Method for transmitting data identification information in SDWAN network and detection method
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-05-27
- Publication Date
- 2026-06-26
AI Technical Summary
Existing technologies struggle to effectively detect data identification information in SDWAN networks and are at risk of being intercepted and illegally detected by intermediate network devices. This is especially true in IPv4 and IPv6 networks where security checks are stringent, making data type fields susceptible to interception or modification.
In SDWAN networks, a data identification field is added to the data packet header, and receive, forward, and terminate mechanisms are set up on CPE and POP. The secure transmission and detection of data identification information are ensured through trusted node lists and restricted transmission lists.
It enables secure transmission and flexible detection of data identification information, avoids interception and unauthorized modification, ensures the ability to detect data flow, prevents data identification information from being transmitted to untrusted network areas, and enhances the data detection capability within the SDWAN network.
Smart Images

Figure CN122293436A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a method for transmitting and detecting data identification information in an SDWAN network, belonging to the field of communication technology. Background Technology
[0002] In network data streams, the type of data content transmitted can be identified by extending or adding fields representing the data type in the application layer, IP header, transport layer header, or ordinary tunneling protocol. The receiving end obtains the type of transmitted data content by parsing the extended or added fields in the data packet header.
[0003] Data type fields added to the application layer or ordinary tunneling protocols cannot be effectively detected by data inspection systems in the network path, making effective detection difficult. Data type fields extended in the IP header may have their validity affected by network device processing of IP header information when traversing the public internet, especially in IPv4 networks, where these non-standard fields are often intercepted and discarded. While IPv6 networks can generally use custom extended fields, network devices with strict security checks can still implement strict security policies to block this type of packet. Data type fields added to the transport layer protocol header can be carried in optional extended headers for TCP traffic, but there is insufficient extension space for UDP protocols. Again, network devices with strict security checks can still implement strict security policies to block this type of packet. Furthermore, the security of these methods cannot be guaranteed, and there is a possibility of unauthorized detection by third parties. Summary of the Invention
[0004] Purpose of the invention: The technical problem to be solved by the present invention is to provide a method for transmitting data identification information in an SDWAN network, which addresses the shortcomings of the prior art. This method ensures the secure transmission of data identification information by setting up receiving, forwarding, and termination mechanisms on each SDWAN device.
[0005] To address the aforementioned technical problems, this invention discloses a method for transmitting data identification information in an SDWAN network, comprising the following steps:
[0006] The data packets sent by the terminal to the CPE carry data identification information; the data identification information indicates the type of data content in the data packet.
[0007] When the CPE and / or POP in the SDWAN network are configured to receive data identifiers, the received data packets are parsed to obtain the data identifier information;
[0008] When the CPE and / or POP in the SDWAN network are configured to forward data identifiers, the following security decisions are made: (1) Determine whether the data identifier information carried in the data packet is restricted transmission; if so, remove the data identifier information from the data packet sent to the next-hop POP; (2) Determine whether the next-hop POP is a trusted node; if the next-hop POP is an untrusted node, remove the data identifier information from the data packet sent to the next-hop POP; (3) When the data identifier information carried in the data packet is not restricted transmission and the next-hop POP is a trusted node, carry the data identifier information in the data packet sent to the next-hop POP.
[0009] Furthermore, the SDWAN data packet header includes an extended data identifier field, which is used to represent data identifier information.
[0010] Furthermore, the controller of the SDWAN network sends a list of restricted data identification information transmissions to the CPE and / or POP; the CPE and / or POP determine whether the data identification information carried in the data packet is restricted by querying the list of restricted data identification information transmissions.
[0011] Furthermore, the controller of the SDWAN network sends a list of trusted nodes to the CPE and / or POP, and the CPE and / or POP determines whether the next-hop POP is a trusted node by querying the list of trusted nodes.
[0012] On the other hand, the present invention also discloses a method for detecting data identification information in an SDWAN network, comprising the following steps:
[0013] The controller of the SDWAN network specifies the execution device for the data detection service, which is a CPE or POP in the SDWAN network;
[0014] The data identification information in the SDWAN network is transmitted according to the above-described method for transmitting data identification information in the SDWAN network.
[0015] The data detection service execution equipment collects the IP address, data identification information, data length, and transmission time from the data packets and reports them to the data detection service system.
[0016] Furthermore, the data detection service system collects information reported by the execution device of the data detection service, performs data flow trend analysis, and issues alarms for data transmission exceeding the range.
[0017] On the other hand, the present invention also discloses a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the computer program is loaded onto the processor, it implements the steps of the above-described method for transmitting or detecting data identification information in the SDWAN network.
[0018] On the other hand, the present invention also discloses a computer-readable storage medium storing a plurality of computer instructions, which are used to cause a computer to execute the above-mentioned method for transmitting or detecting data identification information in the SDWAN network.
[0019] Beneficial effects: Compared with the prior art, the data identification information transmission method in the SDWAN network disclosed in this invention has the following advantages:
[0020] 1. By adding a data identification information field to the SDWAN packet header, the type of transmitted data content can be securely and effectively identified, preventing interception in the middle, and enabling flexible detection of data flow.
[0021] 2. During transmission, data identification information is not directly exposed in the traffic, making it impossible to illegally modify or sniff during transmission, thus avoiding unauthorized detection. In network segments where data identification information no longer needs to be transmitted, data identification termination can be set to prevent transmission to uncontrollable network segments. For example, data identification transmission can be terminated at cross-border POP nodes to prevent data identification information from being passed to untrusted third-party POP nodes. Since the CPEs and POPs along the transmission path are trusted, the security of the entire data identification transmission process is guaranteed.
[0022] 3. Within an SDWAN network, the entire transmission process of data identification information does not modify the IP or TCP headers. Security devices such as firewalls cannot intercept such normal packets, effectively ensuring the effective transmission capability of data identification information.
[0023] 4. Specify the execution device for the data detection service, that is, enable the detection and reporting function on the CPE or POP node that needs to detect data identification information. Relying on the relatively complete service capabilities of the SDWAN system, flexible data flow detection capabilities can be achieved. When the terminal communicates with the CPE, the data identification method is notified to the CPE through the IP layer extended header, so that the CPE can flexibly receive external data identification information. Attached Figure Description
[0024] The present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments, and the advantages of the present invention in the above and / or other aspects will become clearer.
[0025] Figure 1 This is a schematic diagram illustrating the expansion of the SDWAN data packet header in an embodiment of the present invention;
[0026] Figure 2 This is a schematic diagram of the header of the GENEVE extended format in an embodiment of the present invention;
[0027] Figure 3 This is a flowchart of the data identification information transmission method in the SDWAN network disclosed in this invention;
[0028] Figure 4 This is a schematic diagram of the node path for data identification information transmission in an embodiment of the present invention;
[0029] Figure 5 This is a flowchart of the method for detecting data identification information in an SDWAN network disclosed in this invention;
[0030] Figure 6 A diagram illustrating the flow of data;
[0031] Figure 7 This is a schematic diagram of the computer device composition disclosed in an embodiment of the present invention. Detailed Implementation
[0032] This invention discloses a method for transmitting data identification information in an SDWAN network. By extending the SDWAN packet header, data identification information is reported from the terminal, and a receive, forward, and terminate mechanism is set up to ensure the secure transmission of data identification information. In this invention, the data identification information is the type of data content in the data packet, such as PII or satellite navigation information, and can be embedded in the SDWAN data packet header for transmission through proprietary protocol encoding. Figure 1As shown, the header of an SDWAN datagram is divided into four groups of 4 bytes (32 bits). The first row on the top right, numbered 0, 1, 2, and 3, represents the unit numbering for each 10-bit unit. The second row, numbered 0-9, represents the numbering for each bit within that 10-bit unit. Combining the numbers in the first and second rows accurately locates the start and end bits of the field. For example, if the start bit for the Protocol field is numbered 0 in the first row and 8 in the second row, then the start bit is 0*10+8=8; if the end bit is numbered 1 in the first row and 5 in the second row, then the end bit is 1*10+5=15. Therefore, the Protocol field is bits 8-15 in the first 4-byte group. The last 4-byte group in the SDWAN datagram header is the Extended Data Type field, which serves as data identification information, used to identify the data type information transmitted in the current session. In this embodiment, the Data Type field is 4 bytes. The value of the Data Type field is defined according to business needs to represent different data types. For example, a Data Type field set to 1 indicates personally identifiable information (PII), and a value set to 2 indicates satellite navigation data. This allows the transmission node to perceive the data type. Furthermore, since SDWAN typically uses encrypted tunnels between CPEs and POPs, and between POPs themselves, the transmission of data identification information is secure and reliable. Figure 2 As shown, the GENEVE extended format used for cross-regional SDWAN interconnection divides the GENEVE header into four groups of four bytes (32 bits). Figure 2 The numbers in the first and second rows at the top right are... Figure 1 The meaning is the same. In the variable GENEVE header, the GENEVE Option Class in the third 4-byte group is Multi-Segment SD-WAN (0x0163), which is implemented by adding a sub-Type definition with a length of 4 bytes. The last 4-byte group Value is a 4-byte bitmap, which serves as data identification information to indicate the specific data type.
[0033] The controller configures the edge devices (CPEs) and access nodes (POPs) to support data identification information according to business needs. Specifically, this includes whether data identification information is supported; if supported, receiving, forwarding, and termination functions are further configured; if not supported, the data identification information is not processed—it is neither received nor forwarded, but directly discarded. When the uplink data stream uploaded by the terminal is transmitted in the SDWAN network and transmitted externally, each device, according to its own configuration, can ensure the secure transmission of data identification information. Figure 3As shown, a method for transmitting data identification information in an SDWAN network includes the following steps:
[0034] S1. The data packet sent by the terminal to the CPE carries data identification information; the data identification information is the type of data content in the data packet;
[0035] When a terminal sends uplink traffic to a CPE, it carries a data identification information field in the IP header extension field to inform the CPE of the data type carried by the traffic. The data type field is carried on a session-stream basis.
[0036] When the terminal communicates with the CPE using an IPv4 address, data identification information is carried through the IPv4 extension field. When the terminal communicates with the CPE using an IPv6 address, data identification information is carried through the IPv6 Destination Options Header extension field. Because the terminal and CPE communicate within an internal network, the extension header will not be intercepted by unknown intermediate network devices, ensuring the secure transmission of data identification information from the terminal to the CPE.
[0037] S2. When the CPE and / or POP in the SDWAN network are configured to receive data identifiers, parse the received data packets to obtain the data identifier information;
[0038] After receiving the data stream from the terminal, the CPE checks its own configuration. If the data identification function status is TRUE, it parses the data identification information from the data stream. After receiving the data stream from the terminal or CPE, the POP performs the same judgment and parses the data identification information.
[0039] S3. When the CPE and / or POP in the SDWAN network are configured to forward data identifiers, the data identifier information is carried in the data packets sent to the next-hop POP.
[0040] The CPE or POP continues to check its own configuration. If the forwarding data identification function status is TRUE, it maps the parsed data identification information to the SDWAN header when sending to the next-hop POP, forming a structure like... Figure 1 The message header is then forwarded to the next hop POP.
[0041] In some business scenarios, the transmission of certain types of data identification information may be restricted. In such cases, when the CPE or POP confirms that its forwarding data identification function status is TRUE, it will further determine whether the data identification information carried in the data packet is restricted from transmission; if so, the data identification information will be stripped from the data packet sent to the next-hop POP. In this embodiment, the controller of the SDWAN network sends a list of restricted data identification information transmissions to the CPE and / or POP; the CPE and / or POP determine whether the data identification information carried in the data packet is restricted from transmission by querying the list. The data identification information restricted transmission list for each CPE and POP can be shared or customized. By setting the data identification information restricted transmission list, the transmission range of specified types of data identification information is restricted, further ensuring the security of data identification information transmission.
[0042] In some business scenarios, sending data identification information to certain receiving nodes may be restricted, such as when untrusted third-party POP nodes need to offload data identification information. In this case, when the CPE or POP confirms that its forwarding data identification function is TRUE, it will further determine whether the next-hop POP is a trusted node. If the next-hop POP is an untrusted node, the data identification information will be stripped from the data packet sent to the next-hop POP. In this embodiment, the SDWAN network controller sends a list of trusted nodes to the CPE and / or POP. The CPE and / or POP determine whether the next-hop POP is a trusted node by querying the list of trusted nodes. Only when the receiving node is in the list of trusted nodes will it carry data identification information in the data packet it sends, further limiting the scope of the data identification information.
[0043] S4. When the CPE and / or POP in the SDWAN network are configured not to forward data identifiers, i.e., to terminate the transmission of data identifiers, the data identifier information is stripped from the data packet sent to the next-hop POP.
[0044] like Figure 4 As shown in the example, when End System A sends data to CPE, it carries data identification information in the IP extension field DataType; the CPE's receive data identification function status and forward data identification function status are both configured as TRUE, and the data identification information is embedded in the SDWAN header when sending data to POP1.
[0045] POP1's receive data identifier and forward data identifier functions are both configured to TRUE. When the outer tunnel is dismantled, it parses and reads the data identifier information, and simultaneously embeds the data identifier information in the SDWAN header when sending data to POP2. POP2's receive data identifier function is TRUE, but its forward data identifier function is configured to FALSE. When the outer tunnel is dismantled, it parses and reads the data identifier information and continues to send data to POP3. At this time, the SDWAN packet header no longer carries the data identifier. POP3 continues to forward data to End System B according to SDWAN rules. CPE, POP1, and POP2 can all sense the data tag information during this packet forwarding process, enabling detection and awareness of data flow. POP2 disables the transmission of data identifier information, implementing the identifier stripping function and effectively limiting the scope of the detection information.
[0046] like Figure 5 As shown, this invention discloses a method for detecting data identification information in an SDWAN network, including the following steps:
[0047] The controller of the SDWAN network specifies the execution device for the data detection service, which is a CPE or POP in the SDWAN network;
[0048] The data identification information in the SDWAN network is transmitted according to the above-described method for transmitting data identification information in the SDWAN network.
[0049] Each execution device for the data detection service generates a data identification bill, which includes the transmission IP, data identification information, data length, and transmission time. The execution device collects and records relevant information from the data packets and reports it to the data detection service system. Specifically, this is done via CPE or POP uploading to the controller, which then sends the data identification detection information to the data detection service system through a RESTful API interface.
[0050] Furthermore, the data detection business system collects information reported by the execution devices of the data detection business, performs data flow trend analysis, such as displaying the transmission density and traffic trends of different identifiers by region, CPE and / or POP nodes, and time dimension, and performs threshold judgment or interfaces with the compliance filing system to issue alarms for data transmission exceeding the scope. Figure 6 The image shows data flow data with user-side IP as the statistical criterion. Through statistical analysis, the types of data identification information received or sent by each user, as well as specific detection information, can be obtained.
[0051] This invention also discloses a computer device, such as... Figure 7As shown, it includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the computer program is loaded onto the processor, it implements the steps of the above-described method for transmitting and detecting data identification information in an SDWAN network.
[0052] This invention also discloses a computer-readable storage medium storing multiple computer instructions, which are used to cause a computer to execute the above-described method for transmitting and detecting data identification information in an SDWAN network.
[0053] This invention provides a concept and method for the transmission and detection of data identification information in an SDWAN network. Many methods and approaches exist for implementing this technical solution; the above description is merely a preferred embodiment of the invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of this invention, and these improvements and modifications should also be considered within the scope of protection of this invention. All components not explicitly stated in this embodiment can be implemented using existing technologies.
Claims
1. A method for transmitting data identification information in an SDWAN network, characterized in that, Including the following steps: The data packets sent by the terminal to the CPE carry data identification information; the data identification information indicates the type of data content in the data packet. When the CPE and / or POP in the SDWAN network are configured to receive data identifiers, the received data packets are parsed to obtain the data identifier information; When the CPE and / or POP in the SDWAN network are configured to forward data identifiers, the following security judgment is performed: (1) Determine whether the data identifier information carried in the data packet is restricted from transmission; If so, remove the data identification information from the data packet sent to the next hop POP; (2) Determine whether the next hop POP is a trusted node. If the next hop POP is an untrusted node, remove the data identification information from the data packet sent to the next hop POP. (3) When the data identification information carried in the data packet does not belong to the restricted transmission and the next-hop POP is a trusted node, the data identification information is carried in the data packet sent to the next-hop POP.
2. The method of claim 1, wherein, The SDWAN data packet header includes an extended data identifier field, which is used to represent data identifier information.
3. The method of claim 1, wherein, The controller of the SDWAN network sends a list of restricted data identification information transmissions to the CPE and / or POP; the CPE and / or POP determine whether the data identification information carried in the data packet is restricted by querying the list of restricted data identification information transmissions.
4. The method of claim 1, wherein, The controller of the SDWAN network sends a list of trusted nodes to the CPE and / or POP. The CPE and / or POP determine whether the next-hop POP is a trusted node by querying the list of trusted nodes.
5. A method for detecting data identification information in an SDWAN network, the method comprising: Including the following steps: The controller of the SDWAN network specifies the execution device for the data detection service, which is a CPE or POP in the SDWAN network; The method described in any one of claims 1-4 is used to transmit data identification information in an SDWAN network; The data detection service execution equipment collects the IP address, data identification information, data length, and transmission time from the data packets and reports them to the data detection service system.
6. The method of claim 5, wherein the SDWAN network is a network of a service provider. The data detection service system collects information reported by the execution devices of the data detection service, performs data flow trend analysis, and issues alarms for data transmission outside the permitted range.
7. A computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the computer program is loaded into the processor, it implements the steps of the transmission method according to any one of claims 1-4 or the detection method according to any one of claims 5-6.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a plurality of computer instructions, which are used to cause a computer to perform the transmission method of any one of claims 1-4 or the detection method of any one of claims 5-6.