the present invention, by sending a probe packet and authentication data to the destination router from the party to be authenticated, it is confirmed which router the destination IP address belongs to, and thus this router is used as the destination router.

[0083] In an embodiment of the present invention, the step of sending a probe packet and authentication data to the destination router from the party to be authenticated includes: sending the probe packet from the party to be authenticated to the destination router; finding the destination host corresponding to the probe packet through the Address Resolution Protocol in the destination router; obtaining the destination switch corresponding to the destination host; sending the probe packet to the destination host via the destination switch; determining whether a response packet of the destination host regarding the probe packet is received in the destination router; when a response packet of the destination host regarding the probe packet is received in the destination router, sending the authentication data from the party to be authenticated to the destination router.

[0084] Among them, the Address Resolution Protocol (ARP) refers to a network transmission protocol that finds the data link layer address (MAC address) by resolving the network layer address (IP address). The destination switch refers to a data link layer device that receives data sent by the destination router and forwards it to the destination host. The response packet refers to the confirmation information sent by the destination host to the source host after receiving the probe packet.

[0085] It should be noted that when the destination router receives the response packet of the destination host regarding the probe packet, it indicates that the destination IP address of the probe packet is in the network managed by the destination router. Therefore, subsequent data can be sent to this destination router.

[0086] Furthermore, in the embodiment of the present invention, in the destination router, the IP authentication of the data to be authenticated is performed using the probe packet to determine whether the standard source IP address is the same as the source IP address to be verified.

[0087] In an embodiment of the present invention, the IP authentication of the data to be authenticated using the probe packet in the destination router includes: respectively extracting the standard source IP address and the source IP address to be verified from the probe packet and the data to be authenticated; calculating the address Hamming distance between the standard source IP address and the source IP address to be verified using the following formula:

[0088] S1 = (s 11 , s 12 , …, s 1n )

[0089] S2 = (s 21 , s 22 , …, s 2n )

[0090] d H (S1, S2) = popcount(S1 ⊕ S2)

[0091] Among them, d H (S1, S2) represents the address Hamming distance, S1 represents the binary standard source IP address, S2 represents the binary source IP address to be verified, n represents the length of the IP address, popcount(S1 ⊕ S2) represents the number of 1s in the binary S1 ⊕ S2, and ⊕ represents the bitwise exclusive OR operation;

[0092] Calculate the Hamming distance standard corresponding to the standard source IP address using the following formula:

[0093] p(S1) = popcount(S1)

[0094] Among them, p(S1) represents the Hamming distance standard, S1 represents the standard source IP address in binary, and popcount(S1) represents the number of 1s in the binary S1.

[0095] When the address Hamming distance is inconsistent with the Hamming distance standard, it is determined that the IP authentication fails; when the address Hamming distance is consistent with the Hamming distance standard, it is determined that the IP authentication is successful.

[0096] S2. When the IP authentication fails, determine the first security authentication result of the destination router for the data to be authenticated.

[0097] In an embodiment of the present invention, the first security authentication result is a security authentication failure.

[0098] S3. When the IP authentication is successful, calculate the forwarding path similarity between the probe packet and the data to be authenticated.

[0099] In an embodiment of the present invention, by calculating the forwarding path similarity between the probe packet and the data to be authenticated, the path structure formed by the routers through which the data passes is matched, and at the same time, only based on the first path detected initially, it can be designed which paths should be detected subsequently, thereby reducing the huge workload of detecting all paths.

[0100] In an embodiment of the present invention, calculating the forwarding path similarity between the probe packet and the data to be authenticated includes: tracking the standard forwarding path of the probe packet from the party to be authenticated to the destination router; tracking the forwarding path to be verified of the data to be authenticated from the party to be authenticated to the destination router; calculating the sequence Hamming distance between the router address sequence on the standard forwarding path and the router address sequence on the forwarding path to be verified to obtain the forwarding path similarity.

[0101] In another embodiment of the present invention, tracking the standard forwarding path of the probe packet from the party to be authenticated to the destination router includes: obtaining a path tracking tool from the party to be authenticated to the destination router; using the path tracking tool to track the first routing path of the probe packet; according to the first routing path, selecting the next-hop MAC address of the probe packet by the following method:

[0102]

[0103] Among them, Z represents the next-hop MAC address, x1 represents the first next-hop MAC address of the first routing path, x2 represents the second next-hop MAC address of the first routing path, and x i represents the i-th next-hop MAC address of the first routing path. represents at xi any next-hop MAC address other than x queried in the forwarding table of the corresponding router i+1 where x represents the (i + 1)-th next-hop MAC address of the routing path i+1 represents any next-hop MAC address queried in the forwarding table of the corresponding router represents at the destination router's next-hop MAC address, and N represents the number of routers in the first routing path N Generate a sequence of sending addresses for the probe packet through the next-hop MAC address; based on the sequence of sending addresses, send the probe packet from the party to be authenticated to the destination router; use the path tracing tool to trace the second routing path of the probe packet; use the first routing path and the second routing path as the standard forwarding path of the probe packet from the party to be authenticated to the destination router.

[0104] where the path tracing tool refers to Dublin Traceroute, a NAT-aware multi-path traceroute tool designed for modern network environments, the first routing path refers to the router path experienced from the source router to the destination router detected when initially using the path tracing tool, the next-hop MAC address refers to the MAC address of each router that the data passes through when transmitted on the router, the sequence of sending addresses refers to a sequence composed of different next-hop MAC addresses, and the second routing path does not refer to a single path, but refers to all reachable paths to the destination router obtained after probing Z.

[0105] Optionally, the process of sending the probe packet from the party to be authenticated to the destination router based on the sequence of sending addresses means probing the addresses in the sequence of sending addresses in turn, that is, probing one set each time. Since there are multiple different combinations (different Zs) in the set, it is necessary to probe these multiple different combinations in turn.

[0106] It should be noted that the principle of tracing the forwarding path to be verified of the data to be authenticated from the party to be authenticated to the destination router is similar to the principle of tracing the standard forwarding path of the probe packet from the party to be authenticated to the destination router, and will not be elaborated further here. set, and since there are multiple different combinations (different Zs) in the set, it is necessary to probe these multiple different combinations in turn.

[0107]

[0108] ​​Optionally, calculating the sequence Hamming distance between the router address sequences on the standard forwarding path and the router address sequences on the to-be-verified forwarding path, and obtaining the forwarding path similarity as follows: respectively querying the standard router addresses on the standard forwarding path and the to-be-verified router addresses on the to-be-verified forwarding path; constructing the standard address sequence of the standard router addresses; constructing the to-be-verified address sequence of the to-be-verified router addresses; calculating the sequence Hamming distance between the standard address sequence and the to-be-verified address sequence by using the following formula:

[0109] S3 = (s 31 , s 32 , …, s 3n )

[0110] S4 = (s 41 , s 42 , …, s 4n )

[0111] d H (S3, S4) = popcount(S3 ⊕ S4)

[0112] Wherein, d H (S3, S4) represents the sequence Hamming distance, S3 represents the standard address sequence in binary, S4 represents the to-be-verified address sequence in binary, n represents the length of the IP address, popcount(S3 ⊕ S4) represents the number of 1s in the binary S3 ⊕ S4, and ⊕ represents the bitwise exclusive OR operation;

[0113] Taking the sequence Hamming distance as the forwarding path similarity.

[0114] Wherein, both the standard router address and the to-be-verified router address are IP addresses.

[0115] S4. When the forwarding path similarity meets a preset similarity threshold, using the probe packet to determine the second security authentication result of the destination router for the to-be-authenticated data.

[0116] It should be noted that the principle of calculating the similarity threshold is similar to the principle of calculating the Hamming distance standard corresponding to the standard source IP address described above, and will not be elaborated further here.

[0117] In the embodiment of the present invention, by using the standard transmission path and the to-be-verified transmission path to determine the second security authentication result of the destination router for the to-be-authenticated data, for introducing the MAC address to verify the data transmission path in the router intranet, thereby improving the accuracy of security authentication.

[0118] In an embodiment of the present invention, determining the second security authentication result of the destination router regarding the data to be authenticated by using the detection data packet includes: obtaining the standard source IP address corresponding to the detection data packet; identifying the standard transmission path of the standard source IP address in the router network corresponding to the party to be authenticated; identifying the to-be-verified transmission path corresponding to the to-be-verified source IP address of the data to be authenticated; extracting the standard MAC address on the standard transmission path; extracting the to-be-verified MAC address on the to-be-verified transmission path; generating a standard MAC sequence of the standard MAC address and a to-be-verified MAC sequence of the to-be-verified MAC address; sending the standard MAC sequence and the to-be-verified MAC sequence to the destination router; in the destination router, calculating the MAC Hamming distance and the MAC distance standard between the standard MAC sequence and the to-be-verified MAC sequence; when the MAC Hamming distance is consistent with the MAC distance standard, taking successful security authentication as the second security authentication result; when the MAC Hamming distance is inconsistent with the MAC distance standard, taking failed security authentication as the second security authentication result.

[0119] In another embodiment of the present invention, identifying the standard transmission path of the standard source IP address in the router network corresponding to the party to be authenticated includes: obtaining the router network corresponding to the standard source IP address in the party to be authenticated; querying, through a link tracing tool in the router network, the primary switch connected to the source host corresponding to the standard source IP address; querying, through the link tracing tool, the secondary switch from the primary switch to the source router corresponding to the standard forwarding path; generating the standard transmission path by using the source host, the primary switch, the secondary switch, and the source router.

[0120] Wherein, the link tracing tool refers to a tool designed based on the link tracing function. For example, 802.1ag MACTrace is similar to Traceroute, which can detect the path information between devices in the layer 2 network (data link layer), help users understand the path information and locate network problems. The secondary switch refers to all the switches that need to be passed through from the primary switch to the source router corresponding to the standard forwarding path. The standard MAC address refers to the MAC addresses of the hosts, switches, and routers experienced on the standard transmission path. The to-be-verified MAC address is the same. The standard MAC sequence refers to the sequence of MAC addresses composed of the path. For example, for the path from A to B, the MAC address of A is 01 and the MAC address of B is 11, then 0111 is taken as the standard MAC sequence. The to-be-verified MAC sequence is the same. The principle of calculating the MAC distance standard is similar to the principle of calculating the Hamming distance standard corresponding to the standard source IP address described above, and will not be further elaborated here.

[0121] It should be noted that the principle of identifying the to-be-verified transmission path corresponding to the to-be-verified source IP address is similar to the principle of identifying the standard transmission path of the standard source IP address in the router network corresponding to the to-be-authenticated party, and no further elaboration will be made here.

[0122] S5. When the similarity of the forwarding paths does not meet the preset similarity threshold, query the normal data packets sent by the to-be-authenticated party to the destination router to obtain a data query result, and use the data query result to determine the third security authentication result of the destination router regarding the to-be-authenticated data.

[0123] It should be noted that when the similarity of the forwarding paths does not meet the preset similarity threshold, it means that the actual forwarding path composed of routers is different from the standard forwarding path. However, this does not necessarily mean that the current forwarding path is a path for illegal user data transmission. If a new path appears and the new path is not updated to the standard forwarding path in a timely manner, the situation where the similarity of the forwarding paths does not meet the preset similarity threshold will also occur.

[0124] Furthermore, in the embodiment of the present invention, by querying the normal data packets sent by the to-be-authenticated party to the destination router to obtain a data query result, when it is matched that the to-be-verified forwarding path is illegal, it means that the to-be-authenticated data packet that should have been transmitted has its path modified by an illegal user and thus is transmitted to other wrong router networks. Since the destination IP address of the to-be-authenticated data packet cannot be found in the wrong router network all the time, finally, when the forwarding hop count times out, an ICMP timeout protocol data will be sent back to the source host to inform the source host that a data transmission error has occurred. Then, based on the principle of the ICMP timeout protocol data, it can be detected whether the ICMP timeout protocol data can be received on other paths except the wrong to-be-verified forwarding path. If received, it means that the to-be-authenticated data packet has indeed been wrongly transmitted to other routers, thereby verifying that the to-be-verified forwarding path is illegal, rather than the situation where a new path appears and the new path is not updated to the standard forwarding path in a timely manner, and finally improving the accuracy rate of security authentication.

[0125] In an embodiment of the present invention, the querying the normal data packets sent by the to-be-authenticated party to the destination router to obtain a data query result includes: obtaining the to-be-verified forwarding path; and based on the to-be-verified forwarding path, selecting the to-be-traced path of the normal data packet by using the following method:

[0126] L = {X1, X2,..., X j ,..., X m}, j ∈ [0, M]

[0127]

[0128] Among them, G(j) represents the j-th path to be traced, L represents the path to be verified for forwarding, X1, X2,..., X j ,..., X M represent M routers on the path to be verified for forwarding, M represents the number of routers in the path to be verified for forwarding, j represents the serial number of the router in the path to be verified for forwarding, represents any next-hop router in the forwarding table of the router corresponding to X j except X j+1 ;

[0129] Query whether there is ICMP timeout information of the normal data packet on the path to be traced; when there is ICMP timeout information of the normal data packet, take the normal data packet that can query the destination router sent by the party to be authenticated as the data query result; when there is no ICMP timeout information of the normal data packet, take the normal data packet that cannot query the destination router sent by the party to be authenticated as the data query result.

[0130] Among them, the normal data packet refers to the data packet to be authenticated that has not been illegally tampered with.

[0131] In an embodiment of the present invention, the determining the third security authentication result of the destination router for the data to be authenticated by using the data query result includes: querying whether the starting point to be verified of the path to be verified for forwarding is consistent with the standard starting point of the standard forwarding path; when the starting point to be verified of the path to be verified for forwarding is not consistent with the standard starting point, taking the security authentication failure as the third security authentication result; when the starting point to be verified of the path to be verified for forwarding is consistent with the standard starting point, if the data query result is a data query failure, return the step of tracing the standard forwarding path of the probe data packet from the party to be authenticated to the destination router as described above; when the starting point to be verified of the path to be verified for forwarding is consistent with the standard starting point, if the data query result is a data query success, determining that the security authentication is successful as the third security authentication result.

[0132] Among them, the starting point to be verified and the standard starting point are the source routers on the path.

[0133] S6. Take the first security authentication result, the second security authentication result and the third security authentication result as the final security authentication result.

[0134] Compared with the problem described in the background technology, the embodiment of the present invention sends a detection data packet and the data to be authenticated from the party to be authenticated to the destination router to confirm which router the destination IP address belongs to, so as to use this router as the destination router. Furthermore, the embodiment of the present invention performs IP authentication on the data to be authenticated in the destination router using the detection data packet to determine whether the standard source IP address is consistent with the source IP address to be verified. Furthermore, the embodiment of the present invention calculates the forwarding path similarity between the detection data packet and the data to be authenticated to match the path structure formed by the routers through which the data passes. At the same time, it can design which paths should be detected subsequently based on only the first path detected initially, thereby reducing the huge workload of detecting all paths. Furthermore, the embodiment of the present invention determines the second security authentication result of the destination router regarding the data to be authenticated by using the standard transmission path and the transmission path to be verified, so as to introduce the MAC address to verify the data in the router intranet. The transmission path is determined by the authentication party, thereby improving the accuracy of security authentication. Further, the embodiment of the present invention obtains the data query result by querying the normal data packet sent by the authentication party to the destination router, so that when the forwarding path to be verified is matched to be illegal, it indicates that the authentication data packet that should be transmitted has been modified by the illegal user, thereby being transmitted to other error router networks. Since the error router network cannot find the destination IP address of the authentication data packet, when the forwarding hop count times out, an ICMP timeout protocol data will be sent back to the source host to inform the source host that a data transmission error has occurred. The principle of the ICMP timeout protocol data can be used to detect whether the ICMP timeout protocol data can be received on other paths except the error forwarding path to be verified. If received, it indicates that the authentication data packet is indeed transmitted to other routers by mistake, thereby verifying that the forwarding path to be verified is illegal, rather than a new path appears and the new path is not updated to the standard forwarding path in time, and finally extracting the accuracy of security authentication. Therefore, the embedded router security authentication method and system provided by the embodiment of the present invention can improve the accuracy of security authentication under the premise of reducing the workload of path detection.

[0135] Embodiment 2:

[0136] like Figure 2 The figure shows a functional module diagram of an embedded router security authentication system of the present invention.

[0137] The embedded router security authentication system 200 described in the present invention can be installed in an electronic device. According to the functions achieved, the embedded router security authentication system may include an IP authentication module 201, a first authentication module 202, a similarity calculation module 203, a second authentication module 204, a third authentication module 205, and a final authentication module 206. The modules described in the present invention may also be referred to as units, which refer to a series of computer program segments that can be executed by an electronic device processor and can complete fixed functions, and are stored in the memory of the electronic device.

[0138] In the embodiments of the present invention, the functions of each module / unit are as follows:

[0139] The IP authentication module 201 is used to send a probe data packet and authentication data to a destination router from the party to be authenticated, and in the destination router, use the probe data packet to perform IP authentication on the authentication data;

[0140] The first authentication module 202 is used to determine a first security authentication result of the destination router regarding the authentication data when the IP authentication fails.

[0141] The similarity calculation module 203 is used to calculate the forwarding path similarity between the probe data packet and the authentication data when the IP authentication is successful;

[0142] The second authentication module 204 is used to use the probe data packet to determine a second security authentication result of the destination router regarding the authentication data when the forwarding path similarity meets a preset similarity threshold;

[0143] The third authentication module 205 is used to query normal data packets sent by the party to be authenticated to the destination router to obtain a data query result, and use the data query result to determine a third security authentication result of the destination router regarding the authentication data when the forwarding path similarity does not meet the preset similarity threshold;

[0144] The final authentication module 206 is used to use the first security authentication result, the second security authentication result, and the third security authentication result as the final security authentication result.

[0145] Specifically, each module in the embedded router security authentication system 200 in the embodiments of the present invention uses the same technical means as the Figure 1 embedded router security authentication method described above and can produce the same technical effects, which will not be elaborated here.

[0146] It is obvious to those skilled in the art that the present invention is not limited to the details of the above-described exemplary embodiments, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention.

[0147] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention.

Claims

1. An embedded router security authentication method, characterized in that: The method comprises: Sending a detection data packet and the data to be authenticated from the party to be authenticated to a destination router, and performing IP authentication on the data to be authenticated in the destination router using the detection data packet; When IP authentication fails, determining a first security authentication result of the destination router regarding the data to be authenticated; When the IP authentication is successful, calculating the forwarding path similarity between the detection data packet and the data to be authenticated; When the forwarding path similarity meets a preset similarity threshold, using the detection data packet to determine a second security authentication result of the destination router regarding the data to be authenticated; When the forwarding path similarity does not meet the preset similarity threshold, querying the normal data packet sent by the to-be-authenticated party to the destination router to obtain a data query result, and using the data query result to determine the third security authentication result of the destination router regarding the to-be-authenticated data; The first security authentication result, the second security authentication result and the third security authentication result are used as the final security authentication result.

2. The embedded router security authentication method according to claim 1, characterized in that: The sending of the detection data packet and the data to be authenticated from the party to be authenticated to the destination router includes: Sending the detection data packet from the party to be authenticated to the destination router; Find the destination host corresponding to the detection data packet through the address resolution protocol in the destination router; Obtaining a destination switch corresponding to the destination host; Sending the detection data packet to the destination host via the destination switch; Determining whether a response data packet from the destination host regarding the detection data packet is received in the destination router; When the destination router receives a response data packet from the destination host regarding the detection data packet, the data to be authenticated is sent from the party to be authenticated to the destination router.

3. The embedded router security authentication method according to claim 1, characterized in that: The step of performing IP authentication on the data to be authenticated by using the detection data packet in the destination router includes: Respectively extracting the standard source IP address and the source IP address to be verified from the detection data packet and the data to be authenticated; Calculating the address Hamming distance between the standard source IP address and the source IP address to be verified; Calculate the Hamming distance standard corresponding to the standard source IP address; When the address Hamming distance is inconsistent with the Hamming distance standard, it is determined that the IP authentication fails; When the address Hamming distance is consistent with the Hamming distance standard, it is determined that the IP authentication is successful.

4. The embedded router security authentication method according to claim 1, characterized in that: The calculating the forwarding path similarity between the detection data packet and the data to be authenticated includes: Tracking the standard forwarding path of the detection data packet from the party to be authenticated to the destination router; Tracking the forwarding path of the data to be authenticated from the party to be authenticated to the destination router; The sequence Hamming distance between the router address sequence on the standard forwarding path and the router address sequence on the forwarding path to be tested is calculated to obtain the forwarding path similarity.

5. The embedded router security authentication method according to claim 4, characterized in that: The tracing of the standard forwarding path of the detection data packet from the party to be authenticated to the destination router includes: Acquire a path tracing tool from the party to be authenticated to the destination router; tracing a first routing path of the probe data packet using the path tracing tool; According to the first routing path, selecting the next hop MAC address of the detection data packet; Generate a sending address sequence of the detection data packet through the next hop MAC address; Based on the sending address sequence, sending the detection data packet from the party to be authenticated to the destination router; tracing a second routing path of the probe data packet using the path tracing tool; The first routing path and the second routing path are used as standard forwarding paths for the detection data packet from the party to be authenticated to the destination router.

6. The embedded router security authentication method according to claim 1, characterized in that: The step of using the detection data packet to determine the second security authentication result of the destination router regarding the data to be authenticated includes: Obtaining the standard source IP address corresponding to the detection data packet; Identify a standard transmission path of the standard source IP address in a router network corresponding to the party to be authenticated; Identify the transmission path to be verified corresponding to the source IP address to be verified corresponding to the data to be authenticated; Extracting a standard MAC address on the standard transmission path; Extracting the MAC address to be verified on the transmission path to be verified; Generate a standard MAC sequence of the standard MAC address and a to-be-verified MAC sequence of the to-be-verified MAC address; Sending the standard MAC sequence and the to-be-verified MAC sequence to the destination router; In the destination router, calculating the MAC Hamming distance and the MAC distance standard between the standard MAC sequence and the MAC sequence to be tested; When the MAC Hamming distance is consistent with the MAC distance standard, taking security authentication success as a second security authentication result; When the MAC Hamming distance is inconsistent with the MAC distance standard, security authentication failure is taken as the second security authentication result.

7. The embedded router security authentication method according to claim 6, characterized in that: The identifying of a standard transmission path of the standard source IP address in a router network corresponding to the party to be authenticated includes: Acquire the standard source IP address in the router network corresponding to the party to be authenticated; Querying the primary switch connected to the source host corresponding to the standard source IP address through a link tracking tool in the router network; Querying the secondary switch of the source router corresponding to the standard forwarding path from the primary switch to the secondary switch through the link tracking tool; The standard transmission path is generated by using the source host, the primary switch, the secondary switch and the source router.

8. The embedded router security authentication method according to claim 1, characterized in that: The querying of the normal data packets sent by the party to be authenticated to the destination router to obtain the data query result includes: Obtain the forwarding path to be verified; Based on the forwarding path to be verified, selecting a path to be traced of the normal data packet; Querying whether there is ICMP timeout information of the normal data packet on the path to be traced; When there is ICMP timeout information of the normal data packet, the normal data packet sent by the to-be-authenticated party to the destination router can be queried as a data query result; When there is no ICMP timeout information of the normal data packet, it is impossible to query the normal data packet sent by the party to be authenticated to the destination router as a data query result.

9. The embedded router security authentication method according to claim 1, characterized in that: The step of using the data query result to determine the third security authentication result of the destination router regarding the data to be authenticated includes: Check whether the starting point of the forwarding path to be verified is consistent with the standard starting point of the standard forwarding path; When the to-be-verified starting point of the to-be-verified forwarding path is inconsistent with the standard starting point, taking the security authentication failure as the third security authentication result; When the to-be-verified starting point of the to-be-verified forwarding path is consistent with the standard starting point, if the data query result is data query failure, return to the aforementioned step of tracing the standard forwarding path of the detection data packet from the to-be-verified party to the destination router; When the to-be-verified starting point of the to-be-verified forwarding path is consistent with the standard starting point, if the data query result is that the data query is successful, it is determined that the security authentication is successful as the third security authentication result.

10. An embedded router security authentication system, characterized in that: The system comprises: An IP authentication module is used to send a detection data packet and data to be authenticated from the party to be authenticated to a destination router, and in the destination router, perform IP authentication on the data to be authenticated using the detection data packet; The first authentication module is used to determine the first security authentication result of the destination router regarding the data to be authenticated when the IP authentication fails. A similarity calculation module, used for calculating the similarity of the forwarding path between the detection data packet and the data to be authenticated when the IP authentication is successful; A second authentication module, configured to determine, by using the detection data packet, a second security authentication result of the destination router regarding the data to be authenticated when the forwarding path similarity meets a preset similarity threshold; A third authentication module, configured to query a normal data packet sent by the party to be authenticated to the destination router when the forwarding path similarity does not meet a preset similarity threshold, obtain a data query result, and determine a third security authentication result of the destination router regarding the data to be authenticated by using the data query result; The final authentication module is used to use the first security authentication result, the second security authentication result and the third security authentication result as the final security authentication result.

Citation Information

Patent Citations

  • Path tracking method and system, and gateway equipment

    CN103874105A

  • Router authentication method and device and storage medium

    CN114520977A

  • Method and apparatus for detecting network address trnaslation device

    KR101775325B1

  • Internet last-mile outage detection using IP-route clustering

    WO2022031411A1