Routing path verification system, method and equipment and storage medium

By adding routing device attribute information to BGP messages and using a remote verification center for verification, the problem of users not knowing the transmission path is solved, achieving security verification and cost savings.

CN121333766APending Publication Date: 2026-01-13CHINA UNITED NETWORK COMM GRP CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511689426.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-18
Publication Date
2026-01-13

AI Technical Summary

Technical Problem

In the secure routing framework of remote authentication, users cannot know the customer's data transmission path, which poses a risk of data leakage. Furthermore, existing digital signature methods are complex to deploy and have high computational overhead, increasing the cost of routing path verification.

Method used

By selecting the target routing path through the secure routing center, adding routing device attribute information to the BGP message, and using a remote verification center for trusted verification, the routing path verification result is obtained, the security of the transmission path is determined, and router upgrades are avoided.

Benefits of technology

It enables security verification of routing paths, reduces verification costs, improves the reliability of verification results, and eliminates the need to upgrade routers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121333766A_ABST
    Figure CN121333766A_ABST
Patent Text Reader

Abstract

The invention provides a routing path verification system, method and device and a storage medium, relates to the technical field of communication, and is used for verifying a data transmission path and reducing verification cost. A remote attestation center in a routing path verification system of the method comprises the following steps: receiving a BGP (Border Gateway Protocol) message which is sent by a data center and added with attribute information; performing credibility verification on the attribute information of the plurality of routing devices carried in the BGP message, and transmitting credibility verification results of the plurality of routing devices to a secure routing center through a data center, so that the secure routing center obtains a routing path verification result based on the credibility verification results of the plurality of routing devices and the target routing path; the routing path verification result is used for indicating whether the transmission path of the BGP message is the target routing path or not.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of communication, and particularly relates to a routing path verification system and method, equipment and a storage medium. BACKGROUND

[0002] At present, in a Network Attestation for Secure Routing (NASR) framework based on remote attestation, a user does not know a transmission path of customer data in a transmission process, and a security risk of data leakage may exist, which will bring certain risks to the user. In the related technology, a digital signature is used to protect integrity and origin authentication of the customer data in a routing path transmission process, but this way is complex to deploy, has large signature and signature verification calculation overhead, and requires upgrading of a routing device to support, which will increase verification cost of the routing path. SUMMARY

[0003] The present application provides a routing path verification system, method, equipment and storage medium, which are used for verifying a transmission path of data and reducing verification cost.

[0004] In a first aspect, the present application provides a routing path verification system, which comprises a secure routing center, an autonomous system, a data center and a remote attestation center; the secure routing center is connected with the data center through the autonomous system, and the data center is connected with the remote attestation center; the secure routing center is used for selecting a target routing path in the autonomous system according to a user demand, so as to transmit a BGP message to the data center through the target routing path; the target routing path is composed of a plurality of routing devices, when the BGP message passes through each routing device on the target routing path, the routing device adds attribute information of the routing device in the BGP message, to obtain a BGP message with added attribute information; the data center is used for transmitting the BGP message with added attribute information to the remote attestation center; the remote attestation center is used for performing trusted verification on the attribute information of the plurality of routing devices carried in the BGP message, and transmitting trusted verification results of the plurality of routing devices to the secure routing center through the data center; the secure routing center is further used for obtaining a routing path verification result according to the trusted verification results of the plurality of routing devices and the target routing path; and the routing path verification result is used for indicating whether a transmission path of the BGP message is the target routing path.

[0005] The technical scheme provided by the application has at least the following beneficial effects: the remote certification center performs trusted verification on attribute information of a plurality of routing devices carried in a BGP message, and transmits verification results of the plurality of routing devices to a secure routing center through a data center, the secure routing center obtains routing verification results according to the trusted verification results of the plurality of routing devices and a target routing path, the routing verification results indicate whether a transmission path of the BGP message is the target routing path, attribute information of a routing identifier is added in the BGP message, the trusted verification of the routing device is realized through the remote certification center, the verification of the target routing path is realized, and therefore the security of the BGP message in the transmission process is determined, and the verification of the routing path can be realized without upgrading the router, and the verification cost can be saved.

[0006] In a possible implementation, the attribute information of the routing device includes: an AS number corresponding to the routing device, a trusted credential of the routing device, and a current timestamp.

[0007] In a second aspect, the application provides a routing path verification method, applied to a remote certification center in the routing path verification system of the first aspect, and the method includes: receiving a BGP message with added attribute information sent by a data center; wherein the BGP message with added attribute information is sent by a secure routing center to the data center through a target routing path of an autonomous system; the target routing path is composed of a plurality of routing devices, and the BGP message with added attribute information is obtained by adding attribute information of each routing device on the target routing path; trusted verification is performed on attribute information of a plurality of routing devices carried in the BGP message, and trusted verification results of the plurality of routing devices are transmitted to the secure routing center through the data center, so that the secure routing center obtains routing path verification results based on the trusted verification results of the plurality of routing devices and the target routing path; wherein the routing path verification results are used to indicate whether a transmission path of the BGP message is the target routing path.

[0008] The technical scheme provided by the application has at least the following beneficial effects: the remote certification center performs trusted verification on attribute information of a plurality of routing devices carried in a BGP message, and transmits verification results of the plurality of routing devices to a secure routing center through a data center, the secure routing center obtains routing verification results according to the trusted verification results of the plurality of routing devices and a target routing path, the routing verification results indicate whether a transmission path of the BGP message is the target routing path, attribute information of a routing identifier is added in the BGP message, the trusted verification of the routing device is realized through the remote certification center, the verification of the target routing path is realized, and therefore the security of the BGP message in the transmission process is determined, and the verification of the routing path can be realized without upgrading the router, and the verification cost can be saved.

[0009] In a possible implementation, the attribute information of the routing device includes: an AS number corresponding to the routing device, a trusted credential of the routing device, and a current timestamp.

[0010] In another possible implementation, the trusted verification of the attribute information of each routing device carried in the BGP packet includes: obtaining a trusted verification result and a verification timestamp of the routing device pre-stored in the remote attestation center according to the AS number of the routing device; and performing trusted verification according to the trusted credential of the routing device, the current timestamp, the trusted verification result corresponding to the routing device, and the verification timestamp.

[0011] In another possible implementation, each routing device includes at least one trusted verification result, and the trusted verification according to the trusted credential of the routing device, the current timestamp, the trusted verification result corresponding to the routing device, and the verification timestamp includes: determining that the routing device passes the trusted verification when the current timestamp is later than the verification timestamp and the trusted credential of the routing device matches any trusted verification result corresponding to the routing device; or determining that the routing device does not pass the trusted verification when the current timestamp is later than the verification timestamp and the trusted credential of the routing device does not match all trusted verification results corresponding to the routing device.

[0012] In another possible implementation, each routing device includes at least one trusted verification result, and the trusted verification according to the trusted credential of the routing device, the current timestamp, the trusted verification result corresponding to the routing device, and the verification timestamp includes: determining that the routing device passes the trusted verification when the current timestamp is earlier than or equal to the verification timestamp and the trusted credential of the routing device matches the latest trusted verification result corresponding to the routing device; or determining that the routing device does not pass the trusted verification when the current timestamp is earlier than or equal to the verification timestamp and the trusted credential of the routing device does not match the latest trusted verification result corresponding to the routing device.

[0013] In a third aspect, the application provides a route path verification method applied to a secure routing center in the route path verification system of the first aspect, the method comprising: selecting a target route path in an autonomous system according to user demand to transmit a BGP message to a data center through the target route path; wherein the target route path is composed of a plurality of routing devices, and when the BGP message passes through each routing device on the target route path, the BGP message is added with attribute information of the routing device by the routing device; receiving a trusted verification result of the plurality of routing devices transmitted by the data center from the remote attestation center; the trusted verification result of the plurality of routing devices is obtained by the remote attestation center performing trusted verification on attribute information of each routing device carried in the BGP message; and obtaining a route path verification result according to the trusted verification result of the plurality of routing devices and the target route path.

[0014] The technical scheme provided by the application at least brings the following beneficial effects: the secure routing center selects a target route path in an autonomous system according to user demand to provide the user with the selectivity of a safe degree, and determines the transmission path of the BGP message according to the trusted verification result of the plurality of routing devices and the target route path, so that the user knows whether the target transmission path is trusted, and the user experience is improved.

[0015] In a fourth aspect, the application provides a route path verification method applied to an autonomous system in the route path verification system of the first aspect, the method comprising: receiving a BGP message sent by a secure routing center; transmitting the GSP message based on a target route path in the autonomous system; wherein the target route path is selected by the secure routing center according to user demand; the target route path is composed of a plurality of routing devices, and when the BGP message passes through each routing device on the target route path, the routing device adds attribute information of the routing device in the BGP message to obtain a BGP message with added attribute information; the attribute information of the plurality of routing devices carried in the BGP message is used for trusted verification of the routing devices to obtain a trusted verification result of the routing devices; the trusted verification result of the routing devices is used for route path verification to obtain a route path verification result; and the BGP message with added attribute information is transmitted to a data center to make the data center send the BGP message with added attribute information to a remote attestation center for trusted verification.

[0016] The technical solution provided in this application brings at least the following benefits: BGP packets are transmitted to the data center through the target routing path, and during the transmission of the target path, the attribute information of the routing devices traversed by the routing devices is added to the BGP packets using the attribute information of the BGP packets, so as to perform trusted verification of the attribute information of the routing devices. Thus, based on the trusted verification results of multiple routing devices and the target routing path, it is determined whether the transmission of the BGP packets is the target routing path, without the need to upgrade the router, which can save verification costs.

[0017] One possible implementation is that adding the routing device's attribute information to the BGP message includes adding the routing device's attribute information to the global administrator field and the local data field of the BGP message.

[0018] Fifthly, this application provides an electronic device comprising: a processor and a memory; the memory storing processor-executable instructions; when the processor is configured to execute the instructions, causing the electronic device to implement the methods of the second to fourth aspects described above.

[0019] In a sixth aspect, this application provides a computer-readable storage medium comprising: computer software instructions; which, when executed in an electronic device, cause the electronic device to implement the methods described in the second to fourth aspects.

[0020] In a seventh aspect, this application provides a computer program product comprising a computer program; when the computer program is run in an electronic device, the electronic device causes the electronic device to implement the methods described in the second to fourth aspects.

[0021] The beneficial effects of aspects five through seven mentioned above are described in the corresponding descriptions of aspects two through four, and will not be repeated here. Attached Figure Description

[0022] Figure 1 This paper shows a structural diagram of a routing path verification system provided in an embodiment of this application; Figure 2 A flowchart of a routing path verification method provided in an embodiment of this application is shown; Figure 3 A flowchart illustrating another method for verifying a routing path provided in an embodiment of this application is shown; Figure 4 A flowchart illustrating another method for verifying a routing path provided in an embodiment of this application is shown; Figure 5 A flowchart illustrating another method for verifying a routing path provided in an embodiment of this application is shown; Figure 6This illustration shows a structural diagram of a BGP message provided in an embodiment of this application; Figure 7 This paper illustrates an interaction process between a routing device and a remote verification center, as provided in an embodiment of this application. Figure 8 This illustration shows a schematic diagram of customer data being routed to a data center via a NASR trusted routing path, as provided in an embodiment of this application. Figure 9 This illustration shows a schematic diagram of adding the Community attribute to a BGP UPDATE message hop-by-hop according to an embodiment of this application; Figure 10 A schematic diagram of the structure of an electronic device provided in an embodiment of this application is shown. Detailed Implementation

[0023] The following is a detailed description of a routing path verification system, method, device, and storage medium provided in this application, with reference to the accompanying drawings.

[0024] In this article, the term "and / or" is merely a description of the relationship between related objects, indicating that there can be three relationships. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone.

[0025] The terms "first" and "second," etc., used in the specification and drawings of this application are used to distinguish different objects or to distinguish different treatments of the same object, rather than to describe a specific order of objects.

[0026] Furthermore, the terms "comprising" and "having," and any variations thereof, used in the description of this application are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the steps or units listed, but may optionally include other steps or units not listed, or may optionally include other steps or units inherent to such process, method, product, or apparatus.

[0027] It should be noted that in the embodiments of this application, the words "exemplary" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design scheme described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design schemes. Specifically, the use of the words "exemplary" or "for example" is intended to present the relevant concepts in a specific manner.

[0028] To facilitate a clear description of the technical solutions of the embodiments of this application, the terms "first" and "second" are used in the embodiments of this application to distinguish the same or similar items with essentially the same function and effect. Those skilled in the art can understand that the terms "first" and "second" are not intended to limit the quantity or execution order.

[0029] In the description of this application, unless otherwise stated, "a plurality of" means two or more.

[0030] Currently, in Network Attestation for Secure Routing (NASR) frameworks, users are unaware of the data transmission path during transmission, potentially posing a data leakage risk. Related technologies employ digital signatures to protect the integrity and origin authentication of customer data during routing path transmission; however, this approach is complex to deploy, incurs significant signing and verification computational overhead, and requires upgrades to routing devices, increasing the verification cost of the routing path.

[0031] To address the aforementioned technical problems, this application provides a routing path verification system, method, device, and storage medium. The core idea is that a secure routing center selects an Autonomous System (AS) based on user needs. In a System (AS), the target routing path transmits BGP packets to the data center. As the BGP packet passes through each routing device on the target routing path, the routing device adds its attribute information to the BGP packet, resulting in a BGP packet with added attribute information. The data center then sends this attribute-enhanced BGP packet to a remote verification center. The remote verification center performs trusted verification on the attribute information of multiple routing devices carried in the BGP packet and transmits the verification results to a secure routing center through the data center. The secure routing center obtains a routing verification result based on the trusted verification results of multiple routing devices and the target routing path. The routing verification result indicates whether the transmission path of the BGP packet is the target routing path. By adding routing device attribute information to the BGP packet and verifying the trustworthiness of the routing devices through the remote verification center, the security of the BGP packet during transmission is verified. This method achieves routing path verification without requiring router upgrades, saving verification costs.

[0032] The embodiments provided in this application will now be described in detail with reference to the accompanying drawings. Figure 1 A structural diagram of a routing path verification system provided in an embodiment of this application is shown below. Please refer to [link / reference]. Figure 1As shown, the verification system includes: a secure routing center 100, an autonomous system 200, a data center 300, and a remote verification center 400; the secure routing center 100 is connected to the data center 300 through the autonomous system 200, and the data center 300 is connected to the remote verification center 400.

[0033] The secure routing center 100 is used to select the target routing path in the autonomous system 200 according to user needs, so as to transmit BGP messages to the data center 300 through the target routing path.

[0034] The target routing path consists of multiple routing devices. When a BGP message passes through each routing device on the target routing path, the routing device adds its attribute information to the BGP message, resulting in a BGP message with the added attribute information.

[0035] Data center 300 is used to send BGP messages with added attribute information to remote certification center 400.

[0036] The remote verification center 400 is used to perform trusted verification of the attribute information of multiple routing devices carried in BGP messages, and transmits the trusted verification results of multiple routing devices to the secure routing center 100 through the data center 300.

[0037] The secure routing center 100 is also used to obtain routing path verification results based on the trusted verification results of multiple routing devices and the target routing path; the routing path verification results are used to indicate whether the transmission path of the BGP message is the target routing path.

[0038] In some embodiments, the attribute information of the routing device includes: the AS number corresponding to the routing device, the trusted credential of the routing device, and the current timestamp.

[0039] It should be noted that the system architecture described in the embodiments of this application is for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and does not constitute a limitation on the technical solutions provided in the embodiments of this application. As those skilled in the art will know, with the evolution of system architecture, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.

[0040] Figure 2 A flowchart illustrating a routing path verification method provided in an embodiment of this application is shown. Please refer to [link / reference]. Figure 2 As shown, this embodiment provides a method for verifying a routing path, which is applied to the remote verification center in the above-mentioned routing verification system. Specifically, it includes the following steps S110~S120, which are described in detail below.

[0041] S110. Receive the BGP message with added attribute information sent by the data center; wherein, the BGP message with added attribute information is sent by the security routing center to the data center through the target routing path of the autonomous system; the target routing path consists of multiple routing devices, and the BGP message with added attribute information is obtained by adding the attribute information of each routing device on the target routing path.

[0042] For example, the secure routing center is the sender of the BGP message, the autonomous system is the transmission path of the BGP message, the data center is the receiver of the BGP message, and the remote verification center (RATS) is the verification end of the routing devices in the transmission path of the BGP message. The remote verification center, as a third-party verification end, verifies the trustworthiness of the routing devices in the transmission path of the BGP message, thereby improving the trustworthiness of the trusted verification results.

[0043] For example, an autonomous system may include multiple routing devices and may form multiple different destination routing paths.

[0044] For example, multiple destination routing paths include: high-security path, medium-security path, and low-security path. Users can select the corresponding level of destination routing path based on the confidentiality level of the information conveyed in the BGP message.

[0045] For example, a Border Gateway Protocol (BGP) message, specifically a BGPUPDATE message, is a routing protocol used to exchange network layer reachability information in an autonomous system.

[0046] For example, the attribute information of a routing device can be information that proves that a BGP packet has passed through the routing device. When a BGP packet passes through a routing device, the attribute information of the routing device is added to the BGP packet.

[0047] In some embodiments, each time a BGP message passes through a routing device, the attribute information corresponding to that routing device is added to the BGP message, so that the remote verification center can receive the BGP message with added attribute information sent by the data center to verify the trustworthiness of the router.

[0048] S120. Perform trusted verification on the attribute information of multiple routing devices carried in the BGP message, and transmit the trusted verification results of multiple routing devices to the secure routing center through the data center, so that the secure routing center can obtain the routing path verification result based on the trusted verification results of multiple routing devices and the target routing path; wherein, the routing path verification result is used to indicate whether the transmission path of the BGP message is the target routing path.

[0049] In some embodiments, by performing trusted verification on the attribute information of each routing device in the BGP message, the trustworthiness of the routing device that the BGP message passes through during transmission is determined, thereby determining whether the BGP message passes through the routing device. The trusted verification results of multiple routing devices are then transmitted through the data center to the secure routing center to determine whether the routing path transmitted by the BGP message is the target routing path. Transmitting the trusted verification results of multiple routing devices through the data center to the secure routing center allows the data center to obtain the trusted verification results of multiple routing devices, thereby increasing the trustworthiness of the trusted verification results of multiple routing devices received by the secure routing center.

[0050] In some embodiments, the attribute information of the routing device includes: the AS number corresponding to the routing device, the trusted credential of the routing device, and the current timestamp.

[0051] For example, the AS number corresponding to the routing device can be a number that identifies the routing device, the trusted credential of the routing device is a hash value calculated by the routing device based on the remote authentication result, and the current timestamp is the time when the BGP packet passed through the routing device.

[0052] Figure 3 A flowchart illustrating another routing path verification method provided in an embodiment of this application is shown. Please refer to [link / reference]. Figure 3 As shown in the figure, this embodiment provides a method for verifying a routing path, which is applied to the remote verification center in the above-mentioned routing verification system. It performs trusted verification on the attribute information of each routing device carried in the BGP message. Specifically, it includes the following steps S210~S220, which are described in detail below.

[0053] S210. Obtain the trusted verification result and verification timestamp pre-stored in the remote verification center by the routing device according to the AS number of the routing device.

[0054] In some embodiments, after receiving a trusted verification result, the routing device sends the trusted verification result to a remote verification center, so that the remote verification center can verify the routing device's trusted credentials based on the trusted verification result. The remote verification center records the receipt time of the trusted verification result as a verification timestamp.

[0055] For example, the trusted verification result is the hash value calculated by the routing device based on the remote verification result.

[0056] S220. Perform trusted verification based on the trusted credentials of the routing device, the current timestamp, the trusted verification result of the routing device, and the verification timestamp.

[0057] In some embodiments, each routing device includes at least one trusted verification result; trusted verification is performed based on the routing device's trusted credentials, the current timestamp, the trusted verification result corresponding to the routing device, and the verification timestamp, including: If the current timestamp is later than the verification timestamp, and the trusted credentials of the routing device match any trusted verification result corresponding to the routing device, then the routing device is determined to have passed trusted verification. Alternatively, if the current timestamp is later than the verification timestamp, and the trusted credentials of the routing device do not match any of the trusted verification results corresponding to the routing device, then the routing device is determined to have failed trusted verification.

[0058] For example, the trusted verification results stored in the remote verification center may be updated. For instance, the security level of the routing device may change from medium security level to high security level, and the hash value corresponding to the trusted verification result will change. If the current timestamp is later than the verification timestamp, it means that the trusted verification results stored in the remote verification center have not been updated. If the trusted credential of the routing device matches any trusted verification result of the routing device, that is, if the hash value of the trusted credential is the same as the hash value corresponding to any trusted verification result, it means that the BGP message has passed through the routing device, and it is determined that the routing device has passed trusted verification.

[0059] For example, if the current timestamp is later than the verification timestamp, and the trusted credentials of the routing device do not match each trusted verification result of the routing device (i.e., the hash value of the trusted credentials is different from the hash value corresponding to any trusted verification result), it indicates that the BGP message did not pass through the routing device, and it is determined that the routing device failed the trusted verification.

[0060] In some embodiments, each routing verification device includes at least one trusted verification result; trusted verification is performed based on the trusted credentials of the routing device, the current timestamp, the trusted verification result corresponding to the routing device, and the verification timestamp, including: If the current timestamp is earlier than or equal to the verification timestamp, and the trusted credentials of the routing device match the latest trusted verification result corresponding to the routing device, then the routing device is determined to have passed trusted verification. Alternatively, if the current timestamp is earlier than or equal to the verification timestamp, and the trusted credentials of the routing device do not match the latest trusted verification result corresponding to the routing device, the routing device is determined to have failed trusted verification.

[0061] For example, if the current timestamp is earlier than or equal to the verification timestamp, it indicates that the trusted verification result stored in the remote verification center has been updated, and the security level of the routing device may have changed. If the remote verification center stores a trusted verification result that has not been updated, then the trusted credential of the routing device is matched with the latest trusted verification result corresponding to the routing device. If they match, that is, the hash value of the trusted credential is the same as the hash value of the latest trusted verification result, it is determined that the BGP message of the routing device has passed through the routing device, and the routing device has passed trusted verification.

[0062] For example, if the current timestamp is earlier than or equal to the verification timestamp, and the trusted credentials of the routing device do not match each trusted verification result of the routing device (i.e., the hash value of the trusted credentials is different from the hash value corresponding to the latest trusted verification result), it is determined that the trustworthiness of the routing device is low or that the BGP message did not pass through the routing device, and the routing device fails the trusted verification.

[0063] Figure 4 A flowchart illustrating another routing path verification method provided in an embodiment of this application is shown. Please refer to [link / reference]. Figure 4 As shown in the figure, this embodiment provides a method for verifying a routing path, which is applied to the security routing center of the above-mentioned routing verification system. The method includes the following steps S310~330, which are described in detail below.

[0064] S310. Select the target routing path in the autonomous system according to user needs, so as to transmit BGP messages to the data center through the target routing path; wherein, the target routing path consists of multiple routing devices, and when the BGP message passes through each routing device on the target routing path, the BGP message is added with the attribute information of the routing device.

[0065] In some embodiments, there are multiple routing paths with different security levels in the autonomous system. Users can select a target routing path at the security routing center. Users can select the target routing path of the corresponding level according to the confidentiality of the information to be transmitted. The information to be transmitted is placed in the BGP message.

[0066] S320: Receive the trusted verification results of multiple routing devices transmitted by the remote verification center through the data center; the trusted verification results of multiple routing devices are obtained by the remote verification center through trusted verification of the attribute information of each routing device carried in the BGP message.

[0067] In some embodiments, the remote verification center sends the trusted verification results of each routing device it passes through to the secure routing center, and the secure routing center determines the verification result of the target routing path based on the trusted verification results of multiple routing devices.

[0068] S330. Based on the trusted verification results of multiple routing devices and the target routing path, obtain the routing path verification result.

[0069] In some embodiments, the trusted verification result also includes the AS number of the verified routing device. Based on the trusted verification results of multiple routing devices, it can be determined which routing devices have passed the verification. If there are routing devices that have failed the verification, it means that the transmission path of the BGP message is not the target routing path. If all verified routing devices have passed the verification, it means that the transmission path of the BGP message is the target routing path.

[0070] Figure 5 A flowchart illustrating another routing path verification method provided in an embodiment of this application is shown. Please refer to [link / reference]. Figure 5 As shown, this embodiment provides a method for verifying a routing path, which is applied to the autonomous system in the above-mentioned routing verification system. The method includes the following steps S410~S430, which are described in detail below.

[0071] S410 receives BGP messages sent by the security routing center.

[0072] In some embodiments, the BGP messages received by the autonomous system are sent by a security routing center.

[0073] S420. Transmit BGP messages based on the target routing path in the autonomous system; wherein, the target routing path is selected by the security routing center according to user needs; the target routing path consists of multiple routing devices, and when the BGP message passes through each routing device on the target routing path, the routing device adds its attribute information to the BGP message, resulting in a BGP message with added attribute information; the BGP message carries the attribute information of multiple routing devices for trusted verification of the routing devices, resulting in a trusted verification result of the routing devices; the trusted verification result of the routing devices is used for routing path verification, resulting in a routing path verification result.

[0074] In some embodiments, attribute information of the routing device is added to the BGP message, including adding attribute information of the routing device to the global administrator field and the local data field of the BGP message.

[0075] For example, the community attribute of a BGP message can be used to add attribute information of the routing device to the BGP message. Each time the message passes through a routing device, a community attribute will be added. Figure 6 This paper presents a schematic diagram illustrating the structure of a BGP message according to an embodiment of this application. Please refer to [link / reference]. Figure 6As shown, the value of each community attribute is encoded as a 12-byte size. Each community attribute includes a global administrator field (Global Administrator area) and two local data fields (LocalData area). The global administrator field is used to store the AS number of the routing device. The first local data field (Local Data Part 1) can store the trusted credential, i.e., the hash value; the second local data field (Local Data Part 2) can store the current timestamp.

[0076] S430. Transmit the BGP message with added attribute information to the data center, so that the data center can send the BGP message with added attribute information to the remote verification center for trusted verification.

[0077] In some embodiments, the transmission path of BGP messages may be tampered with. BGP messages with added attribute information are transmitted to the data center, so that the data center sends the BGP messages with added attribute information to a remote verification center for verification. The verification result is then sent to the secure routing center, which determines whether the transmission path of the BGP messages is the preset path.

[0078] Figure 7 This paper illustrates an interaction process diagram between a routing device and a remote verification center according to an embodiment of this application. Please refer to [link / reference]. Figure 7 As shown, the system includes router node agent programs corresponding to N routers. Each router node sends the proof and AS number to the remote proof center for verification. For example, 1. Upload the proof and AS number, that is, the router node 1 agent program uploads the proof and AS number to the remote proof center; 2. Verify the proof, obtain the proof result, and store the AS number and the corresponding proof result in the database; 3. Return the proof result, that is, the remote proof center returns the remote proof result to the router node 1 agent program.

[0079] Figure 8 This illustration shows a schematic diagram of customer data being routed to a data center via a NASR trusted routing path, as provided in an embodiment of this application. Please refer to [link / reference]. Figure 8As shown, the customer selects a route at the NASR center, i.e., chooses a routing path. 1. The customer selects the security requirements of the path based on their own data attributes; 2. A matching path is selected according to the customer's requirements, i.e., the NASR center selects a matching path according to the customer's requirements and transmits the BGP UPDATE message to a certain data center; the routing path includes high security level paths, medium security level paths, and low security level paths, and a certain AS represents a router; 3. The corresponding router adds the Community attribute; 4. A BGP UPDATE message is sent to verify the trustworthiness of the path, i.e., a certain data center sends a BGP UPDATE message to the remote verification center; 5. The BGP Community attribute is verified, and the verification result is given; 6. The verification result is returned, i.e., the remote verification center returns the verification result to a certain data center; 7. The message verification result is sent, i.e., the message verification result is sent to the NASR center, and the NASR center verifies whether the transmission path of the BGP UPDATE message is the routing path selected by the customer at the NASR center based on the verification result.

[0080] Figure 9 This illustration shows a schematic diagram of adding the Community attribute hop-by-hop in a BGP UPDATE message according to an embodiment of this application. Please refer to [link / reference]. Figure 9 As shown, the BGP UPDATE message is transmitted to the router (belonging to a certain AS) agent program, which adds [ASN: hash (remote proof result) + current timestamp] to the BGPCommunity attribute. Each router (belonging to a certain AS) agent program adds the above attribute and transmits the BGP UPDATE message with the BGP Community attribute to a certain data center.

[0081] As can be seen, the above mainly describes the solutions provided by the embodiments of this application from a methodological perspective. To achieve the above functions, the embodiments of this application provide corresponding hardware structures and / or software modules for executing each function. Those skilled in the art should readily recognize that, in conjunction with the modules and algorithm steps of the various examples described in the embodiments disclosed herein, the embodiments of this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed by hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this invention.

[0082] Figure 10 A schematic diagram of the structure of an electronic device provided in an embodiment of this application is shown below. Please refer to [link / reference]. Figure 10As shown, the electronic device 900 includes: a processor 902, a communication interface 903, and a bus 904. Optionally, the electronic device 900 may also include a memory 901.

[0083] Processor 902 may implement or execute various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. Processor 902 may be a central processing unit, a general-purpose processor, a digital signal processor, an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It may implement or execute various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. Processor 902 may also be a combination that implements computing functions, such as including one or more microprocessor combinations, a combination of a DSP and a microprocessor, etc.

[0084] The communication interface 903 is used to connect to other devices via a communication network. This communication network can be Ethernet, wireless access network, wireless local area network (WLAN), etc.

[0085] The memory 901 may be a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions, random access memory (RAM) or other type of dynamic storage device capable of storing information and instructions, or electrically erasable programmable read-only memory (EEPROM), disk storage media or other magnetic storage devices, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but is not limited thereto.

[0086] In one possible implementation, the memory 901 can exist independently of the processor 902. The memory 901 can be connected to the processor 902 via a bus 904 and is used to store instructions or program code. When the processor 902 calls and executes the instructions or program code stored in the memory 901, it can implement the routing path verification method provided in this embodiment of the invention.

[0087] In another possible implementation, the memory 901 can also be integrated with the processor 902.

[0088] The 904 bus can be an extended industry standard architecture (EISA) bus, etc. The 904 bus can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 10 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.

[0089] Through the above description of the implementation methods, those skilled in the art can clearly understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the service calling device can be divided into different functional modules to complete all or part of the functions described above.

[0090] This application also provides a computer-readable storage medium. All or part of the processes in the above method embodiments can be executed by computer instructions instructing related hardware. The program can be stored in the aforementioned computer-readable storage medium, and when executed, it can include the processes of the above method embodiments. The computer-readable storage medium can be any of the foregoing embodiments or memory. The aforementioned computer-readable storage medium can also be an external storage device of the aforementioned service invocation device, such as a plug-in hard drive, smart media card (SMC), secure digital (SD) card, flash card, etc., equipped on the aforementioned service invocation device. Further, the aforementioned computer-readable storage medium can include both internal storage units of the aforementioned service invocation device and external storage devices. The aforementioned computer-readable storage medium is used to store the aforementioned computer program and other programs and data required by the aforementioned service invocation device. The aforementioned computer-readable storage medium can also be used to temporarily store data that has been output or will be output.

[0091] This application also provides a computer program product comprising a computer program that, when run on a computer, causes the computer to execute any of the routing path verification methods provided in the above embodiments.

[0092] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A routing path verification system, characterized in that, The system includes: a secure routing center, an autonomous system, a data center, and a remote verification center; the secure routing center is connected to the data center through the autonomous system, and the data center is connected to the remote verification center. The secure routing center is used to select the target routing path in the autonomous system according to user needs, so as to transmit BGP messages to the data center through the target routing path; The target routing path consists of multiple routing devices. When the BGP message passes through each routing device on the target routing path, the routing device adds its attribute information to the BGP message to obtain a BGP message with added attribute information. The data center is used to send the BGP message with added attribute information to the remote proof center; The remote verification center is used to perform trusted verification of the attribute information of multiple routing devices carried in the BGP message, and transmits the trusted verification results of the multiple routing devices to the secure routing center through the data center. The secure routing center is also used to obtain a routing path verification result based on the trusted verification results of the multiple routing devices and the target routing path; the routing path verification result is used to indicate whether the transmission path of the BGP message is the target routing path.

2. The system according to claim 1, characterized in that, The attribute information of the routing device includes: the AS number corresponding to the routing device, the trusted credential of the routing device, and the current timestamp.

3. A method for verifying a routing path, characterized in that, A remote verification center applied to the routing path verification system according to any one of claims 1-2, the method comprising: The system receives BGP messages with added attribute information sent by the data center; wherein, the BGP messages with added attribute information are sent by the security routing center to the data center through the target routing path of the autonomous system; the target routing path consists of multiple routing devices, and the BGP messages with added attribute information are obtained by adding the attribute information of each routing device on the target routing path; The attribute information of multiple routing devices carried in the BGP message is verified for trustworthiness, and the verification results of the multiple routing devices are transmitted to the security routing center through the data center, so that the security routing center can obtain a routing path verification result based on the verification results of the multiple routing devices and the target routing path; wherein, the routing path verification result is used to indicate whether the transmission path of the BGP message is the target routing path.

4. The method according to claim 3, characterized in that, The attribute information of the routing device includes: the AS number corresponding to the routing device, the trusted credential of the routing device, and the current timestamp.

5. The method according to claim 4, characterized in that, The trusted verification of the attribute information of each routing device carried in the BGP message includes: Based on the AS number of the routing device, obtain the trusted verification result and verification timestamp pre-stored in the remote verification center by the routing device; Trust verification is performed based on the trusted credentials of the routing device, the current timestamp, the trusted verification result corresponding to the routing device, and the verification timestamp.

6. The method according to claim 5, characterized in that, Each of the routing devices includes at least one of the trusted verification results; The step of performing trusted verification based on the trusted credentials of the routing device, the current timestamp, the trusted verification result corresponding to the routing device, and the verification timestamp includes: If the current timestamp is later than the verification timestamp, and the trusted credentials of the routing device match any trusted verification result corresponding to the routing device, then the routing device is determined to have passed trusted verification. Alternatively, if the current timestamp is later than the verification timestamp, and the trusted credentials of the routing device do not match any of the trusted verification results corresponding to the routing device, the routing device is determined to have failed trusted verification.

7. The method according to claim 5, characterized in that, Each of the routing verification devices includes at least one trusted verification result; The step of performing trusted verification based on the trusted credentials of the routing device, the current timestamp, the trusted verification result corresponding to the routing device, and the verification timestamp includes: If the current timestamp is earlier than or equal to the verification timestamp, and the trusted credentials of the routing device match the latest trusted verification result corresponding to the routing device, then the routing device is determined to have passed trusted verification. Alternatively, if the current timestamp is earlier than or equal to the verification timestamp, and the trusted credentials of the routing device do not match the latest trusted verification result corresponding to the routing device, the routing device is determined to have failed trusted verification.

8. A method for verifying a routing path, characterized in that, The method, applied to a secure routing center in a system for verifying the routing path according to any one of claims 1-2, comprises: Select the target routing path in the autonomous system according to user needs, so as to transmit BGP packets to the data center through the target routing path; wherein, the target routing path is composed of multiple routing devices, and when the BGP packet passes through each routing device on the target routing path, the BGP packet is added with the attribute information of the routing device. The remote verification center receives trusted verification results from multiple routing devices transmitted through the data center; the trusted verification results from the multiple routing devices are obtained by the remote verification center through trusted verification of the attribute information of each routing device carried in the BGP message. Based on the trusted verification results of the multiple routing devices and the target routing path, the routing path verification result is obtained.

9. A method for verifying a routing path, characterized in that, An autonomous system applied to the routing path verification system according to any one of claims 1-2, the method comprising: Receive BGP messages sent by the security routing center; The GSP message is transmitted based on the target routing path in the autonomous system; wherein the target routing path is selected by the security routing center according to user needs; The target routing path consists of multiple routing devices. When the BGP message passes through each routing device on the target routing path, the routing device adds its attribute information to the BGP message, resulting in a BGP message with added attribute information. The BGP message carries the attribute information of multiple routing devices for trusted verification of the routing devices, resulting in a trusted verification result of the routing devices. The trusted verification result of the routing devices is used for routing path verification, resulting in a routing path verification result. The BGP message with added attribute information is transmitted to the data center, so that the data center sends the BGP message with added attribute information to the remote verification center for trusted verification.

10. The method according to claim 9, characterized in that, Adding the routing device's attribute information to the BGP message includes: The routing device's attribute information is added to the global administrator field and local data field in the BGP message.

11. An electronic device, characterized in that, The device includes a processor and a memory, the processor being coupled to the memory; the memory is used to store computer instructions, which are loaded and executed by the processor to enable the computer device to implement the routing path verification method as described in any one of claims 3 to 9.

12. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes computer-executable instructions that, when executed on a computer, cause the computer to perform the routing path verification method according to any one of claims 3 to 9.