Method for creating a macsec session for a aggregated port, network device and apparatus

CN121077964BActive Publication Date: 2026-08-21NEW H3C TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511389292.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-26
Publication Date
2026-08-21
Estimated Expiration
2045-09-26

AI Technical Summary

Technical Problem

[0006]然而,这种通过命令行对指定的端口进行MACsec使能的方式较为繁琐,在需要对聚合组内的多个成员口建立MACsec会话时,只能一个一个地对每一成员口进行MACsec使能,效率低下

Benefits of technology

[0057]本申请实施例提供的聚合端口MACsec会话创建方法,能够首先确定网络设备中支持MACsec的目标端口,并依次使能目标端口的MACsec会话创建功能,且在成功创建MACsec会话后自动进行链路聚合。由于目标端口的使能过程不需要人工通过命令行进行使能,而是在确定目标端口后自动进行依次使能,因此能够提高聚合端口MACsec会话创建的效率,并且能够避免因为人工疏忽遗漏对部分成员口进行MACsec使能,给聚合组带来安全风险。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121077964B_ABST
    Figure CN121077964B_ABST
Patent Text Reader

Abstract

The embodiment of the application provides a kind of aggregated port MACsec session creation method, network device and device, above-mentioned method includes: determining multiple target ports from the port of network device;Enable the MACsec session creation function of each target port in multiple target ports in turn;Multiple target ports are formed into aggregation group by successively creating MACsec session and interacting link aggregation protocol message with the opposite end port of target port of multiple target ports, and the opposite end port of target port is the port connected with the target port on the opposite end network device.Application the scheme provided by the embodiment of the application can improve the efficiency of aggregated port MACsec session creation, and avoid missing enabling to member port.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to a method, network device, and apparatus for creating a MACsec session on an aggregated port. Background Technology

[0002] Link aggregation refers to the process of bundling multiple Ethernet physical links together to form a single logical link when two network devices are connected by them. This logical link is called an aggregated link, and its bandwidth can be equal to the sum of the bandwidths of the individual links, thus increasing the overall bandwidth. Furthermore, the links within an aggregated link can provide mutual backup; that is, if one link in the aggregated link fails, packets can be forwarded through other links.

[0003] Link bonding is achieved through port bonding. Multiple Ethernet ports are bonded together to form an aggregation group, and these bonded Ethernet ports can be called member ports of the aggregation group.

[0004] MACsec (Media Access Control Security) is a local area network secure communication method based on the IEEE (Institute of Electrical and Electronics Engineers) 802 standard, which can provide users with secure MAC (Media Access Control Layer) data transmission and reception services.

[0005] Technicians can send MACsec enable commands to ports in network devices via command lines to instruct the specified ports to enable MACsec, thereby establishing a MACsec session between the port and the peer to protect the packets transmitted between the two ports.

[0006] However, enabling MACsec on specified ports via command line is cumbersome. When establishing MACsec sessions for multiple member ports within an aggregation group, it requires enabling MACsec on each member port one by one, which is inefficient. Furthermore, sometimes due to technical personnel's negligence, some member ports may be overlooked in enabling MACsec, resulting in some member ports establishing MACsec sessions while others do not, posing a security risk to the aggregation group. Summary of the Invention

[0007] The purpose of this application is to provide a method, network device, and apparatus for creating MACsec sessions on aggregated ports, so as to improve the efficiency of creating MACsec sessions on aggregated ports and avoid omitting the enabling of member ports. The specific technical solution is as follows:

[0008] In a first aspect, embodiments of this application provide a method for creating a MACsec session on an aggregated port, the method comprising:

[0009] Multiple target ports are identified from the ports of the network device, wherein the target ports are ports that support MACsec;

[0010] Enable the Media Access Control Security Protocol (MACsec) session creation function for each of the plurality of target ports in sequence;

[0011] Link aggregation protocol messages are exchanged between the multiple target ports that have successfully created MACsec sessions and their peer ports to form an aggregation group. The peer port of the target port is the port on the peer network device that is connected to the target port.

[0012] In one embodiment of this application, before sequentially enabling the Media Access Control Security Protocol (MACsec) session creation function for each of the plurality of target ports, the method further includes:

[0013] Set all target ports in the member port to the closed state, where data packets are not forwarded;

[0014] After enabling MACsec session creation on the target port each time, the following is also included:

[0015] Set the enabled target port to the enabled state for forwarding data packets.

[0016] In one embodiment of this application, after setting all target ports in the member port to a closed state where they do not forward data packets, the method further includes:

[0017] The target message is switched to an alternate port other than the target port for transmission, wherein the target message is: a message to be transmitted through the target port which is in a closed state;

[0018] After setting the enabled target port to the enabled state for forwarding data packets, the following is also included:

[0019] The message to be transmitted through the backup port is switched to the target port that is in the open state for transmission.

[0020] In one embodiment of this application, determining multiple target ports from within the ports of the network device includes:

[0021] Identify the target slots in the network device that support MACsec;

[0022] Identify the target port that supports MACsec from the ports on the board connected to the target slot.

[0023] Secondly, embodiments of this application provide a network device, the network device comprising:

[0024] processor;

[0025] transceiver;

[0026] A machine-readable storage medium storing machine-executable instructions that can be executed by the processor, the machine-executable instructions causing the processor to perform the following steps:

[0027] Multiple target ports are identified from the ports of the network device, wherein the target ports are ports that support MACsec;

[0028] Enable the Media Access Control Security Protocol (MACsec) session creation function for each of the plurality of target ports in sequence;

[0029] Link aggregation protocol messages are exchanged between the multiple target ports that have successfully created MACsec sessions and their peer ports to form an aggregation group. The peer port of the target port is the port on the peer network device that is connected to the target port.

[0030] In one embodiment of this application, before sequentially enabling the Media Access Control Security Protocol (MACsec) session creation function for each of the plurality of target ports, the machine-executable instructions further cause the processor to perform the following steps:

[0031] Set all target ports in the member port to the closed state, where data packets are not forwarded;

[0032] After enabling MACsec session creation on the target port each time, the following is also included:

[0033] Set the enabled target port to the enabled state for forwarding data packets.

[0034] In one embodiment of this application, after setting all target ports in the member port to a closed state where data packets are not forwarded, the machine-executable instructions further cause the processor to perform the following steps:

[0035] The target message is switched to an alternate port other than the target port for transmission, wherein the target message is: a message to be transmitted through the target port which is in a closed state;

[0036] After setting the enabled target port to the enabled state for forwarding data packets, the machine-executable instructions further cause the processor to perform the following steps:

[0037] The message to be transmitted through the backup port is switched to the target port that is in the open state for transmission.

[0038] In one embodiment of this application, determining multiple target ports from the ports of the network device specifically includes:

[0039] Identify the target slots in the network device that support MACsec;

[0040] Identify the target port that supports MACsec from the ports on the board connected to the target slot.

[0041] Thirdly, embodiments of this application provide an apparatus for creating aggregated port MACsec sessions, the apparatus comprising:

[0042] The target port determination module is used to determine multiple target ports from the ports of the network device, wherein the target ports are ports that support MACsec;

[0043] The port enabling module is used to sequentially enable the Media Access Control Security Protocol (MACsec) session creation function of each of the plurality of target ports;

[0044] The link aggregation module is used to sequentially exchange link aggregation protocol messages with the peer ports of the target ports through the multiple target ports that have successfully created MACsec sessions, and to perform link aggregation on the multiple target ports to form an aggregation group, wherein the peer port of the target port is the port on the peer network device connected to the target port.

[0045] In one embodiment of this application, the apparatus further includes:

[0046] The first setting module is used to set all target ports in the member port to a closed state where data packets are not forwarded;

[0047] The second setting module is used to set the enabled target port to be in the enabled state for forwarding data packets.

[0048] In one embodiment of this application, the apparatus further includes:

[0049] The first message switching module is used to switch the target message to an alternative port other than the target port for transmission, wherein the target message is: a message to be transmitted through the target port which is in a closed state;

[0050] The second message switching module is used to switch messages to be transmitted through the backup port to the target port that is in the open state.

[0051] In one embodiment of this application, the target port determination module is specifically used for:

[0052] Identify the target slots in the network device that support MACsec;

[0053] Identify the target port that supports MACsec from the ports on the board connected to the target slot.

[0054] Fourthly, embodiments of this application provide a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps of any of the methods described in the first aspect.

[0055] Fifthly, embodiments of this application also provide a computer program product containing instructions that, when run on a computer, cause the computer to perform any of the methods described in the first aspect above.

[0056] Beneficial effects of the embodiments in this application:

[0057] The aggregation port MACsec session creation method provided in this application first identifies target ports in the network device that support MACsec, then sequentially enables the MACsec session creation function of the target ports, and automatically performs link aggregation after successfully creating a MACsec session. Since the target port enabling process does not require manual command-line intervention, but is automatically performed sequentially after the target ports are identified, the efficiency of aggregation port MACsec session creation can be improved. Furthermore, it avoids security risks to the aggregation group due to human error in neglecting to enable MACsec for some member ports. Attached Figure Description

[0058] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other embodiments can be obtained based on these drawings.

[0059] Figure 1 A flowchart illustrating the first method for creating a MACsec session on an aggregated port, as provided in this application embodiment;

[0060] Figure 2 This application provides a schematic diagram illustrating the connection relationship between a target port and a peer port in an embodiment of the present application.

[0061] Figure 3 This application provides a schematic diagram of a MACsec session creation and communication process.

[0062] Figure 4 This is a schematic diagram of a port status determination process provided in an embodiment of this application;

[0063] Figure 5 A schematic diagram of link aggregation provided in an embodiment of this application;

[0064] Figure 6 A flowchart illustrating the second method for creating a MACsec session on an aggregated port, as provided in this application embodiment;

[0065] Figure 7 A flowchart illustrating the third method for creating a MACsec session on an aggregated port, as provided in this application embodiment;

[0066] Figure 8 A flowchart illustrating the fourth method for creating a MACsec session on an aggregated port, as provided in this application embodiment;

[0067] Figure 9 A flowchart illustrating the fifth method for creating a MACsec session on an aggregated port, as provided in this application embodiment;

[0068] Figure 10 This application provides a schematic diagram of the structure of a network device according to an embodiment of the present application.

[0069] Figure 11 This is a schematic diagram of the structure of a MACsec session creation device for an aggregated port provided in an embodiment of this application. Detailed Implementation

[0070] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art based on this application are within the scope of protection of this application.

[0071] To address the issues of cumbersome, inefficient, and error-prone methods for manually enabling MACsec on specified ports via command lines in related technologies, this application provides a method, network device, and apparatus for creating aggregated port MACsec sessions.

[0072] See Figure 1 This is a flowchart illustrating the first method for creating a MACsec session on an aggregated port provided in this application, including the following steps S101-S103.

[0073] S101: Identify multiple target ports from within the ports of the network device.

[0074] The target port mentioned above is a port that supports MACsec.

[0075] In one embodiment of this application, the target port can be determined by looking up a soft table configured in the network device. The soft table records the identifier of the target port in the network device that is configured to create a MACsec session.

[0076] In another embodiment of this application, step S101 can be achieved through the following steps A-B.

[0077] Step A: Identify the target slot in the network device that supports MACsec.

[0078] In one embodiment, the soft table can record slots that support MACsec, and the target slot can be determined by reading the soft table.

[0079] In another embodiment, the hardware specifications of each slot can be determined separately, thereby determining the target slot supporting MACsec based on the hardware specifications. Specifically, different models of network devices have different slots with MACsec functionality by default, and the target slot supporting MACsec on the network device can be determined based on the model of the network device implementing the embodiments of this application.

[0080] Step B: Identify the target port that supports MACsec from the ports on the board connected to the target slot.

[0081] In one embodiment, after determining the target slot, the member ports of the aggregation port corresponding to the target slot can be queried from the software table. The member ports of the aggregation port are ports configured for link aggregation. Then, the target port is determined from the member ports. Specifically, the software table can be queried to determine the ports that are member ports and can create MACsec sessions, which are then used as the target ports. It should be noted that ports configured for link aggregation but not supporting MACsec sessions will not be determined as target ports.

[0082] Since the ports on the board connected to the slot that does not support MACsec will not support MACsec, when determining the target port, you can only determine the member ports on the target slot and then determine the target port from them. This can exclude member ports that do not correspond to the target slot and speed up the selection of target ports.

[0083] S102: Enable the MACsec session creation function for each of the above target ports in sequence.

[0084] Once the MACsec session creation feature is enabled, a MACsec session will be created on the target port.

[0085] In one embodiment of this application, the target port establishes a MACsec session by negotiating a MACsec key with the peer port based on a pre-configured pre-shared key. After the MACsec session is established, the target port and the peer port can encrypt packets based on the MACsec key.

[0086] See Figure 2 This is a schematic diagram illustrating the connection relationship between a target port and a peer port, provided in an embodiment of this application.

[0087] In the figure, network device A is a network device that performs the embodiments of this application. The port GE1 / 0 / 1 on network device A is the target port, and the port GE1 / 0 / 1 on the network device B connected to it is the peer port.

[0088] In one embodiment of this application, it can be described as follows: Figure 3 The example shown creates a MACsec session, which will not be described in detail here.

[0089] The MACsec session will then terminate if any of the following occurs.

[0090] 1. When network device A receives a disconnect request message from network device B, network device A clears the corresponding MACsec session.

[0091] 2. If network device A does not receive an EAPOL-MKA message from the peer after the MACsec session timeout timer expires, the MACsec session corresponding to network device A will be cleared. The timeout duration of the above timeout timer can be configured, such as 5s, 10s, etc. If not configured, the timeout duration will be the default value, such as 6s, 8s, etc.

[0092] It should be noted that for target ports where MACsec session creation has not yet been completed, network devices can repeatedly attempt to create a MACsec session for that target port until it is completed. Alternatively, if the number of failed attempts reaches a first preset number, the target port will be skipped and no MACsec session will be created for that target port.

[0093] S103: Sequentially exchange link aggregation protocol messages between the aforementioned multiple target ports that have successfully created MACsec sessions and their peer ports to perform link aggregation on the aforementioned multiple target ports to form an aggregation group.

[0094] The peer port of the target port is the port on the peer network device that is connected to the target port.

[0095] In this embodiment of the application, after the target port completes link aggregation to form an aggregation group, the target port is written into a hard table recorded in the register of the network device's switching chip, so that the switching chip can determine that it is in the selected state, that is, the port that has completed link aggregation.

[0096] If link aggregation fails, the link aggregation protocol messages can be exchanged again between the target port and the peer port to attempt link aggregation again until it succeeds. Alternatively, if the number of link aggregation failures reaches a second preset number, the target port will be skipped and link aggregation will not be performed on that target port.

[0097] In one embodiment of this application, before performing link aggregation on the target port, the following procedure must first be executed. Figure 4 Steps C1-C8, as shown, determine whether the target port is a selected port. Selected ports can perform link aggregation. Detailed descriptions of steps C1-C8 are provided below and will not be elaborated upon here.

[0098] Additionally, it should be noted that for ports on cards connected to slots that do not support MACsec on network devices, and for ports on cards connected to the target slot that do not support MACsec, if these ports are member ports, then link aggregation can also be performed on these member ports. In this case, the aggregated port ultimately formed through link aggregation will include ports that communicate based on MACsec sessions and ports that communicate directly without relying on MACsec sessions.

[0099] See Figure 5 This is a schematic diagram of link aggregation provided in an embodiment of this application.

[0100] Figure 5 In network device A, port A1's peer port is port B1 of network device B; port A2's peer port is port B2 of network device B; and interface A3's peer interface is interface B3 of network device B. The physical links between ports A1 and B1, A2 and B2, and A3 and A3 are aggregated to form a logical link 1. The bandwidth of logical link 1 is at most equal to the sum of the bandwidths of the three physical links.

[0101] If the executing entity of this application embodiment is Figure 5 If network device A is enabled, then network device A enables ports A1, A2, and A3 respectively, and creates MACsec sessions between ports A1 and B1, A2 and B2, and A3 and B3 respectively, thereby achieving secure communication of the entire logical link 1.

[0102] Therefore, if the MACsec session of the aggregated link is created using the methods in the relevant technologies, it is necessary to manually enable ports A1, A2 and A3 of network device A respectively, which is inefficient and may result in omissions.

[0103] The aggregation port MACsec session creation method provided in this application first identifies target ports in the network device that support MACsec, then sequentially enables the MACsec session creation function of the target ports, and automatically performs link aggregation after successfully creating a MACsec session. Since the target port enabling process does not require manual command-line intervention, but is automatically performed sequentially after the target ports are identified, the efficiency of aggregation port MACsec session creation can be improved. Furthermore, it avoids security risks to the aggregation group due to human error in neglecting to enable MACsec for some member ports.

[0104] See Figure 3 This is a schematic diagram of a MACsec session creation and communication process provided in an embodiment of this application, based on the aforementioned... Figure 2 Taking the process of creating a MACsec session and communication between the target port on network device A and the peer port on network device B as an example, this paper describes the process of creating a MACsec session and communication between ports. It should be noted that the data interaction process between network device A and network device B is completed through the target port and the peer port. Both network device A and network device B are pre-configured with PSK (Pre-Shared Key) as CAK (Certificate-based Authorization Key), including the following steps S301-S305.

[0105] Step S301: Network device A sends a key server message to network device B.

[0106] The key server message indicates that the target port of network device A is the port with higher priority elected as the key server, responsible for generating and distributing SAK (Secure Association Key).

[0107] Step S302: Network device A and network device B send each other their own capability information and the parameters required to create a session.

[0108] The aforementioned capability information and parameters include port priority and whether encrypted sessions are desired.

[0109] Step S303: Network device A sends the key name and security association key to network device B.

[0110] Step S304: Network device B sends a security association key configuration completion message to network device A.

[0111] Steps S301-S304 above constitute the session negotiation process. During this process, network device A and network device B transmit a Media Access Control Security Protocol (MACSec) session creation message, which can be an Extensible Authentication Protocol over LANs (EAPOL-MKA) key negotiation message. This enables secure communication between the target port of network device A and the peer port of network device B in step S305 below.

[0112] Step S305: Network device A and network device B transmit encrypted messages.

[0113] The encrypted message is based on SAK encryption. Step S305 is a secure communication process, during which the transmitted message is a Media Access Control Security Protocol (MAC) message.

[0114] Ports participating in link aggregation exist in three states: 1. Selected state: Member ports in this state can participate in user data forwarding; these are called "selected ports." 2. Unselected state: Member ports in this state cannot participate in user data forwarding; these are called "unselected ports." 3. Individual state: Member ports in this state can participate in data forwarding as ordinary ports. When the aggregation interface type is configured as an aggregation edge interface, its member ports are in this state when they do not receive LACP (Link Aggregation Control Protocol) messages from the peer port.

[0115] See Figure 4 This is a schematic diagram of a port status determination process provided in an embodiment of this application, including the following steps C1-C8.

[0116] Step C1: Determine whether the target port is unable to participate in link aggregation due to hardware limitations.

[0117] If yes, proceed to step C8; otherwise, proceed to step C2.

[0118] Step C2: Determine whether the target port is in a connected state.

[0119] It should be noted that the above connection state is the UP state, which means that the target port is not malfunctioning. If the target port fails to create a MACsec session when MACsec session creation is supported, then the target port is in a disconnected state in this application.

[0120] If yes, proceed to step C3; otherwise, proceed to step C8.

[0121] Step C3: Determine whether the operation key and attribute class configuration of the target port are the same as those of the reference port.

[0122] The reference port is elected from the member ports of the network device's aggregation group. Its attribute class configuration and operation key will be used as a reference for other member ports within the same aggregation group to determine the status of these member ports.

[0123] If they are the same, proceed to step C4; otherwise, proceed to step C8.

[0124] Step C4: Determine whether the operation key and attribute class configuration of the peer port of the target port are the same as those of the peer port of the reference port.

[0125] Specifically, the operation key and attribute class configuration of the peer port of the target port and the operation key and attribute class configuration of the peer port of the reference port are both sent to the execution subject of this application by the network device where the peer port is located.

[0126] If they are the same, proceed to step C5; otherwise, proceed to step C8.

[0127] Step C5: Determine whether the number of candidate ports for link aggregation has exceeded the preset upper limit.

[0128] If the limit is not exceeded, proceed to step C6; if the limit is exceeded, proceed to step C7.

[0129] Step C6: Determine that the target port is the selected port.

[0130] Step C7: Sort the candidate ports for link aggregation by port number, and determine whether the target port belongs to the previous preset upper limit of ports.

[0131] If yes, proceed to step C6; otherwise, proceed to step C8.

[0132] Step C8: Determine that the target port is not selected.

[0133] If the port is a selected port, then proceed to step S103 to perform link aggregation.

[0134] In one embodiment of this application, the aforementioned member port does not include a port that has been enabled for MACsec session creation.

[0135] Specifically, when configuring a port as a member port for link aggregation, the network device checks whether the configured port is one that has MACsec session creation enabled. That is, it checks whether the MACsec session creation status of the port is "enabled." If so, the port will not be configured as a member port. In one embodiment, a notification of port configuration failure can also be provided. In other words, in this embodiment, ports that have MACsec session creation enabled will not participate in link aggregation.

[0136] In another embodiment of this application, only the target port in the member port is uniformly enabled to create a MACsec session, but the key configuration of each target port does not need to be uniformly set. That is, the key configuration of each target port can be different, thereby ensuring that the keys of different target ports are independent of each other, improving security, and ensuring the flexibility of key configuration.

[0137] See Figure 6 This is a flowchart illustrating the second method for creating a MACsec session on an aggregated port provided in this application embodiment. It includes the following steps S601-S605, and the following steps S606-S613 are performed for each member port. Taking member port 1 as an example, steps S607-S613 are performed for other member ports in the same way.

[0138] S601: Enable Link Aggregation Media Access Control Security Protocol session creation.

[0139] The solution provided in this application embodiment is executed after the Link Aggregation Media Access Control Security Protocol session is created.

[0140] S602: Traverse all slots.

[0141] S603: Determine whether this slot supports the Media Access Control Security Protocol.

[0142] If supported, proceed to step S604; otherwise, all member ports on the board connected to this slot will continue execution from step S611.

[0143] S604: Enable the aggregation enable media access control security protocol switch for this slot.

[0144] S605: Query the soft table and traverse all member ports of this slot.

[0145] S606: Determine whether member port 1 supports the Media Access Control Security Protocol.

[0146] If supported, it means that member port 1 is the target port, and step S607 is executed. If not supported, for member port 1, execution continues from step S611.

[0147] S607: Member 1 enables Media Access Control Security Protocol session creation.

[0148] S608: Open member port 1 and send a Media Access Control Security Protocol session creation message.

[0149] S609: Determine whether the Media Access Control Security Protocol session was successfully created.

[0150] If successful, proceed to step S610; if unsuccessful, return to step S608.

[0151] S610: Member 1 successfully established a Media Access Control Security Protocol session.

[0152] S611: Send link aggregation protocol message.

[0153] S612: Determine whether the link aggregation was created successfully;

[0154] If successful, proceed to step S613; otherwise, return to step S611.

[0155] S613: Write the selected member port to the hard table.

[0156] See Figure 7 This is a flowchart illustrating the third method for creating a MACsec session on an aggregated port provided in this application, which is consistent with the aforementioned... Figure 1 Compared to the embodiment shown, the following step S104 is performed before step S102 above, and the following step S105 is performed after each time the target port is enabled to create a MACsec session.

[0157] S104: Set all target ports in the member port to the closed state of not forwarding data packets.

[0158] After the target port is set to the closed state, the target port cannot forward data packets and enters the unselected state.

[0159] S105: Set the enabled target port to the enabled state for forwarding data packets.

[0160] Because the target port cannot forward packets during the subsequent MACsec session creation function enablement, packet loss will occur in data packets forwarded through the target port. To handle packet loss, network devices may transfer data packets forwarded through the target port to other ports. However, these transferred target ports may subsequently have MACsec session creation enabled again, leading to further packet loss and causing continuous packet loss, thus affecting the normal forwarding of data packets by the network device. Therefore, this embodiment uniformly sets all target ports in the member ports to a disabled state (no data packet forwarding) to prevent data packets from being switched to target ports where MACsec session creation is about to be enabled, thus avoiding the aforementioned packet loss problem. Furthermore, after each MACsec session creation is enabled on a target port, the enabled target port is set to an enabled state (data packet forwarding enabled), thereby fully utilizing the target ports with MACsec session creation enabled for data packet forwarding and improving forwarding efficiency.

[0161] See Figure 8 This is a flowchart illustrating the fourth method for creating a MACsec session on an aggregated port provided in this application, which is consistent with the aforementioned... Figure 6 Compared to the embodiment shown, the steps S614-S615 are included before step S607, and the step S616 is included after step S607.

[0162] S614: Set member port 1 to the closed state.

[0163] S615: Member port 1 is closed, which is a non-selected port.

[0164] S616: Set member port 1 to the open state.

[0165] See Figure 9 This is a flowchart illustrating the fifth method for creating a MACsec session on an aggregated port provided in this application, which is consistent with the aforementioned... Figure 7 Compared to the illustrated embodiment, step S104 is followed by step S106, and step S105 is followed by step S107.

[0166] S106: Switch the target message to an alternate port other than the target port for transmission.

[0167] The aforementioned target message is a message to be transmitted through a target port that is in a closed state.

[0168] The backup port is a port other than all target ports. It will not be enabled for MACsec session creation. Therefore, the target packets will be transferred to the backup port for forwarding and will not be affected by subsequent steps S102.

[0169] The number of the aforementioned backup ports can be one or more. Target packets from different target ports can be switched to different backup ports for forwarding, or they can be switched to the same backup port for forwarding. This application embodiment does not impose any restrictions on this.

[0170] S107: Switch the message to be transmitted through the above-mentioned backup port to the target port that is in the open state for transmission.

[0171] After enabling the MACsec session creation function on the target port, the target port is restored to the open state and can forward packets. Therefore, switching packets from the backup port to the target port can transmit data packets normally.

[0172] As can be seen from the above, in this embodiment, by uniformly configuring all target ports to a disabled state before enabling the MACsec session creation function of the target port, and then uniformly switching the target packets of the target ports to the backup ports for transmission, the problem of the target ports being temporarily unable to forward data packets can be solved, ensuring the normal forwarding of data packets as much as possible. Furthermore, the backup packets are not affected by the enabled MACsec session creation function, thus minimizing packet loss. Moreover, after the target ports are enabled, they regain their data packet forwarding capability. Switching the packets from the backup ports to the target ports for transmission can alleviate the packet forwarding pressure on the backup ports and improve packet forwarding efficiency.

[0173] Corresponding to the aforementioned method for creating MACsec sessions on aggregated ports, this application also provides a network device.

[0174] See Figure 10 This is a schematic diagram of the structure of a network device provided in an embodiment of this application. The network device includes:

[0175] Processor 1001;

[0176] Transceiver 1004;

[0177] A machine-readable storage medium 1002 stores machine-executable instructions that can be executed by the processor 1001, the machine-executable instructions causing the processor 1001 to perform the following steps:

[0178] Multiple target ports are identified from the ports of the network device, wherein the target ports are ports that support MACsec;

[0179] Enable the Media Access Control Security Protocol (MACsec) session creation function for each of the plurality of target ports in sequence;

[0180] Link aggregation protocol messages are exchanged between the multiple target ports that have successfully created MACsec sessions and their peer ports to form an aggregation group. The peer port of the target port is the port on the peer network device that is connected to the target port.

[0181] like Figure 10 As shown, the network device may also include a communication bus 1003. The processor 1001, machine-readable storage medium 1002, and transceiver 1004 communicate with each other via the communication bus 1003. The communication bus 1003 can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus 1003 can be divided into an address bus, a data bus, a control bus, etc.

[0182] The transceiver 1004 can be a wireless communication module, which interacts with other devices under the control of the processor 1001.

[0183] The machine-readable storage medium 1002 may include random access memory (RAM) or non-volatile memory (NVM), such as at least one disk storage device. Alternatively, the machine-readable storage medium 1002 may also be at least one storage device located remotely from the aforementioned processor.

[0184] The processor 1001 can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.

[0185] The aggregation port MACsec session creation method provided in this application first identifies target ports in the network device that support MACsec, then sequentially enables the MACsec session creation function of the target ports, and automatically performs link aggregation after successfully creating a MACsec session. Since the target port enabling process does not require manual command-line intervention, but is automatically performed sequentially after the target ports are identified, the efficiency of aggregation port MACsec session creation can be improved. Furthermore, it avoids security risks to the aggregation group due to human error in neglecting to enable MACsec for some member ports.

[0186] In one embodiment of this application, before sequentially enabling the Media Access Control Security Protocol (MACsec) session creation function for each of the plurality of target ports, the machine-executable instructions further cause the processor 1001 to perform the following steps:

[0187] Set all target ports in the member port to the closed state, where data packets are not forwarded;

[0188] After enabling MACsec session creation on the target port each time, the following is also included:

[0189] Set the enabled target port to the enabled state for forwarding data packets.

[0190] Because the target port cannot forward packets during the subsequent MACsec session creation function enablement, packet loss will occur in data packets forwarded through the target port. To handle packet loss, network devices may transfer data packets forwarded through the target port to other ports. However, these transferred target ports may subsequently have MACsec session creation enabled again, leading to further packet loss and causing continuous packet loss, thus affecting the normal forwarding of data packets by the network device. Therefore, this embodiment uniformly sets all target ports in the member ports to a disabled state (no data packet forwarding) to prevent data packets from being switched to target ports where MACsec session creation is about to be enabled, thus avoiding the aforementioned packet loss problem. Furthermore, after each MACsec session creation is enabled on a target port, the enabled target port is set to an enabled state (data packet forwarding enabled), thereby fully utilizing the target ports with MACsec session creation enabled for data packet forwarding and improving forwarding efficiency.

[0191] In one embodiment of this application, after setting all target ports in the member port to a closed state where data packets are not forwarded, the machine-executable instructions further cause the processor 1001 to perform the following steps:

[0192] The target message is switched to an alternate port other than the target port for transmission, wherein the target message is: a message to be transmitted through the target port which is in a closed state;

[0193] After setting the enabled target port to the enabled state for forwarding data packets, the machine-executable instructions further cause the processor to perform the following steps:

[0194] The message to be transmitted through the backup port is switched to the target port that is in the open state for transmission.

[0195] As can be seen from the above, in this embodiment, by uniformly configuring all target ports to a disabled state before enabling the MACsec session creation function of the target port, and then uniformly switching the target packets of the target ports to the backup ports for transmission, the problem of the target ports being temporarily unable to forward data packets can be solved, ensuring the normal forwarding of data packets as much as possible. Furthermore, the backup packets are not affected by the enabled MACsec session creation function, thus minimizing packet loss. Moreover, after the target ports are enabled, they regain their data packet forwarding capability. Switching the packets from the backup ports to the target ports for transmission can alleviate the packet forwarding pressure on the backup ports and improve packet forwarding efficiency.

[0196] In one embodiment of this application, determining multiple target ports from the ports of the network device specifically includes:

[0197] Identify the target slots in the network device that support MACsec;

[0198] Identify the target port that supports MACsec from the ports on the board connected to the target slot.

[0199] Corresponding to the aforementioned method for creating a MACsec session on an aggregated port, this application also provides an apparatus for creating a MACsec session on an aggregated port.

[0200] See Figure 11 This is a schematic diagram of a device for creating an aggregated port MACsec session according to an embodiment of this application. The device includes:

[0201] The target port determination module 1101 is used to determine multiple target ports from the ports of the network device, wherein the target ports are ports that support MACsec;

[0202] The port enabling module 1102 is used to sequentially enable the Media Access Control Security Protocol (MACsec) session creation function of each of the plurality of target ports;

[0203] The link aggregation module 1103 is used to sequentially exchange link aggregation protocol messages with the peer ports of the multiple target ports that have successfully created MACsec sessions, and to perform link aggregation on the multiple target ports to form an aggregation group, wherein the peer port of the target port is the port on the peer network device connected to the target port.

[0204] The aggregation port MACsec session creation method provided in this application first identifies target ports in the network device that support MACsec, then sequentially enables the MACsec session creation function of the target ports, and automatically performs link aggregation after successfully creating a MACsec session. Since the target port enabling process does not require manual command-line intervention, but is automatically performed sequentially after the target ports are identified, the efficiency of aggregation port MACsec session creation can be improved. Furthermore, it avoids security risks to the aggregation group due to human error in neglecting to enable MACsec for some member ports.

[0205] In one embodiment of this application, the apparatus further includes:

[0206] The first setting module is used to set all target ports in the member port to a closed state where data packets are not forwarded;

[0207] The second setting module is used to set the enabled target port to be in the enabled state for forwarding data packets.

[0208] Because the target port cannot forward packets during the subsequent MACsec session creation function enablement, packet loss will occur in data packets forwarded through the target port. To handle packet loss, network devices may transfer data packets forwarded through the target port to other ports. However, these transferred target ports may subsequently have MACsec session creation enabled again, leading to further packet loss and causing continuous packet loss, thus affecting the normal forwarding of data packets by the network device. Therefore, this embodiment uniformly sets all target ports in the member ports to a disabled state (no data packet forwarding) to prevent data packets from being switched to target ports where MACsec session creation is about to be enabled, thus avoiding the aforementioned packet loss problem. Furthermore, after each MACsec session creation is enabled on a target port, the enabled target port is set to an enabled state (data packet forwarding enabled), thereby fully utilizing the target ports with MACsec session creation enabled for data packet forwarding and improving forwarding efficiency.

[0209] In one embodiment of this application, the apparatus further includes:

[0210] The first message switching module is used to switch the target message to an alternative port other than the target port for transmission, wherein the target message is: a message to be transmitted through the target port which is in a closed state;

[0211] The second message switching module is used to switch messages to be transmitted through the backup port to the target port that is in the open state.

[0212] As can be seen from the above, in this embodiment, by uniformly configuring all target ports to a disabled state before enabling the MACsec session creation function of the target port, and then uniformly switching the target packets of the target ports to the backup ports for transmission, the problem of the target ports being temporarily unable to forward data packets can be solved, ensuring the normal forwarding of data packets as much as possible. Furthermore, the backup packets are not affected by the enabled MACsec session creation function, thus minimizing packet loss. Moreover, after the target ports are enabled, they regain their data packet forwarding capability. Switching the packets from the backup ports to the target ports for transmission can alleviate the packet forwarding pressure on the backup ports and improve packet forwarding efficiency.

[0213] In one embodiment of this application, the target port determination module 1101 is specifically used for:

[0214] Identify the target slots in the network device that support MACsec;

[0215] Identify the target port that supports MACsec from the ports on the board connected to the target slot.

[0216] In another embodiment provided in this application, a computer-readable storage medium is also provided, which stores a computer program that, when executed by a processor, implements the steps of any of the above-described aggregated port MACsec session creation methods.

[0217] In another embodiment provided in this application, a computer program product containing instructions is also provided, which, when run on a computer, causes the computer to execute any of the aggregation port MACsec session creation methods described in the above embodiments.

[0218] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid state disk (SSD)).

[0219] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0220] The various embodiments in this specification are described in a related manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the embodiments for network devices, apparatuses, computer-readable storage media, and computer program products are basically similar to the method embodiments, and therefore the descriptions are relatively simple; relevant parts can be referred to the descriptions of the method embodiments.

[0221] The above description is merely a preferred embodiment of this application and is not intended to limit the scope of protection of this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application are included within the scope of protection of this application.

Claims

1. A method for creating a MACsec session on an aggregated port, characterized in that, The method includes: Multiple target ports are identified from the ports of the network device, wherein the target ports are ports that support MACsec; Enable the Media Access Control Security Protocol (MACsec) session creation function for each of the plurality of target ports in sequence; Link aggregation protocol messages are exchanged between the multiple target ports that have successfully created MACsec sessions and their peer ports to form an aggregation group. The peer port of the target port is the port on the peer network device that is connected to the target port.

2. The method according to claim 1, characterized in that, Before sequentially enabling the Media Access Control Security Protocol (MACsec) session creation function for each of the plurality of target ports, the method further includes: Set all target ports in the member port to the closed state, where data packets are not forwarded; After enabling MACsec session creation on the target port each time, the following is also included: Set the enabled target port to the enabled state for forwarding data packets.

3. The method according to claim 2, characterized in that, After setting all target ports in the member ports to a closed state where they do not forward data packets, the following is also included: The target message is switched to an alternate port other than the target port for transmission, wherein the target message is: a message to be transmitted through the target port which is in a closed state; After setting the enabled target port to the enabled state for forwarding data packets, the following is also included: The message to be transmitted through the backup port is switched to the target port that is in the open state for transmission.

4. The method according to claim 1, characterized in that, The step of determining multiple target ports from within the ports of the network device includes: Identify the target slots in the network device that support MACsec; Identify the target port that supports MACsec from the ports on the board connected to the target slot.

5. A network device, characterized in that, The network device includes: processor; transceiver; A machine-readable storage medium storing machine-executable instructions that can be executed by the processor, the machine-executable instructions causing the processor to perform the following steps: Multiple target ports are identified from the ports of the network device, wherein the target ports are ports that support MACsec; Enable the Media Access Control Security Protocol (MACsec) session creation function for each of the plurality of target ports in sequence; Link aggregation protocol messages are exchanged between the multiple target ports that have successfully created MACsec sessions and their peer ports to form an aggregation group. The peer port of the target port is the port on the peer network device that is connected to the target port.

6. The network device according to claim 5, characterized in that, Before sequentially enabling the Media Access Control Security Protocol (MACsec) session creation function for each of the plurality of target ports, the machine-executable instructions also cause the processor to perform the following steps: Set all target ports in the member port to the closed state, where data packets are not forwarded; After enabling MACsec session creation on the target port each time, the following is also included: Set the enabled target port to the enabled state for forwarding data packets.

7. The network device according to claim 6, characterized in that, After setting all target ports in the member port to a closed state where data packets are not forwarded, the machine-executable instructions further cause the processor to perform the following steps: The target message is switched to an alternate port other than the target port for transmission, wherein the target message is: a message to be transmitted through the target port which is in a closed state; After setting the enabled target port to the enabled state for forwarding data packets, the machine-executable instructions further cause the processor to perform the following steps: The message to be transmitted through the backup port is switched to the target port that is in the open state for transmission.

8. The network device according to claim 5, characterized in that, The step of determining multiple target ports from within the ports of the network device specifically includes: Identify the target slots in the network device that support MACsec; Identify the target port that supports MACsec from the ports on the board connected to the target slot.

9. A device for creating a MACsec session on an aggregated port, characterized in that, The device includes: The target port determination module is used to determine multiple target ports from the ports of the network device, wherein the target ports are ports that support MACsec; The port enabling module is used to sequentially enable the Media Access Control Security Protocol (MACsec) session creation function of each of the plurality of target ports; The link aggregation module is used to sequentially exchange link aggregation protocol messages between the multiple target ports that have successfully created MACsec sessions and their peer ports to form an aggregation group. The peer port of the target port is the port on the peer network device that is connected to the target port.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the steps of the method described in any one of claims 1-4.

Citation Information

Patent Citations

  • Port-trunking-based message processing method and device

    CN102307140A

  • Media access control security (macsec) enabled links of a link aggregation group (LAG)

    CN111953597A