Access control method, device and system
By adopting hierarchical structure encoding and inheritance transmission mechanism in the enterprise network, the access control rule inheritance transmission of the security group is realized, which solves the problems of cumbersome access control rule configuration and high resource overhead in the enterprise network, and improves configuration efficiency and resource utilization.
Patent Information
- Application Number
- PCT/CN2024/143021
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-03-21
- Filing Date
- 2024-12-27
- Publication Date
- 2025-09-25
AI Technical Summary
In enterprise network scenarios, due to the departmental hierarchical structure, a large number of duplicate access control rules need to be configured on policy execution devices. This configuration is cumbersome and resource-intensive. Especially when the departmental hierarchy increases or resources increase, the configuration difficulty and resource requirements increase exponentially.
Adopting hierarchical structure encoding and inheritance transmission mechanism, access control rules are inherited and transmitted through the encoding information of security groups, so that the inheriting security group automatically matches the rules of the inherited security group without repeated configuration, reducing the access control rule entries on the policy execution device.
This reduces the number of access control rules configured on policy enforcement devices, saves table resources, reduces configuration complexity and management difficulty, and improves the efficiency of network resource configuration.
Smart Images

Figure CN2024143021_25092025_PF_FP_ABST
Abstract
Description
Access control method, device and system
[0001] This application claims priority to Chinese patent application number 202410331367.5, filed on March 21, 2024, entitled “Access Control Method, Device and System,” the entire contents of which are incorporated herein by reference. Technical Field
[0002] The present application relates to the field of communication technology, and in particular to an access control method, device, and system. Background Art
[0003] In some network scenarios, such as enterprise and campus networks, security group-based networking is often used. When a user terminal accesses the intranet, the authentication server authenticates the user terminal and assigns the user to a security group. By configuring access control rules for the security group, users can access network resources based on the permissions assigned to the security group.
[0004] For example, an enterprise usually divides security groups based on departments, and grants each department corresponding network resource access rights at the security group level. Due to the inherent hierarchical structure of enterprise departments, lower-level departments usually have corresponding network resource access rights for upper-level departments. However, it is currently necessary to independently and completely configure all accessible network resources for each security group on the policy execution device. Therefore, when the department hierarchy increases or the network resources corresponding to the upper-level department increase, the number of access control rule entries that need to be configured on the policy execution device will increase exponentially, making the configuration very cumbersome. Among them, the policy execution device can be any data transmission device between the user terminal and the network resource provider. Summary of the Invention
[0005] The present application provides an access control method, device, and system.
[0006] In a first aspect, an access control method is provided. A policy execution device receives a message. The policy execution device obtains the source information or destination information of the message. Based on the source information or destination information, the policy execution device obtains a target access control rule from an access control rule set. The access control rule set includes one or more access control rules, each access control rule includes a matching condition and an action, and the source information or destination information meets the matching condition in the target access control rule. The policy execution device executes the action in the target access control rule on the message. The source device and the destination device of the message meet the following conditions: the source device of the message belongs to a source security group, the source information includes the encoding information corresponding to the source security group, and / or the destination device of the message belongs to a destination security group, and the destination information includes the encoding information corresponding to the destination security group. The encoding information corresponding to a security group is used to identify the security group, and if the security group is configured to inherit a security group, the encoding information corresponding to the security group also indicates the inherited security group on which the security group depends. The inheriting security group is configured to inherit the access control rules corresponding to the inherited security group on which it depends.
[0007] In this application, for a security group configured as an inheriting security group, the encoding information corresponding to the security group can not only identify the security group itself, but also indicate the inherited security group on which the security group depends. Since the inheriting security group is configured to inherit the access control rules corresponding to the inherited security group, the inheriting security group can automatically match the access control rules corresponding to the inherited security group without the need to explicitly reconfigure the same access control rules as the inherited security group for the inheriting security group, thereby reducing the number of access control rule entries required to be configured on the policy execution device and saving table resources.
[0008] Optionally, the source information includes encoding information corresponding to the source security group, and the matching conditions in each access control rule include a pair of source identifiers and destination identifiers, wherein the source identifier in the target access control rule is represented by the encoding information corresponding to the security group, and the source information satisfies the matching conditions in the target access control rule, including: the security group identified by the source identifier in the target access control rule is the source security group identified by the source information or the inherited security group on which the source security group indicated by the source information depends.
[0009] Optionally, the source security group is a user group. This application configures the inheritance and transfer of access control rules by user groups, so that the user group can match not only its own corresponding access control rules, but also automatically match the access control rules corresponding to other user groups that it directly or indirectly inherits. This allows the user group to have access rights to its own unique resources and to the resources owned by other user groups that it directly or indirectly inherits, without the need to explicitly reconfigure the access control rules corresponding to other user groups that the user group inherits.
[0010] Optionally, the destination information includes the destination address of the message, the destination port number of the message or the group identifier of the destination security group, and the destination information satisfies the matching condition in the target access control rule, including: the destination information is the same as the destination identifier in the target access control rule.
[0011] Optionally, the destination security group is an application group. This application uses hierarchical encoding for source information (such as the group identifier of a user group) to achieve inheritance and transmission of access control rules, while the destination information can continue to use the existing solution. Alternatively, if the destination is a security group, hierarchical encoding can also be used to represent the destination information. This application does not limit the expression method of the destination information.
[0012] Optionally, the policy execution device stores coding information corresponding to multiple security groups with an inheritance relationship, the inheritance relationship between the multiple security groups is associated with n inheritance levels, and the coding information corresponding to each security group in the multiple security groups includes n coding segments, and the n coding segments correspond one-to-one to the n inheritance levels, where n is a positive integer greater than 1. For any security group in the multiple security groups that is configured as an inheriting security group, the valid coding segments in the coding information corresponding to the security group include the coding segments corresponding to the inheritance level where the security group is located and the valid coding segments in the coding information corresponding to the inherited security group on which the security group depends, wherein the coding value of the valid coding segment in the coding information corresponding to the security group is used to identify the security group, and the coding value of the valid coding segment in the coding information corresponding to the inherited security group on which the security group depends is used to identify the inherited security group on which the security group depends, and the valid coding segment in the coding information corresponding to a security group is valid matching information for access control rules.
[0013] This application uses segmented hierarchical coding to achieve fuzzy matching of the coding information corresponding to the inherited security group by the coding information corresponding to the inherited security group. The characteristic is that a coding segment is allocated to each inheritance level.
[0014] Optionally, the multiple security groups include a root security group configured as a non-inherited security group, and the valid coding segment in the coding information corresponding to the root security group includes the coding segment corresponding to the inheritance level where the root security group is located.
[0015] Optionally, the encoding information is represented by a code value domain and mask information, where the mask information indicates valid code segments in the code value domain. For any security group configured as an inheriting security group among multiple security groups, the code value domain corresponding to the security group inherits the values of valid code segments in the code value domain corresponding to the inherited security group on which the security group depends.
[0016] Optionally, the mask information is a mask field having the same length as the encoding value field.
[0017] Alternatively, the encoding information satisfies the following conditions: the encoding segment corresponding to the inheritance level of the inherited security group is located in the high bit of the encoding segment corresponding to the inheritance level of the corresponding inheriting security group. The mask information is the mask length, which is used to indicate the valid length of the encoding value range.
[0018] Optionally, the policy execution device generates encoding information corresponding to the multiple security groups according to the inheritance relationship between the configured multiple security groups.
[0019] Alternatively, the policy execution device receives the coded information corresponding to the multiple security groups sent by the policy decision device.
[0020] Optionally, the matching conditions in each access control rule include a pair of source identifiers and destination identifiers. If the source information includes the coding information corresponding to the source security group, the source information satisfies the matching conditions in the target access control rule, including: the valid coding segment in the source identifier of the target access control rule is the valid coding segment in the coding information corresponding to the source security group or the valid coding segment in the coding information corresponding to the inherited security group on which the source security group depends. If the destination information includes the coding information corresponding to the destination security group, the destination information satisfies the matching conditions in the target access control rule, including: the valid coding segment in the destination identifier of the target access control rule is the valid coding segment in the coding information corresponding to the destination security group or the valid coding segment in the coding information corresponding to the inherited security group on which the destination security group depends.
[0021] Optionally, the policy enforcement device includes a ternary content addressable memory (TCAM), and each access control rule is represented by a TCAM entry and a corresponding action entry. Each TCAM entry is used to store a matching condition in an access control rule, and the action entry corresponding to the TCAM entry is used to store an action corresponding to the matching condition in the TCAM entry.
[0022] This application uses the third-state fuzzy matching capability of TCAM to achieve the inheritance and transmission capability of access control rules between different security groups.
[0023] Optionally, the policy execution device is an egress endpoint of a virtual extensible local area network (VXLAN) tunnel, the source information includes encoding information corresponding to the source security group, and the VXLAN header of the message carries the encoding information corresponding to the source security group. The policy execution device obtains the source information of the message by parsing the VXLAN header of the message to obtain the encoding information corresponding to the source security group.
[0024] In this application, when the source device of the message belongs to the source security group and the source security group is configured with the hierarchical structure encoding provided by this application, by carrying the encoding information corresponding to the source security group in the VXLAN header of the VXLAN message, the egress endpoint of the VXLAN tunnel can directly execute the GBP policy based on the encoding information corresponding to the source security group, and there is no need to send the encoding information corresponding to the source security group to the egress endpoint of the VXLAN tunnel.
[0025] Optionally, the VXLAN header of the message further carries a target indication, where the target indication is used to indicate that the source information type carried in the VXLAN header is the encoded information corresponding to the security group.
[0026] Optionally, the encoding information corresponding to the source security group is carried in the reserved bits of the VXLAN header.
[0027] Optionally, the policy execution device is an egress endpoint of a Generic Network Virtualization Encapsulation (Geneve) tunnel, the source information includes encoding information corresponding to the source security group, and the Geneve header of the message carries the encoding information corresponding to the source security group. The policy execution device obtains the source information of the message by parsing the Geneve header of the message to obtain the encoding information corresponding to the source security group.
[0028] Optionally, the encoding information corresponding to the source security group is carried in the option field of the Geneve header in the form of type-length-value (TLV) or type-value (TV).
[0029] Optionally, the policy execution device obtains the source information or destination information of the message, including: the policy execution device obtains the source information of the message based on the source address of the message and / or the policy execution device's receiving port for the message; the policy execution device obtains the destination information of the message based on the destination address of the message and / or the policy execution device's sending port for the message.
[0030] In this implementation mode, the policy execution device first obtains the source security group information or destination security group information of the message based on the message content or the sending and receiving ports of the message, and then obtains the hierarchical structure code corresponding to the source security group information or the destination security group information.
[0031] In a second aspect, an access control method is provided. A policy decision device generates encoding information corresponding to each of the multiple security groups based on the inheritance relationship between the configured multiple security groups. The policy decision device sends the encoding information corresponding to each of the multiple security groups to a policy execution device, so that the policy execution device can perform access control on received messages. The inheritance relationship between the multiple security groups is associated with n inheritance levels, and the encoding information corresponding to each of the multiple security groups includes n encoding segments, each of the n encoding segments corresponds one-to-one to n inheritance levels, where n is a positive integer greater than 1. For any security group configured as an inheriting security group among multiple security groups, the valid coding segment in the coding information corresponding to the security group includes the coding segment corresponding to the inheritance hierarchy where the security group is located and the valid coding segment in the coding information corresponding to the inherited security group on which the security group depends. The coding value of the valid coding segment in the coding information corresponding to the security group is used to identify the security group, and the coding value of the valid coding segment in the coding information corresponding to the inherited security group on which the security group depends is used to identify the inherited security group on which the security group depends. For a root security group configured as a non-inheriting security group among multiple security groups, the valid coding segment in the coding information corresponding to the root security group includes the coding segment corresponding to the inheritance hierarchy where the root security group is located. The valid coding segment in the coding information corresponding to a security group is the valid matching information for the access control rule.
[0032] In a third aspect, an access control device is provided. The access control device includes multiple functional modules that interact with each other to implement the method of the first aspect and its respective embodiments. The multiple functional modules can be implemented based on software, hardware, or a combination of software and hardware, and the multiple functional modules can be arbitrarily combined or divided based on the specific implementation.
[0033] In a fourth aspect, an access control device is provided. The access control device includes multiple functional modules that interact with each other to implement the method of the second aspect and its respective embodiments. The multiple functional modules can be implemented based on software, hardware, or a combination of software and hardware, and the multiple functional modules can be arbitrarily combined or divided based on the specific implementation.
[0034] In a fifth aspect, a policy execution device is provided, comprising: a memory, a network interface, and at least one processor,
[0035] The memory is used to store program instructions,
[0036] After the at least one processor reads the program instructions stored in the memory, it causes the policy execution device to execute the method in the above-mentioned first aspect and its various embodiments.
[0037] For example, after the at least one processor reads the program instructions stored in the memory, the policy execution device performs the following operations:
[0038] Receive a message; obtain source information or destination information of the message; obtain a target access control rule from an access control rule set based on the source information or the destination information; and execute an action in the target access control rule on the message. The access control rule set includes one or more access control rules, each of which includes a matching condition and an action, and the source information or the destination information satisfies the matching condition in the target access control rule. The source device and destination device of the message satisfy the following conditions: the source device of the message belongs to a source security group, the source information includes encoding information corresponding to the source security group, and / or the destination device of the message belongs to a destination security group, and the destination information includes encoding information corresponding to the destination security group. The encoding information corresponding to a security group is used to identify the security group, and if the security group is configured as an inheriting security group, the encoding information corresponding to the security group also indicates the inherited security group on which the security group depends. The inheriting security group is configured to inherit the access control rules corresponding to the inherited security group on which it depends.
[0039] Optionally, the source information includes the encoding information corresponding to the source security group, and the matching conditions in each access control rule include a pair of source identifiers and destination identifiers, respectively, wherein the source identifier in the target access control rule is represented by the encoding information corresponding to the security group, and the source information satisfies the matching conditions in the target access control rule, including: the security group identified by the source identifier in the target access control rule is the source security group identified by the source information or the inherited security group on which the source security group indicated by the source information depends.
[0040] Optionally, the destination information includes the destination address of the message, the destination port number of the message or the group identifier of the destination security group, and the destination information satisfies the matching conditions in the target access control rule, including: the destination information is the same as the destination identifier in the target access control rule.
[0041] Optionally, the policy execution device stores coding information corresponding to a plurality of security groups having an inheritance relationship, wherein the inheritance relationship between the plurality of security groups is associated with n inheritance levels, and the coding information corresponding to each of the plurality of security groups includes n coding segments, wherein the n coding segments correspond one-to-one to the n inheritance levels, and n is a positive integer greater than 1. For any security group configured as an inheriting security group among the plurality of security groups, the valid coding segments in the coding information corresponding to the security group include the coding segments corresponding to the inheritance level where the security group is located and the valid coding segments in the coding information corresponding to the inherited security group on which the security group depends, wherein the coding value of the valid coding segment in the coding information corresponding to the security group is used to identify the security group, and the coding value of the valid coding segment in the coding information corresponding to the inherited security group on which the security group depends is used to identify the inherited security group on which the security group depends, and the valid coding segment in the coding information corresponding to a security group is the valid matching information for the access control rule.
[0042] Optionally, the multiple security groups include a root security group configured as a non-inherited security group, and the valid coding segment in the coding information corresponding to the root security group includes the coding segment corresponding to the inheritance level where the root security group is located.
[0043] Optionally, the encoding information is represented by an encoding value domain and mask information, where the mask information is used to indicate valid encoding segments in the encoding value domain. For any security group among the multiple security groups that is configured as an inheriting security group, the encoding value domain corresponding to the security group inherits the value of the valid encoding segment in the encoding value domain corresponding to the inherited security group on which the security group depends.
[0044] Optionally, the mask information is a mask field having the same length as the encoding value field.
[0045] Alternatively, the encoding information satisfies: the encoding segment corresponding to the inheritance level of the inherited security group is located at the high bit of the encoding segment corresponding to the inheritance level of the corresponding inheriting security group. The mask information is a mask length, and the mask length is used to indicate the valid length of the encoding value range.
[0046] Optionally, after the program instructions are read by the at least one processor, the policy execution device further performs the following operations: generating encoding information corresponding to the multiple security groups respectively according to the configured inheritance relationship between the multiple security groups.
[0047] Alternatively, after the program instructions are read by the at least one processor, the policy execution device further performs the following operations: receiving the encoding information corresponding to the multiple security groups respectively sent by the policy decision device.
[0048] Optionally, the matching conditions in each access control rule include a pair of source identifiers and destination identifiers. If the source information includes the coding information corresponding to the source security group, the source information satisfies the matching conditions in the target access control rule, including: the valid coding segment in the source identifier of the target access control rule is the valid coding segment in the coding information corresponding to the source security group or the valid coding segment in the coding information corresponding to the inherited security group on which the source security group depends. If the destination information includes the coding information corresponding to the destination security group, the destination information satisfies the matching conditions in the target access control rule, including: the valid coding segment in the destination identifier of the target access control rule is the valid coding segment in the coding information corresponding to the destination security group or the valid coding segment in the coding information corresponding to the inherited security group on which the destination security group depends.
[0049] Optionally, the policy execution device includes a TCAM, and each access control rule is represented by a TCAM table entry and a corresponding action table entry. Each TCAM table entry is used to store a matching condition in an access control rule, and the action table entry corresponding to the TCAM table entry is used to store an action corresponding to the matching condition in the TCAM table entry.
[0050] Optionally, the policy execution device is the exit endpoint of the VXLAN tunnel, the source end information includes the encoding information corresponding to the source security group, the VXLAN header of the message carries the encoding information corresponding to the source security group, and after the program instructions are read by the at least one processor, the policy execution device performs the following operations: parse the VXLAN header of the message to obtain the encoding information corresponding to the source security group.
[0051] Optionally, the VXLAN header of the message further carries a target indication, where the target indication is used to indicate that the source information type carried in the VXLAN header is the encoded information corresponding to the security group.
[0052] Optionally, the encoding information corresponding to the source security group is carried in the reserved bit of the VXLAN header.
[0053] Optionally, the policy execution device is the exit endpoint of the Geneve tunnel, the source end information includes the encoding information corresponding to the source security group, the Geneve header of the message carries the encoding information corresponding to the source security group, and after the program instructions are read by the at least one processor, the policy execution device performs the following operations: parse the Geneve header of the message to obtain the encoding information corresponding to the source security group.
[0054] Optionally, the encoding information corresponding to the source security group is carried in the option field of the Geneve header in the form of TLV or TV.
[0055] Optionally, after the program instructions are read by the at least one processor, the policy execution device performs the following operations: obtain the source end information of the message based on the source address of the message and / or the receiving port of the message by the policy execution device; obtain the destination end information of the message based on the destination address of the message and / or the sending port of the message by the policy execution device.
[0056] In a sixth aspect, a policy decision device is provided, comprising: a memory, a network interface, and at least one processor,
[0057] The memory is used to store program instructions,
[0058] After the at least one processor reads the program instructions stored in the memory, it causes the policy execution device to execute the method in the above-mentioned second aspect and its various embodiments.
[0059] For example, after the at least one processor reads the program instructions stored in the memory, the policy decision device performs the following operations:
[0060] Generate encoding information corresponding to each of the multiple security groups based on the configured inheritance relationships among the multiple security groups; and send the encoding information corresponding to each of the multiple security groups to a policy execution device for use by the policy execution device in performing access control on received messages. The inheritance relationships among the multiple security groups are associated with n inheritance levels, and the encoding information corresponding to each of the multiple security groups includes n encoding segments, each of the n encoding segments corresponding one-to-one to the n inheritance levels, where n is a positive integer greater than 1. For any security group among the multiple security groups that is configured as an inheriting security group, the valid coding segment in the coding information corresponding to the security group includes the coding segment corresponding to the inheritance hierarchy where the security group is located and the valid coding segment in the coding information corresponding to the inherited security group on which the security group depends, wherein the coding value of the valid coding segment in the coding information corresponding to the security group is used to identify the security group, and the coding value of the valid coding segment in the coding information corresponding to the inherited security group on which the security group depends is used to identify the inherited security group on which the security group depends; for the root security group among the multiple security groups that is configured as a non-inheriting security group, the valid coding segment in the coding information corresponding to the root security group includes the coding segment corresponding to the inheritance hierarchy where the root security group is located; the valid coding segment in the coding information corresponding to a security group is the valid matching information for the access control rule.
[0061] In the seventh aspect, an access control system is provided, comprising: a policy execution device and a policy decision device, wherein the policy execution device is used to execute the method in the above-mentioned first aspect and its various embodiments, and the policy decision device is used to execute the method in the above-mentioned second aspect and its various embodiments.
[0062] In an eighth aspect, a computer-readable storage medium is provided, on which instructions are stored. When the instructions are executed by a processor, the method of the above-mentioned first aspect and its various embodiments is implemented, and / or the method of the above-mentioned second aspect and its various embodiments is implemented.
[0063] In the ninth aspect, a computer program product is provided, comprising a computer program, which, when executed by a processor, implements the method of the above-mentioned first aspect and its various embodiments, and / or implements the method of the above-mentioned second aspect and its various embodiments.
[0064] In the tenth aspect, a chip is provided, which includes a programmable logic circuit and / or program instructions. When the chip is running, it implements the method of the above-mentioned first aspect and its various embodiments, and / or the method of the above-mentioned second aspect and its various embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0065] FIG1 is a schematic diagram of access control based on CAM provided in an embodiment of the present application;
[0066] FIG2 is a schematic diagram of resource access rights corresponding to enterprise departments provided in an embodiment of the present application;
[0067] FIG3 is a schematic diagram of fuzzy matching based on TCAM provided in an embodiment of the present application;
[0068] FIG4 is a schematic diagram of coding information corresponding to a security group provided in an embodiment of the present application;
[0069] FIG5 is a schematic diagram of binary bit representation of coding information in a TCAM according to an embodiment of the present application;
[0070] FIG6 is a schematic diagram of fuzzy matching based on hierarchical structure coding provided in an embodiment of the present application;
[0071] FIG7 is a schematic diagram of an application scenario provided by an embodiment of the present application;
[0072] FIG8 is a schematic diagram of a system architecture provided by an embodiment of the present application;
[0073] FIG9 is a schematic diagram of the hardware structure of a server provided in an embodiment of the present application;
[0074] FIG10 is a schematic diagram of the hardware structure of a network device provided in an embodiment of the present application;
[0075] FIG11 is a schematic diagram of an implementation flow of an access control method provided in an embodiment of the present application;
[0076] FIG12 is a schematic diagram of a VXLAN networking scenario provided in an embodiment of the present application;
[0077] FIG13 is a schematic diagram of the structure of a standard VXLAN header provided by the related art;
[0078] FIG14 is a schematic diagram of the structure of an extended VXLAN header provided by the related art;
[0079] FIG15 is a schematic diagram of the structure of an extended VXLAN header provided in an embodiment of the present application;
[0080] FIG16 is a schematic structural diagram of a Geneve head provided by the related art;
[0081] FIG17 is a schematic structural diagram of an extended Geneve header provided in an embodiment of the present application;
[0082] FIG18 is a schematic structural diagram of an access control device provided in an embodiment of the present application;
[0083] FIG19 is a schematic structural diagram of another access control device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0084] In order to make the objectives, technical solutions and advantages of this application clearer, the implementation methods of this application will be further described in detail below with reference to the accompanying drawings.
[0085] First, some technical terms involved in this application are explained below.
[0086] 1. Microsegmentation: Microsegmentation is a security isolation technology that uses fine-grained grouping to control traffic based on group identifiers after grouping packets. For example, in a data center network (DCN), servers are grouped according to certain principles, such as grouping based on Internet Protocol (IP) addresses or Media Access Control (MAC) addresses, and then traffic control policies are deployed based on the groups, thereby simplifying operations and security management. A microsegment is a group that divides network devices or endpoints (such as one or a group of servers) according to certain principles. Each microsegment has a globally unique microsegment identifier. The traffic control policy based on microsegmentation is called a group-based policy (GBP).
[0087] 2. Security Group (SG): A security group is a collection of users, network devices, endpoints, or resources that share the same access control rules. Each security group has a globally unique security group identifier, or security group tag (SGT). Security group-based access control lists (ACLs) are called security group access control lists (SGACLs), which define the access control rules between a source security group and a destination security group.
[0088] 3. User Group: A group of network access users classified by a micro-segment or security group. This group is also called a user group. This means that a user group is a micro-segment or security group for a specific target (network access user).
[0089] 4. Application Group: A group of devices, resources, or applications that are targeted by a micro-segmentation or security group classification. This is also called an application group. An application group is a micro-segmentation or security group for a specific object (device, resource, or application).
[0090] Based on the above definitions of micro-segmentation and security group, we can see that both micro-segmentation and security group refer to a collection of similar objects in a data transmission system. This application solution will uniformly use the description of "security group", which can also be replaced by "micro-segmentation" without limitation.
[0091] Content addressable memory (CAM) is a type of memory that is addressed by content. The main working mechanism of CAM is to automatically compare an input data item with all data items stored in the CAM, determine whether the input data item matches the data items stored in the CAM, and output the matching information corresponding to the input data item. Due to the fast search capability of CAM, CAM is often used in data transmission equipment as a flow classification device to implement access control rules. The specific method is to use certain content of the message as the search keyword (key) of CAM. CAM compares all stored table entries with the keyword. If a completely matching table entry is found, the data transmission device executes the action bound to the table entry (including but not limited to discarding the message, forwarding the message, redirecting the message, or modifying certain information of the message). If there are multiple table entries in the CAM that completely match the keyword, the data transmission device executes the action bound to the table entry with the highest priority.
[0092] In some network scenarios, such as enterprise and campus network scenarios, a security group-based networking configuration is usually adopted for both communicating parties, and access control rules are set for the source security group (such as the user group) and the destination security group (such as the application group). By configuring the access control rules on the data transmission device located between the source security group and the destination security group, access control of the source security group to the destination security group is achieved. Each access control rule includes a matching condition and an action. If the matching condition in the access control rule is implemented based on CAM on the data transmission device, each table entry stored in the CAM includes a source security group identifier and a destination security group identifier, and each table entry in the CAM corresponds to an action table entry. For example, Figure 1 is a schematic diagram of access control based on CAM implementation provided in an embodiment of the present application. As shown in Figure 1, the data transmission device first extracts the five-tuple of the received message, which includes the source IP address, destination IP address, transport layer protocol, source port, and destination port; secondly, it obtains the source security group identifier and destination security group identifier corresponding to the message based on the five-tuple of the message; then, it uses the source security group identifier and destination security group identifier corresponding to the message as keywords to search the table entries stored in the CAM for matching; if there is a table entry in the CAM that completely matches the source security group identifier and destination security group identifier corresponding to the message, the action bound to the table entry is executed.
[0093] Taking the enterprise scenario as an example, the enterprise usually divides user groups based on departments and grants resource access rights to user groups, so that different departments have access rights to specific resources. Enterprise departments naturally have a hierarchical structure, and lower-level departments usually have resource access rights corresponding to upper-level departments. For example, Figure 2 is a schematic diagram of resource access rights corresponding to enterprise departments provided in an embodiment of the present application. As shown in Figure 2, the lower-level departments at the company level include the Finance Department and the Information Technology (IT) Department, the lower-level departments of the Finance Department include the Securities Department and the Futures Department, and the lower-level departments of the IT Department include the Network Department. Enterprise resources include email and office automation (OA) systems, asset servers, securities servers, futures servers, operation and maintenance servers, and network management servers. Among them, email and OA systems are company-level resources, accessible to the company level and all its lower-level departments. The asset server is a unique resource of the Finance Department, accessible to the Finance Department and all its lower-level departments. The securities server is a unique resource of the Securities Department, accessible only to the Securities Department. The futures server is a unique resource of the Futures Department, accessible only to the Futures Department. The operations and maintenance server is a resource unique to the IT department, accessible to the IT department and all its subordinate departments. The network management server is a resource unique to the Network department, accessible only to the Network department. Accordingly, employees in the Securities Department (such as Employee A) have access to the department's unique securities server, the superior Finance Department's unique asset server, and even higher-level corporate email and OA systems. Employees in the Futures Department (such as Employee B) have access to the department's unique futures server, the superior Finance Department's unique asset server, and even higher-level corporate email and OA systems. Employees in the Network Department (such as Employee C) have access to the department's unique network management server, the superior IT Department's unique operations and maintenance server, and even higher-level corporate email and OA systems. To ensure that employees in different departments have access to specific resources, you can divide departments into user groups. For example, you can group the corporate level, finance department, securities department, futures department, IT department, and network department into user groups, and assign a globally unique user group ID to each. Additionally, you can group different enterprise resources into application groups. For example, you can group email and OA systems, asset servers, securities servers, futures servers, operations and maintenance servers, and network management servers into application groups, and assign each application group a globally unique application group ID.
[0094] Since the user group identifiers currently assigned to different user groups are independent, that is, there is no correlation between the user group identifiers corresponding to different user groups, when the access control rules in the CAM are represented by user group identifiers, in order to meet the access requirements shown in Figure 2, all accessible application groups need to be independently and completely configured for each user group in the CAM. The table items required to be configured in the CAM are shown in Table 1.
[0095] Table 1
[0096] As shown in Table 1, currently, subordinate departments must explicitly grant permissions to all superior departments. Each subordinate department typically requires multiple entries to ensure access to both its own unique resources and those owned by its superior department. The bold entries in Table 1 essentially duplicate the subordinate department's access to its superior department's resources. This configuration is cumbersome and prone to errors, requiring numerous entries and incurring significant CAM overhead. Furthermore, with this configuration approach, as the number of departmental hierarchies or application groups increases, the number of duplicate entries between superior and subordinate departments will multiply. CAM entry resources can become a configuration bottleneck, exponentially increasing the difficulty for network operations personnel to configure and manage access control rules.
[0097] This application implements the inheritance and transmission of access control rules in the field of access control by designing a definition paradigm of upper and lower level security groups and hierarchical structure encoding. The lower level security group can automatically inherit the access rights possessed by the upper level security group, thereby reducing the number of access control rule entries that need to be manually explicitly configured, while reducing the resource usage of table entries. The technical solution provided by this application is specifically implemented as follows: the policy execution device first obtains the source end information or destination end information of the received message, and then obtains the target access control rule from the access control rule set based on the source end information or destination end information of the message, and executes the action in the target access control rule on the message. Among them, the access control rule set includes one or more access control rules, each access control rule includes a matching condition and an action, and the target access control rule is the access control rule whose source end information or destination end information of the message meets the matching condition. The source device and destination device of the message satisfy the following conditions: the source device of the message belongs to the source security group, the source information of the message includes the encoding information corresponding to the source security group, and / or the destination device of the message belongs to the destination security group, and the destination information of the message includes the encoding information corresponding to the destination security group. The encoding information corresponding to a security group is used to identify the security group, and if the security group is configured as an inheriting security group, the encoding information corresponding to the security group also indicates the inherited security group on which the security group depends. The inheriting security group is configured to inherit the access control rules corresponding to the inherited security group on which it depends. In this application, for a security group configured as an inheriting security group, the encoding information corresponding to the security group can not only identify the security group itself, but also indicate the inherited security group on which the security group depends. Since the inheriting security group is configured to inherit the access control rules corresponding to the inherited security group, the inheriting security group can automatically match the access control rules corresponding to the inherited security group without the need to explicitly reconfigure the same access control rules as the inherited security group for the inheriting security group, thereby reducing the number of access control rule entries required to be configured on the policy execution device and saving table resources.
[0098] In some embodiments, the source information of the message includes encoding information corresponding to the source security group, and the matching conditions in each access control rule include a pair of source identifiers and destination identifiers. The source identifier in the target access control rule is represented by the encoding information corresponding to the security group. The source information of the message satisfies the matching conditions in the target access control rule, including: the security group identified by the source identifier in the target access control rule is the source security group identified by the source information or the inherited security group on which the source security group indicated by the source information depends. Optionally, the source security group is a user group. The present application configures the inheritance and transfer of access control rules by user groups, so that the user group can not only match the access control rules corresponding to itself, but also automatically match the access control rules corresponding to other user groups that it directly or indirectly inherits, thereby allowing the user group to have access rights to its own unique resources and access rights to resources owned by other user groups that it directly or indirectly inherits, without the need to explicitly reconfigure the access control rules corresponding to other user groups that it inherits.
[0099] Optionally, in combination with the above-mentioned embodiment, the destination information of the message includes the destination address of the message, the destination port number of the message or the group identifier of the destination security group. The destination information of the message meets the matching conditions in the target access control rule, including: the destination information is the same as the destination identifier in the target access control rule. Optionally, the destination address is an IP address or a MAC address, and the destination security group is an application group. The present application adopts hierarchical structure encoding to the source information (such as the group identifier of the user group) to realize the inheritance and transmission of the access control rules, and the destination information can follow the existing scheme. Alternatively, if the destination is a security group, hierarchical structure encoding can also be used to represent the destination information, and the present application does not limit the expression method of the destination information.
[0100] For example, when the technical solution provided by the present application is used to implement the access request shown in Figure 2, by configuring the user group identifier corresponding to the subordinate department, the user group identifier corresponding to the subordinate department can not only identify the subordinate department, but also indicate the superior department corresponding to the subordinate department. For example, the user group identifier corresponding to the Finance Department can not only identify the Finance Department, but also indicate the superior department including the company level. In this way, the subordinate department can automatically inherit the access rights of the superior department. Therefore, it is only necessary to configure the unique access rights of each department at each level. For example, see Table 2 for the table items that need to be configured on the policy execution device.
[0101] Table 2
[0102] By comparing Table 1 and Table 2, it can be seen that the technical solution provided by the present application greatly reduces the access control rule entries that need to be configured on the policy execution device compared to the technical solutions provided by the related technologies, thereby saving CAM table entry resource overhead.
[0103] In some embodiments, the technical solution of the present application is implemented using a TCAM on a policy enforcement device. In a typical CAM, each bit can only have two states: "0" or "1." Compared to a typical CAM, each bit in a TCAM has a third state, "don't care," implemented through a mask. By leveraging the three-state characteristics of TCAM, the present application can implement both exact match and fuzzy match lookups. It is precisely the third-state characteristic of TCAM that enables fuzzy match lookups. For example, Figure 3 is a schematic diagram of a TCAM-based fuzzy matching implementation provided in an embodiment of the present application. As shown in Figure 3, the bit representation "1X0X1" (X represents "don't care") in the TCAM can fuzzily match "11011," "11001," "10011," and "10001." The present application can utilize the third-state fuzzy matching capability of TCAM to enable access control rule inheritance and transfer between different security groups. Optionally, the policy enforcement device includes a TCAM, and each access control rule is represented by a TCAM table entry and a corresponding action table entry. Each TCAM entry is used to store a matching condition in an access control rule, and the action entry corresponding to the TCAM entry is used to store the action corresponding to the matching condition in the TCAM entry. The matching condition in each access control rule includes, for example, a pair of source identifier and destination identifier.
[0104] The technical solution provided in this application includes the following four steps in its specific implementation: the first step is to define the inheritance relationship between security groups, the second step is to assign corresponding coding information to the security groups, the third step is to configure access control rules for the security groups in the policy execution device, and the fourth step is for the policy execution device to perform message filtering and forwarding based on the access control rules.
[0105] The first step is to define the inheritance relationship between security groups. By defining the inheriting security group and the inherited security group, the inheriting security group can inherit the access control rules corresponding to the inherited security group, so that the inheriting security group can inherit the resource permissions accessible to the inherited security group. For example, if security group B is the inheriting security group, and security group A is configured as the inherited security group of security group B, then the resources accessible to security group A can also be accessed by security group B. The inheritance relationship can be passed recursively. For example, if security group C inherits security group B, and security group B inherits security group A, then the resources accessible to security group A and security group B can be accessed by security group C, and so on for more levels. This application refers to the security group that does not inherit the permissions of any other security group as the root security group, that is, the root security group is configured as a non-inherited security group. For convenience, this application refers to the inheriting security group that inherits the permissions of the root security group as the first-level inheriting security group, the inheriting security group that inherits the permissions of the first-level inheriting security group as the second-level inheriting security group, and so on. If security group A is the root security group and security group B is its successor, then security group B is a first-level successor security group. If security group C is its successor, then security group C is a second-level successor security group.
[0106] The second step is to assign corresponding coding information to the security group. After defining the inheritance relationship between security groups, it is necessary to assign corresponding coding information to the security group so that the coding information corresponding to the security group configured as the inheriting security group can not only identify the security group, but also indicate the inherited security groups on which the security group depends. The coding information corresponding to the security group defined in this application is also called hierarchical structure coding.
[0107] In some embodiments, the policy execution device stores coding information corresponding to multiple security groups with an inheritance relationship, and the inheritance relationship between the multiple security groups is associated with n inheritance levels, that is, there is an n-1 level inheritance relationship between the multiple security groups. The coding information corresponding to each security group in the multiple security groups includes n coding segments, and the n coding segments correspond one-to-one to the n inheritance levels, where n is a positive integer greater than 1. For any security group in the multiple security groups that is configured as an inheriting security group, the valid coding segments in the coding information corresponding to the security group include the coding segments corresponding to the inheritance level where the security group is located and the valid coding segments in the coding information corresponding to the inherited security group on which the security group depends. Among them, the coding value of the valid coding segment in the coding information corresponding to the security group is used to identify the security group, and the coding value of the valid coding segment in the coding information corresponding to the inherited security group on which the security group depends is used to identify the inherited security group on which the security group depends. The valid coding segment in the coding information corresponding to a security group is the valid matching information for the access control rule. For the source or destination identifier in an access control rule represented by the encoding information corresponding to the security group, the valid encoding segment is the valid matching information in the access control rule. For the source or destination information of a message represented by the encoding information corresponding to the security group, the valid encoding segment is the valid matching information used to match the access control rule.
[0108] Optionally, the multiple security groups include a root security group configured as a non-inherited security group, and the valid coding segment in the coding information corresponding to the root security group includes the coding segment corresponding to the inheritance level where the root security group is located.
[0109] For example, the encoding information corresponding to each security group is represented as "encoding segment 1, encoding segment 2, ..., encoding segment n," where encoding segment 1 is the encoding segment corresponding to the inheritance level of the root security group, encoding segment 2 is the encoding segment corresponding to the inheritance level of the first-level inherited security group, and encoding segment n is the encoding segment corresponding to the inheritance level of the (n-1)-level inherited security group. For the root security group, the valid encoding segments in the encoding information include only encoding segment 1. For the first-level inherited security group, the valid encoding segments in the encoding information include encoding segments 1 and 2, where the content of encoding segment 1 is the same as the content of encoding segment 1 (valid encoding segment) in the encoding information corresponding to the root security group on which the first-level inherited security group depends. For the (n-1)-level inherited security group, the valid encoding segments in the encoding information include encoding segments 1 to n, where the content of encoding segments 1 to n-1 is the same as the content of encoding segments 1 to n-1 (valid encoding segments) in the encoding information corresponding to the (n-2)-level inherited security group on which the (n-1)-level inherited security group depends.
[0110] In some embodiments, the encoding information corresponding to a security group is represented using an encoding value domain and mask information, where the mask information indicates valid encoding segments in the encoding value domain. For any security group among multiple security groups that is configured as an inheriting security group, the encoding value domain corresponding to the security group inherits the value of the valid encoding segment in the encoding value domain corresponding to the inherited security group on which the security group depends. In other words, the valid encoding segment in the encoding value domain of the inheriting security group is the same as the valid encoding segment in the encoding value domain of the inherited security group.
[0111] Optionally, the mask information is a mask field of equal length to the encoding value field, i.e., the encoding information corresponding to the security group consists of an encoding value field and a mask field of equal length. A bit in the mask field takes a first value, indicating that the corresponding bit in the value field is a valid bit, and a bit in the mask field takes a second value, indicating that the corresponding bit in the value field is an invalid bit. The first value and the second value are different, such as the first value is 1 and the second value is 0. For example, FIG4 is a schematic diagram of encoding information corresponding to a security group provided in an embodiment of the present application. As shown in FIG4 , the encoding information adopts a hierarchical encoding format. The encoding information includes three encoding segments, which are encoding segment 1, encoding segment 2, and encoding segment 3 from left to right (i.e., from high bit to low bit). Encoding segment 1 corresponds to the root security group, encoding segment 2 corresponds to the first-level inherited security group, and encoding segment 3 corresponds to the second-level inherited security group. Each encoding segment is 2 bits long. The mask field "110000" in the encoding information of root security group 1 indicates that the top 2 bits of the value field are valid, i.e., the valid encoding segment is encoding segment 1:00. The mask field "110000" in the encoding information of root security group 2 indicates that the most significant two bits of the value range are valid, meaning that the valid encoding segment is encoding segment 1: 01. First-level inherited security group 1 and first-level inherited security group 2 are the inherited security groups of root security group 1. The mask field "111100" in the encoding information of first-level inherited security group 1 indicates that the most significant four bits of the value range are valid, meaning that the valid encoding segments include encoding segments 1 and 2: 0000. The mask field "111100" in the encoding information of first-level inherited security group 2 indicates that the most significant four bits of the value range are valid, meaning that the valid encoding segments include encoding segments 1 and 2: 0001. First-level inherited security group 3 is the inherited security group of root security group 2. The mask field "111100" in the encoding information of first-level inherited security group 3 indicates that the most significant four bits of the value range are valid, meaning that the valid encoding segments include encoding segments 1 and 2: 0100. Second-level inherited security group 1 is the inherited security group of first-level inherited security group 1. The mask field "111111" in the encoding information of second-level inherited security group 1 indicates that all bits in the value range are valid. That is, the valid code segments include code segments 1, 2, and 3: 000000. Second-level inherited security group 2 and second-level inherited security group 3 are the inherited security groups of first-level inherited security group 3. The mask field "111111" in the encoding information of second-level inherited security group 2 indicates that all bits in the value range are valid. That is, the valid code segments include code segments 1, 2, and 3: 010000. The mask field "111111" in the encoding information of second-level inherited security group 3 indicates that all bits in the value range are valid. That is, the valid code segments include code segments 1, 2, and 3: 010001.
[0112] Alternatively, the encoding information satisfies the following conditions: the encoding segment corresponding to the inheritance level of the inherited security group is located in the high-order bit of the encoding segment corresponding to the inheritance level of the corresponding inheriting security group. That is, the encoding segment corresponding to the inheritance level of the inherited security group is located to the left of the encoding segment corresponding to the inheritance level of the corresponding inheriting security group. The mask information is the mask length, which indicates the valid length of the encoding value range. For example, in the example shown in Figure 4, the coding information corresponding to root security group 1 is expressed as 000000 / 2, and the coding information corresponding to root security group 2 is expressed as 010000 / 2. " / 2" indicates that the mask length is 2, indicating that the highest 2 bits of the value range are valid; the coding information corresponding to the first-level inherited security group 1 is expressed as 000000 / 4, the coding information corresponding to the first-level inherited security group 2 is expressed as 000100 / 4, and the coding information corresponding to the first-level inherited security group 3 is expressed as 010000 / 4. " / 4" indicates that the mask length is 4, indicating that the highest 4 bits of the value range are valid; the coding information corresponding to the second-level inherited security group 1 is expressed as 000000 / 6, the coding information corresponding to the second-level inherited security group 2 is expressed as 010000 / 6, and the coding information corresponding to the second-level inherited security group 3 is expressed as 010001 / 6. " / 6" indicates that the mask length is 6, indicating that all 6 bits of the value range are valid.
[0113] The present application uses segmented hierarchical coding to achieve that the coding information corresponding to the inheriting security group can fuzzily match the coding information corresponding to the inherited security group. The characteristic is that a coding segment is assigned to each inheritance level. The present application does not limit the inter-segment ordering of the coding segments corresponding to different inheritance levels. Optionally, the coding segment corresponding to the inheritance level where the inherited security group is located is located at the high bit position of the coding segment corresponding to the inheritance level where the corresponding inheriting security group is located. For example, the coding information corresponding to the second-level inheriting security group is expressed as "AA BB CC / Length3", where "AA" is the coding segment corresponding to the root security group, "BB" is the coding segment corresponding to the first-level inheriting security group, "CC" is the coding segment corresponding to the second-level inheriting security group, and "Length3" is the sum of the lengths of the three coding segments "AA", "BB" and "CC". The inter-segment ordering of the coding segments corresponding to different inheritance levels can have other variations. For example, if the coding segment corresponding to the inheritance level where the inherited security group is located is located at the low bit position of the coding segment corresponding to the inheritance level where the corresponding inheriting security group is located, then the coding information corresponding to the second-level inheriting security group is expressed as "CC BB AA / Length3". Alternatively, the coding segments corresponding to different inheritance levels are discontinuous, and a mask field is used to indicate the valid coding segments in the coding value field. For example, the coding information corresponding to the second-level inheritance security group is expressed as "CC BB 0…0AA / FF FF X…X FF", where F indicates that the corresponding position is valid and X indicates that the corresponding position is invalid (don't care).
[0114] Optionally, the lengths of the coding segments corresponding to different inheritance levels are the same, or the lengths of the coding segments corresponding to different inheritance levels are different. The lengths of the coding segments corresponding to each inheritance level can be selected as needed. In order to effectively utilize the TCAM bit width, for example, the coding value range of the coding segment corresponding to each inheritance level is 0 to 2. x , x is the number of binary bits occupied by the coding segment sent to the TCAM, for example, 3 bits can represent the coding value range of 0 to 7. The bit expression of each coding segment actually sent to the TCAM can be continuous or discontinuous. For example, Figure 5 is a schematic diagram of the binary bit expression of coding information in the TCAM provided by an embodiment of the present application. As shown in Figure 5, coding segment 1 "01" is expressed in a non-continuous 2-bit manner in the TCAM, coding segment 2 "01" is also expressed in a non-continuous 2-bit manner in the TCAM, and coding segment "011" is expressed in a continuous 3-bit manner in the TCAM.
[0115] Optionally, the matching conditions in each access control rule configured in the policy execution device each include a pair of source identifiers and destination identifiers. The source identifier and / or destination identifier are represented using encoding information (a hierarchical encoding structure) corresponding to the security group. The policy execution device generates encoding information corresponding to each of the multiple security groups based on the inheritance relationship between the configured security groups. Alternatively, the policy execution device receives encoding information corresponding to each of the multiple security groups sent by the policy decision device.
[0116] The third step is to configure access control rules for the security group in the policy enforcement device. Optionally, the access control rules for the security group are encoded and identified in the TCAM using their hierarchical structure. Referring to the example shown in Figure 4 , the access control rules for "root security group 2" are identified in the TCAM as "010000 / 2," and the access control rules for "secondary inherited security group 3" are identified in the TCAM as "010001 / 6."
[0117] In the fourth step, the policy execution device filters and forwards the message based on the access control rules. Taking the case where the source device of the message belongs to the source security group as an example, when the policy execution device filters and forwards the message based on the access control rules, it first obtains the message's sending source identifier, such as obtaining the source MAC address or source IP address based on the message as the sending source identifier, or using the message receiving interface as the sending source identifier. Then, the hierarchical structure code corresponding to the source security group is obtained through the sending source identifier, and the hierarchical structure code is used to perform a search and match with the TCAM table entry. For example, Figure 6 is a schematic diagram of fuzzy matching based on hierarchical structure encoding provided in an embodiment of the present application. As shown in Figure 6, the hierarchical structure code "010001 / 6" is obtained based on the sending source identifier of the message from "Secondary Inherited Security Group 3". The hierarchical structure code "010001 / 6" can be matched with the source identifier "010000 / 2" in the access control rule corresponding to "Root Security Group 2" in the TCAM. Therefore, the access control rule corresponding to "Root Security Group 2" is effective for "Secondary Inherited Security Group 3", that is, "Secondary Inherited Security Group 3" inherits the access control rule corresponding to "Root Security Group 2".
[0118] The following is a detailed introduction to the technical solution of this application from multiple perspectives, including application scenarios, system architecture, hardware devices, method flow, software devices, and systems.
[0119] The following is an example of an application scenario of the embodiment of the present application.
[0120] The embodiments of the present application can be applied to devices or systems that act as decision points and execution points for access control rules in various data access models, including but not limited to network devices (such as switches, routers, firewalls, etc.) or servers. The names of their functions may be quality of service (QoS) policies, modular QoS command-line (MQC), message filtering, security policies or access control, etc., which are collectively referred to as access control in the embodiments of the present application.
[0121] For example, Figure 7 is a schematic diagram of an application scenario provided by an embodiment of the present application. As shown in Figure 7, the application scenario includes a user, an application, and a policy execution device located between the user and the application. The policy execution device is, for example, a network device. The user sends a message to the application to request access to the services provided by the application. The policy execution device is configured with access control rules for security groups, and the policy execution device forwards and filters the messages sent by the user to the application according to the configured access control rules to implement access control restrictions on the user. For example, after the policy execution device receives the message sent by the user, it first identifies the source security group, and then searches and matches the matching conditions of the access control rule based on the hierarchical structure encoding of the identified source security group, and finally executes the action in the matching access control rule.
[0122] Optionally, referring to Figure 7, this application scenario also includes a policy decision device. The policy decision device is configured with an inheritance relationship between security groups. The policy decision device is used to assign corresponding coding information to security groups based on the inheritance relationship, generate access control rules for the security groups, and further distribute the coding information and access control rules for the security groups to the policy execution device.
[0123] In the application scenario shown in Figure 7, the policy execution device is deployed with forwarding plane functions, and the policy decision device is deployed with control plane functions. The policy execution device and the policy decision device can be the same device or independent devices.
[0124] The following is an example of the system architecture of the embodiment of the present application.
[0125] For example, Figure 8 is a schematic diagram of a system architecture provided by an embodiment of the present application. As shown in Figure 8, the system architecture involves a control plane and a forwarding plane. The control plane and the forwarding plane are logical concepts. Physically, they can be centralized unified devices, or they can also be distributed multiple devices. The control plane is deployed with a policy decision point, and the forwarding plane is deployed with a policy execution point. As shown in the application scenario shown in Figure 7, the policy decision point is a policy decision device, and the policy execution point is a policy execution device.
[0126] The control plane is used to configure the inheritance relationship between multiple security groups as needed, assign corresponding coding information (hierarchical structure coding) to each security group, and configure access control rules based on security groups as needed. The control plane is used to issue coding information corresponding to each security group and access control rules based on security groups to the forwarding plane. The access control rules include matching conditions and actions, and the matching conditions include, for example, a pair of source identifiers and destination identifiers. The forwarding plane is used to receive control plane instructions, implement message processing as required, and perform message forwarding and filtering based on the issued access control rules. Optionally, referring to Figure 8, the forwarding plane is deployed with a dedicated hardware chip and TCAM, and the dedicated hardware chip is, for example, at least one of an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or a network processor (NP). The TCAM is used to store the matching conditions in the access control rules, and the dedicated hardware chip is used to use the hierarchical structure coding of the source security group and / or destination security group corresponding to the message as a key to search and match in the TCAM table entry. The dedicated hardware chip is also used to execute corresponding actions based on the matching results returned by the TCAM.
[0127] The following describes the implementation process of the solution in the embodiment of the present application in conjunction with the system architecture shown in FIG8 .
[0128] 1. On the control plane, configure the inheritance relationship between multiple security groups as needed. For each inheriting security group, specify the inherited security group it depends on. Alternatively, you can specify the inherited security group based on the inherited security group. This is sufficient as long as the inheritance relationship is clearly expressed.
[0129] 2. After the inheritance relationship between multiple security groups is configured, the control plane assigns a unique hierarchical structure code to each security group and sends the mapping between the security group and the hierarchical structure code to the forwarding plane. Security groups can be represented by their original security group identifiers (such as MAC addresses or IP addresses). For example, the mapping relationship is: MAC / IP<->hierarchical structure code. The first segment of the code represents a unique root security group. All segments except the first segment are set to zero, in the form of AA 0...0 / Length1 (AA is the first segment code value, Length1 is the first segment code length). The first segment of the hierarchical structure code corresponding to a first-level inherited security group uses the first segment code value of the inherited security group. The second segment of the code represents a unique subordinate inherited security group within the inherited security group. All other segments are set to zero, in the form of AA BB 0...0 / Length2 (AA is the inherited security group code value, BB is the unique value assigned to the inheriting security group under the inherited security group, and Length2 is the sum of the first and second segment code lengths). The first and second segments of the hierarchical structure code corresponding to a second-level inherited security group use the first and second segment codes of the inherited security group. The third segment code is assigned within the inherited security group to represent a unique lower-level inherited security group. All other segment codes are set to 0, in the form of AA BB CC 0...0 / Length3 (AA BB is the inherited security group code value, CC is the unique value assigned to the inheriting security group under the inherited security group, and Length3 is the sum of the first, second, and third segment code lengths). For multiple layers of inherited security groups, the code is similar.
[0130] 3. The control plane configures security group-based access control rules as needed, in the form of {source ID: security group, destination ID: □□, action: □□}. When the rules are delivered to the forwarding plane, the source ID is converted into its corresponding hierarchical structure code and stored in the TCAM.
[0131] 4. When the forwarding plane performs access rule filtering on a packet, it first extracts the source identifier based on the packet content or inbound interface. It then uses the source identifier to obtain the hierarchical structure code representing the source security group. This hierarchical structure code is used as the source identifier field in the key to perform a lookup and match with the TCAM entry. Through the TCAM's three-state fuzzy search capability, if the valid bits of the hierarchical structure code corresponding to the descendant inheriting security group are longer than those of the inherited security group (directly or recursively inherited from a higher-level inherited security group), the extra bits are ignored by the "don't care" mask, allowing the access control rule corresponding to the inherited security group to be matched, thus achieving access rights inheritance and transfer.
[0132] The following is an example of the basic hardware structure involved in the embodiments of the present application.
[0133] For example, Figure 9 is a schematic diagram of the hardware structure of a server provided in an embodiment of the present application. As shown in Figure 9, the server 900 includes a processor 901 and a memory 902, and the memory 901 and the memory 902 are connected via a bus 903. Figure 9 illustrates the processor 901 and the memory 902 as being independent of each other. Optionally, the processor 901 and the memory 902 are integrated together. Optionally, in combination with Figure 7, the server 900 shown in Figure 9 is a policy execution device or a policy decision device in the application scenario shown in Figure 7.
[0134] The memory 902 is used to store computer programs, which include an operating system and program code. Optionally, the operating system is a Windows operating system. The memory 902 is various types of storage media, such as read-only memory (ROM), random access memory (RAM), electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM), flash memory, optical memory, register, optical disk storage, optical disc storage, magnetic disk, or other magnetic storage device.
[0135] The processor 901 is a general-purpose processor or a dedicated processor. The processor 901 may be a single-core processor or a multi-core processor. The processor 901 includes at least one circuit to execute the access control method provided in the embodiment of the present application.
[0136] Optionally, the server 900 further includes a network interface 904, which is connected to the processor 901 and the memory 902 via the bus 903. The network interface 904 enables the server 900 to communicate with other devices.
[0137] Optionally, the server 900 further includes an input / output (I / O) interface 905, which is connected to the processor 901 and the memory 902 via the bus 903. The processor 901 can receive input commands or data through the I / O interface 905. The I / O interface 905 is used to connect the server 900 to input devices, such as a keyboard and a mouse. Optionally, in some possible scenarios, the network interface 904 and the I / O interface 905 are collectively referred to as a communication interface.
[0138] Optionally, the server 900 further includes a display 906, which is connected to the processor 901 and the memory 902 via the bus 903. The display 906 can be used to display intermediate results and / or final results generated by the processor 901 executing the access control method provided in the embodiments of the present application. In one possible implementation, the display 906 is a touch screen display to provide a human-computer interaction interface.
[0139] The bus 903 is any type of communication bus for interconnecting the internal components of the server 900, such as a system bus. The embodiments of the present application illustrate the interconnection of the aforementioned components within the server 900 via the bus 903. Alternatively, the aforementioned components within the server 900 may be communicatively connected to each other using other connection methods besides the bus 903, such as interconnecting the aforementioned components within the server 900 via a logical interface within the server 900.
[0140] The above-mentioned devices can be provided on separate chips, or at least partially or entirely on the same chip. Whether to provide each device independently on different chips or to integrate them on one or more chips often depends on the product design requirements. The embodiments of this application do not limit the specific implementation of the above-mentioned devices.
[0141] The server 900 shown in Figure 9 is merely exemplary. During implementation, the server 900 includes other components, which are not listed here. The server 900 shown in Figure 9 can implement access control by executing all or part of the steps of the access control method provided in the embodiment of the present application.
[0142] For example, Figure 10 is a schematic diagram of the hardware structure of a network device provided in an embodiment of the present application. As shown in Figure 10, network device 1000 includes a central processing unit (CPU) 1001, a dedicated hardware chip 1002, and at least one network interface 1003. CPU 1001 and dedicated hardware chip 1002 may be collectively referred to as a processor. Optionally, in conjunction with Figure 7, network device 1000 shown in Figure 10 is a policy execution device or policy decision device in the application scenario shown in Figure 7.
[0143] The CPU 1001 is a general-purpose central processing unit (CPU) with high scalability and flexibility. The CPU 1001 may be, for example, a single-core processor (single-CPU) or a multi-core processor (multi-CPU).
[0144] The dedicated hardware chip 1002 is a high-performance processing hardware module and includes at least one of ASIC, FPGA, or NP.
[0145] At least one network interface 1003 includes, for example, network interface 1, network interface 2, network interface 3, ..., network interface n in FIG10 . The network interface 1003 uses any transceiver-like device for communicating with other devices. For example, the network interface 1 in FIG10 communicates with the user, and the network interface 2 in FIG10 communicates with the application. Optionally, the network interface 1003 includes at least one of a wired network interface or a wireless network interface. The wired network interface is, for example, an Ethernet interface. The Ethernet interface is, for example, an optical interface, an electrical interface, or a combination thereof. The wireless network interface is, for example, a wireless local area network (WLAN) interface, a cellular network interface, or a combination thereof.
[0146] At least one network interface 1003 and the dedicated hardware chip 1002, as well as the dedicated hardware chip 1002 and the CPU 1001, are connected via an internal connection 1004. The internal connection 1004 includes a path for transmitting data between the network interface 1003, the dedicated hardware chip 1002, and the CPU 1001. Optionally, the internal connection 1004 is a single board or a bus. For example, the internal connection 1004 is Ethernet, fiber channel, PCI-E (peripheral component interconnect express, PCI Express, a high-speed serial computer bus), RapidIO (a high-performance, low-pin-count, packet-switched interconnect architecture), InfiniBand, or a XAUI bus (an interface extender that connects the Ethernet MAC layer to the physical layer).
[0147] Optionally, network device 1000 further includes a CAM 1005. CAM 1005 is, for example, a TCAM. CAM 1005 is used to store, for example, matching conditions in access control rules. Optionally, CAM 1005 exists independently and is connected to dedicated hardware chip 1002 via the aforementioned internal connection 1004. Alternatively, CAM 1005 and dedicated hardware chip 1002 are integrated, i.e., CAM 1005 functions as memory within dedicated hardware chip 1002.
[0148] Optionally, the network device 1000 further includes a memory 1006. The memory 1006 may be, for example, a ROM or other type of static storage device capable of storing static information and instructions, or a RAM or other type of dynamic storage device capable of storing information and instructions, or an EEPROM, a CD-ROM or other optical disk storage, an optical disk storage (including a compact disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium capable of carrying or storing the desired program code 1008 in the form of instructions or data structures and accessible by a computer, but is not limited thereto. The memory 1006 may be, for example, independently connected to the CPU 1001 via the internal connection 1004. Alternatively, the memory 1006 and the CPU 1001 may be integrated together.
[0149] An operating system 1007 and program code 1008 are stored in the memory 1006. Optionally, the CPU 1001 reads the operating system 1007 from the memory 1006 and runs the operating system 1007. The CPU 1001 also reads the program code 1008 from the memory 1006, and implements the method provided in the embodiment of the present application by running the program code 1008 on the operating system 1007. For example, the network device 1000 is the policy execution device in the application scenario shown in FIG7 . When running the program code 1008, the CPU 1001 performs the following process: receiving a message, obtaining source information or destination information of the message, obtaining a target access control rule from an access control rule set based on the source information or destination information, and executing the action in the target access control rule on the message.
[0150] Optionally, the above-mentioned devices are respectively provided on independent chips, or at least partially or entirely provided on the same chip. Whether each device is provided independently on different chips or integrated on one or more chips often depends on the needs of product design. The embodiments of the present application do not limit the specific implementation of the above-mentioned devices.
[0151] The following is an example of the method flow of the embodiment of the present application.
[0152] For example, Figure 11 is a schematic diagram of an implementation flow of an access control method provided in an embodiment of the present application. As shown in Figure 11, method 1100 includes, but is not limited to, steps 1101 through 1104. Optionally, in conjunction with the application scenario shown in Figure 7, the policy execution device in method 1100 is the policy execution device in Figure 7. Optionally, the policy execution device in method 1100 has the hardware structure shown in Figure 9 or Figure 10.
[0153] Step 1101: The policy execution device receives a message.
[0154] Optionally, the message is any message received by the policy execution device.
[0155] Step 1102: The policy execution device obtains the source information or destination information of the message.
[0156] The source device and destination device of the message satisfy the following conditions: the source device of the message belongs to the source security group, the source information of the message includes the encoding information corresponding to the source security group, and / or the destination device of the message belongs to the destination security group, and the destination information of the message includes the encoding information corresponding to the destination security group. The encoding information corresponding to a security group is used to identify the security group, and if the security group is configured as an inheriting security group, the encoding information corresponding to the security group also indicates the inherited security group on which the security group depends. The inheriting security group is configured to inherit the access control rules corresponding to the inherited security group on which it depends.
[0157] In the first possible implementation, the policy enforcement device is the egress endpoint of the VXLAN tunnel. The source information includes encoding information corresponding to the source security group. The VXLAN header of the message carries the encoding information corresponding to the source security group. The policy enforcement device then obtains the source information of the message by parsing the VXLAN header to obtain the encoding information corresponding to the source security group.
[0158] Optionally, after receiving the original message, the inbound endpoint of the VXLAN tunnel encapsulates the original message into a tunnel message to obtain a VXLAN message, and then sends the VXLAN message to the outbound endpoint through the VXLAN tunnel. In an embodiment of the present application, when the source device of the message belongs to a source security group, and the source security group is configured with the hierarchical structure encoding provided by the embodiment of the present application, by carrying the encoding information corresponding to the source security group in the VXLAN header of the VXLAN message, the outbound endpoint of the VXLAN tunnel can directly execute the GBP policy based on the encoding information corresponding to the source security group, and there is no need to send the encoding information corresponding to the source security group to the outbound endpoint of the VXLAN tunnel.
[0159] For example, Figure 12 is a schematic diagram of a VXLAN networking scenario provided in an embodiment of the present application. As shown in Figure 12, the VXLAN networking scenario includes two VXLAN tunnel end points (VTEPs), namely VTEP1 and VTEP2. VTEP1 is the ingress end point of the VXLAN tunnel, and VTEP2 is the egress end point of the VXLAN tunnel. VTEP1 performs tunnel message encapsulation on the received original message to obtain a VXLAN message, and sends the VXLAN message to VTEP2 through the VXLAN tunnel. The VXLAN message includes an outer MAC header, an outer IP header, an outer User Datagram Protocol (UDP) header, an outer UDP header, a VXLAN header, and an original message. The policy execution device in the embodiment of the present application is, for example, VTEP2.
[0160] In a VXLAN networking scenario, a common way to implement group policy for data access across tunnel endpoints is for the tunnel ingress endpoint to extend the standard VXLAN header to carry source security group information, such as source security group ID or source security group tag (SGT), and then the tunnel egress endpoint obtains the destination security group information, and then the tunnel egress endpoint performs GBP based on the source security group information and the destination security group information. For example, Figure 13 is a structural diagram of a standard VXLAN header provided by the relevant technology. As shown in Figure 13, the VXLAN header includes a reserved bit (Reserved) and a VXLAN network identifier (VNI). The definition of each field in the VXLAN header shown in Figure 13 can be referred to the VXLAN header format definition in the request for comments (RFC) (abbreviated as: RFC 7348) document numbered 7348. For another example, Figure 14 is a structural diagram of an extended VXLAN header provided by the relevant technology. As shown in Figure 14, the extended VXLAN header defines a Group Policy ID field in the reserved bits of the standard VXLAN header. The source security group ID or source security group tag is carried in the Group Policy ID field. For definitions of the various fields in the VXLAN header shown in Figure 14, refer to the relevant document (14draft-smith-vxlan-group-policy-03VXLAN-GBP Extension).
[0161] Optionally, the encoding information corresponding to the source security group is carried in the reserved bits of the VXLAN header. The feature of this application is that the security group ID or SGT is replaced with a hierarchical structure code during GBP execution. For VXLAN scenarios, the embodiment of this application extends the method of carrying hierarchical structure codes in the VXLAN header, utilizes the reserved bits in the VXLAN header (the "R" and "Reserved" fields in Figure 14) and reuses the "Group Policy ID" bits to directly carry the hierarchical structure code corresponding to the source security group to the tunnel exit endpoint.
[0162] Optionally, the VXLAN header of the message also carries a destination indication, which is used to indicate that the source information type carried in the VXLAN header is encoded information corresponding to the security group. In the embodiment of the present application, the bits used to carry the hierarchical structure code can be flexibly combined and are required to include two parts. The first part uses 1 bit to indicate whether the hierarchical structure code is carried. For example, setting it to 1 indicates that the hierarchical structure code is carried (i.e., setting it to 1 indicates that it is a destination indication), and setting it to 0 indicates that it is not carried. For example, it can be compatible with carrying the original Group Policy ID information. The second part uses various scattered bit combinations to carry the binary expression of the specific hierarchical structure code. For example, Figure 15 is a schematic diagram of the structure of an extended VXLAN header provided in an embodiment of the present application. As shown in Figure 15, the B bit indicates whether the hierarchical structure code is carried. Bit1, Bit2, Bit3, Bit4, and Bit5 are spliced together (the actual number of bits used can be less than this range, and the unused bits can be maintained as reserved bits) to express the binary expression of the specific hierarchical structure code. In specific implementations, the bit occupancy and meaning can also have other variations, as long as the two parts meet the previous requirements.
[0163] Alternatively, the embodiment of the present application sends the encoding information corresponding to the source security group to the egress endpoint of the VXLAN tunnel, using the VXLAN header shown in Figure 14, with the VXLAN header carrying the source security group ID or source security group label. The egress endpoint of the tunnel maps the source security group ID or source security group label to the hierarchical structure encoding corresponding to the source security group based on the encoding information corresponding to the source security group, and then executes the GBP policy based on the encoding information corresponding to the source security group. The difference compared to the existing solution is that the egress endpoint of the tunnel needs to obtain the encoding information corresponding to the source security group, and adds a step of mapping the source security group information to the hierarchical structure encoding when performing GBP policy filtering on the message.
[0164] In a second possible implementation, the policy enforcement device is the egress endpoint of the Geneve tunnel. The source information includes encoding information corresponding to the source security group. The Geneve header of a message carries the encoding information corresponding to the source security group. The policy enforcement device then obtains the source information of the message by parsing the Geneve header to obtain the encoding information corresponding to the source security group.
[0165] Compared with the first possible implementation method, the second possible implementation method adopts Geneve tunnel encapsulation technology to replace VXLAN tunnel encapsulation technology. Accordingly, the difference between Geneve messages and VXLAN messages is that VXLAN messages include VXLAN headers, while Geneve messages include Geneve headers. The variable-length options field in the Geneve header supports flexible and scalable capabilities. For example, Figure 16 is a structural diagram of a Geneve header provided by the relevant technology. For the definition of each field in the Geneve header shown in Figure 16, please refer to the Geneve header format definition in the RFC 8926 document.
[0166] Optionally, the coding information corresponding to the source security group is carried in the option field of the Geneve header in the form of TLV or TV. For example, Figure 17 is a structural diagram of an extended Geneve header provided in an embodiment of the present application. As shown in Figure 17, the extended Geneve header includes an option class field, a type field, a reserved bit (R), a length field, and a variable-length option data field. Among them, the variable-length option data field is used to carry the hierarchical structure encoding corresponding to the source security group, the type field is used to indicate the data type of the variable-length option data field, and the length field is used to indicate the length of the variable-length option data field.
[0167] A third possible implementation method, in which the policy execution device obtains the source information of the message, includes: the policy execution device obtains the source information of the message based on the source address of the message and / or the receiving port of the message by the policy execution device. In this implementation method, the policy execution device stores the hierarchical structure coding corresponding to the source address and / or the receiving port. In this implementation method, the policy execution device obtains the destination information of the message, including: the policy execution device obtains the destination information of the message based on the destination address of the message and / or the sending port of the message by the policy execution device. In this implementation method, the policy execution device stores the hierarchical structure coding corresponding to the destination address and / or the sending port. Optionally, the source address and the destination address are IP addresses or MAC addresses.
[0168] In this implementation mode, the policy execution device first obtains the source security group information or destination security group information of the message based on the message content or the sending and receiving ports of the message, and then obtains the hierarchical structure code corresponding to the source security group information or the destination security group information.
[0169] Step 1103: The policy execution device obtains a target access control rule from the access control rule set according to the source end information or the destination end information of the message.
[0170] An access control rule set includes one or more access control rules, each of which includes a matching condition and an action. The source or destination information of the message meets the matching condition of the target access control rule. In other words, the target access control rule is the access control rule in the access control rule set in which the source or destination information of the message meets the matching condition.
[0171] Optionally, the matching conditions in each access control rule include a pair of source identifiers and destination identifiers. If the source information includes the coding information corresponding to the source security group, the source information satisfies the matching conditions in the target access control rule, including: the valid coding segment in the source identifier of the target access control rule is the valid coding segment in the coding information corresponding to the source security group or the valid coding segment in the coding information corresponding to the inherited security group on which the source security group depends. If the destination information includes the coding information corresponding to the destination security group, the destination information satisfies the matching conditions in the target access control rule, including: the valid coding segment in the destination identifier of the target access control rule is the valid coding segment in the coding information corresponding to the destination security group or the valid coding segment in the coding information corresponding to the inherited security group on which the destination security group depends. Among them, the explanation of the valid coding segment in the coding information corresponding to the security group can refer to the above embodiment, and the embodiments of the present application will not be repeated here.
[0172] For example, Table 3 shows a set of access control rules in a policy enforcement device.
[0173] Table 3
[0174] Assume that the source information of the message is 010001 / 6 and the destination information is application A. Referring to Table 3, the source information and destination information of the message match the first entry.
[0175] Step 1104: The policy execution device executes the action in the target access control rule on the message.
[0176] In the access control method provided in the embodiment of the present application, for a security group configured as an inheriting security group, the encoding information corresponding to the security group can not only identify the security group itself, but also indicate the inherited security group on which the security group depends. Since the inheriting security group is configured to inherit the access control rules corresponding to the inherited security group, the inheriting security group can automatically match the access control rules corresponding to the inherited security group without the need to explicitly reconfigure the same access control rules as the inherited security group for the inheriting security group, thereby reducing the number of access control rule entries required to be configured on the policy execution device, saving table resources, and improving operation and maintenance efficiency.
[0177] The order of the steps of the above-mentioned access control method provided in the embodiment of the present application can be adjusted appropriately, and the steps can also be increased or decreased accordingly according to the circumstances. Any technical personnel familiar with the technical field can easily think of a method of change within the technical scope disclosed in this application, and all of them should be included in the scope of protection of this application. For example, this application utilizes the fuzzy matching capability of TCAM based on bit masks, and such fuzzy query capabilities may be implemented on other devices in the future. This application is also applicable to other scenarios that require the expression of permission transfer in an inheritance relationship, and does not have to be limited to devices or systems based on TCAM devices. In addition, the combination ordering of hierarchical structure encoding, the bit definition in the VXLAN message format, and the bit definition in the Geneve message format in this application are only used as illustrative examples, and any possible variants should be included in the scope of protection of this application.
[0178] The following describes the virtual device in the embodiment of the present application by way of example.
[0179] For example, Figure 18 is a schematic diagram of the structure of an access control device 1800 provided in an embodiment of the present application. Access control device 1800 having the structure shown in Figure 18 is used to implement method 1100 described in the above embodiment. Optionally, access control device 1800 shown in Figure 18 is the policy enforcement device shown in Figure 7. As shown in Figure 18, access control device 1800 includes, but is not limited to, a receiving module 1801 and a processing module 1802.
[0180] Among them, the receiving module 1801 is used to receive the message. The processing module 1802 is used to obtain the source information or destination information of the message, and according to the source information or destination information, obtain the target access control rule from the access control rule set, and execute the action in the target access control rule on the message. Among them, the access control rule set includes one or more access control rules, each access control rule includes a matching condition and an action, and the source information or destination information meets the matching condition in the target access control rule. The source device and the destination device of the message meet: the source device of the message belongs to the source security group, the source information includes the encoding information corresponding to the source security group, and / or, the destination device of the message belongs to the destination security group, and the destination information includes the encoding information corresponding to the destination security group. The encoding information corresponding to a security group is used to identify the security group, and if the security group is configured to inherit the security group, the encoding information corresponding to the security group also indicates the inherited security group on which the security group depends. Among them, the inheriting security group is configured to inherit the access control rules corresponding to the inherited security group on which it depends.
[0181] Optionally, the source information includes encoding information corresponding to the source security group, and the matching conditions in each access control rule include a pair of source identifiers and destination identifiers, wherein the source identifier in the target access control rule is represented by the encoding information corresponding to the security group, and the source information satisfies the matching conditions in the target access control rule, including: the security group identified by the source identifier in the target access control rule is the source security group identified by the source information or the inherited security group on which the source security group indicated by the source information depends.
[0182] Optionally, the destination information includes the destination address of the message, the destination port number of the message or the group identifier of the destination security group, and the destination information satisfies the matching condition in the target access control rule, including: the destination information is the same as the destination identifier in the target access control rule.
[0183] Optionally, the policy execution device stores coding information corresponding to multiple security groups with an inheritance relationship, the inheritance relationship between the multiple security groups is associated with n inheritance levels, and the coding information corresponding to each security group in the multiple security groups includes n coding segments, and the n coding segments correspond one-to-one to the n inheritance levels, where n is a positive integer greater than 1. For any security group in the multiple security groups that is configured as an inheriting security group, the valid coding segments in the coding information corresponding to the security group include the coding segments corresponding to the inheritance level where the security group is located and the valid coding segments in the coding information corresponding to the inherited security group on which the security group depends, wherein the coding value of the valid coding segment in the coding information corresponding to the security group is used to identify the security group, and the coding value of the valid coding segment in the coding information corresponding to the inherited security group on which the security group depends is used to identify the inherited security group on which the security group depends, and the valid coding segment in the coding information corresponding to a security group is valid matching information for access control rules.
[0184] Optionally, the multiple security groups include a root security group configured as a non-inherited security group, and the valid coding segment in the coding information corresponding to the root security group includes the coding segment corresponding to the inheritance level where the root security group is located.
[0185] Optionally, the encoding information is represented by a code value domain and mask information, where the mask information indicates valid code segments in the code value domain. For any security group configured as an inheriting security group among multiple security groups, the code value domain corresponding to the security group inherits the values of valid code segments in the code value domain corresponding to the inherited security group on which the security group depends.
[0186] Optionally, the mask information is a mask field having the same length as the encoding value field.
[0187] Alternatively, the encoding information satisfies the following conditions: the encoding segment corresponding to the inheritance level of the inherited security group is located in the high bit of the encoding segment corresponding to the inheritance level of the corresponding inheriting security group. The mask information is the mask length, which is used to indicate the valid length of the encoding value range.
[0188] Optionally, the processing module 1802 is further configured to generate coding information corresponding to the multiple security groups according to the inheritance relationship between the multiple configured security groups.
[0189] Alternatively, the receiving module 1801 is further configured to receive coded information corresponding to multiple security groups respectively sent by the policy decision device.
[0190] Optionally, the matching conditions in each access control rule include a pair of source identifiers and destination identifiers. If the source information includes the coding information corresponding to the source security group, the source information satisfies the matching conditions in the target access control rule, including: the valid coding segment in the source identifier of the target access control rule is the valid coding segment in the coding information corresponding to the source security group or the valid coding segment in the coding information corresponding to the inherited security group on which the source security group depends. If the destination information includes the coding information corresponding to the destination security group, the destination information satisfies the matching conditions in the target access control rule, including: the valid coding segment in the destination identifier of the target access control rule is the valid coding segment in the coding information corresponding to the destination security group or the valid coding segment in the coding information corresponding to the inherited security group on which the destination security group depends.
[0191] Optionally, the policy execution device includes a TCAM, and each access control rule is represented by a TCAM table entry and a corresponding action table entry. Each TCAM table entry is used to store a matching condition in an access control rule, and the action table entry corresponding to the TCAM table entry is used to store an action corresponding to the matching condition in the TCAM table entry.
[0192] Optionally, the policy execution device is the egress endpoint of the VXLAN tunnel, the source information includes the encoding information corresponding to the source security group, the VXLAN header of the message carries the encoding information corresponding to the source security group, and the processing module 1802 is used to parse the VXLAN header of the message to obtain the encoding information corresponding to the source security group.
[0193] Optionally, the VXLAN header of the message further carries a target indication, where the target indication is used to indicate that the source information type carried in the VXLAN header is the encoded information corresponding to the security group.
[0194] Optionally, the encoding information corresponding to the source security group is carried in the reserved bits of the VXLAN header.
[0195] Optionally, the policy execution device is the egress endpoint of the Geneve tunnel, the source information includes the encoding information corresponding to the source security group, the Geneve header of the message carries the encoding information corresponding to the source security group, and the processing module 1802 is used to parse the Geneve header of the message to obtain the encoding information corresponding to the source security group.
[0196] Optionally, the encoding information corresponding to the source security group is carried in the option field of the Geneve header in the form of TLV or TV.
[0197] Optionally, processing module 1802 is used to obtain the source end information of the message based on the source address of the message and / or the receiving port of the policy execution device for the message, and obtain the destination end information of the message based on the destination address of the message and / or the sending port of the policy execution device for the message.
[0198] The device embodiment described in FIG18 is merely illustrative. For example, the division of modules is merely a logical functional division. In actual implementation, there may be other division methods. For example, multiple modules or components may be combined or integrated into another system, or some features may be ignored or not executed. The functional modules in the various embodiments of the present application may be integrated into a processing module, or each module may exist physically separately, or two or more modules may be integrated into a single module. The modules described above in FIG18 may be implemented in the form of hardware, software functional units, or a combination of software and hardware.
[0199] For example, Figure 19 is a schematic diagram of the structure of an access control device 1900 provided in an embodiment of the present application. Access control device 1900 having the structure shown in Figure 19 is used to implement the actions performed by the policy decision device described in the above embodiment. Optionally, access control device 1800 shown in Figure 19 is the policy decision device shown in Figure 7. As shown in Figure 19, access control device 1900 includes, but is not limited to, a generation module 1901 and a sending module 1902.
[0200] Among them, generation module 1901 is used to generate encoding information corresponding to multiple security groups based on the inheritance relationship between the configured multiple security groups. Sending module 1902 is used to send the encoding information corresponding to the multiple security groups to the policy execution device, so that the policy execution device can perform access control on received messages. Among them, the inheritance relationship between the multiple security groups is associated with n inheritance levels, and the encoding information corresponding to each security group in the multiple security groups includes n encoding segments, and the n encoding segments correspond one-to-one to n inheritance levels, where n is a positive integer greater than 1. For any security group configured as an inheriting security group among multiple security groups, the valid coding segment in the coding information corresponding to the security group includes the coding segment corresponding to the inheritance hierarchy where the security group is located and the valid coding segment in the coding information corresponding to the inherited security group on which the security group depends. The coding value of the valid coding segment in the coding information corresponding to the security group is used to identify the security group, and the coding value of the valid coding segment in the coding information corresponding to the inherited security group on which the security group depends is used to identify the inherited security group on which the security group depends. For a root security group configured as a non-inheriting security group among multiple security groups, the valid coding segment in the coding information corresponding to the root security group includes the coding segment corresponding to the inheritance hierarchy where the root security group is located. The valid coding segment in the coding information corresponding to a security group is the valid matching information for the access control rule.
[0201] The device embodiment described in FIG19 is merely illustrative. For example, the division of the modules is merely a logical functional division. In actual implementation, there may be other division methods, such as multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. The functional modules in the various embodiments of the present application can be integrated into a processing module, or each module can exist physically separately, or two or more modules can be integrated into a single module. The modules in FIG19 can be implemented in the form of hardware, software functional units, or a combination of software and hardware.
[0202] The present application also provides a policy execution device, comprising: a memory, a network interface, and at least one processor. The memory is used to store program instructions, and the at least one processor reads the program instructions stored in the memory, causing the policy execution device to execute the actions performed by the policy execution device in the above-described method embodiments, such as the above-described method 1100. Optionally, the hardware structure of the policy execution device is shown in Figure 9 or Figure 10.
[0203] Embodiments of the present application also provide a policy decision device, comprising: a memory, a network interface, and at least one processor. The memory is configured to store program instructions, and the at least one processor reads the program instructions stored in the memory, causing the policy decision device to execute the actions performed by the policy decision device in the above-described method embodiments. Optionally, the hardware structure of the policy decision device is shown in Figures 9 or 10.
[0204] An embodiment of the present application also provides an access control system, including: a policy execution device and a policy decision device, wherein the policy execution device is used to execute the actions executed by the policy execution device in the above method embodiment, and the policy decision device is used to execute the actions executed by the policy decision device in the above method embodiment.
[0205] An embodiment of the present application further provides a computer-readable storage medium having instructions stored thereon. When the instructions are executed by a processor of a computer device, the steps executed by the computer device in the above method embodiment are implemented; or, when the instructions are executed by a processor of a management device, the steps executed by the management device in the above method embodiment are implemented.
[0206] An embodiment of the present application also provides a computer program product, including a computer program, which, when executed by a processor of a computer device, implements the steps performed by the computer device in the above method embodiment; or, when executed by a processor of a management device, implements the steps performed by the management device in the above method embodiment.
[0207] The various embodiments in this specification are described in a progressive manner. The same or similar parts between the various embodiments can be referenced to each other, and each embodiment focuses on the differences from other embodiments.
[0208] The terms "first" and "second" and the like in the description and claims of the embodiments of the present application are used to distinguish different objects, rather than to describe a specific order of objects, and cannot be understood as indicating or implying relative importance.
[0209] In the description of the embodiments of the present application, unless otherwise specified, "at least one" means one or more, and "a plurality of" means two or more.
[0210] A refers to B, which means that A is the same as B or A is a simple variant of B.
[0211] In this application, the term "and / or" simply describes a relationship between related objects, indicating the existence of three relationships. For example, A and / or B means: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this document generally indicates that the related objects are in an "or" relationship.
[0212] Optionally, in the above embodiments, all or part of the embodiments are implemented by software, hardware, firmware, or any combination thereof. Optionally, when implemented using software, all or part of the embodiments are implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present application are generated. Optionally, the computer is a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. Optionally, the computer instructions are stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. Optionally, the computer-readable storage medium is any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more available media integrated therein. Alternatively, the available medium is a magnetic medium (eg, a floppy disk, a hard disk, a magnetic tape), an optical medium (eg, a digital video disk (DVD)), or a semiconductor medium (eg, a solid state disk (SSD)).
[0213] As described above, the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the above embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the above embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present application.
Claims
1. An access control method, characterized in that: The method comprises: The policy execution device receives the message; The policy execution device obtains source information or destination information of the message; The policy execution device obtains a target access control rule from an access control rule set based on the source information or the destination information, where the access control rule set includes one or more access control rules, each access control rule includes a matching condition and an action, and the source information or the destination information satisfies the matching condition in the target access control rule; The policy execution device executes the action in the target access control rule on the message; In which, the source device and destination device of the message satisfy: the source device of the message belongs to the source security group, the source information includes the coding information corresponding to the source security group, and / or the destination device of the message belongs to the destination security group, and the destination information includes the coding information corresponding to the destination security group; the coding information corresponding to a security group is used to identify the security group, and if the security group is configured as an inherited security group, the coding information corresponding to the security group also indicates the inherited security group on which the security group depends, wherein the inherited security group is configured to inherit the access control rules corresponding to the inherited security group on which it depends.
2. The method according to claim 1, characterized in that The source information includes the encoding information corresponding to the source security group, and the matching conditions in each access control rule include a pair of source identifiers and destination identifiers, wherein the source identifier in the target access control rule is represented by the encoding information corresponding to the security group. The source information satisfies the matching conditions in the target access control rule, including: the security group identified by the source identifier in the target access control rule is the source security group identified by the source information or the inherited security group on which the source security group indicated by the source information depends.
3. The method according to claim 2, characterized in that The destination information includes the destination address of the message, the destination port number of the message or the group identifier of the destination security group. The destination information meets the matching conditions in the target access control rule, including: the destination information is the same as the destination identifier in the target access control rule.
4. The method according to any one of claims 1 to 3, characterized in that: The policy execution device stores encoding information corresponding to a plurality of security groups having an inheritance relationship, wherein the inheritance relationship between the plurality of security groups is associated with n inheritance levels, and the encoding information corresponding to each of the plurality of security groups includes n encoding segments, wherein the n encoding segments correspond one-to-one to the n inheritance levels, and n is a positive integer greater than 1; For any security group among the multiple security groups that is configured as an inheriting security group, the valid coding segment in the coding information corresponding to the security group includes the coding segment corresponding to the inheritance hierarchy where the security group is located and the valid coding segment in the coding information corresponding to the inherited security group on which the security group depends, wherein the coding value of the valid coding segment in the coding information corresponding to the security group is used to identify the security group, and the coding value of the valid coding segment in the coding information corresponding to the inherited security group on which the security group depends is used to identify the inherited security group on which the security group depends, and the valid coding segment in the coding information corresponding to a security group is the valid matching information for the access control rule.
5. The method according to claim 4, characterized in that The multiple security groups include a root security group configured as a non-inherited security group, and the valid coding segment in the coding information corresponding to the root security group includes a coding segment corresponding to the inheritance level where the root security group is located.
6. The method according to claim 4 or 5, characterized in that The coding information is represented by a coding value range and mask information, and the mask information is used to indicate a valid coding segment in the coding value range; For any security group configured as an inherited security group among the multiple security groups, the code value domain corresponding to the security group inherits the value of the valid code segment in the code value domain corresponding to the inherited security group on which the security group depends.
7. The method according to claim 6, characterized in that The mask information is a mask field of the same length as the encoding value field.
8. The method according to claim 6, characterized in that The coding information satisfies: the coding segment corresponding to the inheritance level of the inherited security group is located at the high bit position of the coding segment corresponding to the inheritance level of the corresponding inheriting security group; The mask information is a mask length, and the mask length is used to indicate a valid length of the encoding value field.
9. The method according to any one of claims 4 to 8, characterized in that: The method further comprises: The policy execution device generates encoding information corresponding to each of the multiple security groups according to the configured inheritance relationship between the multiple security groups.
10. The method according to any one of claims 4 to 8, characterized in that: The method further comprises: The policy execution device receives the encoding information corresponding to the multiple security groups respectively sent by the policy decision device.
11. The method according to any one of claims 4 to 10, characterized in that: The matching conditions in each access control rule include a pair of source identifier and destination identifier; If the source information includes the encoding information corresponding to the source security group, the source information satisfies the matching condition in the target access control rule, including: a valid encoding segment in the source identifier of the target access control rule is a valid encoding segment in the encoding information corresponding to the source security group or a valid encoding segment in the encoding information corresponding to an inherited security group on which the source security group depends; If the destination information includes the coding information corresponding to the destination security group, the destination information satisfies the matching conditions in the target access control rule, including: the valid coding segment in the destination identifier of the target access control rule is a valid coding segment in the coding information corresponding to the destination security group or a valid coding segment in the coding information corresponding to the inherited security group on which the destination security group depends.
12. The method according to any one of claims 1 to 11, characterized in that: The policy execution device includes a ternary content addressable memory TCAM, and each access control rule is represented by a TCAM table entry and a corresponding action table entry, wherein each TCAM table entry is used to store a matching condition in an access control rule, and the action table entry corresponding to the TCAM table entry is used to store the action corresponding to the matching condition in the TCAM table entry.
13. The method according to any one of claims 1 to 12, characterized in that: The policy execution device is an egress endpoint of a virtual extensible local area network (VXLAN) tunnel, the source information includes encoding information corresponding to the source security group, the VXLAN header of the message carries the encoding information corresponding to the source security group, and the policy execution device obtains the source information of the message, including: The policy execution device parses the VXLAN header of the message to obtain encoding information corresponding to the source security group.
14. The method according to claim 13, characterized in that The VXLAN header of the message also carries a target indication, and the target indication is used to indicate that the source information type carried in the VXLAN header is the encoding information corresponding to the security group.
15. The method according to claim 13 or 14, characterized in that The encoding information corresponding to the source security group is carried in the reserved bit of the VXLAN header.
16. The method according to any one of claims 1 to 12, characterized in that: The policy execution device is an egress endpoint of a Geneve tunnel of a general network virtual encapsulation, the source end information includes encoding information corresponding to the source security group, and the Geneve header of the message carries the encoding information corresponding to the source security group. The policy execution device obtains the source end information of the message, including: The policy execution device parses the Geneve header of the message to obtain the encoding information corresponding to the source security group.
17. The method according to claim 16, characterized in that The encoding information corresponding to the source security group is carried in the option field of the Geneve header in the form of type-length-value TLV or type-value TV.
18. The method according to any one of claims 1 to 12, characterized in that: The policy execution device obtains source information or destination information of the message, including: The policy execution device obtains source end information of the message according to the source address of the message and / or the port through which the policy execution device receives the message; The policy execution device obtains the destination end information of the message according to the destination address of the message and / or the port through which the policy execution device sends the message.
19. An access control method, characterized in that: The method comprises: The policy decision device generates coding information corresponding to each of the multiple security groups according to the inheritance relationship between the configured multiple security groups; The policy decision device sends the coding information corresponding to the multiple security groups to the policy execution device, so that the policy execution device can perform access control on the received message; The inheritance relationship between the multiple security groups is associated with n inheritance levels, and the coding information corresponding to each security group in the multiple security groups includes n coding segments, and the n coding segments correspond one-to-one to the n inheritance levels, where n is a positive integer greater than 1. For any security group among the multiple security groups that is configured as an inheriting security group, the valid coding segment in the coding information corresponding to the security group includes the coding segment corresponding to the inheritance hierarchy where the security group is located and the valid coding segment in the coding information corresponding to the inherited security group on which the security group depends, wherein the coding value of the valid coding segment in the coding information corresponding to the security group is used to identify the security group, and the coding value of the valid coding segment in the coding information corresponding to the inherited security group on which the security group depends is used to identify the inherited security group on which the security group depends; for the root security group among the multiple security groups that is configured as a non-inheriting security group, the valid coding segment in the coding information corresponding to the root security group includes the coding segment corresponding to the inheritance hierarchy where the root security group is located; the valid coding segment in the coding information corresponding to a security group is the valid matching information for the access control rule.
20. A policy execution device, characterized in that: include: memory, a network interface, and at least one processor, The memory is used to store program instructions, After the at least one processor reads the program instructions stored in the memory, it causes the policy execution device to execute the method according to any one of claims 1 to 18.
21. A policy decision-making device, characterized in that: include: memory, a network interface, and at least one processor, The memory is used to store program instructions, After the at least one processor reads the program instructions stored in the memory, it causes the policy decision device to execute the method according to claim 19.
22. An access control system, characterized in that: include: A policy execution device and a policy decision device, wherein the policy execution device is used to execute the method according to any one of claims 1 to 18, and the policy decision device is used to execute the method according to claim 19.
23. A computer-readable storage medium, characterized in that The computer-readable storage medium stores instructions, and when the instructions are executed by a processor, the method according to any one of claims 1 to 19 is implemented.
24. A computer program product, characterized in that The method comprises a computer program, which, when executed by a processor, implements the method according to any one of claims 1 to 19.
Citation Information
Patent Citations
Access control method and related equipment
CN115225300A
Network access control method and device
CN116155532A
Access control method, device and system
CN116318744A
On-demand security association management
US20190268383A1