Security protection method between SDN components based on SDN-5G network architecture

By adopting asymmetric key signature verification, information encryption and random number consistency verification in the SDN-5G network architecture, combined with a secure data transmission channel, the security problem of communication between SDN components is solved, and the security and reliability of data transmission are achieved.

CN120456006AInactive Publication Date: 2025-08-08孙戎瑶
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510158628.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-13
Publication Date
2025-08-08
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Communication security between SDN components in the SDN-5G network architecture faces threats of forgery and tampering, and the existing technology is difficult to effectively ensure communication security.

Method used

Signature verification, information encryption and random number consistency verification of asymmetric keys are used to ensure the security of communication between SDN components in combination with secure data transmission channels such as VPN or SSL/TLS.

Benefits of technology

It improves the security of communication between SDN components in the SDN-5G network architecture, prevents attackers from forgery and tampering, ensures data confidentiality and integrity, and improves the immediacy and reliability of data transmission.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

The invention provides a security protection method between SDN (Software Defined Network) components based on an SDN-5G network architecture. For security vulnerabilities possibly existing between SDN components in an SDN-5G network architecture, the security of communication between the SDN components is ensured by verifying the signature based on an asymmetric key, the consistency of random numbers and an encryption technology. Meanwhile, the SDN controller and the gateway device are deployed in the mobile device, parallel data transmission of multiple RAN channels is achieved, and the data transmission efficiency is improved. According to the method, the security of the SDN-5G network architecture is effectively improved, and a powerful guarantee is provided for safe operation of the 5G network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This method belongs to the field of information security technology, and specifically involves security protection between SDN components under SDN (software-defined network) and 5G network architecture. Background Art

[0002] With the continuous development of SDN and 5G technologies, network architectures are becoming more flexible and programmable. However, this flexibility also brings new security challenges. In the SDN-5G network architecture, communication security between SDN components has become a key issue. The separation of the control and data planes in the SDN architecture, as well as the high bandwidth and low latency characteristics of 5G networks, make the network more vulnerable to attacks. For example, attackers could disrupt normal network operations by counterfeiting SDN components or tampering with network traffic. Therefore, a new security protection method is needed to ensure the security of communication between SDN components in the SDN-5G network architecture. Summary of the Invention

[0003] In response to the problems raised in the above background technology, Sun Rongyao proposed a security protection method between SDN components based on the SDN-5G network architecture. The method mainly includes the following steps: 1. Authentication: Before SDN components communicate, they verify the authenticity of each other's identities by verifying asymmetric key signatures. This ensures that only legitimate SDN components can communicate, preventing attackers from forging SDN components to launch attacks.

[0004] 2. Information encryption: During communication between SDN components, data is encrypted to ensure confidentiality and integrity. This prevents attackers from eavesdropping or tampering with network traffic to obtain sensitive information or disrupt the normal operation of the network.

[0005] 3. Random number verification: This ensures the security and immediacy of information transmission by verifying the consistency of random numbers. This ensures that data transmitted between SDN components is up-to-date, preventing attackers from disrupting network operations by replaying old data.

[0006] 4. Secure data transmission channels: Establish secure data transmission channels in the network architecture to ensure the security of communication between SDN components. This can be achieved by using protocols such as virtual private networks (VPNs) or secure sockets layer (SSL / TLS).

Claims

1. This method belongs to the field of information security technology, specifically a method for protecting security between SDN components based on the SDN-5G network architecture. This method employs multiple security measures to ensure data transmission security during communication between mobile devices and RAN (radio access network) equipment. These measures include, but are not limited to, 2. Verify the authenticity of the other party's identity by verifying the signature based on an asymmetric key. During the communication process, the two devices will exchange identity information, random numbers, and certificates, and verify the identity of the other party through the encryption and decryption process of public and private keys, thus ensuring that both parties in the communication are authentic and trustworthy.

3. Ensure the security and immediacy of information transmission by verifying the consistency of random numbers. During the communication process, the two devices will exchange random numbers and verify the consistency of these random numbers in subsequent communications to ensure that the information has not been tampered with or delayed during transmission.

4. Establish a secure data transmission channel in the network architecture through encryption. This method uses encryption technology to encrypt the data during the communication process, thereby ensuring the confidentiality and integrity of the data during transmission.

5. This method also involves incorporating an SDN controller (M-OFC) and an SDN gateway (M-OFG) into mobile devices to manage the parallel distribution of upper-layer data across multiple RAN (Radio Access Network) channels, enabling parallel data transmission across different RAN channels. This technology further improves data transmission speed and efficiency.