Message legality verification method and device and related equipment
By configuring a legitimate source prefix and device identifier in the source address verification device, receiving and verifying source prefix announcements and destination prefix probe information, and generating source address verification entries, the problem of router devices being unable to verify source IP addresses is solved, realizing automated packet legitimacy verification, and improving network security and traceability efficiency.
Patent Information
- Application Number
- CN202511767422.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-27
- Publication Date
- 2026-02-17
AI Technical Summary
In existing technologies, router devices cannot effectively verify the source IP address of data packets, which allows attackers to forge source IP addresses to carry out attacks, increasing network security risks and making it more difficult to trace the source of the attack.
By configuring a legitimate source prefix and device identifier in the source address verification device, the system receives and verifies source prefix announcements and destination prefix probe information, generates source address verification entries, verifies the legitimacy of service packets based on these entries, and automatically establishes verification relationships, reducing the need for manual ACL configuration.
It enables automatic validation of business messages, reducing the risk of misconfiguration and maintenance costs, and improving network security and traceability efficiency.
Smart Images

Figure CN121547259A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network communication technology, and in particular to a method, apparatus and related equipment for verifying the legitimacy of messages. Background Technology
[0002] Router devices follow a destination address forwarding mechanism, meaning they only care about the destination IP address of data packets, not the source IP address. This mechanism becomes a vulnerability that attackers can exploit. Attackers can spoof source IP addresses, conceal their identity, and construct attack packets, such as reflection attacks, DDoS attacks, and man-in-the-middle attacks. Such attacks pose a significant threat to network security and also increase the difficulty of tracing the source. Therefore, how to verify the legitimacy of received packets is a pressing issue that needs to be addressed. Summary of the Invention
[0003] This application provides a method, apparatus, and related equipment for verifying the legitimacy of a message.
[0004] In a first aspect, this application provides a message validity verification method, applied to a first source address verification device, wherein a valid source prefix and a device identifier are pre-configured for each source address verification device; the method includes: Receive Source Prefix Advertisement (SPA) information sent by the second source address verification device, wherein the SPA information includes the legitimate source prefix and device identifier of the second source address verification device; The device receives destination prefix probe (DPP) information sent by the second source address verification device, wherein the second source address verification device generates corresponding DPP information based on each non-directly connected forwarding destination prefix in the local FIB table, and each DPP information includes the corresponding non-directly connected forwarding destination prefix and the device identifier of the second source address verification device. For the received target DPP information, determine whether there is target SPA information that matches the target device identifier carried in the target DPP information; If it is determined that it exists, a source address verification entry is generated with the source prefix carried by the target SPA information as the prefix and the ingress interface as the target interface that received the target DPP information. The legality of received service messages is verified based on the generated source address verification entries.
[0005] Optionally, the step of validating the received service message based on the generated source address verification entry includes: Receive service messages sent by other source address verification devices; Determine whether there is an entry in the source address verification table that matches the source prefix of the service packet and the ingress interface that received the service packet; If it is determined that the message exists, then the service message is determined to be a legitimate service message.
[0006] Optionally, the method further includes: The received SPA information and DPP information are forwarded to a third source address verification device, so that the third source address verification device performs the following steps: based on the received target DPP information, it determines whether there is target SPA information that matches the target device identifier carried in the target DPP information; if it is determined that there is, it generates a source address verification table entry with the source prefix carried in the target SPA information and the ingress interface being the target interface that received the target DPP information.
[0007] Optionally, the legitimate source prefix corresponding to each source address verification device is: a legitimate network segment connected to the user's network.
[0008] Optionally, each source address authentication device transmits SPA information and DPP information to other source address authentication devices through IPv6 extended packets. The first extended field in the IPv6 extended header is used to carry the SPA information to be transmitted, and the second extended field is used to carry the DPP information to be transmitted.
[0009] Secondly, this application provides a message validity verification device applied to a first source address verification device, wherein a valid source prefix and device identifier are pre-configured for each source address verification device; the device includes: The receiving unit is configured to receive Source Prefix Advertisement (SPA) information sent by the second source address verification device, wherein the SPA information includes the legitimate source prefix and device identifier of the second source address verification device; The receiving unit is further configured to receive destination prefix probe (DPP) information sent by the second source address verification device, wherein the second source address verification device generates corresponding DPP information based on each non-directly connected forwarding destination prefix in the local FIB table, and each DPP information includes the corresponding non-directly connected forwarding destination prefix and the device identifier of the second source address verification device. The judgment unit is used to determine, based on the received target DPP information, whether there is target SPA information that matches the target device identifier carried by the target DPP information; If the determination unit determines that the target SPA information exists, the generation unit is used to generate a source address verification entry with the source prefix carried by the target SPA information as the prefix and the input interface as the target interface that receives the target DPP information. The verification unit is used to verify the legitimacy of received service messages based on the generated source address verification entries.
[0010] Optionally, when performing validity verification on the received service message based on the generated source address verification entry, the verification unit is specifically used for: Receive service messages sent by other source address verification devices; Determine whether there is an entry in the source address verification table that matches the source prefix of the service packet and the ingress interface that received the service packet; If it is determined that the message exists, then the service message is determined to be a legitimate service message.
[0011] Optionally, the device further includes: The forwarding unit is used to forward the received SPA information and DPP information to the third source address verification device, so that the third source address verification device performs the following steps: based on the received target DPP information, it determines whether there is target SPA information that matches the target device identifier carried in the target DPP information; if it is determined that there is, it generates a source address verification table entry with the prefix of the source prefix carried in the target SPA information and the ingress interface of the target interface that received the target DPP information.
[0012] Optionally, the legitimate source prefix corresponding to each source address verification device is: a legitimate network segment connected to the user's network.
[0013] Optionally, each source address authentication device transmits SPA information and DPP information to other source address authentication devices through IPv6 extended packets. The first extended field in the IPv6 extended header is used to carry the SPA information to be transmitted, and the second extended field is used to carry the DPP information to be transmitted.
[0014] Thirdly, embodiments of this application provide a message validity verification device, which includes: Memory, used to store program instructions; A processor is configured to invoke program instructions stored in the memory and execute the steps of the method as described in any one of the first aspects above, according to the obtained program instructions.
[0015] Fourthly, embodiments of this application also provide a computer-readable storage medium storing computer-executable instructions for causing a computer to perform the steps of the method as described in any of the first aspects above.
[0016] In summary, the message legality verification method provided in this application embodiment is applied to a first source address verification device, wherein a legitimate source prefix and device identifier are pre-configured for each source address verification device; the method includes: receiving source prefix announcement (SPA) information sent by a second source address verification device, wherein the SPA information includes the legitimate source prefix and device identifier of the second source address verification device; receiving destination prefix probe (DPP) information sent by the second source address verification device, wherein the second source address verification device generates corresponding DPP information based on each non-directly connected forwarding destination prefix in its local FIB table, and each DPP information includes the corresponding non-directly connected forwarding destination prefix and the device identifier of the second source address verification device; for the received target DPP information, determining whether there is target SPA information that matches the target device identifier carried by the target DPP information; if it is determined that there is, generating a source address verification table entry with the prefix of the source prefix carried by the target SPA information and the ingress interface of the target interface that received the target DPP information; and performing legality verification on the received service message based on the generated source address verification table entry.
[0017] The message legality verification method provided in this application establishes a correspondence between the legal prefix and interface of the verification device by using the SPA information and DPP information sent by the peer verification device in the network. In the subsequent service message processing, the message is forwarded or dropped based on whether the source IP of the service message corresponds to the legal prefix. The service message is identified and the forwarding of illegal messages is blocked. Each device in the network automatically generates the corresponding verification table entry without the need for manual ACL configuration. Attached Figure Description
[0018] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments of this application or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this application. For those skilled in the art, other drawings can be obtained based on these drawings of the embodiments of this application.
[0019] Figure 1 A detailed flowchart of a message validity verification method provided for embodiments of this application; Figure 2 This application provides another network diagram for an embodiment; Figure 3 A schematic diagram of an IPv6 extension header format provided in an embodiment of this application; Figure 4 A schematic diagram of a valid source address prefix verification entry provided in an embodiment of this application; Figure 5A schematic diagram of a message validity verification device provided in this application embodiment; Figure 6 This is a schematic diagram of the hardware architecture of a message validity verification device provided in an embodiment of this application. Detailed Implementation
[0020] The terminology used in the embodiments of this application is for the purpose of describing particular embodiments only and is not intended to limit the application. The singular forms “a,” “the,” and “the” as used in this application and claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to any and all possible combinations comprising one or more of the associated listed items.
[0021] It should be understood that although the terms first, second, third, etc., may be used to describe various information in embodiments of this application, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, without departing from the scope of this application, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the word "if" may also be interpreted as "when," "when," or "in response to a determination."
[0022] Currently, source address spoofing attacks are a common network security threat, and commonly used protection techniques include ACLs (Access Control Lists). While ACLs provide basic protection for network security, they also have significant drawbacks: High maintenance costs: ACL rules require manual maintenance, which is not only time-consuming but also prone to errors.
[0023] Misconfiguration risk: Incorrect ACL configuration may result in legitimate traffic being blocked incorrectly or malicious traffic being allowed to pass by mistake.
[0024] This application provides a method for verifying packet legitimacy based on source address, which solves the problem that the traditional method of configuring access control lists (ACLs) on each forwarding device in the network is complex, error-prone, and leads to low maintenance efficiency.
[0025] For example, see Figure 1 The diagram shown is a detailed flowchart of a message validity verification method provided in an embodiment of this application. This method is applied to a first source address verification device, wherein a valid source prefix and device identifier are pre-configured for each source address verification device. The method includes the following steps: Step 100: Receive Source Prefix Announcement (SPA) information sent by the second source address verification device, wherein the SPA information includes the legitimate source prefix and device identifier of the second source address verification device.
[0026] In this embodiment of the application, a valid prefix is configured in each source address verification device in the network. Specifically, the valid source prefix corresponding to each source address verification device is: a valid network segment connected to the user network.
[0027] For example, if the legitimate network segment connecting source address verification device 1 to the user network is 100:: / 64, then 100:: / 64 can be used as the legitimate prefix of source address verification device 1. Similarly, if source address verification device 2 is connected to the user network via 101:: / 64, then the legitimate prefix of source address verification device 2 is 101:: / 64; and if source address verification device 3 is connected to the user network via 102:: / 64, then the legitimate prefix of source address verification device 3 is 102:: / 64.
[0028] For example, the device identifier of source address verification device 1 can be System ID1 (e.g., 1.1.1.1); similarly, the device identifier of source address verification device 1 can be System ID2 (e.g., 1.1.1.2); and the device identifier of source address verification device 1 can be System ID3 (e.g., 1.1.1.3). In practical applications, the device identifier of a source address verification device only needs to uniquely identify the source address verification device in the network. In this embodiment, the definition of the device identifier of the source address verification device is not specifically limited. For example, the Router ID of the source address verification device can also be used as its device identifier.
[0029] In this embodiment of the application, each source address verification device establishes a BGP neighbor relationship via the BGP protocol. For example, see the following: Figure 2 As shown, this is a network diagram provided in an embodiment of the present application. DEV 1 establishes a neighbor relationship with DEV 2 through Port 1, and DEV 2 establishes a neighbor relationship with DEV 3 through Port 2.
[0030] Each source address verification device sends Source Prefix Advertisement (SPA) information to its neighboring devices. For example, the SPA information sent by the second source address verification device to the first source address verification device (a neighboring device of the second source address verification device) includes the second source address verification device's valid prefix and device identifier. After receiving the SPA information sent by the second source address verification device, the first source address verification device extracts and maintains the second source address verification device's valid prefix and device identifier locally.
[0031] Step 110: Receive the Destination Prefix Probe (DPP) information sent by the second source address verification device.
[0032] The second source address verification device generates corresponding DPP (Destination Prefix Probing) information based on each non-directly connected forwarding destination prefix in the local FIB table. Each DPP information includes the corresponding non-directly connected forwarding destination prefix and the device identifier of the second source address verification device.
[0033] In this embodiment, the second source address verification device queries its local routing table (e.g., local IPv6 FIB entry) to determine that 101:: / 64 and 102:: / 64 are both non-directly connected forwarding destination prefixes. At this point, a DPP information (e.g., DPP route) can be generated for 101:: / 64 and 102:: / 64 respectively, and sent to the first source address verification device. The DPP information corresponding to 101:: / 64 includes the device identifiers of 101:: / 64 and the second source address verification device, and the DPP information corresponding to 102:: / 64 includes the device identifiers of 102:: / 64 and the second source address verification device.
[0034] It should be noted that, in this embodiment of the application, each source address verification device transmits SPA information and DPP information to other source address verification devices through IPv6 extended packets. The first extended field in the IPv6 extended header is used to carry the SPA information to be transmitted, and the second extended field is used to carry the DPP information to be transmitted.
[0035] For example, see Figure 3 The diagram shown is a schematic of an IPv6 extension header format provided in an embodiment of this application. In the diagram, System ID is the device identifier, which is taken as Router ID by default. Prefix carries prefix information (routing prefix). In SPA information, Prefix is a valid prefix. In DPP information, Prefix is the destination prefix.
[0036] After generating DPP information corresponding to a non-directly connected route, the second source address verification device forwards the information to its neighboring device (e.g., the first source address verification device).
[0037] Step 120: For the received target DPP information, determine whether there is target SPA information that matches the target device identifier carried by the target DPP information.
[0038] In this embodiment of the application, after receiving a DPP message sent by the second source address verification device, the first source address verification device determines whether there is a target SPA message in the locally maintained SPA message that matches the device identifier of the DPP message, based on the device identifier of the DPP message.
[0039] Specifically, if there is SPA information in the locally maintained SPA information whose device identifier is the same as the device identifier of the DPP information, then it is determined that the SPA information matches the device identifier of the DPP information.
[0040] In other words, the first source address verification device needs to determine whether the DPP information is sent by a legitimate device.
[0041] Step 130: If it is determined that it exists, generate a source address verification entry with the source prefix carried by the target SPA information as the prefix and the target interface receiving the target DPP information as the ingress interface.
[0042] In this embodiment of the application, if the first source address verification device determines that there is target SPA information in the received target DPP information that matches the target device identifier carried by the target DPP information, then a source address verification entry is generated with the source prefix carried by the target SPA information as the prefix and the input interface as the target interface that received the target DPP information as the input interface.
[0043] For example, see Figure 4 The diagram shown is a schematic of a valid source address prefix verification table provided in an embodiment of this application. The ingress interface corresponding to valid prefixes D1 and D2 is P1, and the ingress interface corresponding to valid prefixes D3 and D4 is P2.
[0044] Step 140: Verify the legitimacy of the received service message based on the generated source address verification table entry.
[0045] In this embodiment of the application, when performing legality verification on received service messages based on the generated source address verification table entries, a preferred implementation method is as follows: Receive service messages sent by other source address verification devices; Determine whether there is an entry in the source address verification table that matches the source prefix of the service packet and the ingress interface that received the service packet; If it is determined that the message exists, then the service message is determined to be a legitimate service message.
[0046] Furthermore, in this embodiment of the application, the above-mentioned message validity verification method may further include the following steps: The received SPA information and DPP information are forwarded to a third source address verification device, so that the third source address verification device performs the following steps: based on the received target DPP information, it determines whether there is target SPA information that matches the target device identifier carried in the target DPP information; if it is determined that there is, it generates a source address verification table entry with the source prefix carried in the target SPA information and the ingress interface being the target interface that received the target DPP information.
[0047] Specifically, the third source address verification device is another neighbor device of the first source address verification device, but the third source address verification device is not a neighbor device of the second source address verification device. In this case, after receiving the SPA information sent by the second source address verification device, the first source address verification device will forward the SPA information to the third source address verification device. The third source address verification device maintains the legal prefix and device identifier of the second source address verification device locally.
[0048] Next, after receiving the DPP information sent by the second source address verification device, if the destination prefix carried by the DPP information is its own valid prefix, the first source address verification device will not forward the DPP information to the third source address verification device. If the destination prefix carried by the DPP information is not its own valid prefix, it will still forward the DPP information to the third source address verification device. Then, the third source address verification device will also generate a source address verification entry locally with the prefix of the source prefix carried by the DPP information and the ingress interface being the interface that received the DPP information.
[0049] For example, still using Figure 2 As shown, after the first source address authentication device (e.g., DEV 2) receives a DPP route with a destination prefix of 101:: / 64 from the second source address authentication device (e.g., DEV 1), it looks up the source prefix information corresponding to that source Router ID stored locally, based on the source Router ID carried in the DPP route information. This generates an authentication entry with a matching source prefix of 101:: / 64 and an ingress interface of Port 1. In subsequent service packet forwarding, if the first source address authentication device receives a packet with a source IPv6 address belonging to the 101:: / 64 prefix, it will only process the service packet received from Port 1. Since the destination prefix 101:: / 64 is a directly connected forwarding destination prefix in the first source address authentication device's IPv6 FIB entry, the first source address authentication device will not forward the DPP route with the destination prefix 101:: / 64.
[0050] For example, after receiving a DPP route with a destination prefix of 102:: / 64, the first source address verification device looks up the source prefix information corresponding to that source router ID stored locally, based on the source router ID carried in the DPP route information. This generates a matching verification entry with the source prefix 102:: / 64 and the ingress interface Port 1. DPP routes with destination prefixes of 102:: / 64 and 101:: / 64 carry the same source router ID, triggering the generation of the same verification entry. However, the first source address verification device will not generate duplicate verification entries; it will only generate one verification entry.
[0051] The first source address authentication device looks up its local IPv6 FIB entry, where 102:: / 64 is a non-directly connected forwarding destination prefix, and the next-hop outgoing interface is Port 2. The first source address authentication device establishes a direct BGP IPv6 authentication session with the third source address authentication device (e.g., DEV 3) via Port 2. Therefore, the first source address authentication device fills its local Router ID into the DPP route from the second source address authentication device with a destination prefix of 102:: / 64, without modifying the source Router ID in the routing information, and forwards this DPP route to the third source address authentication device via Port 2.
[0052] After receiving a DPP route with a destination prefix of 102:: / 64, the third source address authentication device looks up the source prefix information corresponding to that source router ID stored locally, based on the source router ID carried in the DPP route information. This generates an authentication entry with a matching source prefix of 10:: / 64 and an ingress interface of Port 1. In subsequent packet forwarding, if the third source address authentication device receives a packet with a source IPv6 address belonging to the 10:: / 64 prefix, it will only process packets received from Port 1. Since the destination prefix 102:: / 64 is a directly connected forwarding destination prefix in the third source address authentication device's IPv6 FIB entry, the first source address authentication device will not forward the DPP route with the destination prefix 102:: / 64.
[0053] Based on the same inventive concept as the above-described embodiments, see, for example, the following: Figure 5 The diagram shown is a structural schematic of a message validity verification device provided in an embodiment of this application. This device is applied to a first source address verification device, wherein a valid source prefix and device identifier are pre-configured for each source address verification device. The device includes: The receiving unit 50 is configured to receive Source Prefix Announcement (SPA) information sent by the second source address verification device, wherein the SPA information includes the legitimate source prefix and device identifier of the second source address verification device; The receiving unit 50 is further configured to receive destination prefix probe (DPP) information sent by the second source address verification device, wherein the second source address verification device generates corresponding DPP information based on each non-directly connected forwarding destination prefix in the local FIB table, and each DPP information includes the corresponding non-directly connected forwarding destination prefix and the device identifier of the second source address verification device. The judgment unit 51 is used to determine, based on the received target DPP information, whether there is target SPA information that matches the target device identifier carried by the target DPP information; If the judgment unit 51 determines that it exists, the generation unit 52 is used to generate a source address verification entry with the source prefix carried by the target SPA information as the prefix and the input interface as the target interface that receives the target DPP information. The verification unit 53 is used to verify the legitimacy of the received service message based on the generated source address verification table entry.
[0054] Optionally, when performing legality verification on the received service message based on the generated source address verification entry, the verification unit 53 is specifically used for: Receive service messages sent by other source address verification devices; Determine whether there is an entry in the source address verification table that matches the source prefix of the service packet and the ingress interface that received the service packet; If it is determined that the message exists, then the service message is determined to be a legitimate service message.
[0055] Optionally, the device further includes: The forwarding unit is used to forward the received SPA information and DPP information to the third source address verification device, so that the third source address verification device performs the following steps: based on the received target DPP information, it determines whether there is target SPA information that matches the target device identifier carried in the target DPP information; if it is determined that there is, it generates a source address verification table entry with the prefix of the source prefix carried in the target SPA information and the ingress interface of the target interface that received the target DPP information.
[0056] Optionally, the legitimate source prefix corresponding to each source address verification device is: a legitimate network segment connected to the user's network.
[0057] Optionally, each source address authentication device transmits SPA information and DPP information to other source address authentication devices through IPv6 extended messages. The first extended field in the IPv6 extended header is used to carry the SPA information to be transmitted, and the second extended field is used to carry the DPP information to be transmitted.
[0058] These units can be one or more integrated circuits configured to implement the above methods, such as one or more Application Specific Integrated Circuits (ASICs), one or more digital signal processors (DSPs), or one or more Field Programmable Gate Arrays (FPGAs). Alternatively, when one of these units is implemented using processing element scheduler code, the processing element can be a general-purpose processor, such as a Central Processing Unit (CPU) or other processor capable of calling program code. Furthermore, these units can be integrated together to form a system-on-a-chip (SOC).
[0059] Furthermore, regarding the message validity verification device provided in this application embodiment, from a hardware perspective, the hardware architecture diagram of the message validity verification device can be found in [reference needed]. Figure 6 As shown, the message validity verification device may include: a memory 60 and a processor 61. The memory 60 is used to store program instructions; the processor 61 calls the program instructions stored in the memory 60 and executes the above method embodiment according to the obtained program instructions. The specific implementation method and technical effect are similar, and will not be described again here.
[0060] Optionally, this application also provides a message legitimacy verification device, including at least one processing element (or chip) for performing the above method embodiments.
[0061] Optionally, this application also provides a program product, such as a computer-readable storage medium storing computer-executable instructions for causing the computer to perform the above-described method embodiments.
[0062] Here, a machine-readable storage medium can be any electronic, magnetic, optical, or other physical storage device that can contain or store information, such as executable instructions, data, etc. For example, a machine-readable storage medium can be: RAM (Random Access Memory), volatile memory, non-volatile memory, flash memory, storage drives (such as hard disk drives), solid-state drives, any type of storage disk (such as optical discs, DVDs, etc.), or similar storage media, or combinations thereof.
[0063] The systems, devices, modules, or units described in the above embodiments can be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer, which can take the form of a personal computer, laptop computer, cellular phone, camera phone, smartphone, personal digital assistant, media player, navigation device, email sending and receiving device, game console, tablet computer, wearable device, or any combination of these devices.
[0064] For ease of description, the above devices are described separately by function as various units. Of course, in implementing this application, the functions of each unit can be implemented in one or more software and / or hardware.
[0065] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, embodiments of this application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0066] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0067] Furthermore, these computer program instructions can also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in the process. Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0068] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0069] The above description is merely a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.
Claims
1. A message validity verification method, characterized in that, The method is applied to a first source address verification device, wherein a valid source prefix and device identifier are pre-configured for each source address verification device; the method includes: Receive Source Prefix Advertisement (SPA) information sent by the second source address verification device, wherein the SPA information includes the legitimate source prefix and device identifier of the second source address verification device; The device receives destination prefix probe (DPP) information sent by the second source address verification device, wherein the second source address verification device generates corresponding DPP information based on each non-directly connected forwarding destination prefix in the local FIB table, and each DPP information includes the corresponding non-directly connected forwarding destination prefix and the device identifier of the second source address verification device. For the received target DPP information, determine whether there is target SPA information that matches the target device identifier carried in the target DPP information; If it is determined that it exists, a source address verification entry is generated with the source prefix carried by the target SPA information as the prefix and the ingress interface as the target interface that received the target DPP information. The legality of received service messages is verified based on the generated source address verification entries.
2. The method as described in claim 1, characterized in that, The steps for validating the validity of received service messages based on the generated source address verification entries include: Receive service messages sent by other source address verification devices; Determine whether there is an entry in the source address verification table that matches the source prefix of the service packet and the ingress interface that received the service packet; If it is determined that the message exists, then the service message is determined to be a legitimate service message.
3. The method as described in claim 1 or 2, characterized in that, The method further includes: The received SPA information and DPP information are forwarded to a third source address verification device, so that the third source address verification device performs the following steps: based on the received target DPP information, it determines whether there is target SPA information that matches the target device identifier carried in the target DPP information; if it is determined that there is, it generates a source address verification table entry with the source prefix carried in the target SPA information and the ingress interface being the target interface that received the target DPP information.
4. The method as described in claim 1 or 2, characterized in that, The legitimate source prefix corresponding to each source address verification device is: a legitimate network segment connected to the user's network.
5. The method as described in claim 1 or 2, characterized in that, Each source address authentication device transmits SPA information and DPP information to other source address authentication devices through IPv6 extended packets. The first extended field in the IPv6 extended header is used to carry the SPA information to be transmitted, and the second extended field is used to carry the DPP information to be transmitted.
6. A message validity verification device, characterized in that, An apparatus applied to a first source address verification device, wherein each source address verification device is pre-configured with a valid source prefix and a device identifier; the apparatus includes: The receiving unit is configured to receive Source Prefix Advertisement (SPA) information sent by the second source address verification device, wherein the SPA information includes the legitimate source prefix and device identifier of the second source address verification device; The receiving unit is further configured to receive destination prefix probe (DPP) information sent by the second source address verification device, wherein the second source address verification device generates corresponding DPP information based on each non-directly connected forwarding destination prefix in the local FIB table, and each DPP information includes the corresponding non-directly connected forwarding destination prefix and the device identifier of the second source address verification device. The judgment unit is used to determine, based on the received target DPP information, whether there is target SPA information that matches the target device identifier carried by the target DPP information; If the determination unit determines that the target SPA information exists, the generation unit is used to generate a source address verification entry with the source prefix carried by the target SPA information as the prefix and the input interface as the target interface that receives the target DPP information. The verification unit is used to verify the legitimacy of received service messages based on the generated source address verification entries.
7. The apparatus as claimed in claim 6, characterized in that, When verifying the legitimacy of received service messages based on the generated source address verification table entries, the verification unit is specifically used for: Receive service messages sent by other source address verification devices; Determine whether there is an entry in the source address verification table that matches the source prefix of the service packet and the ingress interface that received the service packet; If it is determined that the message exists, then the service message is determined to be a legitimate service message.
8. The apparatus as claimed in claim 6 or 7, characterized in that, The device further includes: The forwarding unit is used to forward the received SPA information and DPP information to the third source address verification device, so that the third source address verification device performs the following steps: based on the received target DPP information, it determines whether there is target SPA information that matches the target device identifier carried in the target DPP information; if it is determined that there is, it generates a source address verification table entry with the prefix of the source prefix carried in the target SPA information and the ingress interface of the target interface that received the target DPP information.
9. A message validity verification device, characterized in that, The message validity verification device includes: Memory, used to store program instructions; A processor is configured to invoke program instructions stored in the memory and execute the steps of the method as described in any one of claims 1-5 according to the obtained program instructions.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions for causing the computer to perform the steps of the method as described in any one of claims 1-5.