TRANSMISSION METHOD AND DEVICE, PACKAGE-SENDING DEVICE AND RECEIVING DEVICE

DE602019080989T2Active Publication Date: 2026-01-28ZTE CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE602019080989
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2018-12-24
Filing Date
2019-12-10
Publication Date
2026-01-28
Estimated Expiration
2039-12-10

AI Technical Summary

Technical Problem

The existing IPSec protocol is unable to meet the high-flow encryption and decryption processing capabilities required by 5G networks due to limited processing capacity of encryption chips and the use of a single security tunnel for user plane data, which results in difficulty in handling diverse service types.

Method used

Implementing a method that extends the IPSec standard protocol by using negotiation attribute information, such as DSCP, UE IP, or TEID, to establish multiple security tunnels based on service characteristics, allowing for differentiated packet handling and improved processing capacity.

Benefits of technology

This approach enhances the IPSec processing capability by distributing packets of different types of services to different tunnels, effectively meeting the encryption requirements of 5G high-flow services.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The embodiments of the present disclosure relate to, but are not limited to, the field of communication technology.BACKGROUND

[0002] With the development of the Internet and mobile communication, various network security problems have arisen. Network security has become a concern of every user, government, network service provider and device manufacturer, and the capability to guarantee network security has become one of the basic capabilities that each company should have.

[0003] So far the development of network security has produced relatively mature frameworks and theories and involved many scenarios and methods, such as cryptography, infrastructure security, access control, authentication management, transmission security, and sensitive data protection. The transmission security is a main technology for ensuring confidentiality and integrity of data transmission in an untrusted network environment, and the representative techniques of transmission security include Secure Socket Layer / Transport Layer Security (SSL / TLS), Internet Protocol Security (IPSec), etc. The IPSec can solve security problems of network layer and thus is recommended as a secure transmission protocol (3GPP TS33.310) between a base station and a core network by standard organizations such as the 3rd Generation Partnership Project (3GPP).

[0004] Radio Access Network (RAN) is a very important component in wireless communication. With the coming of the fifth generation (5G) network, the current network security protocols such as the IPSec are facing tremendous challenges.

[0005] At present, user plane data from a base station to a core network are generally carried in the same IPSec security tunnel, and the processing capacity of an encryption chip is limited, so that the encryption requirements of 5G high-flow services cannot be met.

[0006] The Chinese Patent CN 102098207 B discloses a method that includes transmitting a differentiated services code point (DSCP) priority value of a start node to a response node; receiving response node DSCP priority value information, matched with the DSCP priority value of the start node, fed back by the response node; acquiring security association (SA) associated with the response node according to the response node DSCP priority value information; and establishing the IPSec channel with the response node by utilizing the SA. The method solves the problem of packet loss caused by using the same SA in the application of different DSCP priority values and improves the quality of security (QoS) of a network.

[0007] The Chinese Patent CN 105812322 B discloses a method for establishing an Internet security protocol security alliance, which can realize that the operator provides the IP spaces which can be independently programmed to various logic devices on the basis of the VRF identifier, provides a fully isolate IPSec protection function and realizes the flow distinguishing between various companies. Besides, one IP address is adopted to protect the flows of multiple companies in order to save the IP address source of the public network.

[0008] The Document ZOLTAN FAIGL "IPsec, IKEv2 and their use in Mobile IPv6", filed on INTERNET CITATION 1 June 2007, pages 1-42, XP002578342, discloses the operation of Internet Security Protocol (IPsec) and Internet Key Exchange Protocol version 2 (IKEv2), and especially, describes their use when protecting Mobile IPv6 (MIPv6) signaling. IPsec and IKEv2 can basically be used in the same way, with any other signaling protocol or data, which they protect. However, it is the security policies and configurations which will vary in function of the information sensitivity that they protect.SUMMARY

[0009] A summary of the subject matter described in detail herein is given below, but the summary is not intended to limit the protection scope of the claims.

[0010] The embodiments of the present disclosure provide a transmission method, a transmission device, a packet transmitting terminal, and a packet receiving terminal.

[0011] The invention is set out in the appended set of claims.BRIEF DESCRIPTION OF THE DRAWINGS

[0012] Fig. 1 is a schematic diagram of a typical network when a base station starts up an IPSec function. Fig. 2 is a schematic diagram illustrating standard IPSec security tunnel negotiation. Fig. 3 is a flowchart illustrating a transmission method (applied to a packet transmitting terminal) according to the present disclosure. Fig. 4 is a flowchart illustrating a transmission method (applied to a packet transmitting terminal) according to the present disclosure. Fig. 5 is a flowchart of step 301 according to the present disclosure. Fig. 6 is a flowchart of step 302 according to the present disclosure. Fig. 7 is a flowchart illustrating a transmission method (applied to a packet transmitting terminal) according to the present disclosure. Fig. 8 is a flowchart illustrating a transmission method according to the present disclosure. Fig. 9 is a schematic diagram illustrating attribute SA negotiation and packet transmission of an IPSec initiator according to the present disclosure. Fig. 10 is a schematic diagram illustrating attribute SA negotiation and packet transmission of an IPSec responder according to the present disclosure. Fig. 11 is a comparison diagram of a conventional IPSec device and an IPSec device equipped with attribute SA negotiation. Fig. 12 is a flowchart illustrating a transmission method (applied to a packet receiving terminal) according to the present disclosure. Fig. 13 is a flowchart illustrating a transmission method (applied to a packet receiving terminal) according to the present disclosure. Fig. 14 is a schematic diagram of a transmission device (applied to a packet transmitting terminal) according to the present disclosure. Fig. 15 is a schematic diagram of a transmission device (applied to a packet receiving terminal) according to the present disclosure. Fig. 16 is a schematic diagram of a packet transmitting terminal according to the present disclosure. Fig. 17 is a schematic diagram of a packet receiving terminal according to the present disclosure. DETAILED DESCRIPTION

[0013] The embodiments of the present disclosure are described in detail below with reference to the accompanying drawings.

[0014] The steps illustrated in the flowcharts of the drawings may be performed in a computer system such as a set of computer-executable instructions. In addition, although a logical order is illustrated in the flowchart, the steps illustrated or described may be performed in an order different from that described herein in some cases.

[0015] The IPSec is a protocol cluster, a control negotiation protocol of the IPSec is Internet Key Exchange (IKE), a current main version of the IKE is IKEv2, and a data encapsulation protocol of the IPSec is based on an Encapsulating Security Payload (ESP) protocol. The IKE protocol negotiates a Security Association (SA) based on a five-tuple (a source Internet protocol (IP) address, a destination IP address, a protocol number, a source port, and a destination port), different types of services are assigned to different SAs, and one SA generally corresponds to one IPSec tunnel. The IPSec protocol has been well deployed and operated for a long time.

[0016] With the coming of 5G, the IPSec protocol has been gradually unable to meet the requirements of services. The network architecture of a 5G base station is merely slightly different from that of a 4G base station, and adopts flat base stations and core networks, and user plane data are carried in general packet radio service (GPRS) tunneling protocol user plane (GTPU) tunnels from the base stations to the core networks. However, with the downstream flow up to 40Gbps and the upstream flow up to 20Gbps, the flow of a single 5G base station far exceeds that of a 4G base station. In most cases, a base station configures only one user plane IP address, a user plane gateway of a core network corresponding to the base station also has only one IP address, and the user plane data between the base station and the core network have only one five-tuple, that is, the same source IP address, destination IP address, protocol number (UDP, User Datagram Protocol), source port, and destination port. Limited by IPSec sequence numbers (SNs) and a sliding window mechanism (see RFC2406: 3.4.3 Sequence Number Verification), the user plane data from a base station to a core network are carried in the same IPSec security tunnel in most cases according to the current IPSec protocol.

[0017] At present, encryption and decryption of data are realized by using internal encryption chips in most IPSec solutions, and all the solutions of the chips to a single security tunnel focus on a single core or a single encryption engine. It is difficult to process the data of the same SA among different cores, different central processing units (CPUs) or different boards, and a single encryption chip has limited processing capacity, which makes it hard to realize high-flow encryption and decryption processing capabilities.

[0018] As shown in Fig. 1 which is a schematic diagram of a typical network when a base station starts up an IPSec function, a base station 101 encrypts a packet, and sends the encrypted packet to a security gateway 102 through an IPSec security tunnel, the security gateway 102 decrypts the received encrypted packet, and sends the obtained plaintext to an element management system (EMS) 103, and an evolved packet core (EPC, a 4G core network) / next generation core (NG-Core, a 5G core network) 104.

[0019] As shown in Fig. 2, taking an IPSec initiator being a packet transmitting terminal as an example, a standard IPSec security tunnel negotiation includes the following steps 201 to 204.

[0020] In the step 201, an IPSec initiator negotiates with an IPSec responder to obtain an SA according to a five-tuple of IKE.

[0021] In the step 202, the IPSec initiator receives a to-be-transmitted packet sent by another network element.

[0022] In the step 203, the IPSec initiator matches the packet with the current five-tuple, and the packet is encrypted by the corresponding SA, and sent to an IPSec security tunnel corresponding to the SA.

[0023] In the step 204, the IPSec responder receives the packet, and decrypts the packet according to an IP address and a matched Security Parameter Index (SPI).

[0024] For sending a packet to the IPSec initiator, the IPSec responder can also negotiate with the IPSec initiator for an SA. The negotiation process of the IPSec responder is similar to that shown in Fig. 2 and is not repeated here. That is, a pair of SAs (corresponding to an upstream direction and a downstream direction respectively) is used for packet transmission between the IPSec initiator and the IPSec responder.

[0025] The present disclosure put forward a high-traffic and single-tunnel IPSec solution for 5G, etc., which makes some extensions to the IPSec standard protocol under the condition of being compatible with the IPSec standard protocol.

[0026] As shown in Fig. 3, a transmission method according to an embodiment of the present disclosure is applied to a packet transmitting terminal, and includes steps 301 and 302.

[0027] In the step 301, a packet transmitting terminal negotiates with a packet receiving terminal using five-tuple information and negotiation attribute information to determine an IPSec security tunnel.

[0028] The packet transmitting terminal is an IPSec initiator, and the packet receiving terminal is an IPSec responder; or the packet transmitting terminal is an IPSec responder, and the packet receiving terminal is an IPSec initiator.

[0029] The IPSec initiator includes, but is not limited to, a hardware device such as a wireless base station (including a 2G base station, a 3G base station, a 4G base station, a 5G base station, etc.) and a set-top box, and may further include a general software module.

[0030] The IPSec responder includes, but is not limited to, a security gateway and a wireless base station, and may further include a general software module.

[0031] The five-tuple information includes a source IP address, a destination IP address, a protocol number, source port information, and destination port information.

[0032] The negotiation attribute information may be related to characteristics of services.

[0033] In some implementations, the negotiation attribute information is related to a type of service of a packet, and is configured to distinguish the service information except the five-tuple information. Different negotiation attribute information can be used to negotiate different security tunnels and allocate service data of different packets to different security tunnels.

[0034] In some implementations, the negotiation attribute information includes one of the following information: type of service, type of service and length, and type of service, length and value.

[0035] The type of service (Type) may be distinguished according to specific services, and may be an enumerated value (e.g. 1, 2, 3...) pre-defined by both the packet transmitting terminal and the packet receiving terminal, or a specific type of service, such as a Differentiated Services Code Point (DSCP), a User Equipment (UE) IP address, and a Tunnel Endpoint Identifier (TEID). The length (Length) is a length of a type-of-service parameter. The value (Value) is a value or range corresponding to the type of service, for example, the Quality of Service (QoS) is in a range of 36 to 46.

[0036] In some implementations, before the step 301, the method further includes that the packet transmitting terminal determines to start up an attribute SA negotiation function. It is possible that it is the network administrator who determines to start up the attribute SA negotiation function. The network administrator or packet transmitting terminal can determine to start up the attribute SA negotiation function according to current flow, packet characteristics, etc.

[0037] As shown in Fig. 4, in some implementations, the method further includes step 401 before the step 301, the step 401 being that the packet transmitting terminal determines a type of service in the negotiation attribute information according to the identification information carried in a packet to be sent.

[0038] In some implementations, the step that the packet transmitting terminal determines the type of service in the negotiation attribute information according to the identification information carried in the packet to be sent includes at least one of the following steps: in the case where the packet to be sent is an IP packet and the identification information includes DSCP information in the IP packet, the packet transmitting terminal takes the DSCP information as the type of service in the negotiation attribute information; in the case where the packet to be sent is a GTPU packet and the identification information includes a UE IP address in the GTPU packet, the packet transmitting terminal takes the UE IP address as the type of service in the negotiation attribute information; and in the case where the packet to be sent is a GTPU packet and the identification information includes a TEID in the GTPU packet, the packet transmitting terminal takes the TEID as the type of service in the negotiation attribute information.

[0039] That is, the negotiation attribute information may include some fields in the network packet, such as a DSCP field in the IP packet, a UE IP field in the GTPU packet, and a TEID field in the GTPU packet, and the related IP may include Internet Protocol Version 4 (IPv4) and (Internet Protocol Version 6, Internet Protocol Version 6 (IPv6).

[0040] In some implementations, the step 301 includes that, when the packet transmitting terminal fails to use the negotiation attribute information to negotiate with the packet receiving terminal or the packet receiving terminal does not support the use of the negotiation attribute information in negotiation, the packet transmitting terminal negotiates with the packet receiving terminal using the five-tuple information to determine a default SA, which corresponds to an IPSec security tunnel.

[0041] When the packet transmitting terminal negotiates with the packet receiving terminal, according to the standard IPSec protocol, the default SA is set up through Traffic Selector (TS) negotiation according to the five-tuple information.

[0042] If the packet receiving terminal does not support attribute SA negotiation or the attribute SA negotiation between the packet transmitting terminal and the packet receiving terminal fails, the packet transmitting terminal associates all packets with the default SA by default and sends the packets only through a default security tunnel.

[0043] As shown in Fig. 5, in some implementations, the step 301 includes steps 501 and 502.

[0044] In the step 501, the packet transmitting terminal negotiates with the packet receiving terminal using the five-tuple information to determine a default SA, which corresponds to an IPSec security tunnel.

[0045] When the packet transmitting terminal negotiates with the packet receiving terminal, according to the standard IPSec protocol, the default SA is set up through TS negotiation according to the five-tuple information.

[0046] In the step 502, the packet transmitting terminal negotiates with the packet receiving terminal using the five-tuple information and the negotiation attribute information to determine one or more attribute SAs, each of which corresponds to one IPSec security tunnel.

[0047] The packet transmitting terminal sets up the attribute SA according to the five-tuple information and the negotiation attribute information. A plurality pieces of negotiation attribute information may exist, each piece of negotiation attribute information can be used for negotiation to set up one attribute SA, and each attribute SA corresponds to one IPSec security tunnel.

[0048] In the step 302, the packet transmitting terminal sends a packet to the packet receiving terminal through the IPSec security tunnel.

[0049] As shown in Fig. 6, in some implementations, the step 302 includes steps 601 to 603.

[0050] In the step 601, the packet transmitting terminal classifies a packet to be sent according to the five-tuple information and the negotiation attribute information.

[0051] In the step 602, when the packet matches the five-tuple information and the negotiation attribute information, the packet is associated with a corresponding attribute SA, and is sent to the packet receiving terminal through an IPSec security tunnel corresponding to the attribute SA.

[0052] The packet transmitting terminal classifies different types of packets according to the characteristics of the packets, the five-tuple information, and the negotiation attribute information, associates the packets with the attribute SAs, and sends the packets to different attribute security tunnels.

[0053] In the step 603, when the packet matches the five-tuple information but does not match the negotiation attribute information, the packet is associated with the default SA, and is sent to the packet receiving terminal through the IPSec security tunnel corresponding to the default SA.

[0054] With more security tunnels being set up through the negotiation using the negotiation attribute, packets of different types of services can be distributed to different tunnels, so that the IPSec processing capability of a device or system can be improved.

[0055] As shown in Fig. 7, in some implementations, the method further includes steps 701 and 702.

[0056] In the step 701, the packet transmitting terminal monitors a state of each SA, the SA including at least one of the default SA and the attribute SA.

[0057] In some implementations, the state of the SA includes at least one of utilization of a CPU core where the SA is located, and network traffic of the IPSec security tunnel corresponding to the SA.

[0058] In the step 702, the packet transmitting terminal sends an adjustment request to the packet receiving terminal according to the state of the SA, and negotiates with the packet receiving terminal to adjust an association relationship between the negotiation attribute information and an attribute SA.

[0059] In some implementations, the packet transmitting terminal sends the adjustment request to the packet receiving terminal according to the state of the SA and a load balancing algorithm. The load balancing algorithm may be polling, weighting, etc. To adjust the association relationship between the negotiation attribute information and the attribute SA is to adjust the association relationships between the different types of packets and the attribute SAs. For example, adjusting a range of a value in the negotiation attribute information is equivalent to adjusting the association relationships between the different types of packets and the attribute SAs.

[0060] According to the present disclosure, the negotiation attribute information is used to determine the IPSec security tunnels, so that the distribution of packets can be realized, the IPSec processing capability can be improved, and the encryption requirements of the 5G high-flow services can be met.

[0061] As shown in Fig. 8 which is a flowchart illustrating a transmission method according to an example, the transmission method includes steps 801 to 810.

[0062] In the step 801, whether to initiate an attribute SA negotiation is determined according to a current application, if yes, the step 803 is to be performed, otherwise the step 802 is to be performed.

[0063] It is possible that it is the network administrator who controls the initiation of the attribute SA negotiation.

[0064] In the step 802, a standard IPSec process is performed.

[0065] In the step 803, a default SA and an attribute SA are configured according to five-tuple information and negotiation attribute information.

[0066] In the step 804, the default SA and the attribute SA are negotiated.

[0067] In the step 805, it is determined whether the attribute SA negotiation succeeds, if yes, the step 806 is to be performed, otherwise the step 808 is to be performed.

[0068] In the step 806, different types of packets are matched with different SAs (including the default SA and the attribute SA).

[0069] In the step 807, the packets are allocated to the IPSec tunnels corresponding to the default SA and the attribute SA, and then the step 810 is to be performed.

[0070] In the step 808, the packets are directly matched with the default SA.

[0071] In the step 809, the packets are allocated to an IPSec security tunnel corresponding to the default SA.

[0072] In the step 810, the packets are sent.

[0073] As shown in Fig. 9, the attribute SA negotiation and packet transmission of an IPSec initiator includes steps 901 to 904.

[0074] In the step 901, a default SA is negotiated according to five-tuple information.

[0075] In the step 902, attributes SA1 to SAn are negotiated according to attributes.

[0076] In the step 903, packets are sent.

[0077] All of the packets that cannot match the negotiation attributes but can match the five-tuple are distributed to a security tunnel queue corresponding to the default SA; the packets matched with the attribute SA1 are distributed to a security tunnel corresponding to the SA1; the packets matched with the attribute SA2 are distributed to a security tunnel corresponding to the SA2; ...; and the packets matched with the attribute SAn are distributed to a security tunnel corresponding to the SAn.

[0078] In the step 904, after a responder receives a packet, the responder decrypts the packet according to an IP address and a matched SPI.

[0079] As shown in Fig. 10, similar to Fig. 9, the attribute SA negotiation and packet transmission of an IPSec responder includes steps 1001 to 1004.

[0080] In the step 1001, a default SA is negotiated according to five-tuple information.

[0081] In the step 1002, attributes SA1 to SAn are negotiated according to attributes.

[0082] In the step 1003, packets are sent.

[0083] All of the packets that cannot match the negotiation attributes but can match the five-tuple are distributed to a security tunnel queue corresponding to the default SA; the packets matched with the attribute SA1 are distributed to a security tunnel corresponding to the SA1; the packets matched with the attribute SA2 are distributed to a security tunnel corresponding to the SA2; ...; and the packets matched with the attribute SAn are distributed to a security tunnel corresponding to the SAn.

[0084] In the step 1004, after an initiator receives a packet, the initiator decrypts the packet according to an IP address and a matched SPI.

[0085] It should be noted that each SA illustrated by Fig. 9 corresponds to a direction from the IPSec initiator to the IPSec responder, each SA illustrated by Fig. 10 corresponds to a direction from the IPSec responder to the IPSec initiator, and the direction illustrated by Fig. 9 is different from that illustrated by Fig. 10.

[0086] As shown in Fig. 11 which is a comparison diagram of a conventional IPSec device and an IPSec device equipped with attribute SA negotiation, the conventional IPSec device includes an IKE protocol module, an ESP protocol module, a Security Policy Database (SPD) module, a Security Association Database (SAD) module, and other protocol modules. Compared with the conventional IPSec device, the IPSec device equipped with attribute SA negotiation further includes an attribute SA switch module, an attribute classification configuration module, an attribute SA module, and a packet classification algorithm module.

[0087] The attribute SA switch module is configured to control whether to start up an attribute SA negotiation function. The attribute classification configuration module is configured to configure negotiation attribute information. The attribute SA module is configured to configure an attribute SA. The packet classification algorithm module is configured to classify packets according to the negotiation attribute information.

[0088] As shown in Fig. 12, corresponding to the packet transmitting terminal, a transmission method of the packet receiving terminal according to an embodiment of the present disclosure includes steps 1201 and 1202.

[0089] In the step 1201, the packet receiving terminal negotiates with the packet transmitting terminal according to the five-tuple information and the negotiation attribute information sent by the packet transmitting terminal to determine an IPSec security tunnel.

[0090] The packet transmitting terminal is an IPSec initiator, and the packet receiving terminal is an IPSec responder; or the packet transmitting terminal is an IPSec responder, and the packet receiving terminal is an IPSec initiator.

[0091] The IPSec initiator includes, but is not limited to, a hardware device such as a wireless base station (including a 2G base station, a 3G base station, a 4G base station, a 5G base station, etc.) and a set-top box, and may further include a general software module.

[0092] The IPSec responder includes, but is not limited to, a security gateway and a wireless base station, and may further include a general software module.

[0093] The five-tuple information includes a source IP address, a destination IP address, a protocol number, source port information, and destination port information.

[0094] The negotiation attribute information may be related to characteristics of services.

[0095] In some implementations, the negotiation attribute information is related to a type of service of a packet, and is configured to distinguish the service information except the five-tuple information. Different negotiation attribute information can be used to negotiate different security tunnels.

[0096] In some implementations, the negotiation attribute information includes one of the following information: type of service, type of service and length, and type of service, length and value. The type of service (Type) may be distinguished according to specific services, and may be an enumerated value (e.g. 1, 2, 3...) pre-defined by both the packet transmitting terminal and the packet receiving terminal, or a specific type of service, such as a DSCP, a UE IP address, and a TEID. The length (Length) is a length of a type-of-service parameter. The value (Value) is a value or range corresponding to the type of service, for example, the QoS is in a range of 36 to 46.

[0097] In some implementations, the step 1201 includes that, when the negotiation with the packet transmitting terminal according to the negotiation attribute information fails or the packet receiving terminal does not support the use of the negotiation attribute information in negotiation, the packet receiving terminal negotiates with the packet transmitting terminal using the five-tuple information to determine a default SA, which corresponds to an IPSec security tunnel.

[0098] In some implementations, the step 1201 includes that the packet receiving terminal negotiates with the packet transmitting terminal according to the five-tuple information to determine a default SA, which corresponds to an IPSec security tunnel; and the packet receiving terminal negotiates with the packet transmitting terminal according to the five-tuple information and the negotiation attribute information to determine one or more attribute SAs, each of which corresponds to one IPSec security tunnel.

[0099] In the step 1202, the packet receiving terminal receives a packet sent by the packet transmitting terminal through the IPSec security tunnel.

[0100] According to the classification of the packets of different types of services, the packet receiving terminal receives the packets through corresponding IPSec security tunnels.

[0101] With more security tunnels being set up through the negotiation using the negotiation attribute, the packets of different types of services can be distributed to different tunnels, so that the IPSec processing capability of a device or system can be improved.

[0102] As shown in Fig. 13, in some implementations, the method further includes step 1301.

[0103] In the step 1301, the packet receiving terminal negotiates with the packet transmitting terminal according to the adjustment request sent by the packet transmitting terminal to adjust the association relationship between the negotiation attribute information and the attribute SA.

[0104] To adjust the association relationship between the negotiation attribute information and the attribute SA is to adjust the association relationships between different types of packets and the attribute SAs. For example, adjusting a range of a value in the negotiation attribute information is equivalent to adjusting the association relationships between the different types of packets and the attribute SAs.

[0105] According to the present disclosure, the negotiation attribute information is used to determine the IPSec security tunnels, so that the distribution of packets can be realized, the IPSec processing capability can be improved, and the encryption requirements of the 5G high-flow services can be met.

[0106] Some application instances are given below to illustrate the present disclosure.

[0107] Application Instance 1 (a base station negotiates with a security gateway, and a TEID of a GTPU packet is used as a negotiation attribute.) 1. An attribute SA negotiation function is started up when the current flow of the base station exceeds an IPSec single-core flow specification or IPSec single-tunnel flow specification. 2. When the base station functioned as an IPSec initiator negotiates with a security gateway functioned as an IPSec responder for an IPSec tunnel, in addition to five-tuple information, TEID information of a GTPU packet is further carried as negotiation attribute information. The negotiation attribute information consists of a type, a length, and a value, etc., the type is configured to be a TEID, the length is a length of a TEID field in the GTPU packet, and the value is a TEID value and usually configured to be a range of TEID value. 3. When the base station negotiates with the security gateway, according to the standard IPSec protocol, a pair of default SAs (corresponding to two directions) is set up through TS negotiation according to the five-tuple information, and each default SA corresponds to one security tunnel. 4. The base station sets up an attribute SA according to the five-tuple information and the configuration of the range of TEID, each TEID field can be used to negotiate one attribute SA, and each attribute SA corresponds to one security tunnel. 5. The base station classifies different packets according to characteristics of data packets, the five-tuple information and the TEID values, associates the packets with corresponding attribute SAs (set up according to the ranges of the TEID values), and sends the packets to different attribute security tunnels. 6. The base station monitors states of a current default SA and each attribute SA, adjusts association relationships between different types of packets and the attribute SAs according to a certain load balancing algorithm (such as polling or weighting), and ensures that the packets having the same attribute are processed in the same attribute SA, and the state of the SA includes utilization of a CPU core where the current SA is located, network traffic, etc. 7. If the security gateway does not support attribute SA negotiation or the attribute SA negotiation between the base station and the security gateway fails, the base station associates all the packets with the default SA by default, and sends the packets through the default security tunnel.

[0108] A process of setting up SAs by the security gateway with the base station is identical to the above process.

[0109] With more security tunnels being set up through the negotiation using the negotiation attribute, packets of different types of services can be distributed to different tunnels, so that the IPSec processing capability of a device or system can be improved.

[0110] Application Instance 2 (a base station negotiates with a security gateway, and a DSCP of a packet is used as a negotiation attribute.) 1. An attribute SA negotiation function is started up when the current flow of the base station exceeds an IPSec single-core flow specification or IPSec single-tunnel flow specification. 2. When the base station functioned as an IPSec initiator negotiates with a security gateway functioned as an IPSec responder for an IPSec tunnel, in addition to five-tuple information, DSCP information of an inner packet of a GTPU tunnel is further carried as negotiation attribute information. The negotiation attribute information consists of a type, a length, and a value, etc., the type is configured to be a DSCP, the length is a length of a DSCP field in the GTPU packet, and the value is a DSCP value and usually configured to be in a range. 3. When the base station negotiates with the security gateway, according to the standard IPSec protocol, a pair of default SAs is set up through TS negotiation according to the five-tuple information, and each default SA corresponds to one security tunnel. 4. The base station sets up an attribute SA according to the five-tuple information and the configuration of the range of DSCP, each DSCP field can be used to negotiate one attribute SA, and each attribute SA corresponds to one security tunnel. 5. The base station classifies different packets according to characteristics of data packets, the five-tuple information and the DSCP values, associates the packets with corresponding attribute SAs (set up according to the ranges of the DSCP values), and sends the packets to different attribute security tunnels. 6. The base station monitors states of a current default SA and each attribute SA, adjusts association relationships between different types of packets and the attribute SAs according to a certain load balancing algorithm (such as polling or weighting), and ensures that the packets having the same attribute are processed in the same attribute SA, and the state of the SA includes utilization of a CPU core where the current SA is located, network traffic, etc. 7. If the security gateway does not support attribute SA negotiation or the attribute SA negotiation between the base station and the security gateway fails, the base station associates all the packets with the default SA by default, and sends the packets through the default security tunnel.

[0111] A process of setting up SAs by the security gateway with the base station is identical to the above process.

[0112] With more security tunnels being set up through the negotiation using the negotiation attribute, the packets of different types of services can be distributed to different tunnels, so that the IPSec processing capability of a device or system can be improved.

[0113] Application Instance 3 (a base station A negotiates with a base station B, and a UE IP of a GTPU packet is used as a negotiation attribute.) 1. An attribute SA negotiation function is started up when the current flow of the base station exceeds an IPSec single-core flow specification or IPSec single-tunnel flow specification. 2. When a base station A functioned as an IPSec initiator negotiates with a base station B functioned as an IPSec responder for an IPSec tunnel, in addition to five-tuple information, UE IP information of a GTPU packet is further carried as negotiation attribute information. The negotiation attribute information consists of a type, a length, and a value, the type is configured to be a UE IP, the length is a length of a UE IP field in the GTPU packet, the value is a UE IP value and usually configured to be a range of UE IP value, and the related IP may be IPv4 or IPv6. 3. When the base station A negotiates with the base station B, according to the standard IPSec protocol, a pair of default SAs is set up through TS negotiation according to the five-tuple information, and each default SA corresponds to one security tunnel. 4. The base station A sets up an attribute SA according to the five-tuple information and the configuration of the range of UE IP, each UE IP field can be used to negotiate one attribute SA, and each attribute SA corresponds to one security tunnel. 5. The base station A classifies different packets according to characteristics of data packets, the five-tuple information and the UE IP values, associates the packets with corresponding attribute SAs (set up according to the ranges of the UE IP values), and sends the packets to different attribute security tunnels. 6. The base station A monitors states of a current default SA and each attribute SA, adjusts association relationships between different types of packets and the attribute SAs according to a certain load balancing algorithm (such as polling or weighting), and ensures that the packets having the same attribute are processed in the same attribute SA, and the state of the SA includes utilization of a CPU core where the current SA is located, network traffic, etc. 7. If the base station B does not support attribute SA negotiation or the attribute SA negotiation between the base station A and the base station B fails, the base station A associates all the packets with the default SA by default, and sends the packets through the default security tunnel.

[0114] A process of setting up SAs by the base station B with the base station A is identical to the above process.

[0115] With more security tunnels being set up through the negotiation using the negotiation attribute, the packets of different types of services can be distributed to different tunnels, so that the IPSec processing capability of a device or system can be improved.

[0116] Application Instance 4 (a set-top box negotiates with a security gateway, and a DSCP of a packet is used as a negotiation attribute.) 1. An attribute SA negotiation function is started up when the current flow of the set-top box exceeds an IPSec single-core flow specification or IPSec single-tunnel flow specification. 2. When the set-top box functioned as an IPSec initiator negotiates with a security gateway functioned as an IPSec responder for an IPSec tunnel, in addition to five-tuple information, DSCP information of an inner packet of a packet is further carried as negotiation attribute information. The negotiation attribute information consists of a type, a length, and a value, the type is configured to be a DSCP, the length is a length of a DSCP field (6 bits), and the value is a DSCP value and usually configured to be in a range. 3. When the set-top box negotiates with the security gateway, according to the standard IPSec protocol, a pair of default SAs is set up through TS negotiation according to the five-tuple information, and each default SA corresponds to one security tunnel. 4. The set-top box sets up an attribute SA according to the five-tuple information and the configuration of the range of DSCP, each DSCP field can be used to negotiate one attribute SA, and each attribute SA corresponds to one security tunnel. 5. The set-top box classifies different packets according to characteristics of data packets, the five-tuple information and the DSCP values, associates the packets with corresponding attribute SAs (set up according to the ranges of the DSCP values), and sends the packets to different attribute security tunnels. 6. The set-top box monitors states of a current default SA and each attribute SA, adjusts association relationships between different types of packets and the attribute SAs according to a certain load balancing algorithm (such as polling or weighting), and ensures that the packets having the same attribute are processed in the same attribute SA, and the state of the SA includes utilization of a CPU core where the current SA is located, network traffic, etc. 7. If the security gateway does not support attribute SA negotiation, the set-top box associates all the packets with the default SA by default, and sends the packets through the default security tunnel.

[0117] A process of setting up SAs by the security gateway with the set-top box is identical to the above process.

[0118] With more security tunnels being set up through the negotiation using the negotiation attribute, the packets of different types of services can be distributed to different tunnels, so that the IPSec processing capability of a device or system can be improved.

[0119] As shown in Fig. 14, an embodiment of the present disclosure further provides a transmission device applied to a packet transmitting terminal, including a first negotiation module 1401 configured to negotiate with a packet receiving terminal using five-tuple information and negotiation attribute information to determine an IPSec security tunnel; and a transmitting module 1402 configured to send a packet to the packet receiving terminal through the IPSec security tunnel.

[0120] In some implementations, the five-tuple information includes a source IP address, a destination IP address, a protocol number, source port information, and destination port information.

[0121] The negotiation attribute information is related to a type of service of the packet.

[0122] In some implementations, the negotiation attribute information includes one of the following information: type of service, type of service and length, and type of service, length and value.

[0123] In some implementations, the device further includes a determination module configured to determine a type of service in the negotiation attribute information according to the identification information carried in a packet to be sent.

[0124] In some implementations, the determination module is configured to take DSCP information as the type of service in the negotiation attribute information in the case where the packet to be sent is an IP packet and the identification information includes the DSCP information in the IP packet, or take an UE IP address as the type of service in the negotiation attribute information in the case where the packet to be sent is a GTPU packet and the identification information includes the UE IP address in the GTPU packet, or take a TEID as the type of service in the negotiation attribute information in the case where the packet to be sent is a GTPU packet and the identification information includes the TEID in the GTPU packet.

[0125] In some implementations, the first negotiation module 1401 is configured to negotiate with the packet receiving terminal using the five-tuple information to determine a default SA which corresponds to an IPSec security tunnel when the negotiation with the packet receiving terminal according to the negotiation attribute information fails or the packet receiving terminal does not support the use of the negotiation attribute information in negotiation.

[0126] In some implementations, the first negotiation module 1401 is configured to negotiate with the packet receiving terminal using the five-tuple information to determine a default SA which corresponds to an IPSec security tunnel, and negotiate with the packet receiving terminal using the five-tuple information and the negotiation attribute information to determine one or more attribute SAs, each of which corresponds to one IPSec security tunnel.

[0127] In some implementations, the transmitting module 1402 is configured to classify a packet to be sent according to the five-tuple information and the negotiation attribute information; when the packet matches the five-tuple information and the negotiation attribute information, the transmitting module 1402 associates the packet with a corresponding attribute SA, and sends the packet to the packet receiving terminal through an IPSec security tunnel corresponding to the attribute SA; or, when the packet matches the five-tuple information but does not match the negotiation attribute information, the transmitting module 1402 associates the packet with the default SA, and sends the packet to the packet receiving terminal through the IPSec security tunnel corresponding to the default SA.

[0128] In some implementations, the device further includes a monitoring and adjusting module configured to monitor a state of each SA, the SA including at least one of the default SA and the attribute SA, send an adjustment request to the packet receiving terminal according to the state of the SA, and negotiate with the packet receiving terminal to adjust an association relationship between the negotiation attribute information and the attribute SA.

[0129] In some implementations, the state of the SA includes at least one of utilization of a CPU core where the SA is located, and network traffic of the IPSec security tunnel corresponding to the SA.

[0130] In some implementations, the monitoring and adjusting module is configured to send the adjustment request to the packet receiving terminal according to the state of the SA and a load balancing algorithm.

[0131] According to the present disclosure, the negotiation attribute information is used to determine the IPSec security tunnels, so that the distribution of packets can be realized, the IPSec processing capability can be improved, and the encryption requirements of the 5G high-flow services can be met.

[0132] As shown in Fig. 15, an embodiment of the present disclosure further provides a transmission device, including a second negotiation module 1501 configured to negotiate with a packet transmitting terminal according to five-tuple information and negotiation attribute information sent by the packet transmitting terminal to determine an IPSec security tunnel; and a receiving module 1502 configured to receive a packet sent by the packet transmitting terminal through the IPSec security tunnel.

[0133] In some implementations, the five-tuple information includes a source IP address, a destination IP address, a protocol number, source port information, and destination port information.

[0134] The negotiation attribute information is related to a type of service.

[0135] In some implementations, the negotiation attribute information includes one of the following information: type of service, type of service and length, and type of service, length and value.

[0136] In some implementations, the second negotiation module 1501 is configured for a packet receiving terminal to negotiate with the packet transmitting terminal using the five-tuple information to determine a default SA which corresponds to an IPSec security tunnel when the negotiation with the packet transmitting terminal according to the negotiation attribute information fails or the packet receiving terminal does not support the use of the negotiation attribute information in negotiation.

[0137] In some implementations, the second negotiation module 1501 is configured for a packet receiving terminal to negotiate with the packet transmitting terminal according to the five-tuple information to determine a default SA which corresponds to an IPSec security tunnel, and negotiate with the packet transmitting terminal according to the five-tuple information and the negotiation attribute information to determine one or more attribute SAs, each of which corresponds to one IPSec security tunnel.

[0138] In some implementations, the device further includes an adjusting module configured to negotiate with the packet transmitting terminal according to an adjustment request sent by the packet transmitting terminal to adjust an association relationship between the negotiation attribute information and the attribute SA.

[0139] According to the present disclosure, the negotiation attribute information is used to determine the IPSec security tunnels, so that the distribution of packets can be realized, the IPSec processing capability can be improved, and the encryption requirements of the 5G high-flow services can be met.

[0140] As shown in Fig. 16, an embodiment of the present disclosure further provides a packet transmitting terminal, including a memory 1601, a processor 1602, and a computer program 1603 which is stored on the memory 1601 and is capable of running on the processor 1602, and the processor 1602 performs the transmission method shown in Fig. 3 when executing the program.

[0141] As shown in Fig. 17, an embodiment of the present disclosure further provides a packet receiving terminal, including a memory 1701, a processor 1702, and a computer program and the processor 1702 performs the transmission method shown in Fig. 12 when executing the program.

[0142] An embodiment of the present disclosure further provides a computer-readable storage medium having a computer-executable instruction stored thereon, and the computer-executable instruction is configured to perform the transmission method.

[0143] In the embodiment, the above storage medium may include, but is not limited to, various media capable of storing program codes, such as a Universal Serial Bus Flash Disk (USB flash disk), a Read-Only Memory (ROM), a Random Access Memories (RAM), a mobile hard disk, a magnetic disk, and an optical disc.

[0144] It should be understood that, all or some of the steps in the method disclosed above, the functional modules / units in the systems and the devices may be implemented as software, firmware, hardware, or suitable combinations thereof. If implemented as hardware, the division between the functional modules / units stated above is not necessarily corresponding to the division of physical components; for example, one physical component may have a plurality of functions, or one function or step may be performed through cooperation of several physical components. Some or all of the components may be implemented as software executed by a processor, such as a digital signal processor or a microprocessor, or may be implemented as hardware, or may be implemented as an integrated circuit, such as an application specific integrated circuit. Such software may be distributed on computer-readable medium, which may include computer storage medium (or non-transitory medium) and communication medium (or transitory medium). The term "computer storage medium" includes volatile / nonvolatile and removable / non-removable medium used in any method or technology for storing information (such as computer-readable instructions, data structures, program modules and other data). The computer storage medium include, but are not limited to, RAMs, ROMs, Electrically Erasable Programmable Read-Only Memories (EEPROMs), flash memories or other memory techniques, Compact Disc Read-Only Memories (CD-ROMs), Digital Video Disks (DVDs) or other optical discs, magnetic cassettes, magnetic tapes, magnetic disks or other magnetic storage devices, or any other medium which can be used to store the desired information and can be accessed by a computer. In addition, the communication medium generally include computer-readable instructions, data structures, program modules or other data in a modulated data signal, such as a carrier wave or other transmission mechanism, and may include any information delivery medium.

Claims

1. A transmission method, comprising: negotiating, by a packet transmitting terminal, with a packet receiving terminal using five-tuple information and negotiation attribute information to determine an Internet Protocol Security, IPSec, security tunnel (301); and sending, by the packet transmitting terminal, a packet to the packet receiving terminal through the IPSec security tunnel (302), characterized by: wherein negotiating with the packet receiving terminal using the five-tuple information and the negotiation attribute information to determine the IPSec security tunnel comprises: negotiating, by the packet transmitting terminal, with the packet receiving terminal using the five-tuple information to determine a default Security Association, SA, which corresponds to an IPSec security tunnel (501); and negotiating, by the packet transmitting terminal, with the packet receiving terminal using the five-tuple information and the negotiation attribute information to determine one or more attribute SAs, each of which corresponds to one IPSec security tunnel (502), wherein sending the packet to the packet receiving terminal through the IPSec security tunnel comprises: classifying, by the packet transmitting terminal, the packet to be sent according to the five-tuple information and the negotiation attribute information; in response to that the packet matches the five-tuple information and the negotiation attribute information, associating the packet with a corresponding attribute SA, and sending the packet to the packet receiving terminal through an IPSec security tunnel corresponding to the attribute SA; or in response to that the packet matches the five-tuple information but does not match the negotiation attribute information, associating the packet with the default SA, and sending the packet to the packet receiving terminal through the IPSec security tunnel corresponding to the default SA.

2. The method of claim 1, wherein the five-tuple information comprises a source Internet Protocol, IP, address, a destination IP address, a protocol number, source port information, and destination port information; and the negotiation attribute information is related to a type of service of the packet.

3. The method of claim 1 or 2, further comprising: before negotiating with the packet receiving terminal using the five-tuple information and the negotiation attribute information to determine the IPSec security tunnel, determining, by the packet transmitting terminal, a type of service in the negotiation attribute information according to identification information carried in the packet to be sent (401).

4. The method of claim 1, wherein the packet transmitting terminal is an IPSec initiator, and the packet receiving terminal is an IPSec responder; or the packet transmitting terminal is an IPSec responder, and the packet receiving terminal is an IPSec initiator.

5. A transmission method, comprising: negotiating, by a packet receiving terminal, with a packet transmitting terminal according to five-tuple information and negotiation attribute information sent by the packet transmitting terminal to determine an IPSec security tunnel (1201); and receiving, by the packet receiving terminal, a packet sent by the packet transmitting terminal through the IPSec security tunnel (1202), characterized by: wherein negotiating with the packet transmitting terminal according to the five-tuple information and the negotiation attribute information to determine the IPSec security tunnel comprises: negotiating, by the packet receiving terminal, with the packet transmitting terminal according to the five-tuple information to determine a default Security Association, SA, which corresponds to an IPSec security tunnel; and negotiating, by the packet receiving terminal, with the packet transmitting terminal according to the five-tuple information and the negotiation attribute information to determine one or more attribute SAs, each of which corresponds to one IPSec security tunnel, wherein receiving the packet sent by the packet transmitting terminal through the IPSec security tunnel comprises: in response to that the packet matches the five-tuple information and the negotiation attribute information, associating the packet with a corresponding attribute SA, and receiving the packet sent by the packet transmitting terminal through an IPSec security tunnel corresponding to the attribute SA; or in response to that the packet matches the five-tuple information but does not match the negotiation attribute information, associating the packet with the default SA, and receiving the packet sent by the packet transmitting terminal through the IPSec security tunnel corresponding to the default SA.

6. The method of claim 5, wherein the five-tuple information comprises a source IP address, a destination IP address, a protocol number, source port information, and destination port information; and the negotiation attribute information is related to a type of service.

7. A transmission device, comprising: a first negotiation module (1401) configured to negotiate with a packet receiving terminal using five-tuple information and negotiation attribute information to determine an IPSec security tunnel; and a transmitting module (1402) configured to send a packet to the packet receiving terminal through the IPSec security tunnel, characterized by: wherein the first negotiation module (1401) is configured to negotiate with the packet receiving terminal using the five-tuple information to determine a default Security Association, SA, which corresponds to an IPSec security tunnel, and negotiate with the packet receiving terminal using the five-tuple information and the negotiation attribute information to determine one or more attribute SAs, each of which corresponds to one IPSec security tunnel; the transmitting module (1402) is configured to classify the packet to be sent according to the five-tuple information and the negotiation attribute information, in response to that the packet matches the five-tuple information and the negotiation attribute information, associate the packet with a corresponding attribute SA, and send the packet to the packet receiving terminal through an IPSec security tunnel corresponding to the attribute SA, or in response to that the packet matches the five-tuple information but does not match the negotiation attribute information, associate the packet with the default SA, and send the packet to the packet receiving terminal through the IPSec security tunnel corresponding to the default SA.

8. A transmission device, comprising: a second negotiation module (1501) configured to negotiate with a packet transmitting terminal according to five-tuple information and negotiation attribute information sent by the packet transmitting terminal to determine an IPSec security tunnel; and a receiving module (1502) configured to receive a packet sent by the packet transmitting terminal through the IPSec security tunnel, characterized by: wherein the second negotiation module (1501) is configured to negotiate with the packet transmitting terminal according to the five-tuple information to determine a default security Association, SA, which corresponds to an IPSec security tunnel, and negotiate with the packet transmitting terminal according to the five-tuple information and the negotiation attribute information to determine one or more attribute SAs, each of which corresponds to one IPSec security tunnel; the receiving module (1502) is configured to associate the packet with a corresponding attribute SA and receive the packet sent by the packet transmitting terminal through an IPSec security tunnel corresponding to the attribute SA in response to that the packet matches the five-tuple information and the negotiation attribute information, or associate the packet with the default SA and receive the packet sent by the packet transmitting terminal through the IPSec security tunnel corresponding to the default SA in response to that the packet matches the five-tuple information but does not match the negotiation attribute information.

9. A packet transmitting terminal, comprising a memory (1601), a processor (1602), and a computer program (1603) which is stored on the memory (1601) and is capable of running on the processor (1602), wherein the processor (1602) performs the transmission method of any one of claims 1 to 4 when executing the program (1603).

10. A packet receiving terminal, comprising a memory (1701), a processor (1702), and a computer program (1703) which is stored on the memory (1701) and is capable of running on the processor (1702), wherein the processor (1702) performs the transmission method of claim 5 or 6 when executing the program (1703).

11. A computer-readable storage medium having a computer-executable instruction stored thereon, wherein the computer-executable instruction is configured to perform the transmission method of any one of claims 1 to 6.