Ipsec tunnel sharing method, and device and system
By establishing an IPsec tunnel sharing method between base stations, the problem of rising tunnel specifications caused by IPsec resource limitation is solved, the utilization rate of the tunnel is improved, and the reliable and efficient operation of services is ensured.
Patent Information
- Application Number
- PCT/CN2024/132985
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-04
- Filing Date
- 2024-11-19
- Publication Date
- 2025-06-12
AI Technical Summary
In the multi-operator or multi-service instance scenario, the base station cannot effectively increase the number of encrypted data flows in the IPsec tunnel due to IPsec resource limitations, resulting in an increase in tunnel specifications and wasting resources.
By establishing an IPsec tunnel sharing method between the first network device and the second network device, multiple target objects (operators or service instances) are allowed to share one or more IPsec tunnels, thereby improving the utilization of the tunnel.
It realizes that in the multi-operator or multi-service instance scenario, the utilization rate of IPsec tunnel is improved, the resource waste of base stations is reduced, and the reliable and efficient operation of services is ensured.
Smart Images

Figure CN2024132985_12062025_PF_FP_ABST
Abstract
Description
IPsec tunnel sharing method, device and system
[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on December 4, 2023, with application number 202311650506.2 and application name “A method, device and system for sharing an IPsec tunnel”, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The present application relates to the field of communication technology, and in particular to a method, device, and system for sharing an IPsec tunnel. Background Art
[0003] The current 3rd Generation Partnership Project (3GPP) supports secure self-establishment over the X2 / Xn interface, such as direct IPsec tunnels (hereinafter referred to as "IPsec tunnels") between two base stations, such as Internet Protocol Security (IPsec) tunnels. In multi-service instance base station scenarios, where a single base station serves multiple operators or multiple service instances simultaneously, transmission and data isolation between service instances is required. Therefore, different service instances typically use different virtual routing and forwarding (VRFs), and each VRF requires a separate IPsec tunnel.
[0004] However, due to IPsec resource limitations, the number of IPsec tunnels that a base station can establish is usually limited. Based on this, when the number of base station IPsec tunnels is limited, how to increase the number of encrypted data flows in the IPsec tunnel in scenarios where the base station provides services for multiple operators or multiple business instances is a problem that needs to be solved. Summary of the Invention
[0005] The present application provides a method, device, and system for sharing an IPsec tunnel, which can improve the utilization rate of the IPsec tunnel while ensuring more reliable and efficient operation of services.
[0006] To achieve the above objectives, this application adopts the following technical solutions:
[0007] In a first aspect, a method for sharing an IPsec tunnel is provided, which is applied to a first network device. The first network device provides services for multiple target objects, where the target objects are operators or service instances. The multiple target objects include a first target object and a second target object. One or more IPsec tunnels are established between the first network device and the second network device. The method may include:
[0008] A first data packet and a second data packet are sent to the second network device via a first IPsec tunnel, wherein the first data packet belongs to the first target object, and the second data packet belongs to a second, different target object. The first data packet includes first service data and first information, and the first information is used to indicate the first target object. The second data packet includes second service data and second information, and the second information is used to indicate the second target object. The first IPsec tunnel is one of the one or more IPsec tunnels. Based on this, one or more IPsec tunnels are established between the first network device and the second network device, and the one or more IPsec tunnels are used to transmit service data between the first network device and the second network device. The first network device and the second network device both provide services for multiple target objects. The first data packet and the second data packet can be from the same or different target objects. The first data packet includes first service data and first information, and the first service data is service data of the first target object. The first information is used to indicate that the first service data is from the first target object. The second data packet includes second service data and second information, and the second service data is service data of the second target object. The second information is used to indicate that the second service data is from the second target object. The target object can be an operator or a business instance. In some examples, it can also be other dedicated networks. There is no limitation here. The business data of multiple target objects served by the first network and the second network can use any one of one or more IPsec tunnels as the first IPsec tunnel to transmit business data. In this way, the IPsec tunnel between the first network device and the second network device is shared among multiple target objects, which improves the IPsec tunnel specifications available to the target object when transmitting business data, and at the same time improves the utilization rate of the IPsec tunnel between the first network device and the second network device, so that the transmission efficiency of business data between the first network device and the second network device is improved.
[0009] As a possible implementation method, sending the first data packet and the second data packet to the second network device through the first IPsec tunnel includes: transmitting the first business data and the second business data to the tunnel interface of the first IPsec tunnel respectively; encrypting the first business data and the second business data at the tunnel interface to obtain the first data packet and the second data packet respectively; and sending the first data packet and the second data packet to the second network device through the first IPsec tunnel. Based on this, when using the first IPsec tunnel to transmit business data, the first business data and the second business data are first transmitted to the tunnel interface of the first IPsec tunnel. The first IPsec tunnel can be any one of multiple IPsec tunnels, and the first business data and the second business data can come from the same or different target objects. At the tunnel interface, the first business data and the second business data are respectively encapsulated and encrypted according to the security protocol policy corresponding to the first IPsec tunnel to obtain the first data packet and the second data packet, and then the first data packet and the second data packet are sent through the first IPsec tunnel. In this way, by controlling the transmission method of the first business data and the second business data, the sharing of the first IPsec tunnel when business data from the same or different target objects is transmitted is achieved. It can be understood that the first IPsec tunnel is any one of one or more IPsec tunnels between the first network device and the second network device, and the first business data and the second business data can be business data of any different target objects served by the first network device.
[0010] As a possible implementation, transmitting the first service data and the second service data, respectively, to the tunnel interface of the first IPsec tunnel includes transmitting the first service data and the second service data to the tunnel interface according to a preset routing method of an inner address. Based on this, when transmitting the first service data and the second service data to the tunnel interface of the first IPsec tunnel, routing can be used to transmit the first service data and the second service data from the same or different target objects to the tunnel interface of the first IPsec tunnel, thereby controlling the data transmission path of the first service data and the second service data to achieve shared use of the IPsec tunnel by different target objects.
[0011] As a possible implementation method, the preset routing method of the inner address includes one or more of the following: destination address routing, source address routing, and policy routing. Based on this, the first service data and the second service data are transmitted from their respective inner addresses to the tunnel interface of the first IPsec tunnel via the preset routing method. Exemplarily, the routing method of destination address routing, the routing method of source address routing, and the routing method of policy routing can be adopted. Policy routing can self-learn the address of the other end and transmit the service data to the tunnel interface of the IPsec tunnel via the source address + destination address method. In some examples, other routing methods that can realize the transmission of service data to the tunnel interface can also be adopted, which are not limited here.
[0012] As a possible implementation, both the first service data and the second service data pass the traffic selection of the tunnel interface. Based on this, after the first service data and the second service data are transmitted to the tunnel interface, traffic selection can be performed on the first service data and the second service data at the tunnel interface, so that both the first service data and the second service data pass the traffic selection of the tunnel interface at the tunnel interface, and the first service data and the second service data are encapsulated or encrypted at the tunnel interface.
[0013] As a possible implementation, the tunnel interface includes a traffic selector, and the encryption of the first business data and the second business data at the tunnel interface includes: performing traffic selection on the first business data and the second business data through the traffic selector at the tunnel interface, and encrypting the first business data and the second business data respectively when the traffic selection passes. Based on this, when the tunnel interface performs traffic selection, the traffic selector can be used to select the business data. Exemplarily, the traffic selector can be used to select the first business data and the second business data. When the inner address of the first business data meets the preset address range of the traffic selector, the first business data and the second business data are allowed to pass through the traffic selector and are encrypted.
[0014] As a possible implementation, the traffic selection for the first service data and the second service data includes: determining that the inner addresses corresponding to the first service data and the second service data meet a preset address range of the traffic selector, and determining that the traffic is selected to be passed. Based on this, the preset address range of the traffic selector can be set according to the transmission requirements of the service data. If the inner addresses corresponding to the first service data and the second service data are within the preset address range of the traffic selector, it is determined that the first service data and the second service data meet the traffic selection rules of the traffic selector, and the traffic of the first service data and the second service data is selected to be passed.
[0015] As a possible implementation method, the traffic selection of the first business data and the second business data by the traffic selector includes: the traffic selector selects the first business data and the second business data based on the any~any selection strategy, wherein the IPv4 address range corresponding to the traffic selector is 0.0.0.0 / 0~0.0.0.0 / 0, and the corresponding IPv6 address range is ::0 / 0~::0 / 0. Based on this, in some examples, the selection strategy of the traffic selector can be any~any, that is, after the first business data and the second business data are transmitted to the tunnel interface through the preset route, the traffic selector can allow the first business data and the second business data to pass the traffic selection, wherein the first business data and the second business data both belong to the preset address range of the traffic selector, the address range of the traffic selector in the IPv4 scenario is 0.0.0.0 / 0~0.0.0.0 / 0, and the address range of the traffic selector in the IPv6 scenario is ::0 / 0~::0 / 0. When the first business data and the second business data belong to the address range, it is determined that the first business data and the second business data traffic selection passes, that is, the traffic selector at the tunnel interface allows all data transmitted to the tunnel interface through the preset route to pass the traffic selection. The traffic selector and the preset route cooperate with each other to control the transmission process of the business data, and transmit the business data to the corresponding tunnel interface, thereby realizing the sharing of the IPsec tunnel between the first network device and the second network device, and improving the transmission efficiency of the business data.
[0016] As a possible implementation, the encryption processing of the first business data and the second business data at the tunnel interface includes: writing the first virtual routing domain identifier corresponding to the first target object in the first information, and then encrypting the first business data; and writing the second virtual routing domain identifier corresponding to the second target object in the second information, and then encrypting the second business data. Based on this, in the process of encrypting the first business data and the second business data, the first business data comes from the first target object, and the first virtual routing domain identifier corresponding to the first target object is written into the first information; the second business data comes from the second target object, and the second virtual routing domain identifier corresponding to the second target object is written into the second information, wherein the first virtual routing domain identifier is used to indicate the first target object, and the second virtual routing domain identifier is used to indicate the second target object.
[0017] As a possible implementation manner, writing the first virtual routing domain identifier corresponding to the first target object in the first information includes: writing the first virtual routing domain identifier corresponding to the first target object into the first information based on a first mapping mechanism; writing the second virtual routing domain identifier corresponding to the second target object into the second information includes: writing the second virtual routing domain identifier corresponding to the second target object into the second information based on the second mapping mechanism; wherein the first mapping mechanism and the second mapping mechanism may be different.
[0018] As a possible implementation method, the first data message includes a field for carrying the first information, and the second data message includes a field for carrying the second information, and the field includes one or more of the following: an extended header field, a special field, a reserved field, a TTL field, a flowlable field, and a dh header field. Based on this, when the first virtual routing domain identifier is written into the first information and the second virtual routing domain identifier is written into the second information, the first virtual routing domain identifier and the second virtual routing domain identifier can be mapped to the extended header field, the special field, the reserved field, the TTL field, the flowlable field, and the dh header field, or to other available fields in the data message, without any limitation here.
[0019] As a possible implementation, the first business data includes first address information, which is used to indicate the first target object, and the second business data includes second address information, which is used to indicate the second target object. Based on this, when the target object sends business data, the business data carries address information that can indicate the corresponding target object. In some examples, the first business data may include first address information, which can indicate source address information and target address information corresponding to the first business data, and the second business data may include second address information, which can indicate source address information and target address information corresponding to the second business data, so as to determine the first target object and the second target object corresponding to the first business data and the second business data.
[0020] In a second aspect, a method for sharing an IPsec tunnel is provided, which is applied to a second network device, where the second network device provides services for multiple target objects, where the target objects are operators or service instances, and the multiple target objects include a first target object and a second target object. One or more IPsec tunnels are established between the second network device and the first network device. The method may include:
[0021] First, a first data packet and a second data packet are received from a first network device through a first IPsec tunnel, wherein the first data packet includes first business data and first information, and the first information is used to indicate the first target object; the second data packet includes second business data and second information, and the second information is used to indicate the second target object. Based on this, one or more IPsec tunnels are established between the first network device and the second network device, and the one or more IPsec tunnels are used to transmit business data between the first network device and the second network device. The first network device and the second network device both provide services for multiple target objects. The second network device receives the first data packet and the second data packet from the first network device. The first data packet and the second data packet can come from the same or different target objects. The target objects can be operators or business instances. In some examples, they can also be other dedicated networks, which are not limited here.
[0022] Then, the first service data and the first information are obtained from the first data packet, and the second service data and the second information are obtained from the second data packet. Based on this, the first service data and the first information are obtained from the first data packet, and the first information is used to indicate that the first service data belongs to the first target object. The second service data and the second information are obtained from the second data packet, and the second information is used to indicate that the second service data comes from the second target object. In this way, the target object to which the data packet belongs can be determined based on the first information or the second information carried in the data packet, and the first service data and the second service data can be received and identified by the second network device, thereby receiving the first service data and the second service data.
[0023] As a possible implementation method, obtaining the first business data and the first information from the first data packet includes: parsing the first data packet according to the security protocol policy corresponding to the first IPsec tunnel to obtain the first business data and the first information. Obtaining the second business data and the second information from the second data packet includes: parsing the second data packet according to the security protocol policy corresponding to the first IPsec tunnel to obtain the second business data and the second information. Based on this, the first data packet and the second data packet received by the second network device from the first IPsec tunnel are both decrypted according to the security protocol policy corresponding to the first IPsec tunnel to obtain the corresponding first business data and the first information, as well as the second business data and the second information, wherein the IPsec tunnel can be configured to set the corresponding security protocol policy for use when encrypting the business data transmitted through the IPsec tunnel.
[0024] As a possible implementation, the method may further include: obtaining a first virtual routing domain identifier corresponding to the first information based on a third mapping mechanism, the first information being encapsulated by the first network device in the first data packet based on the first mapping mechanism; and obtaining a second virtual routing domain identifier corresponding to the second information based on the fourth mapping mechanism, the second information being encapsulated by the first network device in the second data packet based on the first mapping mechanism. The third mapping mechanism and the fourth mapping mechanism may be the same or different. Based on this, when obtaining the corresponding first virtual routing domain identifier based on the first information, the third mapping mechanism may be used to obtain the first virtual routing domain identifier from the field used to carry the first information; and when obtaining the corresponding second virtual routing domain identifier based on the second information, the fourth mapping mechanism may be used to obtain the second virtual routing domain identifier from the field used to carry the second information. The third mapping mechanism and the fourth mapping mechanism may be the same or different. Furthermore, the third mapping mechanism and the first mapping mechanism may be the same or different, and the fourth mapping mechanism and the second mapping mechanism may be the same or different. The specific mapping rules may be determined through negotiation between the first network device and the second network device.
[0025] As a possible implementation method, the first data message and the second data message include one or more of the following fields: an extended header field, a special field, a reserved field, a TTL field, a flowlable field, and a dh header field, and the first information is located in the field. Based on this, when obtaining the corresponding first virtual routing domain identifier based on the first information and obtaining the corresponding second virtual routing domain identifier based on the second information, the first virtual routing domain identifier carried by the first information and the second virtual routing domain identifier carried by the second information can be obtained from the extended header field, the special field, the reserved field, the TTL field, the flowlable field, the dh header field, etc., or they can be obtained from other available fields in the data message, without any limitation herein.
[0026] As a possible implementation, the method may further include: transmitting the first service data to the first target object served by the second network device according to the first virtual routing domain identifier, and the first virtual routing domain identifier is associated with the first target object; transmitting the second service data to the second target object served by the second network device according to the second virtual routing domain identifier, and the second virtual routing domain identifier is associated with the second target object. Based on this, it can be understood that the first virtual routing domain identifier is associated with the first target object, and the second virtual routing domain identifier is associated with the second target object. Therefore, the first service data can be sent to the first target object served by the second network device according to the first virtual routing domain identifier and the association between the first virtual routing domain identifier and the first target object, and the second service data can be sent to the second target object served by the second network device according to the second virtual routing domain identifier and the association between the second virtual routing domain identifier and the second target object, so as to complete the reception of the first service data and the second service data.
[0027] As a possible implementation, the first business data includes first address information, which is used to indicate the first target object, and the second business data includes second address information, which is used to indicate the second target object. Based on this, after the business data is acquired, the business data carries address information that can indicate the corresponding target object. In some examples, the first business data may include first address information, which can indicate the target address information corresponding to the first business data, and the second business data may include second address information, which can indicate the target address information corresponding to the second business data. Based on the target address information, the first target object and the second target object corresponding to the first business data and the second business data can be determined.
[0028] As a possible implementation, the method further includes: transmitting the first business data to the first target object served by the second network device according to the first address information; transmitting the second business data to the second target object served by the second network device according to the second address information. Based on this, the address information may include source address information and target address information. In some examples, the target object corresponding to the business data can be determined by obtaining the target address information in the address information. For example, the first target object corresponding to the first business data can be determined according to the target address information in the first address information, and the first business data can be sent to the first target object. The second target object corresponding to the second business data can be determined according to the target address information in the second address information, and the second business data can be sent to the second target object to complete the reception of the first business data and the second business data.
[0029] According to a third aspect, a communication system is provided, which may include a first network device and a second network device, wherein the first network device is used to implement the method described in any one of the first aspects, and the second network device is used to implement the method described in any one of the second aspects.
[0030] In a fourth aspect, an electronic device is provided, which may include: a transceiver for sending and receiving signals; a memory for storing computer program instructions; and a processor for executing computer program instructions to support the electronic device in implementing a method in any possible implementation of the first aspect or the second aspect.
[0031] In a fifth aspect, a computer-readable storage medium is provided, on which computer program instructions are stored. When the computer program instructions are executed by a processing circuit, the method in any possible implementation of the first aspect or the second aspect is implemented.
[0032] In a sixth aspect, a computer program product comprising instructions is provided, which, when the computer program product is run on a computer, enables the computer to execute the method in any possible implementation of the first aspect or the second aspect.
[0033] In the seventh aspect, a chip system is provided, which includes a processing circuit and a storage medium, wherein the storage medium stores computer program instructions; when the computer program instructions are executed by the processing circuit, the method in any possible implementation manner of the first aspect or the second aspect is implemented. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] FIG1 is a schematic diagram of data transmission based on an IPsec tunnel provided by the related art;
[0035] FIG2 is a schematic diagram of a system architecture provided by related technology;
[0036] FIG3 is a schematic diagram of another system architecture provided by related technology;
[0037] FIG4 is a schematic diagram of data transmission based on an IPsec tunnel provided in an embodiment of the present application;
[0038] FIG5 is a schematic diagram of the hardware structure of a network device provided in an embodiment of the present application;
[0039] FIG6 is a schematic diagram of a system architecture provided in an embodiment of the present application;
[0040] FIG7 is a schematic diagram of another system architecture provided in an embodiment of the present application;
[0041] FIG8 is a flow chart of a method for sharing an IPsec tunnel provided in an embodiment of the present application;
[0042] FIG9 is a schematic diagram of data transmission based on policy routing according to an embodiment of the present application;
[0043] FIG10 is a schematic diagram of a data packet during data transmission in an IPsec tunnel according to an embodiment of the present application;
[0044] FIG11 is a schematic diagram showing a principle of indicating a virtual routing domain according to an embodiment of the present application;
[0045] FIG12 is a schematic diagram showing another method of indicating a virtual routing domain according to an embodiment of the present application;
[0046] FIG13 is a detailed flowchart of an IPsec tunnel sharing method provided in an embodiment of the present application. DETAILED DESCRIPTION
[0047] The technical solutions in the embodiments of the present application will be described below in conjunction with the accompanying drawings in the embodiments of the present application. In the description of the embodiments of the present application, unless otherwise specified, " / " means or, for example, A / B can mean A or B; "and / or" in this article is merely a description of the association relationship of associated objects, indicating that three relationships can exist, for example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In addition, in the description of the embodiments of the present application, "multiple" means two or more than two.
[0048] Hereinafter, the terms "first," "second," and so on are used solely to distinguish different descriptive objects and have no limiting effect on the position, order, priority, quantity, or content of the described objects. For example, if the described object is a "field," the ordinal number preceding the "field" in "first field" and "second field" does not define the position or order of the "fields." "First" and "second" do not define whether the modified "fields" are in the same message, nor do they restrict the order of the "first field" and "second field." For another example, if the described object is a "level," the ordinal number preceding the "level" in "first level" and "second level" does not define the priority of the "levels." For another example, the number of described objects is not limited by the ordinal number and can be one or more. For example, in the case of "first device," the number of "devices" can be one or more. Furthermore, the objects modified by different prefixes can be the same or different. For example, if the described object is a "device," the "first device" and "second device" can be the same type of device or different types of devices. For another example, if the described object is "information," the "first information" and "second information" can be information of the same content or different contents. In short, the use of prefixes such as ordinal numbers to distinguish the described objects in the embodiments of the present application does not constitute a restriction on the described objects. For the statement of the described objects, please refer to the description in the context of the claims or embodiments, and no unnecessary restrictions should be constituted due to the use of such prefixes.
[0049] Furthermore, in the embodiments of the present application, "connection" may be a direct connection or an indirect connection; in addition, it may refer to an electrical connection or a communication connection; for example, the connection between two electrical components A and B may refer to a direct connection between A and B, or may refer to an indirect connection between A and B through other electrical components or connection media, or may refer to an indirect connection between A and B through other communication devices or communication media, as long as communication between A and B can be achieved.
[0050] Currently, wireless base station applications support secure self-establishment over the X2 / Xn interface (e.g., two base stations directly establishing an X2 / Xn IPsec tunnel). X2 is the interface between LTE stations, and Xn is the interface between NR stations. This approach is referred to as Direct IPsec. This Direct IPsec does not support sharing of IPsec tunnels between base stations. Therefore, to avoid address conflicts between multiple operators or service instances (a common scenario), which can lead to the inability to isolate and distinguish between multiple operators or service instances, each operator or service instance requires its own Direct IPsec. This means that a single Direct IPsec tunnel cannot be shared across multiple operators or service instances. In this scenario, as shown in Figure 1, if there are N (N is a positive integer greater than 1) inner VRFs, base station 1 and base station 2 must provide N local Internet Key Exchange (IKE) addresses and N Direct IPsec tunnels. The operator can be exemplified by the virtual routing and forwarding (VRF) domain shown in Figure 1, which can include VRF 1, VRF 2, and VRF 3. In some cases, an operator or service instance can also be referred to as a "VRF instance." A VRF is an instance created on a physical device through logical partitioning of the physical device. Each instance is isolated at the routing level, enabling data or service isolation. Each VRF has independent interfaces, routing tables, and routing protocol processes. In other words, current protocols cannot support the sharing of IPsec tunnels between base stations, both in terms of protocol functionality and the prescribed communication process.
[0051] Furthermore, due to IPsec resource limitations, each base station generally has a specification limit, such as 512 Direct IPsec lines. However, in a multi-operator scenario, since transmission isolation is required between operators (such as independent planning of transmission IP, routing, etc., as well as data isolation between operators), different VRFs are generally adopted. Each operator's VRF requires a separate direct IPsec tunnel. While the total specification of base station Direct IPsec remains unchanged, the direct IPsec available to each operator is reduced by N times, where N is the number of operators. In a multi-operator scenario, if the number of operators is 3 and each operator requires 500+ Direct IPsec lines, the total direct IPsec specification required is 1500+, while the base station Direct IPsec specification is 512, which cannot meet the needs of the operators.
[0052] On the other hand, in mixed scenarios of business-oriented (2B) and customer-oriented (2C), 2B and 2C also need to independently plan transmission and data isolation, and use different VRF methods. This requires the Direct IPsec specifications between stations to be expanded N times, where N is the number of slices, resulting in the base station being unable to meet the requirements of the scenario.
[0053] In the wireless base station application scenario, as shown in Figure 2, secure communication between the base station and the core network can be achieved by establishing a secure protocol channel between the base station and the security gateway (SeGW) to carry collaborative services between base stations, where the core network may include the local area network (LAN), SeGW, mobility management entity (MME) / authentication management function (AMF), signaling gateway (SGW) / user plane function (UPF), etc. shown in Figure 2.
[0054] To reduce the traffic load on the security gateway and the latency between base stations, an IPsec tunnel, such as a Direct IPsec tunnel (hereinafter referred to as "IPsec tunnel"), can be directly established between base stations. As shown in Figure 2, secure transmission between base station 1 and base station 2 can not only utilize the security protocol channel between the base station and the core network's security gateway (SeGW), but also utilize the IPsec tunnel between base station 1 and base station 2. Specifically, as shown in Figure 3, in some scenarios, when the IPsec tunnel exceeds the specifications, the remaining data transmission (excluding IPsec transmission) is forwarded through the security gateway via X2 / Xn, resulting in a decrease in data transmission speed.
[0055] In multi-operator base station scenarios, such as when a base station serves multiple operators simultaneously, or in RAN Sharing scenarios where multiple operators share the same base station, different operators typically use different Virtual Formats (VRFs) to isolate transmission and data between operators. Each VRF requires its own IPsec tunnel. To achieve transmission and data isolation between operators, for example, base station 1 and base station 2 serve four operators. Four inter-site IPsec tunnels need to be established between base station 1 and base station 2, based on the operator granularity. Similarly, multiple IPsec tunnels need to be established between base station 1 and other base stations, and between base station 2 and other base stations to ensure isolation between different operators.
[0056] As we all know, IPsec resources are limited. For example, the IPsec board hardware is limited. For example, in some examples, the IPsec tunnel specification of the entire board is 512, which means that a base station can have 512 neighboring stations. If, based on the conventional inter-station IPsec tunnel establishment mechanism, base station 1 has four operators and establishes four IPsec tunnels with each of the other base stations, base station 1 will need to establish a total of 512*4=2048 IPsec tunnels with the other base stations. Therefore, based on the conventional inter-station IPsec tunnel establishment mechanism, the inter-station IPsec tunnel specification will increase dramatically. The essence of this problem is that IPsec tunnels cannot be shared as a common channel for all operators, which greatly wastes base station resources. In other words, the key to solving the above-mentioned problem of a sharp increase in IPsec tunnel specifications lies in improving IPsec tunnel utilization through IPsec tunnel sharing when the number of base station IPsec tunnels is limited. The key to IPsec tunnel establishment lies in negotiating the security parameters used to protect the IPsec tunnel and the security parameters used to protect service data.
[0057] In order to solve the problem of a sharp increase in the specifications of IPsec tunnels between stations in the network in conventional technology, an embodiment of the present application provides a method for sharing IPsec tunnels, which can support multiple operators to share one or more IPsec tunnels between network devices, and the multiple IPsec tunnels are available to any operator served by the first network device and the second network device. As shown in Figure 4, the data of any operator between base station 1 and base station 2 can be transmitted through IPsec tunnel 1, wherein IPsec tunnel 1 is provided with encryption and other security protections by IKE1. In other words, regardless of the data transmission requirements of any operator served by the first network device and the second network device, the first network device can complete the data transmission through any IPsec tunnel between the first network device and the second network device. Based on this, the problem of a sharp increase in the specifications of IPsec tunnels between stations can be solved, system computing, storage, IP address and other resources can be saved, customer operation and maintenance costs can be reduced, while the utilization rate of IPsec tunnels can be improved, and the business can be guaranteed to run more reliably and efficiently.
[0058] It is understandable that in some scenarios, an operator or service instance may also be a VPN instance.
[0059] The network device described in the embodiment of the present application may be the base station in the above example, such as a macro base station, a micro base station (also known as a "small station"), a distributed unit-control unit (DU-CU), etc., wherein the DU-CU is a device deployed in a wireless access network that enables terminal devices to perform wireless communications. In addition, the above base station may also be a wireless controller in a cloud radio access network (CRAN) scenario, or a relay station, access point, vehicle-mounted device, wearable device, or a network device in a future evolved public land mobile network (PLMN) network.
[0060] In some examples, the base station may be a gNB or a transmission / reception point (TRP). It may also be a base station defined by the 3rd Generation Partnership Project (3GPP), such as an eNB or e-NodeB.
[0061] In addition, when an eNB connects to the NR core network, the next generation core (NGC), or the 5G core network (5GC), the eNB can also be called an eLTE eNB. Specifically, an eLTE eNB is an LTE base station device that has evolved from the eNB and can directly connect to the 5G CN. An eLTE eNB is also a base station device in NR.
[0062] In some examples, the network devices described in the embodiments of the present application may also include network devices of other types, functions, and structures, such as wireless terminals (WTs), access points (APs), access controllers (ACs), or other network devices capable of communicating with terminal devices and core networks. The embodiments of the present application do not specifically limit this.
[0063] Please refer to Figure 5, which shows a schematic diagram of the hardware structure of a network device. As shown in Figure 5, the network device may include a processor 501, a communication line 502, a memory 503, and at least one communication interface (Figure 5 is merely an example of including a communication interface 504).
[0064] The processor 501 may be a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits for controlling the execution of the program of the present application.
[0065] Communication link 502 may include a pathway for transmitting information between the aforementioned components.
[0066] The communication interface 504 uses any transceiver or other device for communicating with other devices or communication networks, such as Ethernet, RAN, WLAN, etc.
[0067] In the embodiment of the present application, the communication line 502 and the communication interface 504 can be used to support the transmission of business data corresponding to an operator or a business instance between a network device and other network devices (such as a first network device and a second network device).
[0068] The memory 503 may be a read-only memory (ROM) or other static storage device that can store static information and instructions, a random access memory (RAM) or other dynamic storage device that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, an optical disc storage (including a compact disc, a laser disc, an optical disc, a digital versatile disc, a Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory may exist independently and be connected to the processor via a communication line 502. The memory may also be integrated with the processor.
[0069] The memory 503 is used to store computer-executable instructions for executing the solution of the present application. The memory 503 can store instructions for implementing two modular functions: sending instructions, receiving instructions, and processing instructions, and is controlled by the processor 501 for execution. The processor 501 is used to execute the computer-executable instructions stored in the memory 503, thereby implementing the methods provided in the following embodiments of the present application. The memory 503 shown in FIG5 is only a schematic diagram. The memory may also include other functional instructions, which are not limited by the present invention.
[0070] Optionally, the computer-executable instructions in this application may also be referred to as application code, which is not specifically limited in this application.
[0071] In a specific implementation, as an embodiment, the processor 501 may include one or more CPUs, such as CPU0 and CPU1 in FIG. 5 .
[0072] It is understandable that FIG5 is only an example of a network device and does not limit the specific structure of the network device. For example, the network device may also include other functional modules.
[0073] The following will describe in detail the IPsec tunnel sharing method provided in the embodiment of the present application with reference to the accompanying drawings.
[0074] The embodiments of the present application achieve the situation where the physical hardware remains unchanged by sharing an IPsec tunnel through the inner layer data of multiple operators or multiple business instances and using the same IPsec SA. In the scenario of multiple operators or multiple business instances, the IPsec tunnel specifications of each operator or business instance are not reduced.
[0075] In some examples, please refer to Figure 6, which shows a system architecture diagram provided by an embodiment of the present application. As shown in Figure 6, in a wireless base station application scenario, secure communication between the base station and the core network can be achieved by establishing a secure protocol channel between the base station and the security gateway to carry collaborative services between base stations, where the core network may include MME / AMF, SGW / UPF, etc.
[0076] To reduce the traffic load on the security gateway and the latency between base stations, IPsec tunnels can be established directly between base stations. As shown in Figure 6, secure transmission between base stations 1 and 2 can be achieved through the secure protocol channel between the base stations and the core network's security gateway (SGW). In some scenarios, as shown in Figure 7, base stations 1 and 2 can directly transmit data through an IPsec tunnel.
[0077] In some embodiments, the present application provides an IPsec tunnel sharing method, which is applied to a first network device, where the first network device provides services for multiple target objects, where the target objects are operators or service instances, and the multiple target objects include a first target object and a second target object. One or more IPsec tunnels are established between the first network device and the second network device. When the first network device serves as a sending end, the method may include:
[0078] A first data packet and a second data packet are sent to the second network device through a first IPsec tunnel, where the first data packet belongs to the first target object, and the second data packet belongs to a second different target object. The first data packet includes first business data and first information, and the first information is used to indicate the first target object. The second data packet includes second business data and second information, and the second information is used to indicate the second target object. The first IPsec tunnel is one of the one or more IPsec tunnels.
[0079] It can be understood that one or more IPsec tunnels are established between the first network device and the second network device, and the one or more IPsec tunnels are used to transmit business data between the first network device and the second network device. The first network device and the second network device both provide services for multiple target objects. The first data packet and the second data packet can come from the same or different target objects. The first data packet includes first business data and first information. The first business data is the business data of the first target object, and the first information is used to indicate that the first business data comes from the first target object. The second data packet includes second business data and second information. The second business data is the business data of the second target object, and the second information is used to indicate that the second business data comes from the second target object. The target object can be an operator or a business instance. In some examples, it can also be other dedicated networks. There is no limitation here. The business data of multiple target objects served by the first network and the second network can use any one of one or more IPsec tunnels as the first IPsec tunnel to transmit business data. In this way, the IPsec tunnel between the first network device and the second network device is shared among multiple target objects, which improves the IPsec tunnel specifications available to the target object when transmitting business data, and at the same time improves the utilization rate of the IPsec tunnel between the first network device and the second network device, so that the transmission efficiency of business data between the first network device and the second network device is improved.
[0080] In some examples, sending the first data packet and the second data packet to the second network device through the first IPsec tunnel includes: transmitting the first business data and the second business data to the tunnel interface of the first IPsec tunnel, respectively; encrypting the first business data and the second business data at the tunnel interface to obtain the first data packet and the second data packet, respectively; and sending the first data packet and the second data packet to the second network device through the first IPsec tunnel.
[0081] In some examples, when using a first IPsec tunnel for business data transmission, the first business data and the second business data are first transmitted to the tunnel interface of the first IPsec tunnel. The first IPsec tunnel can be any one of multiple IPsec tunnels, and the first business data and the second business data can come from the same or different target objects. At the tunnel interface, the first business data and the second business data are respectively encapsulated and encrypted according to the security protocol policy corresponding to the first IPsec tunnel to obtain the first data packet and the second data packet, and then the first data packet and the second data packet are sent through the first IPsec tunnel. In this way, by controlling the transmission method of the first business data and the second business data, the sharing of the first IPsec tunnel is achieved when business data from the same or different target objects are transmitted. It can be understood that the first IPsec tunnel is any one of one or more IPsec tunnels between the first network device and the second network device, and the first business data and the second business data can be business data of any different target objects served by the first network device.
[0082] In some examples, see FIG8 , which shows a flow chart of a method for sharing an IPsec tunnel provided in an embodiment of the present application. As shown in FIG8 , based on a first network device, the method may include:
[0083] S801: Transmit first service data and second service data to the tunnel interface of the first IPsec tunnel.
[0084] It is understood that transmitting the first service data and the second service data to the tunnel interface of the first IPsec tunnel, respectively, may include transmitting the first service data and the second service data to the tunnel interface according to a preset routing method of the inner address. When transmitting the first service data and the second service data to the tunnel interface of the first IPsec tunnel, a routing method may be used to transmit the first service data and the second service data from the same or different target objects to the tunnel interface of the first IPsec tunnel, and the data transmission path of the first service data and the second service data may be controlled to achieve sharing of the IPsec tunnel by different target objects.
[0085] In some examples, the preset routing method of the inner address includes one or more of the following: destination address routing, source address routing, and policy routing. The first business data and the second business data are transmitted from their respective inner addresses to the tunnel interface of the first IPsec tunnel through the preset routing method. Exemplarily, the routing method of destination address routing, the routing method of source address routing, and the routing method of policy routing can be adopted. In some examples, other routing methods that can realize the transmission of business data to the tunnel interface can also be adopted, and no limitation is made here. Among them, destination address routing can be based on the address of the second network device to which the business data needs to be transmitted to route the business data, source address routing can be based on the address of the first network device that sends the business data to route the business data, and policy routing can be based on the source address + destination routing method to transmit the business data. The router matches the source address and destination address of the business data to route the business data, and controls the transmission path of the business data through one or more of the above-mentioned routing methods to realize the transmission of the business data to the tunnel interface of the corresponding first IPsec tunnel.
[0086] In some examples, refer to Figure 9 which shows a data transmission diagram based on policy routing provided by an embodiment of the present application. As shown in Figure 9, the first network device may include multiple operators or multiple business instances. For example, it may include operator 1 (VRF1), operator 2 (VRF2) and operator 3 (VRF3). Multiple operators correspond to their respective policy routing methods. For example, operator 1 corresponds to policy routing 1, operator 2 corresponds to policy routing 2, and operator 3 corresponds to policy routing 3. For the three operators in the first network device, all business data can pass through the traffic selector (TS). Accordingly, when the business data arrives at the IPsec tunnel interface, it also needs to be encrypted according to the security policy protocol corresponding to the IPsec tunnel to obtain the corresponding data packet, and finally sent to the second network device through the IPsec tunnel in the form of a data packet. There can be one or more IPsec tunnels between the first network device and the second network device.
[0087] In some examples, see Figure 10, which shows a schematic diagram of a data packet in the data transmission process of an IPsec tunnel provided by an embodiment of the present application. As shown in Figure 10, a layer of IPsec tunnel header is encapsulated in front of the original IP packet, and AH or ESP authentication can be used. For example, ESP authentication can be used. The inner layer data is the original IP packet, which can include an IP header, a TCP header, data, a TCP tail, etc. The outer layer is a tunnel header added by IPsec, which can include an IP header and an ESP header.
[0088] In some examples, after sending the first business data and the second business data to the tunnel interface of the IPsec tunnel, the method may also include: encrypting the first business data and the second business data at the tunnel interface to obtain the first data packet and the second data packet.
[0089] In some examples, the first and second service data both pass the traffic selection of the tunnel interface. After the first and second service data are transmitted to the tunnel interface, traffic selection can be performed on the first and second service data at the tunnel interface, so that the first and second service data both pass the traffic selection of the tunnel interface at the tunnel interface, and the first and second service data are encapsulated or encrypted at the tunnel interface.
[0090] In some examples, the tunnel interface includes a traffic selector, and the encryption of the first business data and the second business data at the tunnel interface includes: performing traffic selection on the first business data and the second business data through the traffic selector at the tunnel interface, and encrypting the first business data and the second business data when the traffic selection passes. When the tunnel interface performs traffic selection, the traffic selector can be used to select the business data. Exemplarily, the traffic selector can be used to select the first business data and the second business data. When the inner address of the first business data meets the preset address range of the traffic selector, the first business data and the second business data are allowed to pass through the traffic selector, and the first business data and the second business data are encrypted.
[0091] In some examples, the traffic selection for the first business data and the second business data includes: determining that the inner addresses corresponding to the first business data and the second business data meet a preset address range of the traffic selector, and determining that the traffic is selected to be passed. The preset address range of the traffic selector can be set according to the transmission requirements of the business data. If the inner addresses corresponding to the first business data and the second business data are within the preset address range of the traffic selector, it is determined that the first business data and the second business data meet the traffic selection rules of the traffic selector, and the traffic of the first business data and the second business data is selected to be passed.
[0092] In some examples, the traffic selection of the first business data and the second business data by the traffic selector includes: the traffic selector selects the first business data and the second business data based on the any~any selection strategy, wherein the IPv4 address range corresponding to the traffic selector is 0.0.0.0 / 0~0.0.0.0 / 0, and the corresponding IPv6 address range is ::0 / 0~::0 / 0. In some examples, the selection strategy of the traffic selector can be any~any, that is, after the first business data and the second business data are transmitted to the tunnel interface through a preset route, the traffic selector can allow the first business data and the second business data to pass through the traffic selection, wherein the first business data and the second business data both belong to the preset address range of the traffic selector, the address range of the traffic selector in the IPv4 scenario is 0.0.0.0 / 0~0.0.0.0 / 0, and the address range of the traffic selector in the IPv6 scenario is ::0 / 0~::0 / 0. When the first business data and the second business data belong to the address range, it is determined that the first business data and the second business data traffic selection passes, that is, the traffic selector at the tunnel interface allows all data transmitted to the tunnel interface through the preset route to pass through the traffic selection. The traffic selector and the preset route cooperate with each other to control the transmission process of the business data, and transmit the business data to the corresponding tunnel interface, thereby realizing the sharing of the IPsec tunnel between the first network device and the second network device, and improving the transmission efficiency of the business data.
[0093] In some examples, the encryption processing of the first business data and the second business data at the tunnel interface includes: writing the first virtual routing domain identifier corresponding to the first target object into the first information, and then encrypting the first business data; and writing the second virtual routing domain identifier corresponding to the second target object into the second information, and then encrypting the second business data. In the process of encrypting the first business data and the second business data, the first business data comes from the first target object, and the first virtual routing domain identifier corresponding to the first target object is written into the first information; the second business data comes from the second target object, and the second virtual routing domain identifier corresponding to the second target object is written into the second information, wherein the first virtual routing domain identifier is used to indicate the first target object, and the second virtual routing domain identifier is used to indicate the second target object.
[0094] In some examples, writing the first virtual routing domain identifier corresponding to the first target object in the first information includes: writing the first virtual routing domain identifier corresponding to the first target object into the first information based on a first mapping mechanism; writing the second virtual routing domain identifier corresponding to the second target object into the second information includes: writing the second virtual routing domain identifier corresponding to the second target object into the second information based on the second mapping mechanism; wherein the first mapping mechanism and the second mapping mechanism may be the same or different. When writing the first virtual routing domain identifier into the first information, the first mapping mechanism may be used to map the first virtual routing domain identifier to a field used to carry the first information, and the second mapping mechanism may be used to map the second virtual routing domain identifier to a field used to carry the second information. The specific mapping rules may be negotiated between the first network device and the second network device. In some examples, the first mapping mechanism and the second mapping mechanism may be the same. In other examples, the first mapping mechanism and the second mapping mechanism may be different.
[0095] In some examples, the first data packet includes a field for carrying the first information, and the second data packet includes a field for carrying the second information, wherein the field includes one or more of the following: an extended header field, a special field, a reserved field, a TTL field, a flowlable field, and a dh header field. When writing the first virtual routing domain identifier into the first information and the second virtual routing domain identifier into the second information, the first virtual routing domain identifier and the second virtual routing domain identifier can be mapped to the extended header field, the special field, the reserved field, the TTL field, the flowlable field, and the dh header field, or to other available fields in the data packet, without any limitation herein.
[0096] In some examples, the first business data includes first address information, which is used to indicate the first target object, and the second business data includes second address information, which is used to indicate the second target object. When the target object sends business data, the business data carries address information that can indicate the corresponding target object. In some examples, the first business data may include first address information, which can indicate source address information and target address information corresponding to the first business data, and the second business data may include second address information, which can indicate source address information and target address information corresponding to the second business data, to determine the first target object and the second target object corresponding to the first business data and the second business data.
[0097] S802: Send a first data packet and a second data packet through the first IPsec tunnel (the first data packet includes first service data and first information, and the second data packet includes second service data and second information).
[0098] It can be understood that the first IPsec tunnel is any one of the one or more IPsec tunnels between the first network device and the second network device, the first data packet includes first business data and first information, and the second data packet includes second business data and second information, wherein the first business data and the second business data can come from any one of the target objects served by the first network device, that is, multiple target objects served by the first network device can use any IPsec tunnel between the first network device and the second network device to transmit business data, thereby realizing the sharing of IPsec tunnels between different target objects.
[0099] In some examples, as shown in FIG8 , the method is applied to a second network device, where the second network device provides services for multiple target objects, where the target objects are operators or service instances, and the multiple target objects include a first target object and a second target object. One or more IPsec tunnels are established between the second network device and the first network device. When the second network device serves as a receiving end, the method may include:
[0100] S803: Acquire first service data and first information from the first data packet, and acquire second service data and second information from the second data packet.
[0101] It can be understood that a first data packet and a second data packet sent by a first network device through a first IPsec tunnel are received, wherein the first data packet includes first business data and first information, and the first information is used to indicate the first target object, and the second data packet includes second business data and second information, and the second information is used to indicate the second target object. One or more IPsec tunnels are established between the first network device and the second network device, and the one or more IPsec tunnels are used to transmit business data between the first network device and the second network device. The first network device and the second network device both provide services for multiple target objects. The second network device receives the first data packet and the second data packet from the first network device. The first data packet and the second data packet can come from the same or different target objects. The target object can be an operator or a business instance. In some examples, it can also be other dedicated networks, and no limitation is made here.
[0102] In some examples, first business data and first information are obtained from the first data packet, and second business data and second information are obtained from the second data packet. The first business data and first information are obtained from the first data packet, with the first information used to indicate that the first business data belongs to the first target object, and the second business data and second information are obtained from the second data packet, with the second information used to indicate that the second business data comes from the second target object. In this way, the target object to which the data packet belongs can be determined based on the first information or the second information carried in the data packet, enabling the second network device to receive and identify the first business data and the second business data, thereby enabling the first business data and the second business data to be received.
[0103] In some examples, obtaining the first business data and the first information from the first data packet includes: parsing the first data packet according to the security protocol policy corresponding to the first IPsec tunnel to obtain the first business data and the first information. Obtaining the second business data and the second information from the second data packet includes: parsing the second data packet according to the security protocol policy corresponding to the first IPsec tunnel to obtain the second business data and the second information. The first data packet and the second data packet received by the second network device from the first IPsec tunnel are both decrypted according to the security protocol policy corresponding to the first IPsec tunnel to obtain the corresponding first business data and the first information, as well as the second business data and the second information, wherein the IPsec tunnel can be configured to set the corresponding security protocol policy for use when encrypting business data transmitted through the IPsec tunnel.
[0104] S804: Send the first service data to the first target object indicated by the first information, and send the second service data to the second target object indicated by the second information.
[0105] It can be understood that the first information is used to indicate that the first business data belongs to the first target object, and the second information is used to indicate that the second business data comes from the second target object. In this way, the target object to which the data packet belongs can be judged by the first information or the second information carried in the data packet, so that the second network device can judge the target objects corresponding to the first business data and the second business data. According to the result of the judgment, the first business data is sent to the target object indicated by the first information, and the second business data is sent to the target object indicated by the second information, wherein the target object may include an operator or a business instance.
[0106] In some examples, the method may further include: obtaining a first virtual routing domain identifier corresponding to the first information based on a third mapping mechanism, the first information being encapsulated by the first network device in the first data packet based on the first mapping mechanism; and obtaining a second virtual routing domain identifier corresponding to the second information based on the fourth mapping mechanism, the second information being encapsulated by the first network device in the second data packet based on the first mapping mechanism. The third mapping mechanism and the fourth mapping mechanism may be the same or different. When obtaining the corresponding first virtual routing domain identifier based on the first information, the third mapping mechanism may be used to obtain the first virtual routing domain identifier from a field used to carry the first information. When obtaining the corresponding second virtual routing domain identifier based on the second information, the fourth mapping mechanism may be used to obtain the second virtual routing domain identifier from a field used to carry the second information. The third mapping mechanism and the fourth mapping mechanism may be the same or different. Furthermore, the third mapping mechanism and the first mapping mechanism may be the same or different, and the fourth mapping mechanism and the second mapping mechanism may be the same or different. The specific mapping rules may be determined through negotiation between the first network device and the second network device.
[0107] In some examples, the first data packet and the second data packet include one or more of the following fields: an extended header field, a special field, a reserved field, a TTL field, a flowlable field, and a dh header field, and the first information is located in the field. When obtaining the corresponding first virtual routing domain identifier based on the first information and obtaining the corresponding second virtual routing domain identifier based on the second information, the first virtual routing domain identifier carried by the first information and the second virtual routing domain identifier carried by the second information can be obtained from the extended header field, the special field, the reserved field, the TTL field, the flowlable field, the dh header field, etc., or can be obtained from other available fields in the data packet, without any limitation herein.
[0108] In some examples, the method may further include: transmitting the first service data to the first target object served by the second network device according to the first virtual routing domain identifier, the first virtual routing domain identifier being associated with the first target object; transmitting the second service data to the second target object served by the second network device according to the second virtual routing domain identifier, the second virtual routing domain identifier being associated with the second target object. It can be understood that the first virtual routing domain identifier is associated with the first target object, and the second virtual routing domain identifier is associated with the second target object. Therefore, the first service data can be sent to the first target object served by the second network device according to the first virtual routing domain identifier and the association between the first virtual routing domain identifier and the first target object, and the second service data can be sent to the second target object served by the second network device according to the second virtual routing domain identifier and the association between the second virtual routing domain identifier and the second target object, so as to complete the reception of the first service data and the second service data.
[0109] In some examples, see Figure 11, which shows a schematic diagram of the principle of a virtual routing domain indication method provided by an embodiment of the present application. As shown in Figure 11, the virtual routing domain identifier corresponding to the target object is mapped to generate a virtual local area network identifier (VID) parameter, and an association relationship between the virtual routing domain and the VID parameter is established. In this way, the VID parameter can be written into an available field as a virtual routing domain identifier to indicate the operator or service instance corresponding to the service data. In some examples, the corresponding VID parameter can be carried through an inner or outer layer through an extension header, a special field, or an optional field. Since the VID parameter is bound to the virtual routing forwarding domain VRF, and the VID corresponding to the same operator or service instance between base station 1 and base station 2 needs to be consistent. Exemplarily, mapping can also be performed through the next hop extension header of Internet Protocol Version 6 (IPv6).
[0110] Exemplarily, between base station 1 and base station 2, the vid value corresponding to VRF1 in base station 1 and the vid value corresponding to VRF3 in base station 2 remain the same, so that after the service data is transmitted to base station 2, it can be determined through the vid value that the service data belongs to VRF3. In some examples, the mapping mechanism between VRF1 and vid in base station 1 and the mapping mechanism between VRF3 and vid in base station 2 can be the same or different, and the mapping mechanism between different VRFs and vid in the same base station can be the same or different. It is understandable that, based on the same principle, it is also possible to choose to use existing fields for mapping. Exemplarily, the existing fields may include one or more of the following: the TTL field of the message representing vid, the option field of Internet Protocol Version 4 (IPv4), the flowlable of IPv6, the DH header of IPv6, etc., and other optional existing fields, which are not limited here.
[0111] In some examples, the first business data includes first address information, which is used to indicate the first target object, and the second business data includes second address information, which is used to indicate the second target object. After the business data is acquired, the business data carries address information that can indicate the corresponding target object. In some examples, the first business data may include first address information, which can indicate the target address information corresponding to the first business data, and the second business data may include second address information, which can indicate the target address information corresponding to the second business data. The first target object and the second target object corresponding to the first business data and the second business data can be determined based on the target address information.
[0112] In some examples, the method further includes: transmitting the first business data to a first target object served by the second network device according to the first address information; and transmitting the second business data to a second target object served by the second network device according to the second address information. The address information may include source address information and target address information. In some examples, the target object corresponding to the business data can be determined by obtaining the target address information in the address information. For example, the first target object corresponding to the first business data can be determined based on the target address information in the first address information, and the first business data can be sent to the first target object. The second target object corresponding to the second business data can be determined based on the target address information in the second address information, and the second business data can be sent to the second target object to complete the reception of the first business data and the second business data.
[0113] In some embodiments, referring to FIG12 , a schematic diagram showing a principle of an indication method of a virtual routing domain provided in an embodiment of the present application is shown. As shown in FIG12 , the service data sent by VRF1 includes the inner address ip1 corresponding to VRF1, and the service data sent by VRF2 includes the inner address ip2 corresponding to VRF2. After the service data is sent from base station 1 to base station 2, the corresponding VRF domain can be determined by different inner IP addresses. Different target objects are associated with different VRFs, and the inner addresses of different target objects are different. The corresponding VRF domain can be determined by the inner IP address.
[0114] In some embodiments, an IPsec tunnel is a data transmission path. Other similar data transmission paths are also applicable to the concept of the IPsec tunnel sharing method provided in this application, and no limitation is made here.
[0115] It is understandable that an IPsec tunnel header is encapsulated before the original IP packet, and AH or ESP can be used. When the commonly used ESP method is used, the inner layer data is the original IP message, and the outer layer is the tunnel header added by IPsec.
[0116] In some embodiments, the inner layer data of multiple operators share one IPsec tunnel and use the same IPsec SA, which is the sharing of the IPsec tunnel in the above embodiments.
[0117] In some examples, network devices can establish an outer IKE local address through an IPsec tunnel, shared by multiple carriers. The IPsec tunnel creation rule is any to any, and traffic is directed to the IPsec tunnel through policy-based routing. One of the security protocol policies (IPsec policies) established by multiple carriers is determined and bound to the tunnel interface of the IPsec tunnel.
[0118] The principles of the sending and receiving processes in this embodiment include:
[0119] Sending processing: The plaintext (before encryption) of the sender modifies the message content and maps the internal VRF id to field x.
[0120] Receiving and processing: After decryption based on the IPsec SA match, the ID in the inner message field x is mapped to the inner VRF.
[0121] It can be understood that field x can be the first information in the aforementioned embodiment, the sending end can be the first network device in the aforementioned embodiment, and the receiving end can be the second network device in the aforementioned embodiment. Similarly, the first network device can also serve as the receiving end, and the second network device can also serve as the sending end. Furthermore, the IDs of the sending end and the receiving end must be uniformly mapped with the VRF.
[0122] In other examples, see FIG. 13 , which shows a detailed flowchart of a method for sharing an IPsec tunnel provided in an embodiment of the present application. As shown in FIG. 13 , the method may include:
[0123] S1: Specifies the outer IKE negotiation tunnel and the local and remote IKE addresses.
[0124] In some examples, IKE is first created between network devices, that is, the parameters of the first phase of IPsec tunnel negotiation are established, and one or more IPsec tunnels are established. Through negotiation between the first network device and the second network device, the local address and the remote address of the outer layer of the IPsec tunnel are determined.
[0125] S2: Creates an IPsec tunnel interface based on the IPsec tunnel.
[0126] Specifically, a corresponding interface is created according to the IPsec tunnel. Different IPsec tunnels correspond to their own tunnel interfaces, which are used to match the traffic of business data and encrypt the business data (specifically, business data can be directed to the tunnel interface through routing, and then the IPsec policy is bound to the tunnel interface to determine the encryption method of the business data).
[0127] S3: Bind the IPsec policy to the IPsec tunnel interface.
[0128] Bind the IPsec policy to the IPsec tunnel interface (for encapsulating or encrypting the service data according to the IPsec policy corresponding to the IPsec tunnel when the service data is transmitted to the IPsec tunnel interface).
[0129] Based on this, the negotiation and creation process based on IPsec tunnels between network devices is realized, so that IPsec tunnels can serve multiple business instances and improve the data transmission efficiency between network devices.
[0130] S4: Service data from the operator or service instance selects the IPsec tunnel interface through policy routing.
[0131] The sender directs the service data that needs to be encrypted to the IPsec tunnel interface through routing, which can adopt destination address routing, source address routing and policy routing.
[0132] It is understandable that during the transmission of service data, when transmitting the service data to the tunnel interface of the first IPsec tunnel, destination address routing or source address routing may be used. Furthermore, policy routing may also be used. Destination address routing may be based on the address of the second network device to which the service data needs to be transmitted, source address routing may be based on the address of the first network device that sends the service data, and policy routing may be based on the source address + destination address method, with the router determining whether the service data is sent through this route. By controlling the transmission path of the service data through policy routing, the purpose of transmitting the service data to the corresponding first IPsec tunnel is achieved.
[0133] In some embodiments, the inner layer of the network device can divert the service data of the operator or service instance through policy routing. The policy routing can divert the service data to the IPsec tunnel interface for the user plane or signaling plane of X2 / Xn by using the source IP address + destination IP address (SRC IP + DST IP), so as to facilitate IPsec encryption of the user plane or signaling plane of X2 / Xn between stations. When it is the signaling plane, the SRC IP is the local address of the signaling plane of X2 / Xn, and the DST IP is the address carried by the MME / AMF to the base station through the signaling interface of S1 / NG; when it is the user plane, the SRC IP is the local address of the user plane of X2 / Xn, and the DST IP is the address carried to the base station through the signaling interface of X2 / Xn. The outgoing interface of the policy routing is the tunnel interface of the direct IPsec between stations, thereby ensuring that only the service data of X2 / Xn between stations is encrypted by direct IPsec.
[0134] In some embodiments, the X2 / Xn between network device stations may first establish a control plane (CP), and then establish a user plane (UP) through the CP.
[0135] S5. Select matching service data based on the traffic selector and encrypt the matching service data according to the IPsec policy.
[0136] Configure the TS for the second phase of IPsec negotiation. This TS is used to match service data after it arrives at the IPsec tunnel interface.
[0137] It can be understood that the selection mode of the traffic selector setting is any~any, that is, the service data transmitted to the tunnel interface through the preset route can be encrypted and encapsulated to obtain the corresponding data message.
[0138] It can be understood that the key step in business data encryption is to first transmit the business data to the iSpec tunnel interface through the preset route, and then bind the IPsec interface to the traffic selector TS corresponding to the IPsec policy. If the business data matches the preset rules of TS, it will be encrypted and encapsulated to obtain the data packet corresponding to the business data.
[0139] In some embodiments, during the direct IPsec self-establishment process between network devices, TS uses the any~any selection rule. The address range corresponding to IPv4 is 0.0.0.0~0.0.0.0, and the address range corresponding to IPv6 is ::0~::0, so that one IPsec tunnel uses one IPsec SA, saving IPsec SA resources and improving data transmission efficiency.
[0140] S6: After encrypting the service data based on the above security protocol policy, an IPsec tunnel transmission request is made.
[0141] In some embodiments, after a data packet is received at a receiving end, a method for sharing an iSpec tunnel with inner packet data may include:
[0142] During the mapping process, mapping can be performed through the inner or outer extension header, special field, optional field, etc. to obtain the corresponding VRF domain. The specific method is as follows: the extension header, special field, and optional field carry the vid parameter of the IPSec security proposal. The vid parameter is bound to the virtual routing forwarding domain VRF. The vid between base station BTS1 and base station BTS2 needs to be consistent. For details, please refer to the relevant expansion of Figure 11 in the previous embodiment, which will not be repeated here.
[0143] In some examples, different VRF domains can also be determined by the inner IP addresses carried by different service data. For details, please refer to the relevant expansion of Figure 12 in the above embodiment, which will not be repeated here.
[0144] The embodiments of the present application provide a method for sharing IPsec tunnels. Multiple operators share the outer layers of direct IPsec tunnels, meaning multiple IPsec networks share a single IKE and IPsec tunnel. First, the direct IPsec network established by the network device uses policy-based routing, employing a VRF+srcIP+DST IP scheme. Second, the direct IPsec SA established by the network device is any to any. Finally, the mapping of the inner message VRF uses existing fields, IP addresses, or extended fields to distinguish data packets from different service instances within the same network device. This increases the specifications of direct IPsec shared by multiple operators by a factor of N, without the need to expand the security gateway.
[0145] It is understandable that direct IPsec shared by multiple operators between network devices reduces the IP / routing specification from N to 1, reducing network planning and construction costs; the direct IPsec specification shared by multiple operators changes from 1 / N to N, meeting the requirements of CA services, and the specification of multi-operator sharing does not decrease; operators independently plan IP networks, and there is no need for operators to communicate and verify IP plans.
[0146] It is understood that by supporting the deletion of IPsec tunnels and the modification of the association between IPsec tunnels and service instances (such as adding or deleting them), network devices in the embodiments of the present application can achieve more flexible IPsec tunnel sharing. For example, network devices can negotiate with other network devices at any time regarding IPsec tunnel management based on actual needs, including adding or deleting IPsec tunnels and adding / deleting the association between IPsec tunnels and service instances on demand. This supports on-demand allocation of system computing, storage, IP address, and other resources through on-demand adjustments, achieving more scientific resource allocation.
[0147] It should be understood that the various schemes of the embodiments of the present application can be reasonably combined and used, and the explanations or descriptions of the various terms appearing in the embodiments can be referenced or explained with each other in the various embodiments, without limitation to this.
[0148] It should also be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0149] It is understandable that, in order to implement the functions of any of the above-mentioned embodiments, the network device (such as the first network device or the second network device) includes a hardware structure and / or software module corresponding to the execution of each function. Those skilled in the art should easily appreciate that, in combination with the units and algorithm steps of each example described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0150] The embodiments of the present application can divide the network device into functional modules. For example, each functional module can be divided according to each function, or two or more functions can be integrated into a processing module. The above-mentioned integrated modules can be implemented in the form of hardware or software functional modules. It is understood that the division of modules in the embodiments of the present application is schematic and is only a logical functional division. In actual implementation, other division methods may be used.
[0151] It should also be understood that each module in a network device can be implemented in software and / or hardware, without specific limitation. In other words, the network device is presented in the form of functional modules. "Module" here can refer to an application-specific integrated circuit (ASIC), circuits, processors and memories that execute one or more software or firmware programs, integrated logic circuits, and / or other devices that can provide the aforementioned functions.
[0152] In an optional manner, when data transmission is implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present application is implemented in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more available media. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a digital video disk (DVD)), or a semiconductor medium (e.g., a solid state disk (SSD)).
[0153] The steps of the method or algorithm described in conjunction with the embodiments of the present application can be implemented in hardware or by executing software instructions by a processor. The software instructions can be composed of corresponding software modules, which can be stored in random access memory (RAM), flash memory, read-only memory (ROM), erasable programmable read-only memory (EPROM), electrically erasable read-only memory (EEPROM) memory, registers, hard disk, mobile hard disk, compact disc read-only memory (CD-ROM) or any other form of storage medium known in the art. An exemplary storage medium is coupled to a processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be an integral part of the processor. The processor and storage medium can be located in an application specific integrated circuit (ASIC). In addition, the ASIC can be located in a network device. Of course, the processor and storage medium can also exist as discrete components.
[0154] Through the description of the above implementation methods, technical personnel in the relevant field can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional modules is used as an example. In actual applications, the above-mentioned functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.
Claims
1. A method for sharing an IPsec tunnel, characterized in that: Applied to a first network device, the first network device provides services for multiple target objects, the target objects are operators or service instances, the multiple target objects include a first target object and a second target object, one or more IPsec tunnels are established between the first network device and the second network device, and the method includes: Sending a first data packet and a second data packet to the second network device through the first IPsec tunnel, where the first data packet belongs to the first target object, and the second data packet belongs to a second different target object, the first data packet includes first service data and first information, and the first information is used to indicate the first target object, and the second data packet includes second service data and second information, and the second information is used to indicate the second target object; The first IPsec tunnel is one of the one or more IPsec tunnels.
2. The method according to claim 1, characterized in that: The sending the first data packet and the second data packet to the second network device through the first IPsec tunnel includes: Transmitting the first service data and the second service data to the tunnel interface of the first IPsec tunnel respectively; The first service data and the second service data are encrypted at the tunnel interface to obtain the first data message and the second data message; The first data packet and the second data packet are sent to the second network device through the first IPsec tunnel.
3. The method according to claim 2, characterized in that The transmitting the first service data and the second service data to the tunnel interface of the first IPsec tunnel respectively includes: The first service data and the second service data are transmitted to the tunnel interface according to a preset routing mode of the inner address.
4. The method according to claim 3, characterized in that The preset routing mode of the inner address includes one or more of the following: destination address routing, source address routing, and policy routing.
5. The method according to any one of claims 2 to 4, characterized in that: Both the first service data and the second service data pass the traffic selection of the tunnel interface.
6. The method according to any one of claims 2 to 5, characterized in that: The tunnel interface includes a traffic selector, and the encrypting the first service data and the second service data at the tunnel interface respectively includes: The traffic selector is used to select the first service data and the second service data at the tunnel interface, and the first service data and the second service data are encrypted respectively when the traffic selection is passed.
7. The method according to claim 6, characterized in that The performing flow selection on the first service data and the second service data includes: It is determined that the inner addresses corresponding to the first business data and the second business data meet the preset address range of the traffic selector, and it is determined that the traffic is selected to pass.
8. The method according to claim 6 or 7, characterized in that: The performing flow selection on the first service data and the second service data by the flow selector includes: The traffic selector performs traffic selection on the first service data and the second service data based on the any-any selection strategy, Among them, the IPv4 address range corresponding to the traffic selector is 0.0.0.0 / 0~0.0.0.0 / 0, and the corresponding IPv6 address range is ::0 / 0~::0 / 0.
9. The method according to any one of claims 2 to 8, characterized in that: The encrypting the first service data and the second service data at the tunnel interface respectively includes: After writing the first virtual routing domain identifier corresponding to the first target object into the first information, encrypting the first service data; And after writing the second virtual routing domain identifier corresponding to the second target object into the second information, the second service data is encrypted.
10. The method according to claim 9, characterized in that The step of writing the virtual routing domain identifier corresponding to the first target object into the first information includes: Writing a first virtual routing domain identifier corresponding to the first target object into the first information based on a first mapping mechanism; The step of writing the virtual routing domain identifier corresponding to the second target object into the second information includes: Writing the second virtual routing domain identifier corresponding to the second target object into the second information based on the second mapping mechanism; The first mapping mechanism and the second mapping mechanism may be the same or different.
11. The method according to claim 10, characterized in that The first data packet includes a field for carrying first information, and the second data packet includes a field for carrying second information, and the field includes one or more of the following: an extended header field, a special field, a reserved field, a TTL field, a flowlable field, and a dh header field.
12. The method according to claim 1, characterized in that The first business data includes first address information, and the first address information is used to indicate the first target object. The second business data includes second address information, and the second address information is used to indicate the second target object.
13. A method for sharing an IPsec tunnel, characterized in that: Applied to a second network device, the second network device provides services for multiple target objects, the target objects are operators or service instances, the multiple target objects include a first target object and a second target object, one or more IPsec tunnels are established between the second network device and the first network device, and the method includes: Receive a first data packet and a second data packet sent by a first network device through a first IPsec tunnel, wherein the first data packet includes first service data and first information, and the first information is used to indicate the first target object, and the second data packet includes second service data and second information, and the second information is used to indicate the second target object; The first service data and the first information are obtained from the first data packet, and the second service data and the second information are obtained from the second data packet.
14. The method according to claim 13, characterized in that The acquiring the first service data and the first information from the first data message includes: Parsing the first data message according to the security protocol policy corresponding to the first IPsec tunnel to obtain the first service data and the first information; The acquiring the second service data and the second information from the second data message includes: The second data packet is parsed according to the security protocol policy corresponding to the first IPsec tunnel to obtain the second business data and the second information.
15. The method according to claim 13 or 14, characterized in that The method further comprises: Acquire a first virtual routing domain identifier corresponding to the first information based on a third mapping mechanism, where the first information is encapsulated in the first data message by the first network device based on the first mapping mechanism; The second virtual routing domain identifier corresponding to the second information is obtained based on the fourth mapping mechanism, and the second information is encapsulated in the second data message by the first network device based on the first mapping mechanism. The third mapping mechanism and the fourth mapping mechanism may be the same or different.
16. The method according to claim 15, characterized in that The first data message and the second data message include one or more of the following fields: an extended header field, a special field, a reserved field, a TTL field, a flowlable field, and a dh header field, and the first information is located in the field.
17. The method according to any one of claims 13 to 16, characterized in that: The method further comprises: According to the first virtual routing domain identifier, the first service data is transmitted to a first target object served by the second network device, and the first virtual routing domain identifier is associated with the first target object; According to the second virtual routing domain identifier, the second service data is transmitted to a second target object served by the second network device, and the second virtual routing domain identifier is associated with the second target object.
18. The method according to claim 13, characterized in that The first business data includes first address information, and the first address information is used to indicate the first target object. The second business data includes second address information, and the second address information is used to indicate the second target object.
19. The method according to claim 18, characterized in that The method further comprises: transmitting the first service data to a first target object served by the second network device according to the first address information; The second service data is transmitted to a second target object served by the second network device according to the second address information.
20. A communication system, characterized in that: The communication system comprises a first network device and a second network device, wherein the first network device is used to implement the method according to any one of claims 1 to 12, and the second network device is used to implement the method according to any one of claims 13 to 19.
21. A network device, characterized in that: The network equipment includes: A transceiver, used for sending and receiving signals; a memory for storing computer program instructions; A processor, configured to execute the computer program instructions to support the network device to implement the method as described in any one of claims 1-12 or 13-19.
22. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer program instructions, and when the computer program instructions are executed by the processing circuit, the method according to any one of claims 1-12 or 13-19 is implemented.
23. A computer program product comprising instructions, characterized in that When the computer program product is run on a computer, the computer is caused to perform the method according to any one of claims 1 to 12 or 13 to 19.
24. A chip system, characterized in that: The chip system includes a processing circuit and a storage medium, wherein the storage medium stores computer program instructions; when the computer program instructions are executed by the processing circuit, the method as described in any one of claims 1-12 or 13-19 is implemented.
Citation Information
Patent Citations
Method, device and system for sharing IPsec tunnel
CN120111495A
Method, system and access gateway for traffic flows to share resources
CN101998494A
Service routing function for flexible packet path for secured traffic
CN113875199A
Method and system for realizing small base station sharing
CN114039815A
System and methods for routing internet protocol, IP, traffic
WO2023073350A1