Security parameter synchronization method and network equipment
By extending the routing protocol packets carry security parameters, point-to-point security parameter synchronization between network devices is achieved, and synchronization problems under controller dependence and different manufacturers are solved, improving security and compatibility.
Patent Information
- Application Number
- CN202410094714.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-22
- Publication Date
- 2025-07-22
AI Technical Summary
In the prior art, the synchronization of security parameters is overly dependent on the controller, resulting in the security parameters no longer being trustworthy when the controller is attacked, and it is difficult to synchronize in different manufacturers' networking scenarios.
By extending routing protocol messages carry security parameters, network devices can directly synchronize security parameters, including security status and trustworthiness levels, using the extensive support of routing protocols to reduce dependence on controllers.
The security parameter synchronization is achieved in different manufacturers' equipment and controller-free scenarios, reducing the risk of controller being attacked and improving the compatibility and security of the solution.
Smart Images

Figure CN120358245A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technologies, and particularly relates to a method for synchronizing security parameters and a network device. Background Art
[0002] Security parameters (such as security status, attacked status, or trust level) are important indicators for measuring the security of a device. To improve the overall security of a network, it is necessary to synchronize the security parameters of devices in the network.
[0003] Taking the synchronization of the security parameters of device A to device B as an example, during the process of synchronizing the security parameters, device A reports security logs to the controller; the controller determines the security parameters of device A based on the received security logs. The controller sends the security parameters of device A to device B, so that the security parameters of device A are transmitted to device B through the controller.
[0004] When using the above method, the synchronization of security parameters is overly dependent on the controller. Once the controller is attacked and there is a security risk, the security parameters synchronized through the controller are no longer trustworthy. Summary of the Invention
[0005] This application provides a method for synchronizing security parameters and a network device. Since routing protocol packets are used to carry the security parameters of a device, it supports the distributed synchronization of security parameters between devices, thereby reducing the dependence on the controller for security parameter synchronization. The technical solutions are as follows.
[0006] In a first aspect, a method for synchronizing security parameters is provided. The method includes: a first network device obtains the security parameters of the first network device; the first network device generates a routing protocol packet based on the security parameters, and the routing protocol packet includes the security parameters; the first network device sends the routing protocol packet to a second network device.
[0007] Since the format of the routing protocol packet is extended in the above method, and the security parameters of the network device are carried by the routing protocol packet, the network device can obtain the security parameters of the peer network device through the received routing protocol packet. Based on this, a distributed security parameter synchronization scheme is implemented, which supports the peer-to-peer communication between network devices to announce their respective security parameters, reduces the dependence on the controller for security parameter synchronization, and reduces the risk that the security parameters synchronized in the network are no longer trustworthy after the controller is attacked and there is a security risk.
[0008] In particular, since the routing protocol is a general and standard communication protocol widely supported by network devices, extending the routing protocol to transmit security states helps network devices produced by various manufacturers to obtain the security states of other network devices based on the received routing protocol messages. Therefore, it helps to reduce the implementation difficulty of security state synchronization caused by cross-vendor networking and improve the compatibility of the solution. In scenarios where network devices produced by different manufacturers are deployed in the network or where there is no controller deployed in the network, the synchronization of security states is still supported, and the applicable networking scenarios are more diverse.
[0009] Based on the method provided in the first aspect, in some embodiments, the second network device and the first network device belong to the same autonomous system (AS), and the routing protocol message includes an internal gateway protocol (IGP) message, and the IGP message includes security parameters.
[0010] Based on the method provided in the first aspect, in some embodiments, the IGP message includes an open shortest path first (OSPF) message, the OSPF message includes a link-state advertisement (LSA) field, the LSA field includes an option field, and the option field includes security parameters.
[0011] The above method can synchronize security parameters in a networking scenario where multiple network devices are deployed in the same AS (or an IGP domain).
[0012] Based on the method provided in the first aspect, in some embodiments, the IGP message includes a link state protocol data unit (LSP) message in the intermediate system-to-intermediate system (IS-IS) protocol; the LSP message includes a reserved field, and the reserved field includes security parameters; or, the LSP message includes a type length value (TLV), and the value field in the TLV includes security parameters.
[0013] Based on the method provided in the first aspect, in some embodiments, the second network device and the first network device belong to different ASs, and the routing protocol message includes a border gateway protocol (BGP) message, and the BGP message includes security parameters.
[0014] The above method can synchronize security parameters in a networking scenario where multiple network devices are deployed in different ASs, realizing cross-AS synchronization of security parameters.
[0015] Based on the method provided in the first aspect, in some embodiments, the BGP message includes a BGP update message, the BGP update message includes a path attribute field, and the path attribute field includes security parameters.
[0016] Since the BGP update message is used to announce routes, and the path attribute field is usually used to indicate route selection, by using the path attribute field to carry security parameters, it can implicitly indicate that the forwarding path is bypassed from devices with an insecure state based on the security parameters, improving the transmission security of service data.
[0017] Based on the method provided in the first aspect, in some embodiments, the BGP message includes a BGP open message, the BGP open message includes an optional parameter field, and the optional parameter field includes security parameters.
[0018] Since the purpose of the BGP open message in the standard protocol is to establish a BGP neighbor, by using the BGP open message to carry whether the network device supports security state transfer and the security state of the network device, the synchronization process of the security state can affect whether neighbors are established between network devices.
[0019] Based on the method provided in the first aspect, in some embodiments, the security parameters include a secure state, an insecure state, or a trust level. The secure state indicates that the first network device has not been under a network attack. The insecure state indicates that the first network device has been under a network attack. The trust level indicates the intensity or type of the network attack that the first network device has suffered.
[0020] The above method supports the synchronization of multiple network security-related parameters such as the secure state, insecure state, and trust level between devices based on the routing protocol, and the matching application scenarios are richer.
[0021] Based on the method provided in the first aspect, in some embodiments, the security parameters include a secure state, and the routing protocol message further includes a remote attestation result, and the remote attestation result is used to prove that the first network device is in a secure state.
[0022] By using the remote attestation mechanism to prove that the device is in a secure state, the credibility of the secure state is further improved, and the security risk caused by an attacker forging the secure state is reduced.
[0023] Based on the method provided in the first aspect, in some embodiments, before the first network device generates a routing protocol message based on security parameters, the method further includes: the first network device sends the security log of the first network device to a remote attestation server, where the security log is used to determine the security parameters; the first network device receives the security parameters and the remote attestation result sent by the remote attestation server.
[0024] In a second aspect, a method for synchronizing security parameters is provided, and the method includes:
[0025] The second network device receives a first routing protocol message from the first network device, where the first routing protocol message includes the first security parameter of the first network device;
[0026] The second network device adjusts the forwarding path of the data stream passing through the first network device based on the first security parameter.
[0027] Based on the method provided in the second aspect, in some embodiments, the second network device adjusts the forwarding path of the data stream passing through the first network device based on the first security parameter, including:
[0028] The second network device determines that the first security parameter is in an insecure state or the trust level included in the first security parameter does not meet the trust condition, and the second network device adjusts the forwarding path of the data stream passing through the first network device so that the forwarding path does not pass through the first network device.
[0029] Based on the method provided in the second aspect, in some embodiments, the method further includes:
[0030] The second network device generates a second routing protocol message based on the first security parameter of the first network device, where the second routing protocol message includes the first security parameter of the first network device;
[0031] The second network device sends the second routing protocol message to a third network device.
[0032] Based on the method provided in the second aspect, in some embodiments, the second network device and the third network device belong to the same AS, and the second routing protocol message is an IGP message, where the IGP message includes the first security parameter of the first network device.
[0033] Based on the method provided in the second aspect, in some embodiments, the second network device and the third network device belong to different ASs, and the second routing protocol message is a BGP message, where the BGP message includes the first security parameter of the first network device.
[0034] Based on the method provided in the second aspect, in some embodiments, the method further includes:
[0035] When the second network device determines that the first security parameter is in an insecure state or the trust level included in the first security parameter does not meet the trust condition, the second network device disconnects the neighbor relationship between the second network device and the first network device.
[0036] Based on the method provided in the second aspect, in some embodiments, when the first security parameter is in an insecure state or the trust level in the first security parameter does not meet the trust condition, after the second network device receives the first routing protocol message from the first network device, the method further includes:
[0037] The second network device receives the second security parameter of the first network device from M network devices, and the second security parameter includes a security state or / and the trust level in the second security parameter meets the trust condition;
[0038] Based on M being greater than or equal to a threshold and the trust level of each of the M network devices meeting the trust condition, the second network device determines that the security parameter of the first network device is restored to the second security parameter.
[0039] Based on the method provided in the second aspect, in some embodiments, when the first security parameter is in an insecure state or the trust level in the first security parameter does not meet the requirement, after the second network device receives the first routing protocol message from the first network device, the method further includes:
[0040] The second network device receives the second security parameter and the remote attestation result from the first network device, and the second security parameter includes a security state or / and the trust level in the second security parameter meets the trust condition;
[0041] Based on the remote attestation result passing the verification, the second network device determines that the security parameter of the first network device is restored to the second security parameter.
[0042] Based on the method provided in the second aspect, in some embodiments, the second network device receiving the second security parameter and the remote attestation result from the first network device includes:
[0043] The second network device receives a third routing protocol message from the first network device, and the third routing protocol message includes the second security parameter and the remote attestation result; or,
[0044] The second network device receives a link layer protocol message from the first network device, and the link layer protocol message includes the second security parameter and the remote attestation result.
[0045] Based on the method provided in the second aspect, in some embodiments, when the first security parameter is in an insecure state or the trust level in the first security parameter does not meet the requirements, after the second network device receives the first routing protocol message from the first network device, the method further includes:
[0046] The second network device obtains the security log of the first network device;
[0047] Based on the security log, the second network device determines that the security parameter of the first network device is restored to the second security parameter, where the second security parameter includes a security state or / and the trust level in the second security parameter meets the trust condition.
[0048] In a third aspect, a network device is provided, characterized in that the network device is the first network device, and the device includes:
[0049] A processing unit, configured to obtain the security parameter of the first network device; generate a routing protocol message based on the security parameter, where the routing protocol message includes the security parameter;
[0050] A sending unit, configured to send the routing protocol message to the second network device.
[0051] In some embodiments, the second network device and the first network device belong to the same AS, the routing protocol message includes an IGP message, and the IGP message includes the security parameter.
[0052] In some embodiments, the IGP message includes an OSPF message, the OSPF message includes an LSA field, the LSA field includes an option field, and the option field includes the security parameter.
[0053] In some embodiments, the IGP message includes an LSP message in the IS-IS protocol;
[0054] The LSP message includes a reserved field, and the reserved field includes the security parameter; or, the LSP message includes a TLV, and the value field in the TLV includes the security parameter.
[0055] In some embodiments, the second network device and the first network device belong to different ASs, the routing protocol message includes a BGP message, and the BGP message includes the security parameter.
[0056] In some embodiments, the BGP message includes a BGP update message, the BGP update message includes a path attribute field, and the path attribute field includes the security parameter.
[0057] In some embodiments, the BGP message includes a BGP open message, the BGP open message includes an optional parameter field, and the optional parameter field includes the security parameter.
[0058] In some embodiments, the security parameter includes a secure state, an insecure state, or a trust level. The secure state indicates that the first network device is not under a network attack. The insecure state indicates that the first network device is under a network attack. The trust level indicates the intensity or type of the network attack on the first network device.
[0059] In some embodiments, the security parameter includes a secure state, and the routing protocol message further includes a remote attestation result for attesting that the first network device is in the secure state.
[0060] In some embodiments, the sending unit is further configured to send the security log of the first network device to a remote attestation server, where the security log is used to determine the security parameter.
[0061] The device further includes a receiving unit configured to receive the security parameter and the remote attestation result sent by the remote attestation server.
[0062] In a fourth aspect, a network device is provided. The network device is a second network device, and the device includes:
[0063] A receiving unit configured to receive a first routing protocol message from a first network device, where the first routing protocol message includes a first security parameter of the first network device.
[0064] A processing unit configured to adjust a forwarding path of a data stream passing through the first network device based on the first security parameter.
[0065] In some embodiments, the processing unit is configured to determine that the first security parameter is in an insecure state or the trust level included in the first security parameter does not meet the trust condition, and adjust the forwarding path of the data stream passing through the first network device so that the forwarding path does not pass through the first network device.
[0066] In some embodiments, the processing unit is further configured to generate a second routing protocol message based on the first security parameter of the first network device, where the second routing protocol message includes the first security parameter of the first network device.
[0067] A sending unit configured to send the second routing protocol message to a third network device.
[0068] In some embodiments, the second network device and the third network device belong to the same AS, and the second routing protocol message is an IGP message, where the IGP message includes the first security parameter of the first network device.
[0069] In some embodiments, the second network device and the third network device belong to different ASes, the second routing protocol message is a BGP message, and the BGP message includes the first security parameter of the first network device.
[0070] In some embodiments, the processing unit is further configured to determine that the first security parameter is in an insecure state or the trust level included in the first security parameter does not meet the trust condition, and disconnect the neighbor relationship between the second network device and the first network device.
[0071] In some embodiments, when the first security parameter is in an insecure state or the trust level in the first security parameter does not meet the trust condition, the receiving unit is further configured to receive the second security parameter of the first network device from M network devices, where the second security parameter includes a security state or / and the trust level in the second security parameter meets the trust condition;
[0072] The processing unit is further configured to determine that the security parameter of the first network device is restored to the second security parameter based on M being greater than or equal to a threshold and the trust level of each of the M network devices meeting the trust condition.
[0073] In some embodiments, when the first security parameter is in an insecure state or the trust level in the first security parameter does not meet the requirement, the receiving unit is further configured to receive the second security parameter and the remote attestation result from the first network device, where the second security parameter includes a security state or / and the trust level in the second security parameter meets the trust condition;
[0074] The processing unit is further configured to determine that the security parameter of the first network device is restored to the second security parameter based on the remote attestation result passing the verification.
[0075] In some embodiments, the receiving unit is further configured to receive a third routing protocol message from the first network device, where the third routing protocol message includes the second security parameter and the remote attestation result; or, receive a link layer protocol message from the first network device, where the link layer protocol message includes the second security parameter and the remote attestation result.
[0076] In some embodiments, when the first security parameter is in an insecure state or the trust level in the first security parameter does not meet the requirement, the receiving unit is further configured to obtain the security log of the first network device;
[0077] The processing unit is configured to determine that the security parameter of the first network device is restored to the second security parameter based on the security log, where the second security parameter includes a security state or / and the trust level in the second security parameter meets the trust condition.
[0078] In a fifth aspect, a network device is provided. The network device includes a processor coupled to a memory. At least one computer program instruction is stored in the memory and is loaded and executed by the processor to enable the network device to implement the method provided in the first aspect or any optional manner of the first aspect. For the specific details of the network device provided in the fifth aspect, reference may be made to the first aspect or any optional manner of the first aspect, which will not be elaborated here.
[0079] In a sixth aspect, a network device is provided. The network device includes a processor coupled to a memory. At least one computer program instruction is stored in the memory and is loaded and executed by the processor to enable the network device to implement the method provided in the second aspect or any optional manner of the second aspect. For the specific details of the network device provided in the sixth aspect, reference may be made to the second aspect or any optional manner of the second aspect, which will not be elaborated here.
[0080] In a seventh aspect, a computer-readable storage medium is provided. At least one instruction is stored in the storage medium. When the instruction runs on a computer, the computer is enabled to execute the method provided in the first aspect or any optional manner of the first aspect.
[0081] In an eighth aspect, a computer-readable storage medium is provided. At least one instruction is stored in the storage medium. When the instruction runs on a computer, the computer is enabled to execute the method provided in the second aspect or any optional manner of the second aspect.
[0082] In a ninth aspect, a computer program product is provided. The computer program product includes one or more computer program instructions. When the computer program instructions are loaded and run on a computer, the computer is enabled to execute the method provided in the first aspect or any optional manner of the first aspect.
[0083] In a tenth aspect, a computer program product is provided. The computer program product includes one or more computer program instructions. When the computer program instructions are loaded and run on a computer, the computer is enabled to execute the method provided in the second aspect or any optional manner of the second aspect.
[0084] In an eleventh aspect, a chip is provided, including a memory and a processor. The memory is used to store computer instructions, and the processor is used to call and run the computer instructions from the memory to execute the method in the first aspect and any possible implementation manner of the first aspect.
[0085] In a twelfth aspect, a chip is provided, including a memory and a processor. The memory is used to store computer instructions, and the processor is used to call and run the computer instructions from the memory to execute the method provided in the above second aspect or any optional implementation manner of the second aspect.
[0086] In a thirteenth aspect, a network system is provided. The network system includes the network device provided in the above third aspect and the network device provided in the fourth aspect. Alternatively, the network system includes the network device provided in the above fifth aspect and the network device provided in the sixth aspect.
[0087] Based on the implementation manners provided in the above aspects of the present application, further combinations can be made to provide more implementation manners. BRIEF DESCRIPTION OF THE DRAWINGS
[0088] Figure 1 FIG. shows a schematic diagram of a network deployment scenario provided by an embodiment of the present application;
[0089] Figure 2 FIG. shows a schematic diagram of another network deployment scenario provided by an embodiment of the present application;
[0090] Figure 3 is a flowchart of a method for synchronizing security parameters provided by an embodiment of the present application;
[0091] Figure 4 FIG. shows a flowchart of another method for synchronizing security parameters provided by an embodiment of the present application;
[0092] Figure 5 FIG. shows a flowchart of another method for synchronizing security parameters provided by an embodiment of the present application;
[0093] Figure 6 FIG. shows a flowchart of another method for synchronizing security parameters provided by an embodiment of the present application;
[0094] Figure 7 FIG. shows a flowchart of another method for synchronizing security parameters provided by an embodiment of the present application;
[0095] Figure 8 FIG. shows a flowchart of another method for synchronizing security parameters provided by an embodiment of the present application;
[0096] Figure 9 FIG. shows a schematic diagram of the format of the router-LSA field in an OSPF protocol packet provided by an embodiment of the present application;
[0097] Figure 10 FIG. shows a schematic diagram of the format of the network-LSA field in an OSPF protocol packet provided by an embodiment of the present application;
[0098] Figure 11 Shows a schematic diagram of the message format of an LSP in the IS-IS protocol provided by an embodiment of the present application;
[0099] Figure 12 Shows a schematic diagram of the message format of a CSNP in the IS-IS protocol provided by an embodiment of the present application;
[0100] Figure 13 Shows a schematic diagram of the format of a BGP open message provided by an embodiment of the present application;
[0101] Figure 14 Shows a schematic diagram of the format of a BGP update message provided by an embodiment of the present application;
[0102] Figure 15 Is a schematic diagram of the structure of a network device provided by an embodiment of the present application;
[0103] Figure 16 Is a schematic diagram of the structure of a network device provided by an embodiment of the present application;
[0104] Figure 17 Is a schematic diagram of the structure of a network device provided by an embodiment of the present application. Detailed implementation manners
[0105] To make the objectives, technical solutions and advantages of the present application clearer, the following will further describe in detail the embodiments of the present application with reference to the accompanying drawings.
[0106] The following explains some term concepts related to the embodiments of the present application.
[0107] (1) Security parameter
[0108] A security parameter refers to a parameter that can characterize the security and trustworthiness of a network device. Exemplarily, the security parameter includes a secure state or an insecure state. The secure state indicates that the network device has not been attacked by the network. The insecure state indicates that the network device has been attacked by the network.
[0109] Optionally, the security parameter further includes a trust level. The trust level is equivalent to a finer-grained definition of the secure state. The trust level indicates the intensity or type of network attack suffered by the network device. The types of network attacks include, for example, distributed denial-of-service attack (DDoS) attacks, web shell attacks, outbound request attacks, or server-side request forgery (SSRF) attacks. The intensity of the network attack includes attack success or attack failure.
[0110] In some embodiments, the trust level is used to characterize the degree of security. For example, when the network device is in a secure operating state, without being under a network attack and without performing any abnormal behavior, the trust level of the network device is the first trust level, which is the highest trust level, indicating the highest degree of security. Another example is that when the network device is under a network attack but the attack fails, the trust level of the network device is the second trust level, and the degree of security represented by the second trust level is lower than that represented by the first trust level. Another example is that when the network device is under a network attack and the attack is successful, the trust level of the network device is the third trust level, and the degree of security represented by the third trust level is lower than that represented by the second trust level. Another example is that when the network device detects that a malicious program has been implanted at its end, the trust level of the network device is the fourth trust level, which represents the lowest degree of security. Another example is that the network device determines the trust level of its end based on the detected type of network attack and the type of trust level.
[0111] In some embodiments, the security parameter is in the form of an integer. For example, 0 indicates that the network device is in a secure state, and 1 indicates that the network device is in an insecure state. Another example is that 0010 indicates that the network device is in a secure state and the trust level is 1. 0100 indicates that the network device is in a secure state and the trust level is 2. Another example is that 0110 indicates that the network device is in a secure state and the trust level is 3. Another example is that 1000 indicates that the network device is in a secure state and the trust level is 4. Another example is that 1010 indicates that the network device is in a secure state and the trust level is 5.
[0112] (2) Network device
[0113] A network device is, for example, a device deployed in a network for forwarding service data. For example, the network device is a general router or switch. Also, for example, the network device is a device supporting network security protection functions. For example, the network device is a firewall, security gateway, intrusion detection system (IDS) device, intrusion prevention system (IPS) device, unified threat management (UTM) device, anti-virus (AV) device, anti-distributed denial-of-service attack (DDoS) (anti-DDoS) device, next-generation firewall (NGFW), and so on. In the embodiments of the present application, the network device supports the ability to communicate based on a routing protocol. The network device can carry data that needs to be disseminated in a routing protocol message and send it to other network devices. The network device can parse to obtain the data carried in the routing protocol message from other network devices. In addition, the network device supports network attack detection and / or abnormal behavior detection. For example, the network device supports the ability of security intrusion detection. The network device can determine the security parameters of the local end by performing network attack detection and / or abnormal behavior detection.
[0114] (3) Security log
[0115] A security log refers to a log record of a network device that can be used to analyze the security and trustworthiness level. For example, the security log includes the usage status of resources in the network device, the operating status of hardware such as the processor and memory in the network device, the operating log of the operating system, the operations of users (such as login, logout, permission change), or the process behavior in the network device, the file system of the network device, or the network connection information of the network device.
[0116] The application scenarios of the embodiments of the present application are illustrated by examples below.
[0117] The embodiments of the present application are applied to scenarios where parameters related to network security (such as security status or trust level) are synchronized in a network.
[0118] In some implementation manners of synchronizing the security status, when a network device is maliciously invaded, the network device communicates with the controller, and the network device sends the security log of the network device to the controller. The controller performs network security situation awareness analysis based on the security log to obtain the security status of the network device. The controller distributes the analyzed security status of the network device to each network device managed by the controller, so that the security status of the maliciously invaded network device is synchronized to other network devices.
[0119] The above-described embodiment is equivalent to a centralized security state synchronization scheme. Since the analysis of the security state depends on the execution of the controller and the transmission of the security state also depends on the execution of the controller, once there is a security risk in the controller, the synchronized security state in the network is no longer trustworthy. For example, when an attacker compromises the controller, the attacker can modify the security state obtained from the situation awareness on the controller. For instance, the security state originally analyzed by the controller is that the network device is in an insecure state, but the attacker modifies the analysis result to that the network device is in a secure state and instructs the controller to synchronize the secure state of the network device to each network device, resulting in the synchronized security state in the network not being the actual security state.
[0120] In addition, in the case of heterogeneous manufacturer networking, it is difficult to deploy the above-described security state synchronization scheme for network devices. For example, there may be network devices produced by multiple manufacturers deployed in the network, and it is difficult for the controller to analyze the security states of network devices produced by each manufacturer.
[0121] In view of this, some embodiments of the present application provide a distributed security state synchronization scheme. The network device determines its own security state, and the network device generates a routing protocol message carrying its own security state, such as a routing protocol message of the internal gateway protocol (IGP) or the border gateway protocol (BGP), etc., and sends the routing protocol message to other network devices, which is equivalent to the network devices notifying each other of their security states in a point-to-point communication manner, thereby realizing the synchronization of the security states of network devices and reducing the dependence on the security situation analysis of the controller. For example, network device A sends a routing protocol message to network device B, and the routing protocol message carries the security state of network device A, which is equivalent to network device A directly notifying network device B whether it is secure at its end, rather than network device A first notifying the controller of the security log of network device A and then the controller notifying network device B of the security state of network device A, thereby reducing the risk that the security state notified by the controller is untrustworthy due to the controller being compromised.
[0122] In particular, since the routing protocol is a common standard communication protocol generally supported by network devices, extending the routing protocol to transmit the security state helps each network device produced by each manufacturer to obtain the security states of other network devices based on the received routing protocol message. Therefore, it helps to reduce the implementation difficulty of security state synchronization caused by heterogeneous manufacturer networking and improve the compatibility of the scheme. In the scenario where network devices produced by different manufacturers are deployed in the network or there is no controller deployed in the network, the synchronization of the security state is still supported, and the applicable networking scenarios are richer.
[0123] Reference Figure 1 , Figure 1 shows a schematic diagram of a network deployment scenario provided by an embodiment of the present application. Figure 1 The devices in the shown network system 10 belong to the same autonomous system (AS). For example, the devices in the network system 10 are deployed in the same IGP domain. An IGP domain refers to an area within an AS where routing information can be exchanged based on the IGP protocol. As Figure 1 shown, the network system 10 includes multiple network devices, and the multiple network devices include, for example, network device A, network device B, network device C, and network device D. The network devices are deployed at the boundary of the AS or inside the AS.
[0124] Each network device among the multiple network devices in the network system 10 supports IGP and security intrusion detection capabilities. IGP neighbor relationships are established among the multiple network devices in the network system 10. For example, IGP neighbor relationships are established between any two of the network devices A, B, C, and D. The network devices A, B, C, and D use the same link state database (LSDB) to generate routing tables.
[0125] Reference Figure 2 , Figure 2 shows a schematic diagram of another network deployment scenario provided by an embodiment of the present application. Figure 2 Some of the devices in the shown network system 10 belong to the same AS, and some other devices belong to another AS. As Figure 2 shown, the network system 10 includes multiple network devices deployed in the first AS and multiple network devices deployed in the second AS.
[0126] The multiple network devices deployed in the first AS include, for example, network device A, network device B, network device C, and network device D. IGP neighbor relationships are established among the multiple network devices deployed in the first AS. For example, IGP neighbor relationships are established between any two of the network devices A, B, C, and D. For example, network devices B, C, and D are all IGP neighbors of network device A, and network devices A, C, and D are all IGP neighbors of network device B.
[0127] The multiple network devices deployed in the second AS include, for example, network device E, network device F, network device G, and network device H. An IGP neighbor relationship is established between the multiple network devices deployed in the second AS. For example, an IGP neighbor relationship is established between network device E and any two of network devices F, network device G, and network device H. For example, network device F, network device G, and network device H are all IGP neighbors of network device E. Network device E, network device G, and network device H are all IGP neighbors of network device F.
[0128] The network device deployed at the border of the first AS establishes a BGP neighbor relationship with the network device deployed at the border of the second AS. For example, network device D establishes a BGP neighbor relationship with network device E. In other words, network device E is the BGP neighbor of network device D. The network devices at the border of the first AS and the network devices at the border of the second AS support IGP and security intrusion detection capabilities.
[0129] Optionally, a controller is further deployed in the cross-domain scenario, and the controller establishes a BGP link-state (BGP-LS) neighbor relationship with the border network devices of each AS. For example, the controller establishes a BGP-LS neighbor relationship with network device B and network device F respectively. In other words, network device B and network device F are both BGP-LS neighbors of the controller. The controller is the network management platform for the entire network. The controller has the function of security situation awareness and the function of notifying the security status to the network devices.
[0130] The following is an example of the method flow of the embodiment of the present application.
[0131] Attached Figure 3 Attached is a flowchart of a method for synchronizing security parameters provided in an embodiment of the present application. Figure 3 The method shown involves interaction between multiple network devices. In order to distinguish different network devices, a network device that is a sender of security parameters is described as a "first network device", and a network device that is a receiver of security parameters is described as a "second network device". Figure 3 The method shown is applied to Figure 1 In the network system 10 shown, for example, the first network device is Figure 1 The network device A in the second network device is Figure 1 In some other implementations, the network device B, network device C or network device D is attached. Figure 3 The method shown is applied to Figure 2 In the network system 10 shown, for example, the first network device is Figure 2 The network device D in the second network device is Figure 2 Network device E in.
[0132] Appended Figure 3 The method shown includes the following steps S310 to S350.
[0133] S310, the first network device obtains the security parameters of the first network device.
[0134] In some embodiments, the first network device performs network attack detection based on the traffic transmitted by the first network device, and determines the security parameters of the first network device based on the results of the network attack detection.
[0135] In some embodiments, the first network device collects the security logs recorded by the first network device. The first network device performs network attack detection and / or abnormal behavior detection based on the collected security logs, and determines the security parameters of the first network device based on the detection results.
[0136] S320, the first network device generates a routing protocol message based on the security parameters.
[0137] The routing protocol message includes the security parameters. For example, the routing protocol message includes a secure state or an insecure state. Also, for example, the routing protocol message includes the trust level of the first network device.
[0138] In some embodiments, the routing protocol message not only includes a secure state or an insecure state, but further includes the trust level of the first network device. Since the secure state and the trust level are carried by the same message, the actions of announcing the secure state and the actions of announcing the trust level can be executed simultaneously, saving the bandwidth resources and message overhead occupied by the secure state and the trust level as a whole.
[0139] In other embodiments, the first network device generates multiple routing protocol messages based on the security parameters, and sends the multiple routing protocol messages to the second network device. For example, the multiple routing protocol messages include a routing protocol message and a second routing protocol message. The routing protocol message includes a secure state or an insecure state. The second routing protocol message includes the trust level of the first network device.
[0140] In some embodiments, the routing protocol message further includes an identifier of the first network device. The identifier of the first network device is used to identify the first network device. The identifier of the first network device, for example, is the Internet Protocol (IP) address of the first network device, the device name of the first network device, or the number of the first network device. Since the security parameters and the identifier of the device are carried by the same message, it is convenient for the receiving end to clearly identify the network device to which the received security parameters belong.
[0141] In some embodiments, the routing protocol message further includes a capability identifier, which is used to identify that the first network device supports the transfer of security parameters. For example, the capability identifier includes a first capability identifier and / or a second capability identifier. The first capability identifier is used to identify that the first network device supports the transfer of security status. The second capability identifier is used to identify that the first network device supports the transfer of trust level. Since the security parameters and the capability identifier are carried in the same message, it is equivalent to notifying the security parameters and also notifying that the local end supports the transfer of security parameters.
[0142] The routing protocol messages are divided into IGP messages and BGP messages. IGP is a routing protocol used within an AS. As an example, when the first network device and the second network device belong to the same AS, IGP messages are used to synchronize security parameters within the AS. The routing protocol message sent by the first network device to the second network device is an IGP message, the second network device is an IGP neighbor of the first network device, and the IGP message includes the security parameters of the first network device.
[0143] BGP is an external gateway protocol and is a routing protocol used between different ASs. As an example, when the first network device and the second network device belong to different ASs, BGP messages are used to synchronize security parameters between the ASs. The routing protocol message sent by the first network device to the second network device is a BGP message, the second network device is a BGP neighbor of the first network device, and the BGP message includes the security parameters of the first network device.
[0144] For the specific extended structure of the protocol message, please refer to the following description.
[0145] In some embodiments, the routing protocol message further includes a remote attestation result, which is used to prove the credibility of the security parameters. For example, the remote attestation result includes the certificate of the remote attestation server, and the certificate identifies the identity of the remote attestation server. Another example is that the remote attestation result includes the digital signature of the remote attestation server. Since the routing protocol message also includes the remote attestation result, the credibility of the security parameter synchronization is improved, and the security risk caused by an attacker deceiving or forging security parameters is reduced. For example, the routing protocol message includes not only the security status but also the remote attestation result, and the remote attestation result is used to prove that the first network device is indeed in a secure state, reducing the security risk caused by an attacker forging the security state. Another example is that the routing protocol message includes not only the trust level but also the remote attestation result, and the remote attestation result is used to prove that the first network device indeed has this trust level, reducing the security risk caused by an attacker forging the trust level.
[0146] In some embodiments, the remote attestation result is obtained by a network device through interaction with a remote attestation server. For example, a first network device sends security logs of the first network device to the remote attestation server, and the security logs are used to determine security parameters; the remote attestation server performs network security situation awareness analysis based on the security logs to obtain the security parameters of the first network device. The remote attestation server generates a remote attestation result. The controller sends the security parameters and the remote attestation result of the first network device to the first network device, and the first network device receives the security parameters and the remote attestation result sent by the remote attestation server.
[0147] S330, the first network device sends a routing protocol message to the second network device.
[0148] In some embodiments, the first network device and the second network device are in the same routing management domain. A routing management domain refers to an area where each network device can exchange routing information based on the same routing protocol. The first network device and the second network device have established a neighbor relationship, and the first network device sends a routing protocol message to the neighbor device on its own side in the routing management domain.
[0149] As an example, the first network device includes an intrusion prevention system (IPS). When the first network device is under a network attack and the traffic of the network attack hits the security policy of the IPS of the first network device, the first network device converts its own security state to an insecure state. Triggered by the conversion of the security state to an insecure state, the first network device generates a routing protocol message carrying the insecure state and sends the routing protocol message to other devices outside the first network device in the routing domain.
[0150] S340, the second network device receives the routing protocol message from the first network device.
[0151] After receiving the routing protocol message, the second network device can parse the routing protocol message to obtain the security parameters of the first network device carried in the routing protocol message.
[0152] In some embodiments, the routing protocol message further includes a remote attestation result. The second network device verifies the remote attestation result. If the remote attestation result is verified to be passed, the second network device determines that the security parameters of the first network device are trustworthy, and further performs a predetermined action based on the security parameters. For example, the second network device verifies the remote attestation result based on the public key of the remote attestation server.
[0153] In some embodiments, the second network device stores a predetermined policy. The predetermined policy includes the correspondence between security parameters and predetermined actions. The predetermined policy is, for example, a routing policy or a security policy. The second network device matches based on the security parameters with the predetermined policy, and in response to the security parameters hitting the predetermined policy, executes the predetermined action. Exemplarily, the second network device executes S350 as follows.
[0154] S350, the second network device adjusts the forwarding path of the data stream passing through the first network device based on the security parameters.
[0155] Considering that service data usually needs to be forwarded by multiple network devices during the transmission process, the transmission security of service data and the transmission quality of service data are usually related to the security parameters of the network devices. For example, if the first network device is under a network attack, the first network device may affect the security of service data or the transmission quality of service data when forwarding service data. For example, the first network device is implanted with malicious programs such as Trojans due to a network attack, and the malicious programs in the first network device may steal service data. Another example is that the first network device has poor forwarding performance due to a DDoS attack, such as a relatively large forwarding delay of the first network device. In view of this, since the second network device adjusts the forwarding path of the data stream based on the security parameters of the first network device, it is equivalent to improving the transmission security of service data and the transmission quality of service data.
[0156] In some embodiments, the second network device determines that the first network device is in an insecure state or the trust level of the first network device does not meet the trust condition based on the security parameters. The second network device adjusts the forwarding path of the data stream passing through the first network device so that the forwarding path does not pass through the first network device. The adjusted forwarding path is equivalent to bypassing the insecure network device, thereby reducing the impact of the insecure network device on the security of service data or the transmission quality of service data.
[0157] In some embodiments, the second network device determines that the first network device is in an insecure state or the trust level of the first network device does not meet the trust condition based on the security parameters. The second network device determines the first routing information related to the first network device in the local routing table. The second network device adjusts the attributes of the first routing information to adjust the forwarding path of the data stream passing through the first network device.
[0158] The first routing information is, for example, the routing information received from the first network device. The next hop in the first routing information includes the identifier of the first network device. The forwarding path indicated by the first routing information usually passes through the first network device.
[0159] The attributes of the first routing information are also referred to as path attributes. The role of the attributes of the first routing information is equivalent to a basis for route selection. The attributes of the first routing information can affect the priority degree of selecting the first routing information from multiple reachable routing information of the data flow destination IP address to forward the data flow. When the first network device is insecure or untrusted, the routing information received from the first network device may be forged routing information by an attacker. If the data flow is still forwarded according to the routing information received from the first network device, the risks of network attacks such as route hijack, route injection, and traffic detour are relatively high. By modifying the attributes of the routing information received from the first network device, the risks of network attacks such as route hijack attacks and route injection are reduced, the probability that the forwarding path passes through the first network device is reduced, and the forwarding path is made to bypass to other network devices outside the first network device as much as possible.
[0160] In some embodiments, the attributes of the first routing information include at least one of the cost value, priority, metric, or security parameter of the first routing information.
[0161] The cost value of the routing information refers to the cost paid to select a certain path to reach the destination host. The cost value of the routing information is usually a numerical value used to measure the quality of the forwarding path. The smaller the cost value of the routing information, the greater the probability that the routing information is selected, and the greater the probability that the data flow is forwarded according to the routing information. In some embodiments, if the second network device determines that the security parameter is in an insecure state or the trust level included in the security parameter does not meet the trust condition, the second network device increases the cost value of the first routing information, thereby reducing the probability that the forwarding path of the data packet passes through the first network device and improving the transmission security of the data packet.
[0162] The priority of the routing information is used to indicate the priority degree or importance of selecting the routing information to reach a certain destination address. In some embodiments, if the second network device determines that the security parameter is in an insecure state or the trust level included in the security parameter does not meet the trust condition, the second network device reduces the priority of the first routing information, thereby reducing the probability that the forwarding path of the data packet passes through the first network device and improving the transmission security of the data packet.
[0163] In some embodiments, the second network device adds a security parameter to the routing attributes of the first routing information. Since the security parameter is reflected in the routing attributes, the routing forwarding operation is associated with the security status handling operation. For example, when the second network device looks up the updated routing table based on the destination IP address of the data packet, it determines whether to forward the data packet using the first routing information based on the security parameter in the first routing information. For example, if the first routing information includes an insecure state or the trust level does not meet the trust condition, forwarding the data packet through the first routing information is prohibited. If the first routing information includes a secure state or the trust level meets the trust condition, forwarding the data packet through the first routing information is allowed.
[0164] As an example, in Figure 1 the scenario shown, network devices B, C, and D respectively receive routing protocol packets from network device A. Network devices B, C, and D respectively extract the security status of network device A from the routing protocol packets. Network devices B, C, and D change the cost value of the routing information received from network device A according to a predetermined policy, implementing a closed loop of the security policy.
[0165] In some embodiments, the second network device determines which data flow forwarding paths to adjust based on the trust level of the first network device and the security level of the data flow. The security level of the data flow is used to describe the security requirements for data flow transmission. For example, if the trust level of the first network device is less than the first trust level, the forwarding paths of all data flows passing through the first network device are adjusted. If the trust level of the first network device is less than the second trust level and greater than the second trust level, the forwarding path of the first data flow passing through the first network device is adjusted. The first data flow is a data flow with a high security level, and the security level of the first data flow is greater than the security level threshold.
[0166] In some other embodiments, the second network device determines that the security parameter is in a secure state or the trust level included in the security parameter meets the trust condition. For example, if the first network device is under a network attack but the network attack is not successful, in this case, the trust level of the first network device may still meet the trust condition, and the second network device does not need to adjust the forwarding paths of the data flows passing through the first network device.
[0167] In some embodiments, after the second network device obtains the security parameters of the first network device, if the second network device determines that the security parameters are in an unsafe state or the trust level included in the security parameters does not meet the trust condition, the second network device disconnects the neighbor relationship between the second network device and the first network device. Considering that establishing a neighbor relationship with an unsafe or untrustworthy network device may cause the local end to be attacked or deceived, for example, an unsafe network device may continue to send messages to the local end frequently to occupy the utilization rate of the processor of the local end. Based on this, some embodiments of the present application maintain a neighbor relationship based on the received security parameters. For example, if the security parameters received by the second network device indicate that the first network device is unsafe or untrustworthy, the second network device does not establish a neighbor relationship with the first network device. If the security parameters received by the second network device indicate that the first network device is safe and trustworthy, the second network device will establish a neighbor relationship with the first network device, thereby reducing the risk of the first network device launching a network attack on the second network device through the neighbor relationship, which helps to improve the security of establishing a neighbor relationship.
[0168] The method provided in this embodiment expands the format of the routing protocol message, and carries the security parameters of the network device through the routing protocol message, so that the network device can obtain the security parameters of the opposite network device through the received routing protocol message. Based on this, a distributed security status synchronization scheme is implemented, which supports the network devices to notify each other of their security parameters in a point-to-point communication manner, reduces the dependence of the synchronization of security parameters on the controller, and reduces the risk that the synchronized security parameters in the network are no longer credible after the controller is attacked and there is a security risk.
[0169] Furthermore, since the routing protocol is a universal standard communication protocol generally supported by network devices, network devices produced by various manufacturers are likely to support the identification of routing protocol messages. Therefore, in scenarios where different manufacturers are networked (network devices produced by different manufacturers are deployed in the network) or where no controller is deployed in the network, the synchronization of security parameters is also supported, and the applicable networking scenarios are richer.
[0170] Figure 3 The embodiment focuses on describing how a network device synchronizes the security parameters of the local end to other network devices. In some implementations, the network device is also responsible for further synchronizing the security parameters of neighboring devices to other network devices.
[0171] For example, a first network device advertises its own security parameters to a second network device based on a routing protocol. The second network device further advertises the security parameters of the first network device to a third network device based on the routing protocol, so that the security parameters of the first network device are synchronized to the third network device through the second network device. The interaction process between the second network device and the third network device is illustrated by way of example below.
[0172] Reference Figure 4 , Figure 4 shows a flowchart of another method for synchronizing security parameters provided by an embodiment of the present application. Figure 4 The method shown Figure 3 On the basis of the method shown, further includes the following S360 to S390. In the method shown Figure 4 In the method shown, in order to distinguish the routing protocol packets sent by the first network device and the routing protocol packets sent by the second network device, the routing protocol packets sent by the first network device are described as "first routing protocol packets", and the routing protocol packets sent by the second network device are described as "second routing protocol packets".
[0173] S360, the second network device generates a second routing protocol packet based on the security parameters of the first network device.
[0174] The second routing protocol packet includes the security parameters of the first network device. The interaction process between the second network device and the third network device is similar to the interaction process between the first network device and the second network device.
[0175] As an example, when the second network device and the third network device belong to the same AS, the second routing protocol packet sent by the second network device to the third network device is an IGP packet, the third network device is an IGP neighbor of the second network device, and the IGP packet includes the security parameters of the first network device.
[0176] As an example, when the second network device and the third network device belong to different ASs, the second routing protocol packet sent by the second network device to the third network device is a BGP packet, the third network device is a BGP neighbor of the second network device, and the BGP packet includes the security parameters of the first network device.
[0177] S370, the second network device sends the second routing protocol packet to the third network device.
[0178] S380, the third network device receives the second routing protocol packet.
[0179] S390, the third network device adjusts the forwarding path of the data stream passing through the first network device based on the security parameters of the first network device.
[0180] The actions performed by the third network device based on the security parameters are similar to those performed by the second network device based on the security parameters. For example, if the third network device determines that the security parameters of the first network device are in an insecure state or the trust level included in the security parameters of the first network device does not meet the trust condition, the third network device increases the cost value of the first routing information or decreases the priority of the first routing information. As an example, in Figure 2 In the scenario shown, the routing table of network device H stores the first routing information received from network device A and the second routing information received from network device B, and the first routing information and the second routing information have the same destination IP address. Based on the IGP protocol packet received from network device E, network device H learns that network device A is in an insecure state while network device B is in a secure state. Network device H preferentially selects to forward data packets based on the second routing information rather than the first routing information.
[0181] For example, in Figure 2 In the scenario shown, the method shown in Figure 3 is applied. The first network device is, for example, Figure 2 network device A in Figure 2 , the second network device is, for example, Figure 2 network device B, network device C, or network device D in Figure 2 , and the third network device is, for example, Figure 2 network device E, network device F, network device G, and network device H in Figure 2 . When network device A confirms that its own end is in an insecure state through detecting a network attack, network device A sends IGP protocol packet A to its own IGP neighbors (network device B, network device C, and network device D) respectively. The IGP protocol packet A includes the identifier of network device A and the insecure state, so that each network device in the first AS can perceive that network device A is in an insecure state. After receiving the IGP protocol packet A, network device D sends a BGP protocol packet to its own BGP neighbor (network device E). The BGP protocol packet includes the identifier of network device A and the insecure state, so that the insecure state of network device A is transmitted from the first AS to the second AS through network device D. After receiving the BGP protocol packet, network device E sends IGP protocol packet B to its own IGP neighbors (network device F, network device G, and network device H) respectively. The IGP protocol packet B includes the identifier of network device A and the insecure state, so that each network device in the second AS can also perceive that network device A is in an insecure state.
[0182] In the method provided in this embodiment, the second network device advertises the security parameters of the first network device to the third network device through routing protocol messages. This is equivalent to the security parameters being diffused to the third network device through the second network device, enabling the third network device to obtain the security parameters of the first network device based on the received routing protocol messages, and further expanding the scope of synchronization of the security parameters. In particular, when the first network device is deployed within the first AS, the second network device is deployed at the boundary of the first AS, and the third network device is deployed at the boundary of the second AS, it supports the transmission of the security parameters of the devices within one AS to another AS, realizing cross-AS synchronization of the security parameters.
[0183] Figure 4 The embodiment focuses on describing the process of cross-device (such as cross-AS) synchronization by forwarding security parameters based on routing protocols by network devices. In some other embodiments, the security parameters of network devices are forwarded by a controller to achieve cross-device (such as cross-AS) synchronization of the security parameters. The following combines Figure 5 embodiments for illustration by examples.
[0184] Refer to Figure 5 , Figure 5 which shows the flowchart of another method for synchronizing security parameters provided by the embodiments of the present application. Figure 5 The method shown Figure 3 is further included with the following S460 to S488 based on the method shown.
[0185] S460, the second network device generates a first advertisement message.
[0186] The first notification message includes the security parameters of the first network device and the identifier of the first network device. The first notification message is a control plane protocol message or a management plane protocol message. The management plane protocol message is, for example, a Network Configuration Protocol (NETCONF) message, a Representational State Transfer Configuration (RESTCONF) message, or a Simple Network Management Protocol (SNMP) message, etc. The control plane protocol message is, for example, a Border Gateway Protocol Link-State (BGP LS) message, a Path Computation Element Protocol (PCEP) message, or a Border Gateway Protocol Flow Specification (BGP flow spec or BGP FS) message.
[0187] S470, the second network device sends the first notification message to the controller.
[0188] For example, in Figure 2 the scenario shown, the first network device is, for example, Figure 2 network device A in the middle network, the second network device is, for example, Figure 2 network device B in the middle network, and the third network device is, for example, Figure 2 network device F in the middle network. When network device A confirms that its local end is in an insecure state through detecting a network attack, network device A sends IGP protocol message A to its local IGP neighbors (network device B, network device C, and network device D) respectively. The IGP protocol message A includes the identifier of network device A and the insecure state, so that each network device within the first AS can perceive that network device A is in an insecure state. After receiving the IGP protocol message A, network device B sends a BGP-LS protocol message A to its local BGP-LS neighbor (the controller). The BGP-LS protocol message A includes the identifier of network device A and the insecure state, so that the insecure state of network device A is transmitted to the controller.
[0189] S480, the controller receives the first notification message.
[0190] S482, the controller generates a second notification message based on the security parameters of the first network device and the identifier of the first network device carried in the first notification message.
[0191] The second advertisement message carries the security parameters of the first network device and the identifier of the first network device. The second advertisement message is a control plane protocol message or a management plane protocol message.
[0192] S484, the controller sends the second advertisement message to the third network device.
[0193] S486, the third network device receives the second advertisement message.
[0194] S488, the third network device adjusts the forwarding path of the data stream passing through the first network device based on the security parameters of the first network device.
[0195] The third network device advertises the security parameters of the first network device to the fourth network device based on the IGP protocol, so that the security parameters are passed to the network devices in another AS through multiple network devices and the controller. Among them, the first network device and the second network device both belong to the first AS, and the third network device and the fourth network device both belong to the second AS.
[0196] For example, in Figure 2 the scenario shown, after the controller receives the BGP-LS protocol message, the controller sends the BGP-LS message B to its local BGP-LS neighbor (network device F). The BGP-LS protocol message B includes the identifier of network device A and the insecure state. After network device F receives the BGP-LS protocol message B, network device F sends the IGP protocol message B to its local IGP neighbors (network device E, network device G, and network device H) respectively. The IGP protocol message B includes the identifier of network device A and the insecure state, so that each network device in the second AS can also perceive that network device A is in an insecure state.
[0197] The method provided in this embodiment supports distributed synchronization of security parameters among devices within an AS based on the IGP protocol, and centralized synchronization of security parameters between ASs by the controller based on the BGP-LS protocol. It is equivalent to combining the two methods of distributed synchronization and centralized synchronization, and can also achieve cross-AS synchronization of security parameters.
[0198] Some embodiments of this application also provide a recovery mechanism for security parameters.
[0199] The restoration of security parameters is as follows. For example, the second network device has recorded that the first network device is in an insecure state. After the first network device resumes from the insecure state to the secure state, how to update the insecure state of the first network device recorded on the second network device to the secure state on the premise of ensuring the credibility of the restored secure state of the first network device. For example, when the first network device switches from the secure state to the insecure state, since the first network device notifies the second network device of its insecure state, the second network device will regard the first network device as an untrusted device. When the first network device resumes to the secure state and notifies the second network device of its restoration to the secure state, the second network device does not trust the credibility of the secure state notified by the first network device. To address the difficulty in synchronizing the secure state caused by the first network device's inability to resume the secure state on its own, in some embodiments of this application, a third party other than the first network device that has restored the secure state and the second network device that receives the secure state is used to prove the credibility of the secure state to which the first network device has been restored.
[0200] The restoration of security parameters is also as follows. For example, the second network device has recorded that the trust level of the first network device does not meet the trust condition. After the trust level of the first network device resumes to meet the trust condition, how to update the trust level of the first network device recorded on the second network device to meet the trust condition on the premise of ensuring the credibility of the restored trust level of the first network device. In some embodiments of this application, a third party other than the first network device that has restored the trust level and the second network device that receives the trust level is used to prove the credibility of the trust level to which the first network device has been restored.
[0201] To distinguish between the states or levels before and after restoration, the "first security parameter" is used to describe the state or level before restoration, and the "second security parameter" is used to describe the state or level after restoration. For example, the first security parameter is the insecure state, and the second security parameter is the secure state; or, the first security parameter is the first trust level, the second security parameter is the second trust level, the first trust level does not meet the trust condition, and the second trust level meets the trust condition.
[0202] The following further illustrates the restoration mechanism of security parameters with three implementation methods.
[0203] Implementation method 1 for the restoration of security parameters: A trusted neighbor acts as a third party to notify the whole network that the first network device has been restored to the secure state.
[0204] A trusted neighbor refers to a network device whose trust level meets the trust condition and has a neighbor relationship with the local device. For example, the trust level of a trusted neighbor is greater than a level threshold. In some embodiments, a multi-node proof mechanism is adopted to restore the synchronous security state. The multi-node proof mechanism means that multiple network devices prove that another network device has been restored to a safe state.
[0205] For example, the first network device originally notified the second network device that the local device was in an insecure state (for example, the first security parameter carried in the above first routing protocol message was in an insecure state); the second network device locally recorded that the first network device was in an insecure state. Subsequently, M network devices notified the second network device that the first network device was in a safe state. The second network device determines that the first network device has been restored to a safe state based on M being greater than or equal to the threshold and the trust level of each of the M network devices meeting the trust condition.
[0206] For example, an AS includes N network devices. After synchronizing the insecure state of network device A within the AS, it is necessary to prove that network device A has been restored to a safe state through M network devices within the AS. The M network devices spread the safe state of network device A within the AS. When any network device within the AS receives a protocol message from the M network devices proving that network device A is in a safe state, the network device switches the security parameter of network device A from an insecure state to a safe state. Here, N represents the total number of network devices deployed within the AS, M is less than N, and the trust level of each of the M network devices meets the trust condition. The value of M can be configured. M is at least greater than 2; alternatively, using a consensus algorithm such as the Byzantine algorithm, the number of M is recommended.
[0207] Considering that a network device with an insecure state has a certain probability of being controlled by an attacker to execute operations, if it is determined that the device has been restored to a safe state only based on the self-notification of the network device with an insecure state that it has restored security, the credibility is weak. Only when enough trusted network devices (M is greater than or equal to the threshold) prove that the first network device has been restored to a safe state, does the second network device determine that the first network device has been restored to a safe state, thereby improving the credibility of the restoration synchronization of the safe state.
[0208] Reference Figure 6 , Figure 6 shows a flowchart of another method for synchronizing security parameters provided by an embodiment of the present application. Figure 6 The method shown Figure 3 On the basis of the method shown, further includes the following S560 to S592.
[0209] S560, each of the M network devices determines that the security parameter of the first network device has been restored.
[0210] For example, each of the M network devices determines that the security parameter of the first network device is restored from the first security parameter to the second security parameter. The second security parameter includes a security state or / and a trust level in the second security parameter that meets the trust condition.
[0211] Regarding the manner in which the second network device determines that the trust levels of the M network devices meet the trust condition, in some embodiments, the routing protocol message generated by the i-th network device among the M network devices further carries the trust level of the i-th network device. The second network device determines whether the trust level of the i-th network device carried in the routing protocol message meets the trust condition. In other embodiments, the routing protocol message generated by the i-th network device among the M network devices further carries the identifier of the i-th network device. The second network device has a correspondence relationship recorded locally, and the correspondence relationship includes the identifier of the network device and the trust level of the network device. After the second network device receives the routing protocol message of the i-th network device carrying the second security parameter of the first network device, the second network device looks up the correspondence relationship based on the identifier of the i-th network device, obtains the trust level of the i-th network device, and determines that the trust level of the i-th network device meets the trust condition. In some embodiments, after the second network device previously receives the routing protocol message from the i-th network device carrying the trust level of the i-th network device, the second network device adds the identifier of the i-th network device and the trust level of the i-th network device to the correspondence relationship.
[0212] Since all M network devices use the routing protocol to announce the security state of the first network device, the implementation complexity of restoring the security state between network devices is reduced.
[0213] In some embodiments, when announcing that an untrusted network device at the local end is restored to a trusted state, a multi-node proof mechanism is used to restore and synchronize the trust level. For example, the first network device originally announces to the second network device that the local end is untrusted (for example, the trust level in the first security parameter carried in the above first routing protocol message does not meet the trust condition, such as the trust level being the lowest level), and the second network device records locally that the trust level of the first network device does not meet the trust condition; afterwards, the M network devices announce to the second network device that the trust level in the first network device meets the trust condition (for example, the trust level is the highest level), and the second network device determines that the trust level of the first network device has been restored to meet the trust condition based on M being greater than or equal to the threshold and the trust level of each of the M network devices meeting the trust condition.
[0214] In some embodiments, M network devices use a remote attestation mechanism to determine that a first network device has been restored to a secure state, and the M network devices further notify a second network device of a routing protocol message. The ways for the M network devices to use the remote attestation mechanism to determine that the first network device has been restored to a secure state include the following ways.
[0215] Way 1 for the M network devices to determine the restoration of the first network device: After the first network device is restored to be secure and trustworthy, it interacts with a remote attestation server. The M network devices obtain the remote attestation result of the first network device and determine that the first network device has been restored to be secure and trustworthy.
[0216] In some embodiments where the first network device interacts with the remote attestation server, the first network device collects the security logs recorded by the first network device. The first network device sends the security logs to the remote attestation server. The security logs are used to determine a second security parameter. The remote attestation server performs network security situation awareness analysis based on the security logs recorded by the first network device to determine the second security parameter. The remote attestation server generates a remote attestation result. The remote attestation server sends the remote attestation result and the second security parameter to the first network device. The remote attestation result is used to prove the credibility of the second security parameter. The first network device receives the remote attestation result and the second security parameter from the remote attestation server.
[0217] In the process of the first network device notifying the M network devices of the second security parameter, the routing protocol message sent by the first network device to each network device among the M network devices includes not only the second security parameter but also the remote attestation result. Each network device among the M network devices receives the routing protocol message from the first network device; after each network device among the M network devices obtains the remote attestation result from the routing protocol message, it verifies the remote attestation result. If the remote attestation result is verified successfully, it is determined that the first network device has been restored to a secure state or the trust level has been restored to meet the trust condition.
[0218] Way 2 for the M network devices to determine the restoration of the first network device: The M network devices act as a remote attestation server to interact with the first network device, and determine that the first network device has been restored to be secure and trustworthy based on the security logs reported by the first network device.
[0219] In some embodiments, the first network device sends the security logs of the first network device to each network device among the M network devices. Each network device among the M network devices performs network security situation awareness analysis based on the security logs of the first network device to determine that the security parameter of the first network device has been restored to a second security parameter, and the second security parameter includes that the security state or / and the trust level in the second security parameter meets the trust condition.
[0220] M network devices determine the third way for the first network device to recover. The network administrator configures the first network device to be in a secure state in each of the M network devices. Based on the configuration operation of the network administrator, the M network devices determine that the first network device is restored to the secure state.
[0221] S570, each of the M network devices generates a routing protocol message, obtaining M routing protocol messages.
[0222] The routing protocol messages generated by each of the M network devices carry the identifier of the first network device and the second security parameter of the first network device.
[0223] In some embodiments, each of the M routing protocol messages is an IGP message. For example, first, within the IGP domain where network device A is located, the security parameter of network device A is restored from an insecure state to a secure state. When the security parameter of network device A recorded by each network device within the IGP domain has been restored from an insecure state to a secure state, the secure state of network device A is then transmitted to other domains outside the IGP domain where network device A is located through BGP.
[0224] S580, each of the M network devices sends the routing protocol message to the second network device.
[0225] S590, the second network device receives the M routing protocol messages from the M network devices.
[0226] S592, the second network device obtains the second security parameter of the first network device carried in the M routing protocol messages. The second network device determines that the security parameter of the first network device is restored based on M being greater than or equal to a threshold and the trust level of each of the M network devices meeting the trust condition.
[0227] For example, it is determined that the first network device is restored to the secure state or the trust level of the first network device is restored to meet the trust condition.
[0228] In some embodiments, the second network device updates the security parameter of the first network device recorded locally to the second security parameter. In some embodiments, the second network device updates the routing attributes in the routing table saved by the second network device based on the second security parameter. For example, the second network device determines the first routing information received from the first network device from the routing table based on the identifier of the first network device. The second network device updates the security parameter in the routing attributes of the first routing information from the first security parameter to the second security parameter. Also, for example, the second network device adjusts the cost value, priority, or metric in the first routing information based on the second security parameter.
[0229] Implementation method 2 for security parameter recovery, where the controller or the remote attestation server acts as a third party to announce to the entire network that the first network device has restored security or trustworthiness.
[0230] In some embodiments, when the first network device determines that the security parameters on its own end are updated from the first security parameters to the second security parameters, the first network device interacts with the controller using the remote attestation mechanism. The controller determines that the security parameters of the first network device are the second security parameters. The controller announces the second security parameters of the first network device to the second network device.
[0231] For example, after the first network device recovers from an insecure state to a secure state, the first network device interacts with the controller using mechanisms such as remote attestation. The controller determines that the first network device has restored the secure state. The controller announces to the second network device that the first network device has restored the secure state. Also, for example, after the trust level of the first network device recovers from not meeting the trust condition (e.g., the trust level is lower than the threshold) to meeting the trust condition (e.g., the trust level is higher than the threshold), the first network device interacts with the controller using mechanisms such as remote attestation. The controller determines that the trust level of the first network device has been restored to meet the trust condition. The controller announces to the second network device that the trust level of the first network device has been restored to meet the trust condition.
[0232] Reference Figure 7 , Figure 7 shows a flowchart of another method for synchronizing security parameters provided by an embodiment of the present application. Figure 7 The method shown Figure 3 On the basis of the method shown, further includes the following S660 to S694. S660 to S694 focus on describing the process of interaction between the first network device and the controller.
[0233] S660, the first network device generates a first announcement message.
[0234] The first announcement message carries the security log of the first network device. The protocol type of the first announcement message can refer to the description of S460.
[0235] S670, the first network device sends the first announcement message to the controller.
[0236] S680, the controller receives the first announcement message, and the controller obtains the second security parameters of the first network device based on the security log of the first network device.
[0237] In some embodiments, the controller itself acts as a remote attestation server, and the controller obtains the security log of the first network device carried in the BGP-LS message. The controller performs network security situation awareness analysis based on the security log of the first network device to determine a second security parameter. In other embodiments, the controller interacts with a dedicated remote attestation server. The controller sends the security log of the first network device to the dedicated remote attestation server. The dedicated remote attestation server performs network security situation awareness analysis on the first network device based on the security log of the first network device to determine a second security parameter. The dedicated remote attestation server sends the second security parameter to the controller. The controller receives the second security parameter of the first network device from the remote attestation server.
[0238] S690, the controller generates a second advertisement message.
[0239] S692, the controller sends the second advertisement message to the second network device, and the second advertisement message includes the identifier of the first network device and the second security parameter of the first network device.
[0240] For example, the controller advertises the second security parameter of the first network device in the following manner A or manner B.
[0241] Manner A: The controller sends an advertisement message to all network devices in the network. The advertisement message is used to indicate that the first network device has recovered to a secure state. The advertisement message is, for example, a BGP-LS protocol message or other control plane protocol message. The advertisement message includes the carried security state and the identifier of the first network device. All network devices in the network receive the advertisement message from the controller, all network devices in the network obtain the security state and the identifier of the first network device carried in the advertisement message, access the local record based on the identifier of the first network device, and update the insecure state of the first network device in the local record to the secure state.
[0242] For example, when the controller can manage all network devices in the network, the controller advertises to all network devices in the network that the first network device has recovered to a secure state, thereby triggering all network devices in the network to update the insecure state of the first network device in the local record to the secure state.
[0243] In Mode B, the controller sends an announcement message to M network devices in the network. The announcement message is used to indicate that the first network device has resumed the secure state. After receiving the announcement message from the controller, the M network devices send routing protocol messages to other network devices in the network. The routing protocol messages carry the identifier and the secure state of the first network device. When a network device within the AS receives the announcement messages from the M network devices that can prove the resumption of the secure state of the first network device, the network device updates the insecure state of the first network device recorded locally to the secure state.
[0244] For example, in a scenario where the controller can manage a part of the network devices in the network but cannot manage another part of the network devices, the controller announces to the M network devices within the managed scope that the first network device has resumed the secure state, and then the M network devices further spread the secure state of the first network device to other network devices in the network based on the routing protocol.
[0245] S694, the second network device updates the security parameter of the first network device recorded from the first security parameter to the second security parameter.
[0246] Implementation method 3 for the recovery of security parameters. The first network device proves that the local end has resumed security or trustworthiness based on the remote attestation result provided by the remote attestation server.
[0247] In some embodiments, when the first network device determines that the security parameter of the local end is updated from the first security parameter to the second security parameter, the first network device interacts with the remote attestation server using the remote attestation mechanism, thereby obtaining the remote attestation result provided by the remote attestation server. The first network device further announces to the entire network the second security parameter of the first network device and the remote attestation result. The remote attestation result is used to prove the trustworthiness of the second security parameter.
[0248] Reference Figure 8 , Figure 8 shows a flowchart of another method for synchronizing security parameters provided by an embodiment of the present application. Figure 8 The method shown Figure 3 On the basis of the method shown, it further includes the following S760 to S796. S760 to S796 focus on describing the process of interaction between the first network device and the remote attestation server.
[0249] S760, the first network device collects the security logs recorded by the first network device.
[0250] The security logs are used to determine the second security parameter. The second security parameter is, for example, the secure state and the trust level that meets the trust conditions.
[0251] S770, the first network device sends security logs to the remote attestation server.
[0252] S780, the remote attestation server performs network security situation awareness analysis based on the security logs recorded by the first network device, determines the second security parameter, and generates a remote attestation result.
[0253] S790, the remote attestation server sends the remote attestation result and the second security parameter to the first network device.
[0254] S792, the first network device receives the remote attestation result and the second security parameter from the remote attestation server.
[0255] For example, after the first network device recovers from an insecure state to a secure state, the first network device uses the remote attestation mechanism to interact with the remote attestation server to obtain the remote attestation result. The remote attestation result is used to prove that the first network device is in a secure state. The first network device announces to the whole network that the first network device has recovered to a secure state and the remote attestation result. Another example is that after the first network device recovers from an untrusted state to a trusted state, the first network device uses the remote attestation mechanism to interact with the remote attestation server to obtain the remote attestation result. The remote attestation result is used to prove that the trust level of the first network device meets the trust conditions. The first network device announces to the whole network that the trust level of the first network device has recovered to meet the trust conditions and the remote attestation result.
[0256] S794, the first network device announces the remote attestation result and the second security parameter to the second network device.
[0257] In some embodiments, the first network device announces the remote attestation result and the second security parameter to the second network device based on a routing protocol. For example, the first network device generates a third routing protocol packet. The third routing protocol packet includes the second security parameter and the remote attestation result. The first network device sends the third routing protocol packet to the second network device. For example, the first network device and the second network device are deployed in the same AS, and the third routing protocol packet is an IGP packet. Another example is that the first network device and the second network device are respectively deployed in two adjacent ASs, and the third routing protocol packet is a BGP packet.
[0258] In some other embodiments, the first network device advertises the remote attestation result and the second security parameter to the second network device based on the link layer protocol. For example, the first network device generates a link layer protocol message. The link layer protocol message includes the second security parameter and the remote attestation result. The first network device sends the link layer protocol message to the second network device. The link layer protocol message is, for example, a link layer discovery protocol (LLDP) message or a media access control security (MACsec) message. The second network device is a neighbor device of the first network device.
[0259] S796. The second network device updates the security parameter of the first network device recorded at its end from the first security parameter to the second security parameter.
[0260] In some embodiments, the second network device verifies the remote attestation result. If the remote attestation result is verified successfully, the second network device updates the security parameter of the first network device recorded at its end from the first security parameter to the second security parameter.
[0261] In some embodiments, when the remote attestation result is verified successfully, the second network device further spreads the security state and the remote attestation result of the first network device to other devices in the network. When a network device within the domain receives the security state and the remote attestation result of the first network device from M network devices and deems them trustworthy, it updates the insecure state of the first network device recorded at its end to a secure state.
[0262] The following gives an example of the format of the routing protocol message provided in the embodiments of the present application.
[0263] The format of the routing protocol message described below supports carrying security parameters. Optionally, Figure 3 the methods shown up to Figure 8 any one of the methods shown use a routing protocol message in the following format when transmitting security parameters between different network devices. For example, in Figure 3 the method shown, the routing protocol message in S320 to S340 has Figures 9 to 14 the message format shown in any one of the accompanying drawings in Figure 4 the method shown, the routing protocol message in S320 to S340 and S370 to S380 has Figures 9 to 14 the message format shown in any one of the accompanying drawings in Figure 5 the method shown, the routing protocol message in S320 to S340 has Figures 9 to 14 the message format shown in any one of the accompanying drawings in Figure 6In the method shown, the first routing protocol packets in S320 to S340 and the M routing protocol packets in S570 to S590 have Figures 9 to 14 the packet format shown in any of the attached drawings. In Figure 7 the method shown, the routing protocol packets in S320 to S340 have Figures 9 to 14 the packet format shown in any of the attached drawings. In Figure 8 the method shown, the routing protocol packets in S320 to S340 have Figures 9 to 14 the packet format shown in any of the attached drawings.
[0264] The ways of carrying security parameters in routing protocol packets include the following Embodiment 1 and Embodiment 2.
[0265] Embodiment 1: Expand the fields in the IGP protocol packets to synchronize the security parameters of network devices within the same AS.
[0266] Taking the synchronization of the security parameters of the first network device to the second network device as an example. For example, the first network device generates an IGP packet based on the security parameters. The first network device sends the IGP packet to the second network device. The IGP packet includes the security parameters. The first network device and the second network device belong to the same AS. The second network device is an IGP neighbor of the first network device.
[0267] Taking the application of the method shown in Figure 1 the scenario shown in Figure 3 as an example, the first network device is, for example, Figure 1 network device A in Figure 1 and the second network device is, for example, network device B, network device C or network device D in
[0268] IGP packets include Open Shortest Path First (OSPF) protocol packets and Intermediate System-to-Intermediate System (IS-IS) protocol packets. In some embodiments, the fields in the extended OSPF protocol packets are used to carry the security parameters of network devices, thereby realizing the synchronization of the security parameters of network devices within an AS. For example, by extending the fields in the OSPF protocol packets, the fields in the OSPF protocol packets are used to carry the security status of network devices, thereby realizing the synchronization of the security status of network devices within an AS. Another example is that by extending the fields in the OSPF protocol packets, the fields in the OSPF protocol packets are used to carry the trust level of network devices, thereby realizing the synchronization of the trust levels of network devices within an AS.
[0269] OSPF protocol packets include Link-State Advertisement (LSA) fields. The LSA fields include one or more option fields. The LSA fields are generally used to carry routing information. In some embodiments of this application, the LSA fields in the OSPF protocol packets are extended to carry the security parameters of network devices. For example, a first network device generates an OSPF packet, the OSPF packet includes an LSA field, the LSA field includes an option field, and the option field includes the security parameters of the first network device.
[0270] In some embodiments where the security status is carried by the option field, when the value carried by the last 4 bits in the option field is 0001, it indicates that the network device is in an insecure state; when the value carried by the last 4 bits in the option field is 0000, it indicates that the network device is in a secure state. When the value carried by the first 4 bits in the option field is 0001, it indicates that the network device supports the transmission of the security status. When the value carried by the first 4 bits in the option field is 0000, it indicates that the network device does not support the transmission of the security status.
[0271] In some embodiments where the security status and trust level are carried in the option field, when the value carried in the last 4 bits of the option field is 0010, it indicates that the network device is in a secure state and the trust level of the network device is 1; when the value carried in the last 4 bits of the option field is 0100, it indicates that the network device is in a secure state and the trust level of the network device is 2; when the value carried in the last 4 bits of the option field is 0110, it indicates that the network device is in a secure state and the trust level of the network device is 3; when the value carried in the last 4 bits of the option field is 1000, it indicates that the network device is in a secure state and the trust level of the network device is 4; when the value carried in the last 4 bits of the option field is 1010, it indicates that the network device is in a secure state and the trust level is 5. When the value carried in the first 4 bits of the option field is 0001, it indicates that the network device supports the transmission of the security status. When the value carried in the first 4 bits of the option field is 0000, it indicates that the network device does not support the transmission of the security status and does not support the transmission of the trust level. When the value carried in the first 4 bits of the option field is 0011, it indicates that the network device supports the transmission of the security status and supports the transmission of the trust level. When the value carried in the last 4 bits of the option field is 0001, it indicates that the network device is in an insecure state.
[0272] The LSA fields include several types such as router - Link State Advertisement (router - LSA), network - Link State Advertisement (network - LSA), network summary - Link State Advertisement (network - summary - LSA), Autonomous System Boundary Router summary - Link State Advertisement (ASBR - summary - LSA), and Autonomous System External Link State Advertisement (AS - External - LSA). The LSA carrying the security parameter is, for example, any of the above LSA types.
[0273] In some embodiments, the option field in the extended router - LSA is used to carry the security parameter by using the option field in the router - LSA. Refer to Figure 9 , Figure 9 shows a schematic diagram of the format of the router - LSA field in an OSPF protocol packet provided by an embodiment of the present application. Figure 9 In the router - LSA field, the LSA header includes one or more options fields, and the options field carries the security status of the network device and whether the network device supports the transmission of the security status.
[0274] In some other embodiments, the option field in the network-LSA is extended, and the security parameter is carried using the option field in the network-LSA. Refer to Figure 10 , Figure 10 FIG. Figure 10 shows a schematic diagram of the format of the network-LSA field in an OSPF protocol packet provided by an embodiment of the present application. Figure 10 In the network-LSA field in Figure 10 , the LSA header includes one or more option fields, and the option field carries the security status of the network device and whether the network device supports the transfer of the security status.
[0275] In some other embodiments, the option field in the network-summary-LSA is extended, and the security parameter is carried using the option field in the network-summary-LSA. In some other embodiments, the option field in the ASBR-summary-LSA is extended, and the security parameter is carried using the option field in the ASBR-summary-LSA. In some other embodiments, the option field in the AS-External-LSA is extended, and the security parameter is carried using the option field in the AS-External-LSA.
[0276] In some embodiments, the trigger condition for sending an LSA is that the network device detects a change in its own security parameter. For example, after the first network device performs network attack detection or abnormal behavior detection in the first time period, it obtains the first security parameter. After the first network device performs network attack detection or abnormal behavior detection in the second time period, it obtains the second security parameter. The first network device compares the first security parameter and the second security parameter to determine that the security parameter of the first network device has changed. The first network device generates an LSA based on the second security parameter. The LSA carries the second security parameter. The first network device sends the LSA to the second network device in the first AS to which the first network device belongs. After receiving the LSA, the second network device calculates the LSDB to obtain the first routing information. The routing attribute of the first routing information includes the second security parameter. The second network device updates the routing table based on the first routing information. The updated routing table includes the first routing information. Since a routing attribute including the second security parameter is newly added to the routing table, the routing forwarding operation is associated with the security status handling operation. For example, after the second network device looks up the updated routing table based on the destination IP address of the data packet, it determines whether to forward the data packet using the first routing information based on the second security parameter in the first routing information.
[0277] As an example, the first security parameter indicates that the first network device is in a secure state, and the second security parameter indicates that the first network device is in an insecure state. For example, when the security state of the first network device changes from secure to insecure, the first network device sends an LSA carrying the identifier of the insecure state. As an example, the first security parameter includes a first trust level, and the first trust level meets the trust condition. The second security parameter includes a second trust level, and the second trust level does not meet the trust condition. For example, when the trust level of the first network device changes from trusted to untrusted, the first network device sends an LSA carrying the untrusted level.
[0278] In some embodiments, by extending the fields in the IS-IS protocol message and using the fields in the IS-IS protocol message to carry the security parameters of the network device, the synchronization of the security parameters of the network devices within the AS is achieved. For example, by extending the fields in the IS-IS protocol message and using the fields in the IS-IS protocol message to carry the security state of the network device, the synchronization of the security states of the network devices within the AS is achieved. For example, by extending the fields in the IS-IS protocol message and using the fields in the IS-IS protocol message to carry the trust level of the network device, the synchronization of the trust levels of the network devices within the AS is achieved.
[0279] The IS-IS protocol message includes LSP (link state protocol data Unit, or link state packet, link state protocol data unit or link state message), sequence number PDUs (SNP), and Hello message. LSP is divided into two types: Level-1 LSP and Level-2 LSP. Level-1 routers transmit Level-1 LSP, Level-2 routers transmit Level-2 LSP, and Level-1-2 routers can transmit both of the above two types of LSP. SNP is used to confirm the latest received LSP between neighbors, and its function is similar to an acknowledge message.
[0280] SNPs include complete sequence number PDUs (CSNPs) and partial sequence number PDUs (PSNPs), which can be further divided into Level-1 CSNP, Level-2 CSNP, Level-1 PSNP, and Level-2 PSNP. Hello messages are used to establish and maintain neighbor relationships and are also known as IIHs (IS-to-IS Hello PDUs). Among them, Level-1 routers in a broadcast network use Level-1 LAN IIHs, Level-2 routers in a broadcast network use Level-2 LAN IIHs, and routers in a point-to-point network use P2P IIHs.
[0281] LSP messages include a reserved field and type length values (TLVs). In some embodiments of the present application, the reserved field in the LSP message of the extended IS-IS protocol message is used to carry security parameters of the network device. Alternatively, the TLV in the LSP message of the extended IS-IS protocol message is used to carry security parameters of the network device. For example, the type field in the TLV identifies the security parameters, and the value field in the TLV includes the security parameters.
[0282] Exemplarily, when the value carried by the last 4 bits in the reserved field is 0001, it indicates that the network device is in an insecure state; when the value carried by the last 4 bits in the reserved field is 0000, it indicates that the network device is in a secure state. When the value carried by the first 4 bits in the reserved field is 0001, it indicates that the network device supports the transmission of the secure state. When the value carried by the first 4 bits in the reserved field is 0000, it indicates that the network device does not support the transmission of the secure state.
[0283] Reference Figure 11 , Figure 11 shows a schematic diagram of the message format of an LSP in the IS-IS protocol provided by an embodiment of the present application. Figure 3 The routing protocol message sent by the first network device in the method shown includes Figure 11 the LSP message shown. Figure 11 The reserved field or TLV in
[0284] Reference Figure 12 , Figure 12 shows a schematic diagram of the message format of a CSNP in the IS-IS protocol provided by an embodiment of the present application. Figure 3 The routing protocol message sent by the first network device in the method shown includes Figure 12 the CSNP message shown. Figure 12The reserved field or TLV carries the security status of the network device and whether the network device supports the transmission of the security status.
[0285] In some embodiments, the trigger condition for sending an LSP is that the network device detects a change in its own security parameters. For example, after the first network device performs network attack detection or abnormal behavior detection in the first time period, it obtains the first security parameter. After the first network device performs network attack detection or abnormal behavior detection in the second time period, it obtains the second security parameter. The first network device compares the first security parameter and the second security parameter to determine that the security parameter of the first network device has changed. The first network device generates an LSP based on the second security parameter. The LSP carries the second security parameter. The first network device sends the LSP to the second network device within the first AS to which the first network device belongs. After receiving the LSP, the second network device calculates the LSDB to obtain the first routing information. The routing attribute of the first routing information includes the second security parameter. The second network device updates the routing table based on the first routing information. The updated routing table includes the first routing information.
[0286] As an example, the first security parameter indicates that the first network device is in a secure state, and the second security parameter indicates that the first network device is in an insecure state. For example, when the security state of the first network device changes from secure to insecure, it sends an LSP carrying the identification of the insecure state. As an example, the first security parameter includes a first trust level, and the first trust level meets the trust condition. The second security parameter includes a second trust level, and the second trust level does not meet the trust condition. For example, when the trust level of the first network device changes from trusted to untrusted, it sends an LSP carrying the untrusted level.
[0287] Through Embodiment 1, the reserved field of the IGP packet is extended, and the reserved field of the IGP packet is used to carry the security status of the network device, realizing a mechanism for distributed propagation of the security status of the network device and processing the security status of the network device. In the scenario where different network devices deployed in the network come from different manufacturers or there is no deployed controller, the problem that it is difficult to propagate the security status of devices within the IGP domain is solved. In addition, the dependence on the controller's situation awareness is reduced, and the security status of the network device can also be synchronized in the scenario where the controller is untrusted. Or, the reserved field of the IGP packet is used to carry the trust level of the network device, realizing a mechanism for distributed propagation of the trust level of the network device and processing the trust level of the network device. In the scenario where different network devices deployed in the network come from different manufacturers or there is no deployed controller, the problem that it is difficult to propagate the trust level of devices within the IGP domain is solved. In addition, the dependence on the controller's situation awareness is reduced, and the trust level of the network device can also be synchronized in the scenario where the controller is untrusted.
[0288] Embodiment 2: Extend the fields in the BGP protocol message to synchronize the security parameters of network devices across ASs.
[0289] Taking the synchronization of the security parameters of the first network device to the second network device as an example, for instance, the first network device generates a BGP message based on the security parameters. The first network device sends the BGP message to the second network device. The BGP message includes the security parameters. The first network device and the second network device belong to different ASs. For example, the first network device is deployed at the boundary of the first AS, and the second network device is deployed at the boundary of the second AS. The second AS is a neighbor AS of the first AS. The second network device is, for example, a BGP neighbor device of the first network device.
[0290] For example, in Figure 2 the scenario shown, applying Figure 3 the method shown, the first network device is, for example, Figure 2 network device D in Figure 2 and the second network device is, for example,
[0291] By extending the reserved fields of the BGP protocol message and using the reserved fields of the BGP protocol message to carry the security state of the network device, a mechanism for distributed propagation and processing of the security state of network devices is realized. In the scenario where different network devices deployed in the network are from different manufacturers or there is no deployed controller, the problem of difficult propagation of the device security state between ASs is solved. In addition, the dependence on the controller's situational awareness is reduced, and the security state of network devices can be synchronized between ASs even in the scenario where the controller is untrusted.
[0292] The BGP protocol is specifically divided into 5 different types of messages, namely BGP open message, BGP update message, BGP notification message, BGP keepalive message, and BGP route-refresh message. The BGP open message is used to establish a BGP neighbor relationship. The BGP update message is used to announce routes. The BGP notification message is used to handle various errors in the BGP process.
[0293] In some embodiments, the BGP open message is extended to carry security parameters and the transfer of the security state supported by the first network device (the first capability identifier) using the BGP open message. For example, refer to Figure 13 , Figure 13 FIG. shows a schematic diagram of the format of a BGP open message provided by an embodiment of the present application. The BGP open message includes one or more optional parameters fields. The optional parameters field includes the security parameters of the first network device. The length of the optional parameters field is variable. The optional parameters field adopts the TLV format. The optional parameters field includes a parameter type (parm.type) field, a parameter length (parm.length) field, and a parameter value (parameter.value) field. The parameter value field adopts the TLV format. The parameter value field includes a capability code field, a capability length field, and a capability value field. Exemplarily, the parameter type field carries a value indicating the negotiated capability, and the capability code field or the capability value field in the parameter value field is used to carry the security parameters of the first network device. Since the standard use of the BGP open message is to establish a BGP neighbor, by using the BGP open message to carry whether the network device supports the transfer of the security state and the security state of the network device, the synchronization process of the security state can affect whether a neighbor is established between network devices. For example, if the second network device receives a BGP open message from the first network device, and the BGP open message carries the insecure state of the first network device or the first network device does not support the transfer of the security state, the second network device refuses to establish a BGP neighbor relationship with the first network device.
[0294] In some embodiments, the BGP update message is extended to carry security parameters. For example, refer to Figure 14 , Figure 14A schematic diagram of the format of a BGP update message provided by an embodiment of the present application is shown. The BGP update message includes an unfeasible routes length field with a length of 2 bytes, one or more variable-length withdrawn routes fields, a total path attribute length field with a length of 2 bytes, one or more variable-length path attributes fields, and a variable-length network layer reachability information (NLRI) field. The path attributes field includes security parameters. The NLRI field contains an updated list of address prefixes.
[0295] In some embodiments, the trigger condition for sending a BGP update message is that the network device detects a change in the local security parameters. For example, after the first network device performs network attack detection or abnormal behavior detection in the first time period, it obtains the first security parameter. After the first network device performs network attack detection or abnormal behavior detection in the second time period, it obtains the second security parameter. The first network device compares the first security parameter and the second security parameter to determine that the security parameter of the first network device has changed. The first network device generates a BGP update message based on the second security parameter. The BGP update message carries the second security parameter. The first network device sends the BGP update message to a BGP neighbor (for example, the second network device in the adjacent AS of the first AS to which the first network device belongs). The second network device receives the BGP update message and performs routing calculation to obtain the first routing information. The routing attributes of the first routing information include the second security parameter. The second network device updates the routing table based on the first routing information. The updated routing table includes the first routing information.
[0296] As an example, the first security parameter indicates that the first network device is in a secure state, and the second security parameter indicates that the first network device is in an insecure state. For example, when the security state of the first network device changes from secure to insecure, it sends a BGP update message carrying an identifier of the insecure state. As an example, the first security parameter includes a first trust level that meets the trust condition. The second security parameter includes a second trust level that does not meet the trust condition. For example, when the trust level of the first network device changes from trusted to untrusted, it sends a BGP update message carrying the untrusted level.
[0297] In some embodiments, the BGP notification message is extended to carry security parameters using the BGP notification message. For example, when the trust level of the first network device changes from the first trust level to the second trust level, the first network device generates a BGP notification message, and the BGP notification message carries the second trust level, and the second trust level does not meet the trust condition. The first network device sends the BGP notification message to the second network device. The second network device receives the BGP notification message, and based on the second trust level carried in the BGP notification message, disconnects the BGP neighbor relationship with the first network device.
[0298] Attached Figure 15 is a schematic structural diagram of a network device 700 provided by an embodiment of the present application. In some embodiments, attached Figure 15 the network device 700 shown is Figure 1 network device A in Figure 2 In other embodiments, the network device 700 is
[0299] The network device 700 includes a processing unit 710 and a sending unit 720. The processing unit 710 is used to execute S310 and S320; the sending unit 720 is used to execute S330.
[0300] In some embodiments, the processing unit 710 is further used to execute S660.
[0301] In some embodiments, the processing unit 710 is further used to execute S760.
[0302] In some embodiments, the sending unit 720 is further used to execute S770 and S794.
[0303] In some embodiments, the network device 700 further includes a receiving unit 730, and the receiving unit 730 is used to execute S792.
[0304] Attached Figure 15 The device embodiments described above are merely illustrative. For example, the above unit division is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In various embodiments of the present application, each functional unit can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit.
[0305] Each unit in the network device 700 is implemented in whole or in part by software, hardware, firmware, or any combination thereof.
[0306] The following describes some possible implementation manners of using hardware or software to implement each functional unit in the network device 700 in combination with the network device 900 described later.
[0307] In the case of software implementation, for example, the above processing unit 710 and sending unit 720 are implemented by software functional units generated after at least one processor 901 in Figure 17 reads the program code stored in the memory 902.
[0308] In the case of hardware implementation, for example, each of the above units in Figure 15 is implemented by different hardware in the network device. For example, the processing unit 710 is implemented by a part of the processing resources (such as one core or two cores in a multi-core processor) in at least one processor 901 in Figure 17 , or is completed by a programmable device such as a field-programmable gate array (FPGA) or a coprocessor. The receiving unit 730 and the sending unit 720 are implemented by the network interface 903 in Figure 17 .
[0309] Figure 16 is a schematic structural diagram of a network device 800 provided by an embodiment of the present application. In some embodiments, the network device 800 shown in Figure 16 is Figure 1 network device B, network device C, or network device D in Figure 2 . In other embodiments, the network device 800 is
[0310] The network device 800 includes a receiving unit 810 and a processing unit 820. The receiving unit 810 is used to execute S340. The processing unit 820 is used to execute S350.
[0311] In some embodiments, the processing unit 820 is further used to execute S360.
[0312] In some embodiments, the network device 800 further includes a sending unit 830, and the sending unit 830 is used to execute S370.
[0313] In some embodiments, the processing unit 820 is further used to execute S460. The sending unit 830 is further used to execute S470.
[0314] In some embodiments, the receiving unit 810 is used to execute S590. The processing unit 820 is used to execute S592.
[0315] In some embodiments, the processing unit 820 is configured to execute S694.
[0316] Appendix Figure 16 The described device embodiments are merely illustrative. For example, the above division of units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. In each embodiment of the present application, each functional unit may be integrated in a processing unit, or each unit may exist physically alone, or two or more units may be integrated in one unit.
[0317] Each unit in the network device 800 is implemented in whole or in part by software, hardware, firmware, or any combination thereof.
[0318] The following describes some possible implementation manners of using hardware or software to implement each functional unit in the network device 800 in combination with the network device 900 described later.
[0319] In the case of software implementation, for example, the above processing unit 820 is implemented by a software functional unit generated after at least one processor 901 in Appendix 17 reads the program code stored in the memory 902.
[0320] In the case of hardware implementation, for example, in Appendix Figure 16 the above units are respectively implemented by different hardware in the network device. For example, the processing unit 820 is implemented by a part of the processing resources (such as one core or two cores in a multi-core processor) in at least one processor 901 in Appendix Figure 17 , or implemented by a programmable device such as a field-programmable gate array (FPGA) or a coprocessor. The receiving unit 810 and the transmitting unit 830 are implemented by the network interface 903 in Appendix Appendix Figure 17 .
[0321] Appendix Figure 17 is a schematic structural diagram of a network device 900 provided by an embodiment of the present application.
[0322] The network device 900 includes at least one processor 901, a memory 902, and at least one network interface 903.
[0323] The processor 901 is, for example, a general-purpose central processing unit (CPU), a network processor (NP), a graphics processing unit (GPU), a neural-network processing unit (NPU), a data processing unit (DPU), a microprocessor, or one or more integrated circuits for implementing the solution of this application. For example, the processor 901 includes an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The PLD is, for example, a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.
[0324] The memory 902 is, for example, a read-only memory (ROM) or other type of static storage device that can store static information and instructions, or a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM), or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media, or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. Optionally, the memory 902 exists independently and is connected to the processor 901 through an internal connection 904. Alternatively, optionally, the memory 902 and the processor 901 are integrated together.
[0325] The network interface 903 uses any transceiver-like device for communicating with other devices or communication networks. The network interface 903 includes, for example, at least one of a wired network interface or a wireless network interface. Among them, the wired network interface is, for example, an Ethernet interface. The Ethernet interface is, for example, an optical interface, an electrical interface, or a combination thereof. The wireless network interface is, for example, a wireless local area networks (WLAN) interface, a cellular network interface, or a combination thereof, etc.
[0326] In some embodiments, the processor 901 includes one or more CPUs, such as the CPU0 and CPU1 shown in the appendix. Figure 17 as shown.
[0327] In some embodiments, the network device 900 optionally includes multiple processors, such as the processor 901 and the processor 905 shown in the appendix. Each of these processors is, for example, a single-CPU (single-CPU) or a multi-CPU (multi-CPU). Here, the processor optionally refers to one or more devices, circuits, and / or processing cores for processing data (such as computer program instructions). Figure 17 as shown.
[0328] In some embodiments, the network device 900 also includes an internal connection 904. The processor 901, the memory 902, and at least one network interface 903 are connected through the internal connection 904. The internal connection 904 includes paths for transmitting information between the above components. Optionally, the internal connection 904 is a single board or a bus. Optionally, the internal connection 904 is divided into an address bus, a data bus, a control bus, etc.
[0329] In some embodiments, the network device 900 also includes an input / output interface 906. The input / output interface 906 is connected to the internal connection 904.
[0330] Optionally, the processor 901 implements the methods in the above embodiments by reading the program code stored in the memory 902, or the processor 901 implements the methods in the above embodiments by the program code stored internally. In the case where the processor 901 implements the methods in the above embodiments by reading the program code stored in the memory 902, the memory 902 stores the program code 910 for implementing the methods provided in the embodiments of the present application.
[0331] For more details on how the processor 901 implements the above functions, please refer to the descriptions in the previous method embodiments and will not be repeated here.
[0332] Each embodiment in this specification is described in a progressive manner. Similar parts among the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments.
[0333] A referring to B means that A is the same as B or A is a simple variation of B.
[0334] In the description of the embodiments of this application, terms such as "first" and "second" in the specification and claims are used to distinguish different objects, rather than to describe a specific order of the objects, nor can they be construed as indicating or implying relative importance. For example, the first network device and the second network device are used to distinguish different network devices, rather than to describe a specific order of the network devices, nor can it be understood that the first network device is more important than the second network device.
[0335] In the embodiments of this application, unless otherwise specified, "at least one" means one or more, and "a plurality" means two or more. For example, a plurality of network devices means two or more network devices.
[0336] The above embodiments can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of this application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that the computer can access or a data storage device such as a server or data center that includes one or more integrated available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid-state disk (SSD)).
[0337] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit it; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present application.
Claims
1. A method for synchronizing security parameters, characterized in that The method includes: A first network device obtains security parameters of the first network device; The first network device generates a routing protocol message based on the security parameters, and the routing protocol message includes the security parameters; The first network device sends the routing protocol message to a second network device.
2. The method according to claim 1, wherein The second network device and the first network device belong to the same autonomous system (AS), the routing protocol message includes an Interior Gateway Protocol (IGP) message, and the IGP message includes the security parameters.
3. The method according to claim 2, characterized in that, The IGP message includes an Open Shortest Path First (OSPF) message, the OSPF message includes a Link State Advertisement (LSA) field, the LSA field includes an Option field, and the Option field includes the security parameters.
4. The method according to claim 2, characterized in that, The IGP message includes a Link State Protocol Data Unit (LSP) message in the Intermediate System to Intermediate System (IS-IS) protocol; The LSP message includes a reserved field, and the reserved field includes the security parameters; or the LSP message includes a Type Length Value (TLV), and a value field in the TLV includes the security parameters.
5. The method according to claim 1, wherein The second network device and the first network device belong to different ASs, the routing protocol message includes a Border Gateway Protocol (BGP) message, and the BGP message includes the security parameters.
6. The method according to claim 5, wherein The BGP message includes a BGP Update message, and the BGP Update message includes a path attribute field, and the path attribute field includes the security parameters.
7. The method according to claim 5, wherein The BGP message includes a BGP Open message, and the BGP Open message includes an optional parameter field, and the optional parameter field includes the security parameters.
8. The method according to claim 1, wherein The security parameters include a secure state, an insecure state, or a trust level. The secure state indicates that the first network device is not under a network attack. The insecure state indicates that the first network device is under a network attack. The trust level indicates the intensity of the network attack on the first network device or the type of the network attack.
9. The method according to claim 1, characterized in that, The security parameters include a secure state, and the routing protocol message further includes a remote attestation result for attesting that the first network device is in the secure state.
10. The method according to claim 1, characterized in that, Before the first network device generates a routing protocol message based on the security parameters, the method further includes: The first network device sends security logs of the first network device to a remote attestation server, and the security logs are used to determine the security parameters; The first network device receives the security parameters and the remote attestation result sent by the remote attestation server.
11. A method for synchronizing security parameters, characterized in that, The method includes: A second network device receives a first routing protocol message from a first network device, and the first routing protocol message includes first security parameters of the first network device; The second network device adjusts a forwarding path of a data stream passing through the first network device based on the first security parameters.
12. The method according to claim 11, characterized in that, The second network device adjusts the forwarding path of the data stream passing through the first network device based on the first security parameter, including: The second network device determines that the first security parameter is in an insecure state or the trust level included in the first security parameter does not meet the trust condition. The second network device adjusts the forwarding path of the data stream passing through the first network device so that the forwarding path does not pass through the first network device.
13. The method according to claim 11, characterized in that The method further includes: The second network device generates a second routing protocol message based on the first security parameter of the first network device, and the second routing protocol message includes the first security parameter of the first network device; The second network device sends the second routing protocol message to a third network device.
14. The method according to claim 13, characterized in that, The second network device and the third network device belong to the same autonomous system AS, the second routing protocol message is an Interior Gateway Protocol IGP message, and the IGP message includes the first security parameter of the first network device.
15. The method according to claim 13, wherein The second network device and the third network device belong to different ASs, the second routing protocol message is a Border Gateway Protocol BGP message, and the BGP message includes the first security parameter of the first network device.
16. The method according to claim 11, characterized in that, The method further includes: The second network device determines that the first security parameter is in an insecure state or the trust level included in the first security parameter does not meet the trust condition. The second network device disconnects the neighbor relationship between the second network device and the first network device.
17. The method according to claim 11, wherein When the first security parameter is in an insecure state or the trust level in the first security parameter does not meet the trust condition, after the second network device receives the first routing protocol message from the first network device, the method further includes: The second network device receives the second security parameter of the first network device from M network devices, and the second security parameter includes a security state or / and the trust level in the second security parameter meets the trust condition; The second network device determines that the security parameter of the first network device is restored to the second security parameter based on M being greater than or equal to a threshold and the trust level of each of the M network devices meeting the trust condition.
18. The method according to claim 11, wherein When the first security parameter is in an insecure state or the trust level in the first security parameter does not meet the requirement, after the second network device receives the first routing protocol message from the first network device, the method further includes: The second network device receives the second security parameter and the remote attestation result from the first network device, and the second security parameter includes a security state or / and the trust level in the second security parameter meets the trust condition; The second network device determines that the security parameter of the first network device is restored to the second security parameter based on the remote attestation result passing the verification.
19. The method according to claim 18, wherein The second network device receiving the second security parameter and the remote attestation result from the first network device includes: The second network device receives a third routing protocol message from the first network device, where the third routing protocol message includes the second security parameter and the remote attestation result; or, The second network device receives a link layer protocol message from the first network device, where the link layer protocol message includes the second security parameter and the remote attestation result.
20. The method according to claim 11, wherein When the first security parameter is in an insecure state or the trust level in the first security parameter does not meet the requirement, after the second network device receives a first routing protocol message from the first network device, the method further includes: The second network device obtains the security log of the first network device; Based on the security log, the second network device determines that the security parameter of the first network device is restored to a second security parameter, where the second security parameter includes a security state or / and the trust level in the second security parameter meets the trust condition.
21. A network device, characterized in that, The network device is a first network device, and the device includes: A processing unit, configured to obtain the security parameter of the first network device; generate a routing protocol message based on the security parameter, where the routing protocol message includes the security parameter; A sending unit, configured to send the routing protocol message to a second network device.
22. A network device, characterized in that, The network device is a second network device, and the device includes: A receiving unit, configured to receive a first routing protocol message from a first network device, where the first routing protocol message includes a first security parameter of the first network device; A processing unit, configured to adjust the forwarding path of the data stream passing through the first network device based on the first security parameter.
23. The device according to claim 22, wherein, When the first security parameter is in an insecure state or the trust level in the first security parameter does not meet the trust condition, the receiving unit is further configured to receive a second security parameter of the first network device from M network devices, where the second security parameter includes a security state or / and the trust level in the second security parameter meets the trust condition; The processing unit is further configured to determine that the security parameter of the first network device is restored to the second security parameter based on M being greater than or equal to a threshold and the trust level of each of the M network devices meeting the trust condition.
24. The device according to claim 22, characterized in that, When the first security parameter is in an insecure state or the trust level in the first security parameter does not meet the requirement, the receiving unit is further configured to receive a second security parameter and a remote attestation result of the first network device from the first network device, where the second security parameter includes a security state or / and the trust level in the second security parameter meets the trust condition; The processing unit is further configured to determine that the security parameter of the first network device is restored to the second security parameter based on the remote attestation result passing the verification.
25. A network device, characterized in that, The network device includes: a processor, where the processor is coupled to a memory, and at least one computer program instruction is stored in the memory. The at least one computer program instruction is loaded and executed by the processor to enable the network device to implement the method according to any one of claims 1-20.
26. A network system, characterized in that, The system includes the network device as described in claim 21 and the network device as described in any one of claims 22 to 24.
27. A computer-readable storage medium, characterized in that, At least one instruction is stored in the storage medium, and when the instruction runs on a computer, the computer is caused to execute the method as described in any one of claims 1-20.
28. A computer program product, characterized in that, The computer program product includes one or more computer program instructions, and when the computer program instructions are loaded and run by a computer, the computer is caused to execute the method as described in any one of claims 1-20.