Discovery method and device of link layer encryption equipment, equipment and medium

By using broadcast and unicast message exchanges, mutual discovery and authentication of link encryption devices are achieved, solving the problem of legitimate access of link encryption devices in existing technologies and improving network security and management efficiency.

CN121333593APending Publication Date: 2026-01-13CETC CYBERSPACE SECURITY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511662432.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-13
Publication Date
2026-01-13

AI Technical Summary

Technical Problem

In network and line protection scenarios at the Ethernet link layer, link encryption devices need to discover and verify each other's legitimacy in order to negotiate keys. However, existing technologies such as the LLDP link discovery method lack security measures and cannot enable legitimate access for link encryption devices.

Method used

The first message, broadcast, contains the device identifier, physical address, signature certificate, and signature result of the encryption certificate. The receiving end performs legality verification and device conflict detection, records the binding relationship, and responds by unicasting the second message after a preset silence period, thereby realizing mutual discovery and authentication of encrypted devices on the link.

Benefits of technology

It enables mutual discovery and legitimate access of link-layer encrypted devices, enhances management and security in large-scale network scenarios, avoids network traffic bursts, and ensures the security of data communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121333593A_ABST
    Figure CN121333593A_ABST
Patent Text Reader

Abstract

The invention discloses a discovery method and device of link layer encryption equipment, equipment and a medium, and relates to the technical field of data communication. The method comprises the following steps: acquiring a first information message broadcasted by a sending end of link layer encryption equipment by using a target security entity; after the receiving end of the link layer encryption equipment receives the first information message in the physical local area network or the virtual local area network to which the receiving end belongs, carrying out validity verification on the first information message, and carrying out equipment conflict detection by utilizing the equipment identifier after the verification is passed; and after the device conflict detection is passed, recording a binding relationship between the device identifier and the physical address, and after a preset silent period, sending a second information message in a unicast manner by using the target security entity with the recorded physical address as a destination address so as to respond to the first information message. Through the technical scheme of the invention, discovery and authentication of the Ethernet link layer encryption equipment can be realized.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data communication, in particular to a discovery method, device and equipment of link layer encryption equipment and a medium. BACKGROUND

[0002] In the network protection scene and line protection scene of the Ethernet link layer, the link encryption equipment is respectively inserted into the link layer exchange network or the line, the data transmitted is encrypted and decrypted by the link encryption equipment, and the safe communication of the data is realized. However, in order to realize the safe communication, the link encryption equipment needs not only to realize the mutual discovery, but also to realize the mutual authentication between the link encryption equipment, and then the subsequent key negotiation and other work can be completed.

[0003] Therefore, how to provide a solution to the above technical problems is a problem that those skilled in the art need to solve at present. SUMMARY

[0004] Therefore, the purpose of the present application is to provide a discovery method, device and equipment of link layer encryption equipment, which can not only realize the mutual discovery of the link layer encryption equipment, but also realize the mutual authentication between the link layer encryption equipment, and ensure the legal access of the link layer encryption equipment. The specific scheme is as follows:

[0005] In a first aspect, the present application discloses a discovery method of link layer encryption equipment, comprising:

[0006] Obtaining a first message packet broadcasted by a sending end of the link layer encryption equipment using a target security entity; the first message packet comprises a device identifier, a physical address, a message sequence number, a signature certificate, an encryption certificate and a signature result generated by a signature private key based on a digital certificate authentication method of the sending end;

[0007] When a receiving end of the link layer encryption equipment receives the first message packet under the physical local area network or the virtual local area network, the first message packet is verified for legality, and the device conflict detection is performed using the device identifier after the legality verification is passed;

[0008] After the device conflict detection is passed, the binding relationship between the device identifier and the physical address is recorded, and after a preset silent period, the second message packet is unicast sent using the target security entity with the recorded physical address as the destination address, so as to respond to the first message packet.

[0009] Optionally, the discovery method of the link layer encryption equipment further comprises:

[0010] signing the device identifier and the message serial number in the first message packet by using a signature private key of the sending end through the target security entity, to generate a corresponding signature result, and appending the signature result to the first message packet;

[0011] Correspondingly, the legality verification on the first message packet comprises:

[0012] judging the legality of the message serial number in the first message packet, and verifying the signature certificate after determining that the message serial number is legal;

[0013] if the signature certificate passes the verification, verifying the signature result by using a public key in the signature certificate, and recording the device identifier and the message serial number of the sending end after the signature verification passes.

[0014] Optionally, the message serial number is an 8-byte unsigned integer, and the high 4 bytes of the message serial number are stored as the system date and time when the first message packet is sent, and the low 4 bytes of the message serial number are stored as the total number of the first message packet and the second message packet sent by the target security entity; correspondingly, the judgment on the legality of the message serial number in the first message packet comprises:

[0015] judging whether the message serial number is monotonically increasing;

[0016] when the message serial number is monotonically increasing, determining that the message serial number is legal;

[0017] when the message serial number is flat or decreasing, determining that the message serial number is not legal, and discarding the first message packet.

[0018] Optionally, the discovery method of the link layer encryption device further comprises:

[0019] when the high 4 bytes of the message serial number are rolled back due to system time modification, modifying the device identifier of the target link layer encryption device with time error, or restarting other link layer encryption devices outside the target link layer encryption device to clear the record of the device identifier of the target link layer encryption device.

[0020] Optionally, the device conflict detection by using the device identifier after the legality verification passes comprises:

[0021] after the legality verification passes, judging whether the device identifier in the first message packet conflicts with the own device identifier of the receiving end;

[0022] if the device identity in the first message packet conflicts with the self device identity of the receiving end, an error notification message is broadcasted to other link layer encryption devices in the network except the receiving end to inform the device identity and physical address of the sending end;

[0023] if the device identity in the first message packet does not conflict with the self device identity of the receiving end, it is determined that the device conflict detection passes, and the step of recording the binding relationship between the device identity and the physical address is triggered.

[0024] Optionally, the discovery method of the link layer encryption device further comprises:

[0025] When there are at least two sending ends simultaneously sending the first message packet in the network of the link layer, the first message packet is authenticated based on a preset authentication rule to generate the second message packet; wherein the preset authentication rule is used to avoid multiple repeated authentications between devices.

[0026] Optionally, the authentication of the first message packet based on the preset authentication rule to generate the second message packet comprises:

[0027] determining whether the sending end has sent the first message packet within a time before the lower limit of the preset silence period;

[0028] if the sending end has not sent the first message packet within the time before the lower limit of the preset silence period, triggering the step of unicasting the second message packet after the preset silence period using the target security entity with the recorded physical address as the destination address to respond to the first message packet;

[0029] if the sending end has sent the first message packet within the time before the lower limit of the preset silence period, determining the size between the self device identity of the receiving end and the device identity in the first message packet;

[0030] when the self device identity of the receiving end is smaller than the device identity in the first message packet, triggering the step of unicasting the second message packet after the preset silence period using the target security entity with the recorded physical address as the destination address to respond to the first message packet;

[0031] when the self device identity of the receiving end is not smaller than the device identity in the first message packet, the first message packet is not responded to.

[0032] In a second aspect, the application discloses a discovery device of a link layer encryption device, characterized by comprising:

[0033] The device discovery module is configured to acquire a first message packet broadcast by a sending end of a link layer encryption device using a target security entity; the first message packet includes a device identifier, a physical address, a message sequence number, a signature certificate, an encryption certificate, and a signature result generated by a signature private key using a digital certificate-based authentication method of the sending end.

[0034] The authentication module is configured to, after the receiving end of the link layer encryption device receives the first message packet under a physical local area network or a virtual local area network to which the receiving end belongs, perform legality verification on the first message packet, and perform device conflict detection using the device identifier after the legality verification is passed.

[0035] The response module is configured to, after the device conflict detection is passed, record a binding relationship between the device identifier and the physical address, and after a preset silence period, unicast a second message packet using the target security entity and taking the recorded physical address as a destination address to respond to the first message packet.

[0036] In a third aspect, the present application discloses an electronic device, which comprises a processor and a memory; wherein the memory is configured to store a computer program, and the computer program is loaded and executed by the processor to implement the discovery method of the link layer encryption device as described above.

[0037] In a fourth aspect, the present application discloses a computer readable storage medium configured to store a computer program; wherein the computer program is executed by a processor to implement the discovery method of the link layer encryption device as described above.

[0038] The present application provides a discovery method of a link layer encryption device, which comprises: acquiring a first message packet broadcast by a sending end of a link layer encryption device using a target security entity; the first message packet includes a device identifier, a physical address, a message sequence number, a signature certificate, an encryption certificate, and a signature result generated by a signature private key using a digital certificate-based authentication method of the sending end; after a receiving end of the link layer encryption device receives the first message packet under a physical local area network or a virtual local area network to which the receiving end belongs, performing legality verification on the first message packet, and performing device conflict detection using the device identifier after the legality verification is passed; after the device conflict detection is passed, recording a binding relationship between the device identifier and the physical address, and after a preset silence period, unicast a second message packet using the target security entity and taking the recorded physical address as a destination address to respond to the first message packet.

[0039] The beneficial technical effect of the present application is that in the network at the link layer, the sending end of the link layer encryption device announces the whole network through broadcasting, ensures that all receiving ends can receive the message, and realizes mutual discovery of the link layer encryption device. The first message packet of the broadcast contains the local device identifier and physical address of the sending end, and compared with the LLDP link device discovery, the information content carried is simpler and more suitable for the link layer encryption device. Moreover, compared with the LLDP link device discovery, the authentication function is added, the authentication mode based on the digital certificate can not only ensure that the access link encryption device is a legal device, but also is convenient for management when the network scale is relatively large, and the security is more advantageous. It can be seen that through the two-way interactive message mode, not only the mutual discovery of the link layer encryption device is realized, but also the mutual authentication between the link encryption devices is realized, and the legal access of the link layer encryption device is ensured.

[0040] In addition, the present application provides a link layer encryption device discovery device, equipment and storage medium, which correspond to the link layer encryption device discovery method described above, and have the same effect. BRIEF DESCRIPTION OF DRAWINGS

[0041] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the drawings needed to be used in the embodiments or the prior art description will be briefly introduced. Obviously, the drawings in the following description are only embodiments of the present application, and for those skilled in the art, other drawings can be obtained without creative labor on the basis of the provided drawings.

[0042] Figure 1 A safety communication schematic diagram in a line protection scenario disclosed by the present application;

[0043] Figure 2 A safety communication schematic diagram in a network protection scenario disclosed by the present application;

[0044] Figure 3 A flow chart of a link layer encryption device discovery method disclosed by the present application;

[0045] Figure 4 A structure schematic diagram of a link layer encryption device discovery device disclosed by the present application;

[0046] Figure 5 A structure diagram of an electronic equipment disclosed by the present application. DETAILED DESCRIPTION

[0047] With reference to the accompanying drawings: clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, not all. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative labor fall within the scope of the present application.

[0048] Before introducing the present application, in order to better understand the present application, first of all, the network scene of the Ethernet link layer in the present application, and the current discovery method of some link layer devices in the Ethernet link layer communication technology are introduced.

[0049] In the line protection scene, the Ethernet link layer switches (or routers, PCs, etc. any device with Ethernet interface) are connected through a physical line (direct network cable, optical fiber, etc.) or a virtual line (such as the point-to-point L2VPN (Virtual Private Network, Virtual Private Network) service VPWS (Virtual Private Wire Service) provided by the operator). There can be transmission devices, relay devices, operator network devices, etc. on the line between switches to realize the extension of the line, but there will be no Ethernet switching device (including virtual Ethernet switching function) on the line. The connection between two switches is a point-to-point connection. The point-to-multipoint connection can also be attributed to multiple point-to-point connections, as long as the center point has no switching function and can be counted as a line protection scene. In this scenario, the Ethernet plaintext frame is transmitted on the line between switches, and the security of the line is not guaranteed. Mainly reflected in the scene of a very long physical line, it is difficult to implement physical protection, so there is a risk of signal leakage, which needs to be protected. In addition, in the virtual line scenario, since the line passes through the operator network in the middle, it may share routers and other network devices with the Internet, and there is a risk that attackers will illegally steal messages or inject and tamper with messages and replay messages from these intermediate devices. Therefore, the line protection scene needs to be protected for confidentiality, integrity, and anti-replay attack. As shown in Figure 1 In order to realize the security protection of confidentiality, integrity and anti-replay, a pair of link encryption devices are generally deployed in series on the line between switches, and are directly connected with the switches at both ends through the network cable. Among them, Figure 1 After deploying the link encryption device, a Figure 1 b, the secure communication of data in this scenario is realized. The Ethernet plaintext frame is transmitted between the switch and the link encryption device, and the Ethernet ciphertext frame is transmitted between the link encryption devices through the original physical or virtual line, which realizes the protection of data messages on the line from illegal monitoring and malicious tampering, and replay and other injection attacks.

[0050] In network protection scenarios, Ethernet link-layer switches (or routers, PCs, or any devices with Ethernet interfaces) are connected via a physical Ethernet network (composed of one or more switches) or a virtual Ethernet network (such as the Virtual Private LAN Services (VPLS) provided by ISPs). The Ethernet network between switches can contain transmission equipment, relay equipment, ISP-supported network equipment, etc., to achieve line extension and Layer 2 switching functions, and the switches can be arbitrarily interconnected. The essential difference between this scenario and line protection scenarios lies in whether data packets are switched based on MAC (Media Access Control) addresses during transmission. If packets are switched to different lines based on MAC addresses, it's a network protection scenario; otherwise, it's a line protection scenario where packets can only be transmitted along a specific line. In this scenario, plaintext Ethernet frames are transmitted over the Ethernet switching network, and network security is not guaranteed. This is particularly problematic in scenarios with large network spans, where it's difficult to implement physical protection for all lines, thus posing a risk of signal eavesdropping and leakage, requiring confidentiality protection. Furthermore, when effective physical protection is difficult to implement with intermediate switches, or in the scenario of a virtual switching network (VSN), since the VSN belongs to the carrier's network and may share network equipment such as routers with the Internet, there is a risk that attackers may illegally steal packets, inject tampered packets, or replay packets from these intermediate devices. Therefore, network protection scenarios require confidentiality protection, integrity protection, and replay attack protection. Figure 2 As shown, in this scenario, Figure 2 a is obtained by connecting a link-layer encryption device in series with each switch to the switching network. Figure 2 b) Implement secure data communication in this scenario. Plaintext Ethernet frames are transmitted between the switch and the link-layer encryption device, while encrypted Ethernet frames are transmitted between the link-layer encryption devices via the existing Ethernet switching network. The MAC header of the data frame cannot be encrypted (because switching functionality relies on MAC addresses); only the payload of the data frame is encrypted. Ethernet management and control protocol frames also cannot be encrypted to maintain normal network topology and management functions. The link-layer encryption device provides network data security protection for the existing switching network, protecting data from attacks such as unauthorized mirroring, unauthorized eavesdropping, malicious tampering, replay attacks, and injection attacks.

[0051] In the above two Ethernet link layer network scenarios, the link encryption devices are respectively inserted into the line or link layer switching network, and the link encryption devices encrypt and decrypt the transmitted data, so that the secure communication of the data is finally realized. However, in order to realize the secure communication, the link encryption devices not only need to realize mutual discovery, but also need to realize that the link encryption devices confirm each other as a legal device, and then the subsequent key negotiation and the like can be completed.

[0052] In the Ethernet link layer communication technology, there are some discovery methods of link layer devices, and the link layer discovery protocol (LLDP) can be used to realize the discovery of the link layer switch device. However, the LLDP provides a link layer discovery method, and can encapsulate the main capabilities, management addresses, device identifiers, interface identifiers and the like of the local device into the LDP (Label Distribution Protocol) message and transmit them to the neighbor node. The neighbor node saves the information in the form of a standard MIB (Management Information Base) after receiving the information, and the NMS (Network Management System) queries and judges the communication status of the link. Since the LLDP link discovery method is a simple protocol with a multicast address as a destination for unidirectional transmission of information, the encapsulation format is a simple TLV (Tag-Length-Value), and the basic information of the encapsulation device and port is encapsulated. Therefore, the LLDP link discovery method has no security measures, and the information publisher is not authenticated. In addition, the LLDP link discovery method allows the use of a multicast destination address, and is only suitable for application to adjacent network switching devices, and cannot pass through all devices in the network.

[0053] Therefore, the application provides a discovery scheme of a link layer encryption device, which is mainly applied to the link layer encryption device instead of the link layer switch device like the LLDP link layer discovery method. The discovery scheme not only realizes the mutual discovery of the link layer encryption devices, but also realizes the mutual authentication between the link encryption devices, so that the legal access of the link layer encryption device is ensured.

[0054] The embodiment of the application discloses a discovery method of a link layer encryption device, which is applied to a receiving end of the link layer encryption device, as shown in Figure 3 The method comprises the following steps.

[0055] Step S11: obtaining a first message packet broadcast by a sending end of the link layer encryption device using a target security entity; the first message packet includes the device identifier, the physical address, the message sequence number, the signature certificate, the encryption certificate of the sending end, and a signature result generated by a signature private key based on the authentication mode of the digital certificate.

[0056] In the embodiments of the present application, the receiving end of the link layer encryption device is described. The sending end of the link layer encryption device advertises all receiving ends in the network of the link layer in a broadcast manner. The advertisement information is the first message packet broadcast, which contains the device identifier, the physical address, the message sequence number, the signature certificate, the encryption certificate of the sending end, and the signature result generated by the signature private key based on the authentication mode of the digital certificate.

[0057] The device identifier is LSID (Link Security Identifier, link encryption device identifier), which is used to distinguish different devices in the broadcast domain, can be configured by a user and is unique in the broadcast domain.

[0058] In the Ethernet link layer communication layer, the communication device needs the physical address of MAC (Media Access Control, media access control) as the identifier. However, from the application of the link encryption device, the port itself can not need the MAC address, and the source MAC address of its external communication is the bridge MAC address of the link encryption device. Therefore, in the advertisement message in the embodiments of the present application, the source MAC address corresponding to the physical address specifically refers to the bridge MAC address. By broadcasting the first message packet, all receiving ends of the link encryption device in the broadcast domain know the LSID of the new sending end of the link encryption device, check the uniqueness, bind the MAC address of the new device, and then other link encryption devices can realize the authentication function with the new device.

[0059] Generally, the first message packet broadcasted by the sending end will cause the response of all other receiving ends of the link layer encryption device, and the legitimacy must be judged, so the authentication process must start from the first message packet. Therefore, the application not only realizes the device discovery, but also realizes the function of device authentication. In the authentication aspect of the application, compared with the pre-shared key authentication, the certificate authentication has more advantages in the network scale and security. Therefore, in the embodiment of the application, the certificate-based authentication mode is adopted. In order to reduce the number of interactions of the discovery and authentication messages, the first message packet also realizes the authentication of the message sender. Therefore, the target security entity in the sending end includes the signature result generated by signing the LSID and the sequence number and other key information based on the digital certificate authentication mode by using the signature private key of the sending end. The signature result is attached to the first message packet and broadcasted to the network together with the first message packet, and the legitimacy of the first message packet is verified through the signature result.

[0060] In addition, the security entity (Security Entity, SecY) is the entity for the link layer encryption device discovery and authentication, and it is also unique in a broadcast domain. In the embodiment of the application, the interface of the link layer encryption device is divided according to the VLAN (Virtual Local Area Network, virtual local area network), and each VLAN includes a plaintext interface and a ciphertext interface. The plaintext and ciphertext interfaces in a VLAN can be physical interfaces or VLAN sub-interfaces. The processing and forwarding of the packet are carried out in the respective VLANs, and the forwarding relationship is always plaintext interface in and encrypted ciphertext interface out, or ciphertext interface in and decrypted plaintext interface out. The link layer encryption device does not implement forwarding based on the MAC address or the IP address, and the link layer encryption device corresponds to a security entity for processing the packet for each VLAN, and corresponds to a bridge interface.

[0061] Therefore, the target security entity is the security entity of the sending end in the current VLAN. After the SecY is started, the first packet, i.e., the first message packet, is sent from the ciphertext interface to the protected network with the broadcast MAC address as the destination address. The basic information of the sending end is announced to all other receiving ends of the link layer encryption device in the broadcast domain, including the LSID (the ID of the link layer encryption device), the MAC address (the source MAC address specifically refers to the bridge MAC address), and the signature result used for the legitimacy verification. Because the link layer encryption device surrounds the protected network, the first message packet will be received and processed by all other receiving ends of the link layer encryption device in the broadcast domain corresponding to the SecY, and this process will not affect the communication user equipment connected outside the link layer encryption device on the network.

[0062] Step S12: When the receiving end of the link layer encryption device receives the first message packet under the physical local area network or virtual local area network, the first message packet is verified for legitimacy, and the device identifier is used to detect device conflicts after the legitimacy verification is passed.

[0063] In the embodiments of the present application, after the SecY on the receiving end of each link layer encryption device receives the broadcast first message packet, the legitimacy of the packet is first authenticated, and the illegal packet is directly discarded without response. Then, the LSID in the packet is checked for conflict with the LSID of the SecY itself, that is, the SecY of the link layer encryption device that finds the conflict will immediately notify an error. In this way, after the other link layer encryption devices authenticate the legitimacy of the error notification message, the binding relationship between the LSID and the MAC address established after the conflict detection will be directly abandoned, and the subsequent interaction with the newly added conflict LSID will not be performed.

[0064] In a specific implementation, the process of verifying the legitimacy of the first message packet is described, which specifically includes the following steps:

[0065] The legitimacy of the message sequence number in the first message packet is judged, and after the message sequence number is determined to be legitimate, the signature certificate is verified.

[0066] If the signature certificate verification is passed, the public key in the signature certificate is used to verify the signature result, and after the signature verification is passed, the device identifier and the message sequence number of the sending end are recorded.

[0067] Based on the foregoing steps, in order to reduce the number of interactions of the discovery and authentication messages, the first message packet also implements authentication of the message sender. In the first message packet, not only the message sequence number, the LSID of the sender SecY, the sender signature certificate, the encryption certificate and other information are included, but also the signature result generated by the sender SecY by signing the sequence number and LSID and other key information with the signature private key of the sender SecY. The signature result is broadcast together with the first message packet to the network.

[0068] When the receiving end of all link layer encryption devices in the network receives the first message packet, the legitimacy of the message sequence number is first judged, and if it is illegal, the message is directly discarded. After the message sequence number is determined to be legitimate, the signature certificate verification and the digital signature verification are performed.

[0069] It is worth noting that after the signature verification is passed, the LSID of the sending end in the first message packet and the latest sequence number in the first message packet are recorded, so as to facilitate the sequence number legitimacy test on the messages received later.

[0070] In another specific embodiment, the process of device conflict detection using device identification after the legality verification is passed is described, which specifically includes the following steps:

[0071] After the legality verification is passed, it is judged whether the device identification in the first message packet collides with the self device identification of the receiving end;

[0072] If the device identification in the first message packet collides with the self device identification of the receiving end, an error notification message is broadcasted to other link layer encryption devices except the receiving end of the network link layer to notify the device identification and physical address of the sending end;

[0073] If the device identification in the first message packet does not collide with the self device identification of the receiving end, it is determined that the device conflict detection is passed, and the step of recording the binding relationship between the device identification and the physical address is triggered.

[0074] In the embodiment of the application, after the legality verification is passed, the receiving end checks whether the LSID in the first message packet collides with the LSID of itself. If it collides, an error notification message is immediately broadcasted to notify the LSID and MAC address of the SecY of all other link layer encryption devices of the conflict; wherein the SecY of the sending end of the link layer encryption device sending the first message packet is included, which facilitates the prompt of the user to configure an error. If the LSID does not collide, the binding relationship between the LSID and the MAC address is recorded, and then a second message packet, i.e., a second message packet, is unicast sent with the MAC address just recorded as the destination address after a preset silence period, to continue the authentication and subsequent processes.

[0075] Step S13: After the device conflict detection is passed, the binding relationship between the device identification and the physical address is recorded, and the second message packet is unicast sent with the recorded physical address as the destination address by the target security entity after a preset silence period, to respond to the first message packet.

[0076] It can be understood that in order to unify the authentication mode of both parties, the receiving end adopts the same mode as the first message packet to realize the authentication of the sender of the second message packet in the returned second message packet. The second message packet includes two certificates (signature certificate and encryption certificate) of the responder and the sequence number, LSID, MAC address (source MAC address), signature and other information required for authenticating the responder, and only the second message packet is unicast packet for response. Since the first message packet and the second message packet both use the sequence number and are associated with the (SecY) context, the sequence numbers in the two messages need to be uniformly numbered based on a SecY.

[0077] In the embodiment of the present application, a silence period is designed to leave time for LSID conflict detection and error notification. The silence period is usually a random time in the range of 2000-2500 milliseconds. Generally, from sending the first message packet to the arrival of the error notification, there can be nearly 2 seconds of time on a long distance link, that is, an RTT (Round Trip Time) is close to 2 seconds, so the lower limit of the sleep time can be set to 2000 milliseconds.

[0078] It can be understood that when a large number of link layer encryption devices in the network send the first message packet at almost the same time, a traffic burst phenomenon will occur. That is, when the link layer encryption device receives the first message packet broadcast packet, if all receiving end link layer encryption devices immediately send the second message packet, a network traffic burst problem will occur in the case of a large network. The method mentioned in the present application can smooth the network traffic by designing a silence period, that is, all receiving end link layer encryption devices that receive the first message packet sleep for a random time before responding to the second message packet.

[0079] As can be seen, in the embodiment of the present application, it is no longer a one-way delivery of information, but after the sending end of the link encryption device adopts a broadcast mode to notify the entire network, it is ensured that all receiving ends of the link layer encryption devices in the network can receive the message. The receiving end of the link encryption device responds to the information notified by the sending end in a unicast mode, realizes mutual discovery and authentication, and is no longer limited to the discovery of adjacent network devices.

[0080] The present application provides a discovery method of a link layer encryption device, comprising: obtaining a first message packet broadcast by a sending end of a link layer encryption device using a target security entity; the first message packet includes a device identifier of the sending end, a physical address, a message sequence number, a signature certificate, an encryption certificate, and a signature result generated by a signature private key based on a digital certificate authentication mode; when a receiving end of the link layer encryption device receives the first message packet under a physical local area network or a virtual local area network to which it belongs, the first message packet is verified for legitimacy, and after the legitimacy verification is passed, a device conflict detection is performed using the device identifier; after the device conflict detection is passed, a binding relationship between the device identifier and the physical address is recorded, and after a preset silence period, a second message packet is unicast sent using the target security entity with the recorded physical address as a destination address to respond to the first message packet.

[0081] The beneficial technical effects of the present application are: in the network at the link layer, the sending end of the link layer encryption device announces the whole network through broadcasting, ensuring that all receiving ends can receive the message, and realizing mutual discovery of the link layer encryption devices. The first message packet of the broadcast contains the local device identifier and physical address of the sending end, and compared with the LLDP link device discovery, the information content carried is simpler and more suitable for the link layer encryption device. Moreover, compared with the LLDP link device discovery, the authentication function is added, and the authentication mode based on the digital certificate can not only ensure that the access link encryption device is a legal device, but also is convenient for management when the network scale is relatively large, and the security will be more advantageous. It can be seen that through the way of bidirectional interactive messages, not only the mutual discovery of the link layer encryption devices is realized, but also the mutual authentication between the link encryption devices is realized, ensuring the legal access of the link layer encryption devices.

[0082] Based on the foregoing embodiments, in a specific implementation, the design principle of the sequence number is according to the requirements of “GBT 15843.3-2023 Information Technology ▪ Security Technology ▪ Entity Authentication Part 3: Mechanism Using Digital Signature Technology”. In this embodiment, one-way authentication of one-time transmission can be realized, and a time-varying parameter (timestamp or sequence number) can be generally used in the first message packet and the second message packet. In order to reduce the overhead of time synchronization between the link encryption devices, the method mentioned in the present application adopts the sequence number instead of the timestamp mode. In order to realize that the sequence number is not permanently saved and also supports the restart of the device, the sequence number is further designed.

[0083] Specifically, the message sequence number is an 8-byte unsigned integer, and the high 4 bytes of the message sequence number store the system date and time when the first message packet is sent, and the low 4 bytes of the message sequence number store the total number of the first message packet and the second message packet sent by the target security entity.

[0084] In the embodiment of the present application, the high 4 bytes of the sequence number are the system date and time when the message is sent, accurate to seconds; and the low 4 bytes of the sequence number are the total number of the first message packet and the second message packet sent after SecY starts. Further, the legality of the message sequence number in the first message packet is judged, specifically including the following steps:

[0085] determining whether the message sequence number is monotonically increasing;

[0086] when the message sequence number is monotonically increasing, determining that the message sequence number is legal;

[0087] when the message sequence number is flat or decreasing, determining that the message sequence number is not legal, and discarding the first message packet.

[0088] The message receiver understands the high 4 bytes as an unsigned integer, not as time, and does not synchronize with the local time, that is, the high 4 bytes can only increase or remain unchanged, but cannot decrease. When the high 4 bytes remain unchanged, the low 4 bytes can only increase (a second message packet is sent within 1 second after the first message packet). When the high 4 bytes increase, the low 4 bytes can be reset to 1 (SecY is restarted). In summary, the sequence number is always strictly monotonically increasing as an 8-byte unsigned integer, and remaining unchanged or decreasing is determined as an illegal sequence number.

[0089] When the device is restarted, the system real-time clock continues to run, ensuring the monotonicity of the high 4 bytes. The system factory default time is generally behind the accurate time, and the sequence number can work normally even if the system time is not set by the configuration administrator. When the system administrator sets the correct system time, the sequence number can also work normally. Only when the system time is reversed, for example, the administrator newly sets the time greatly behind the original system time, can the high 4 bytes be reversed. At this time, there are two solutions: modifying the LSID of the device with the time error, or restarting the SecY of all other link encryption devices to clear the record of the message sequence number of the device.

[0090] Specifically, when the high 4 bytes of the message sequence number are reversed due to the modification of the system time, the device identifier of the target link layer encryption device with the time error is modified, or other link layer encryption devices outside the target link layer encryption device are restarted to clear the record of the device identifier of the target link layer encryption device. The low 4 bytes of the sequence number are used to distinguish messages sent to different devices within 1 second, so that each message has a different sequence number in any case, avoiding message replaying and impersonation between different devices.

[0091] Based on the foregoing embodiment, when the receiving end link layer encryption device responds to the first message packet, if two or more sending end link layer encryption devices in the network send the first message packet almost simultaneously, and the responder immediately sends the second message packet, it can cause two repeated authentications to be started between the two link layer encryption devices. In order to solve the phenomenon of repeated authentication, the method can further include the following steps:

[0092] When there are at least two sending ends in the link layer network that send the first message packet simultaneously, the first message packet is authenticated based on a preset authentication rule to generate the second message packet; wherein the preset authentication rule is used to avoid starting multiple repeated authentications between devices.

[0093] The design of the preset authentication rule in the embodiment of the application follows the following two principles, and specifically includes the following steps:

[0094] determining whether the sending end has sent the first message packet within a time before the lower limit of the preset silence period;

[0095] if the sending end has not sent the first message packet within a time before the lower limit of the preset silence period, triggering the step of unicasting a second message packet after the preset silence period using the target security entity with the recorded physical address as the destination address in response to the first message packet;

[0096] if the sending end has sent the first message packet within a time before the lower limit of the preset silence period, determining the size between the own device identifier of the receiving end and the device identifier in the first message packet;

[0097] when the own device identifier of the receiving end is smaller than the device identifier in the first message packet, triggering the step of unicasting a second message packet after the preset silence period using the target security entity with the recorded physical address as the destination address in response to the first message packet;

[0098] when the own device identifier of the receiving end is not smaller than the device identifier in the first message packet, then not responding to the first message packet.

[0099] That is, (1) if the device itself has not sent the first message packet within a time before the lower limit of the silence period (<2000 milliseconds), there is no possibility of message interleaving, and the device directly processes according to the normal process, that is, after the received first message packet is authenticated, a second message packet is sent after a silence period;

[0100] (2) if the device itself has sent the first message packet within a time before the lower limit of the silence period, first compare the size of the own LSID and the LSID in the first message packet sent by the opposite end, only when the own LSID is smaller than the LSID of the opposite end, process according to the normal process, otherwise ignore the received first message packet; (that is, the LSID is small as the responder).

[0101] Based on the foregoing embodiment, the present embodiment describes the whole process of mutual discovery and mutual authentication between Ethernet link layer encryption devices:

[0102] (1) First, the sender sends the first message (referred to as message ①) in a broadcast manner, wherein the message ① contains MAC address (source MAC address specifically refers to bridge MAC address), sequence number, sender SecY LSID, sender signature certificate, encryption certificate and other information;

[0103] (2) The SecY in the sender's link layer encryption device signs the serial number and LSID and other key information with its own signature private key, and broadcasts the signature result together with the message 1 to the network;

[0104] (3) All the link layer encryption devices in the network judge the legality of the serial number when receiving the message 1, and if the serial number is illegal, the message is discarded without response. If the serial number is legal, signature certificate verification and digital signature verification are performed, and the LSID of the sender of the message 1 and the latest serial number in the message 1 are recorded to facilitate the legality verification of the serial number of the received message in the future;

[0105] (4) Then, the LSID in the message is checked for conflict with the LSID of the device itself. If there is a conflict, an error notification message is immediately broadcast to notify all other link encryption devices SecY (including the SecY of the link encryption device sending the message 1) of the conflicting LSID and MAC address to facilitate the prompt of the user to configure the error. If the LSIDs are not in conflict, the binding relationship between the LSID and the MAC address is recorded, and then a second message (referred to as message 2) is unicast sent with the MAC address recorded as the destination address after a silent period (sleeping for a random time in the range of 2000-2500 milliseconds), to continue the authentication and subsequent processes.

[0106] (5) In order to unify the authentication mode of both parties, the same way as in the message 1 is adopted in the message 2 to realize the authentication of the sender of the message 2. The message 2 includes the two certificates (signature certificate and encryption certificate) of the responder and the serial number, LSID, MAC address (source MAC address), signature and other information required for authenticating the responder, and the message 2 is a unicast packet for response.

[0107] It can be seen that the present application is no longer a one-way transmission of information and a broadcast mode to notify all the link layer encryption devices in the network. The notification information includes the ID and digital certificate of the local link encryption device SecY and other information. The receiving end of the link encryption device responds to the information notified by the sending end in a unicast manner, and includes the ID and digital certificate of the receiving end of the link encryption device SecY and other information. Through this two-way interactive message mode, not only the mutual discovery of the link layer encryption devices is realized, but also the mutual authentication between the link encryption devices is realized, and the legal access of the link layer encryption device is ensured.

[0108] Correspondingly, the application also discloses a link layer encryption device discovery device, which is applied to the receiving end of the link layer encryption device, and refers to Figure 4 as shown, the device comprises:

[0109] The device discovery module 11 is configured to acquire a first message packet broadcast by a sending end of a link layer encryption device using a target security entity; the first message packet comprises a device identifier, a physical address, a message sequence number, a signature certificate, an encryption certificate, and a signature result generated by a signature private key based on a digital certificate authentication method of the sending end;

[0110] The authentication module 12 is configured to, after the receiving end of the link layer encryption device receives the first message packet under the physical local area network or the virtual local area network, verify the legality of the first message packet, and perform device conflict detection using the device identifier after the legality verification is passed;

[0111] The response module 13 is configured to, after the device conflict detection is passed, record a binding relationship between the device identifier and the physical address, and after a preset silence period, unicast a second message packet using the target security entity and taking the recorded physical address as a destination address to respond to the first message packet.

[0112] The more specific working processes of the above modules can refer to the corresponding contents disclosed in the foregoing embodiments, and will not be described here.

[0113] It can be seen that, by the above scheme of the embodiment, the sending end of the link layer encryption device acquires a first message packet broadcast using a target security entity; the first message packet comprises a device identifier, a physical address, a message sequence number, a signature certificate, an encryption certificate, and a signature result generated by a signature private key based on a digital certificate authentication method of the sending end; after the receiving end of the link layer encryption device receives the first message packet under the physical local area network or the virtual local area network, the legality of the first message packet is verified, and device conflict detection is performed using the device identifier after the legality verification is passed; after the device conflict detection is passed, a binding relationship between the device identifier and the physical address is recorded, and after a preset silence period, a second message packet is unicast using the target security entity and taking the recorded physical address as a destination address to respond to the first message packet.

[0114] The beneficial technical effects of the present application are: in the network of the link layer, the sending end of the link layer encryption device announces the whole network through broadcasting, ensures that all receiving ends can receive the message, and realizes mutual discovery of the link layer encryption device. The first message packet of the broadcast contains the local device identifier and physical address of the sending end, and compared with the LLDP link device discovery, the information content carried is simpler and more suitable for the link layer encryption device. Compared with the LLDP link device discovery, the authentication function is increased, the authentication mode based on the digital certificate can not only ensure that the link encryption device accessed is a legal device, but also is convenient for management when the network scale is relatively large, and the security is more advantageous. It can be seen that through the way of the bidirectional interactive message, not only the mutual discovery of the link layer encryption device is realized, but also the mutual authentication between the link encryption devices is realized, and the legal access of the link layer encryption device is ensured.

[0115] Further, the embodiment of the present application further discloses an electronic device, Figure 5 is an electronic device 20 structure diagram shown according to an exemplary embodiment, the contents in the figure cannot be considered as any limitation on the use range of the present application.

[0116] Figure 5 The structure of the electronic device 20 provided by the embodiment of the present application is shown. The electronic device 20 can specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25 and a communication bus 26. The memory 22 is used to store a computer program, the computer program is loaded and executed by the processor 21, to realize the related steps in the discovery method of the link layer encryption device disclosed in any of the preceding embodiments.

[0117] In the embodiment, the power supply 23 is used to provide working voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and the external device, and the communication protocol followed by the communication interface 24 can be any communication protocol applicable to the technical solution of the present application, which is not limited here; the input / output interface 25 is used to obtain external input data or output data to the outside, and the specific interface type can be selected according to the specific application needs, which is not limited here.

[0118] In addition, the memory 22 as a resource storage carrier can be a read-only memory, a random access memory, a magnetic disk or an optical disk, etc., and the resources stored thereon can include an operating system 221, a computer program 222 and data 223, etc., and the data 223 can include various data. The storage mode can be temporary storage or permanent storage.

[0119] The operating system 221 is configured to manage and control each hardware device on the electronic device 20 and the computer program 222, which can be Windows Server, Netware, Unix, Linux, etc. The computer program 222 can further include computer programs capable of performing other specific tasks in addition to the computer program capable of performing the link layer encryption device discovery method disclosed by the electronic device 20 in any of the foregoing embodiments.

[0120] Further, the embodiments of the present application further disclose a computer readable storage medium, which includes random access memory (RAM), memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, register, hard disk, magnetic disk or optical disk, or any other form of storage medium known in the technical field. The computer program is executed by the processor to implement the foregoing link layer encryption device discovery method. The specific steps of the method can refer to the corresponding content disclosed in the foregoing embodiments, and will not be described here.

[0121] The embodiments in the specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts of each embodiment can be referred to each other. For the device disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple, and the relevant parts can refer to the method part.

[0122] The steps of the link layer encryption device discovery method or algorithm described in combination with the embodiments disclosed herein can be directly implemented by hardware, software module executed by the processor, or combination of the two. The software module can be placed in random access memory (RAM), memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, register, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the technical field.

[0123] Finally, it needs to be pointed out that in this article, the relationship terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between the entities or operations. Moreover, the term "includes", "contains" or any other variant thereof is intended to cover non-exclusive inclusion, so that the process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or device. Without more limitations, the element defined by the statement "includes a" does not exclude the presence of other identical elements in the process, method, article or device including the element.

[0124] The above describes in detail the discovery method, device, equipment and medium of the link layer encryption device provided by the present application. The principles and implementation manners of the present application are described by applying specific examples in this article. The above description of the embodiments is only used to help understand the method of the present application and its core idea. Meanwhile, for those skilled in the art, according to the idea of the present application, the specific implementation manners and application ranges will be changed. In view of the above, the content of the specification should not be understood as a limitation of the present application.

Claims

1. A method for discovering a link-layer encryption device, characterized in that, include: Obtain the first message broadcast by the sender of the link-layer encryption device using the target security entity; The first message includes the device identifier, physical address, message sequence number, signature certificate, encryption certificate, and signature result generated by the signature private key based on the digital certificate authentication method; When the receiving end of the link layer encryption device receives the first message packet under its physical local area network or virtual local area network, it performs a legality verification on the first message packet, and after the legality verification is passed, it uses the device identifier to perform device conflict detection. Once the device conflict detection passes, the binding relationship between the device identifier and the physical address is recorded. After a preset quiet period, the target security entity unicasts a second message message with the recorded physical address as the destination address to respond to the first message message.

2. The method for discovering link-layer encryption devices according to claim 1, characterized in that, Also includes: The target security entity uses the sending end's signature private key to sign the device identifier and message sequence number in the first message message to generate a corresponding signature result, and then appends the signature result to the first message message. Accordingly, the legality verification of the first message message includes: The validity of the message sequence number in the first message message is determined, and after determining that the message sequence number is valid, the signature certificate is verified. If the signature certificate is verified, the signature result is verified using the public key in the signature certificate, and after the signature verification is successful, the device identifier and message sequence number of the sending end are recorded.

3. The method for discovering link-layer encryption devices according to claim 2, characterized in that, The message sequence number is an 8-byte unsigned integer, and the high 4 bytes of the message sequence number store the system date and time when the first message packet was sent, and the low 4 bytes of the message sequence number store the total number of the first message packet and the second message packet sent by the target security entity; correspondingly, the determination of the validity of the message sequence number in the first message packet includes: Determine whether the message sequence number is monotonically increasing; When the message sequence number monotonically increases, the message sequence number is determined to be valid; When the message sequence number remains unchanged or decreases, the message sequence number is determined to be invalid, and the first message packet is discarded.

4. The method for discovering link-layer encryption devices according to claim 3, characterized in that, Also includes: When the high 4 bytes of the message sequence number are rolled back due to system time modification, the device identifier of the target link layer encryption device with the time error is modified, or other link layer encryption devices other than the target link layer encryption device are restarted to clear the record of the device identifier of the target link layer encryption device.

5. The method for discovering link-layer encryption devices according to claim 1, characterized in that, The step of using the device identifier to perform device conflict detection after the legality verification is passed includes: After the legality verification is passed, it is determined whether the device identifier in the first message message conflicts with the device identifier of the receiving end. If the device identifier in the first message message conflicts with the receiver's own device identifier, an error notification message is broadcast to other link layer encryption devices in the link layer network other than the receiver to notify the sender of the device identifier and physical address. If the device identifier in the first message does not conflict with the receiver's own device identifier, the device conflict detection is deemed successful, and the step of recording the binding relationship between the device identifier and the physical address is triggered.

6. The method for discovering a link-layer encryption device according to any one of claims 1 to 5, characterized in that, Also includes: When at least two senders simultaneously transmit the first message packet within the link layer network, the first message packet is authenticated based on a preset authentication rule to generate the second message packet; wherein, the preset authentication rule is used to avoid multiple duplicate authentications between devices.

7. The method for discovering link-layer encryption devices according to claim 6, characterized in that, The step of authenticating the first message message based on preset authentication rules to generate the second message message includes: Determine whether the sending end has sent the first message packet within the time limit before the preset silence period; If the sending end has not sent the first message packet within the time limit before the preset silence period, the step of unicasting the second message packet with the recorded physical address as the destination address after the preset silence period is triggered to respond to the first message packet. If the sending end has already sent the first message packet within the time limit before the preset silence period, then determine the size between the receiving end's own device identifier and the device identifier in the first message packet; When the device identifier of the receiving end is less than the device identifier in the first message packet, the step of unicasting the second message packet with the recorded physical address as the destination address after a preset silence period is triggered to respond to the first message packet. If the receiver's own device identifier is not less than the device identifier in the first message message, then it will not respond to the first message message.

8. A device for discovering link-layer encryption devices, characterized in that, include: The device discovery module is used to obtain the first message packet broadcast by the sender of the link layer encryption device using the target security entity; The first message includes the device identifier, physical address, message sequence number, signature certificate, encryption certificate, and signature result generated by the signature private key based on the digital certificate authentication method; The authentication module is used to verify the legitimacy of the first message message when the receiving end of the link layer encryption device receives the first message message in its physical local area network or virtual local area network, and to perform device conflict detection using the device identifier after the legitimacy verification is passed. The response module is used to record the binding relationship between the device identifier and the physical address after the device conflict detection passes, and after a preset silence period, use the target security entity to unicast a second message message with the recorded physical address as the destination address to respond to the first message message.

9. An electronic device, characterized in that, The electronic device includes a processor and a memory; wherein the memory is used to store a computer program, which is loaded and executed by the processor to implement the method for discovering a link layer encryption device as described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, Used to store a computer program; wherein the computer program, when executed by a processor, implements the discovery method of the link layer encryption device as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Method, system and node equipment for detecting link layer address collision

    CN101414892A

  • Secure neighbor discovery between hosts connected through a proxy

    CN101843075A