Validation information generation method, apparatus and device, and storage medium and computer program product

By dynamically generating a source address verification table in the verification information generation device and combining it with BGP and IGP routing information, the false negative and false positive problems in source address verification technology are solved, thereby improving the security of the Internet.

WO2025246857A1PCT designated stage Publication Date: 2025-12-04CHINA MOBILE COMM LTD RES INST +1
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/093766
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-05-29
Filing Date
2025-05-09
Publication Date
2025-12-04

AI Technical Summary

Technical Problem

Existing source address verification technologies suffer from false negatives and false positives on the Internet, resulting in relatively low Internet security.

Method used

The verification information generation device determines the first routing information corresponding to the Border Gateway Protocol (BGP) type. Based on the first routing information and the first source address verification table, a second source address verification table is dynamically generated. The routing information of the Interior Gateway Protocol (IGP) type is analyzed to generate the final source address verification table, so as to achieve dynamic and accurate protection with low overhead, fast convergence and easy deployment.

Benefits of technology

It achieves low-overhead, fast-convergence, and easy-to-deploy dynamic and precise protection within an autonomous domain, thereby improving internet security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025093766_04122025_PF_FP_ABST
    Figure CN2025093766_04122025_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed in the present disclosure is a validation information generation method. The method comprises: determining first routing information corresponding to a border gateway protocol (BGP) type; and obtaining a second source address validation table on the basis of the first routing information and a first source address validation table. Further disclosed in the present disclosure are a validation information generation apparatus and device, and a storage medium and a computer program product.
Need to check novelty before this filing date? Find Prior Art

Description

A method, apparatus, device, storage medium, and computer program product for generating verification information.

[0001] Cross-reference to related applications

[0002] This disclosure is based on and claims priority to Chinese Patent Application No. 202410677748.9, filed on May 29, 2024, the entire contents of which are incorporated herein by reference. Technical Field

[0003] This disclosure relates to the field of communication technology, and in particular to a method, apparatus, device, storage medium, and computer program product for generating verification information. Background Technology

[0004] With the rapid development of internet technology, the security issues of internet applications have become increasingly prominent and serious. Statistics show that many network attacks are carried out through source address spoofing (SAV). SAV attacks are diverse and frequent, causing significant economic losses to users and severely impacting their normal applications. To mitigate the impact of SAV attacks, many Source Address Validation (SAV) technologies have been proposed. The feasibility of SAV technology stems from the fact that devices spoofing source addresses and devices with legitimate source addresses typically have different geographical or access locations. Therefore, spoofed and legitimate packets heading to the same destination will use different forwarding paths and pass through routers along the way from different ingress interfaces. Routers can thus identify which information is legitimate and which is spoofed through the mapping relationship between source addresses and ingress interfaces. Currently, the most commonly used source address validation technology within autonomous systems includes Unicast Reverse Path Forwarding (uRPF), mainly with two methods: loose uRPF and strict uRPF.

[0005] However, both relaxed and strict uRPF schemes still suffer from false negatives and false positives in some scenarios, resulting in relatively low internet security. Summary of the Invention

[0006] To address the aforementioned technical problems, this disclosure aims to provide a verification information generation method, apparatus, device, storage medium, and computer program product. It solves the problem that current source address verification technology is not perfect, resulting in relatively low internet security. The disclosure proposes a method for determining information in source address verification technology, dynamically generating source address validation (SAVNET) entries based on the actual state of the internet, achieving low-overhead, fast-convergence, and easily deployable dynamic and precise protection within an autonomous system.

[0007] The technical solution disclosed herein is implemented as follows:

[0008] This disclosure provides a method for generating verification information, the method comprising:

[0009] Determine the first routing information corresponding to the Border Gateway Protocol (BGP) type;

[0010] Based on the first routing information and the first source address verification table, a second source address verification table is obtained.

[0011] In the above scheme, obtaining the second source address verification table based on the first routing information and the first source address verification table includes:

[0012] If the first indication information is detected, the community attribute information included in the first routing information is determined; wherein, the first indication information is used to instruct the generation of the second source address verification table based on the community attribute information;

[0013] Based on the community attribute information, the first routing information and the first source address verification table are analyzed and processed to obtain the second source address verification table.

[0014] In the above scheme, the step of analyzing and processing the first routing information and the first source address verification table based on the community attribute information to obtain the second source address verification table includes:

[0015] If the group attribute information is the first attribute information, determine the next-hop information included in the first routing information; wherein, the next-hop information is associated with the group attribute information;

[0016] Determine the first network interface corresponding to the source prefix that matches the next-hop information from the first source address verification table;

[0017] Based on the target source prefix information corresponding to the first network interface and the first routing information, a second source address verification table is generated; wherein the target source prefix information is associated with the next-hop information.

[0018] The method in the above scheme further includes:

[0019] If the second indication information is detected, the next-hop information included in the first routing information is determined; wherein, the second indication information indicates that the community attribute information is not considered when generating the second source address verification table;

[0020] Determine the first network interface corresponding to the source prefix that matches the next-hop information from the first source address verification table;

[0021] Based on the target source prefix information corresponding to the first network interface and the first routing information, a second source address verification table is generated; wherein the target source prefix information is associated with the next-hop information.

[0022] In the above scheme, before obtaining the second source address verification table based on the first routing information and the first source address verification table, the method further includes:

[0023] Obtain the second routing information corresponding to the Interior Gateway Protocol (IGP) type;

[0024] The second routing information is analyzed and processed based on connectivity to generate the first source address verification table.

[0025] In the above scheme, the step of analyzing and processing the second routing information based on connectivity to generate the first source address verification table includes:

[0026] Based on connectivity, the link state information corresponding to the second routing information is calculated and analyzed to determine the source prefix information corresponding to each second network interface included in the verification information generating device.

[0027] Based on each of the second network interfaces and the corresponding source prefix information, the first source address verification table is obtained.

[0028] In the above scheme, the step of calculating and analyzing the link state information corresponding to the second routing information based on connectivity to determine the source prefix information corresponding to each second network interface included in the verification information generating device includes:

[0029] Based on connectivity, the link state information in the second routing information is calculated and analyzed to determine the set of reachable devices corresponding to each second network interface.

[0030] Detect whether each set of reachable devices includes a peer device to obtain a detection result; wherein, the peer device is at least two devices belonging to the same network layer and having a direct link in a connected state;

[0031] Based on the detection results, the source prefix information corresponding to the second network interface is determined.

[0032] In the above scheme, determining the source prefix information corresponding to the second network interface based on the detection result includes:

[0033] If the detection result includes at least one group of peer devices, connectivity analysis is performed based on the devices in the corresponding reachable device set other than at least one group of peer devices and the first detected device in each group of peer devices to determine the source prefix information corresponding to the second network interface.

[0034] If the detection result indicates that the co-located device does not exist, a connectivity analysis is performed on the corresponding set of reachable devices to determine the source prefix information corresponding to the second network interface.

[0035] This disclosure provides a verification information generation apparatus, the apparatus comprising: a determining unit and a first processing unit; wherein:

[0036] The determining unit is used to determine the first routing information corresponding to the Border Gateway Protocol (BGP) type;

[0037] The first processing unit is configured to obtain a second source address verification table based on the first routing information and the first source address verification table.

[0038] This disclosure provides a verification information generation device, the device comprising at least: a communication interface, a memory, a processor, and a communication bus; wherein:

[0039] The memory is used to store executable instructions;

[0040] The communication bus is used to realize the communication connection between the communication interface, the processor and the memory;

[0041] The processor is configured to execute the verification information generation program stored in the memory, and implement the steps of the verification information generation method as described in any of the preceding claims.

[0042] This disclosure provides a storage medium storing a verification information generation program, which, when executed, implements the steps of the verification information generation method as described in any of the preceding claims.

[0043] This disclosure provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the verification information generation method as described in any of the preceding claims.

[0044] This disclosure provides a method, apparatus, device, storage medium, and computer program product for generating verification information. After determining the first routing information corresponding to a BGP type using the verification information generation device, a second source address verification table is obtained based on the first routing information and a first source address verification table. In this way, by supplementing the existing first source address verification table with the first routing information of the BGP type using the verification information generation device, a second source address verification table is obtained. This solves the problem that current source address verification technology is not perfect, resulting in relatively low Internet security. It proposes a method for determining information in source address verification technology, dynamically generating SAVNET entries in the source address verification table based on the actual Internet state, so that the address information of received data packets can be verified and processed according to this table. This achieves low-overhead, fast-convergence, and easily deployable dynamic and precise protection within an autonomous system. Attached Figure Description

[0045] Figure 1 is a flowchart illustrating a verification information generation method provided in an embodiment of this disclosure;

[0046] Figure 2 is a flowchart illustrating another verification information generation method provided in an embodiment of this disclosure;

[0047] Figure 3 is a schematic diagram of an application scenario of a verification information generation method provided in an embodiment of this disclosure;

[0048] Figure 4 is a schematic diagram of an application scenario of a verification information generation method provided in an embodiment of this disclosure;

[0049] Figure 5 is a schematic diagram of an application scenario of a verification information generation method provided in an embodiment of this disclosure;

[0050] Figure 6 is a schematic diagram of an application scenario of a verification information generation method provided in an embodiment of this disclosure;

[0051] Figure 7 is a schematic diagram of an application scenario of a verification information generation method provided in an embodiment of this disclosure;

[0052] Figure 8 is a schematic diagram of a verification information generation device provided in an embodiment of this disclosure;

[0053] Figure 9 is a schematic diagram of the structure of a verification information generation device provided in an embodiment of this disclosure. Detailed Implementation

[0054] To make the objectives, technical solutions, and advantages of this disclosure clearer, the disclosure will be further described in detail below with reference to the accompanying drawings. The described embodiments should not be regarded as limitations on this disclosure. All other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this disclosure.

[0055] Embodiments of this disclosure provide a method for generating verification information. Referring to FIG1, the method is applied to a verification information generation device and includes the following steps:

[0056] Step 101: Determine the first routing information corresponding to the Border Gateway Protocol (BGP) type.

[0057] In this embodiment of the disclosure, the authentication information generating device is a device with routing capabilities, such as a router or a virtual router. The authentication information generating device obtains all the routing information it receives that is of the Border Gateway Protocol (BGP) type, and obtains the first routing information.

[0058] Step 102: Based on the first routing information and the first source address verification table, obtain the second source address verification table.

[0059] In this embodiment, the first source address verification table can be an existing source address verification table in the verification information generating device, or it can be a source address verification table generated based on routing information corresponding to other gateway protocols. The first and second source address verification tables primarily store the correspondence between the network interfaces of the verification information generating device and the source addresses, where the source address is the communication network address of the final device that the verification information generating device can access. The second source address verification table is used to verify the legality of the received access address.

[0060] The verification information generating device updates the first source address verification table using the first routing information to obtain the second source address verification table. The first routing information is the routing information corresponding to the verification information generating device within a certain period of time. In this way, the second source address verification table is related to the actual application scenario of the verification information generating device and is dynamically updated according to the actual situation, ensuring the reliability of the second source address verification table.

[0061] The verification information generation method provided in this disclosure determines the first routing information corresponding to the BGP type through a verification information generation device, and then obtains a second source address verification table based on the first routing information and a first source address verification table. In this way, by supplementing the existing first source address verification table with the first routing information of the BGP type using the verification information generation device, a second source address verification table is obtained. This solves the problem that current source address verification technology is not perfect, resulting in relatively low Internet security. It proposes a method for determining information in source address verification technology, dynamically generating SAVNET entries based on the actual Internet state, so that the address information of received data packets can be verified and processed according to this table. This achieves low-overhead, fast-convergence, and easily deployable dynamic and precise protection within an autonomous system.

[0062] Based on the foregoing embodiments, embodiments of this disclosure provide a verification information generation method, which is applied to a verification information generation device, and includes the following steps:

[0063] Step 201: Determine the first routing information corresponding to the Border Gateway Protocol (BGP) type.

[0064] In this embodiment of the disclosure, the verification information generating device is taken as a routing device as an example. The routing device obtains the first routing information of the currently stored BGP type. The first routing information may be newly added routing information during use, or, in the initial analysis, all routing information stored in the routing device.

[0065] Step 202: Based on the first routing information and the first source address verification table, obtain the second source address verification table.

[0066] In this embodiment, the example given is that the first source address verification table is an existing verification table in the verification information generation device. The verification information generation device uses first routing information and generates a second source address verification table based on the first source address verification table. It should be noted that before updating the first source address verification table, it can be backed up and stored. This ensures that in the event of subsequent faults, the backed-up first source address verification table can be used for recovery analysis.

[0067] Based on the foregoing embodiments, in other embodiments of this disclosure, step 202 can be implemented by steps 202a-202b or steps 202c-202e:

[0068] Step 202a: If the first indication information is detected, determine the community attribute information included in the first routing information.

[0069] The first instruction information is used to instruct the generation of a second source address verification table based on the group attribute information.

[0070] In this embodiment of the disclosure, the first indication information is selection indication information for supporting the generation of a source address verification table based on the community attribute information in the first routing information. For example, it may be an identifier 1, or "yes", or an on button corresponding to whether the community attribute information is needed to generate a second source address verification table.

[0071] When determining whether to select the first indication information for generating the second source address verification table based on community attribute information, the verification information generating device analyzes the first routing information to obtain all the community attribute information included therein.

[0072] Step 202b: Based on the community attribute information, analyze and process the first routing information and the first source address verification table to obtain the second source address verification table.

[0073] In this embodiment of the disclosure, the verification information generation device analyzes the group attribute information and determines whether to use the first routing information to analyze and update the first source address verification table to obtain the second source address verification table based on the analysis results.

[0074] Step 202c: If the second indication information is detected, determine the next-hop information included in the first routing information.

[0075] The second instruction information indicates that group attribute information is not considered when generating the second source address verification table.

[0076] In this embodiment of the disclosure, the second indication information is used to indicate that community attribute information does not need to be considered when generating the second source address verification table. At this time, the second indication information can be identified by indication information such as 0, or "no", or a button, etc.

[0077] When the second indication information is detected, the verification information generating device does not consider the community attribute information in the first routing information, but directly determines all the next-hop information included in the first routing information, so as to analyze and update the first source address verification table based on the determined all next-hop information.

[0078] Step 202d: Determine the first network interface corresponding to the source prefix that matches the next-hop information from the first source address verification table.

[0079] In this embodiment of the disclosure, a source prefix matching the next-hop information is searched in a first source address verification table, and the first network interface of the source prefix in the first source address verification table is determined. In some application scenarios, the network interface may also be a network port or a port.

[0080] Step 202e: Generate a second source address verification table based on the target source prefix information corresponding to the first network interface and the first routing information.

[0081] Among them, the target source prefix information and the next hop information are related.

[0082] In this embodiment, the target source prefix information is the routing information corresponding to the next-hop information. Thus, a correspondence is established between the first network interface and the target source prefix information. Using this correspondence, a second source address verification table is generated based on the first source address verification table. In some application scenarios, the second source address verification table can also be obtained by storing the first network interface, the target source prefix information, and the correspondence between them in a new source address verification table.

[0083] Based on the foregoing embodiments, in other embodiments of this disclosure, step 202b can be implemented by steps a11 to a13:

[0084] Step a11: If the group attribute information is the first attribute information, determine the next-hop information included in the first routing information.

[0085] The next hop information is related to the group attribute information.

[0086] In this embodiment of the disclosure, the first attribute information is an indication of whether the source prefix to source address verification table corresponding to the community attribute information is allowed to be added. The community attribute information is pre-configured. When the community attribute information is the second attribute information used to indicate whether the source prefix to source address verification table corresponding to the community attribute information is not to be added, it is not added to the second source address verification table based on the source prefix corresponding to the community attribute information.

[0087] When the community attribute information is the first attribute information, the verification information generating device determines all next-hop information corresponding to the community attribute information in the first routing information.

[0088] Step a12: Determine the first network interface corresponding to the source prefix that matches the next-hop information from the first source address verification table.

[0089] In this embodiment of the disclosure, a source prefix matching the next-hop information is determined from a first source address verification table, and the network interface corresponding to the determined source prefix is ​​obtained from the first source address verification table to obtain a first network interface.

[0090] Step a13: Generate a second source address verification table based on the target source prefix information corresponding to the first network interface and the first routing information.

[0091] Among them, the target source prefix information and the next hop information are related.

[0092] In this embodiment of the disclosure, the target source prefix information corresponding to the next hop information in the first routing information is obtained, and the first network interface and the target source prefix information are stored according to the corresponding association relationship to obtain the second source address verification table.

[0093] Based on the foregoing embodiments, and referring to FIG2, before the verification information generation device performs step 202, it is also used to perform steps 203 to 204:

[0094] Step 203: Obtain the second routing information corresponding to the Interior Gateway Protocol (IGP) type.

[0095] In this embodiment of the disclosure, the verification information generating device obtains all routing information of the Interior Gateway Protocol (IGP) type to obtain the second routing information.

[0096] Step 204: Analyze and process the second routing information based on connectivity to generate the first source address verification table.

[0097] In this embodiment of the disclosure, the process of determining connectivity can be as follows: if device A and device B establish a bidirectional neighbor relationship, then device A and device B are considered to be connected; if device B and device C also establish a bidirectional neighbor relationship, then device B and device C are connected, and consequently device A and device C are also connected.

[0098] The verification information generation device uses connectivity analysis to analyze the transmission nodes in the second routing information, and determines the final reachable source prefix address corresponding to all network interfaces included in the verification information generation device, and the first source address verification table of all network interfaces.

[0099] Based on the foregoing embodiments, in other embodiments of this disclosure, step 204 can be implemented by steps 204a to 204b:

[0100] Step 204a: Calculate and analyze the link state information corresponding to the second routing information based on connectivity, and determine the source prefix information corresponding to each second network interface included in the verification information generating device.

[0101] In this embodiment of the disclosure, the link status information corresponding to the second routing information can be directly obtained from the link information status table obtained by the verification information generation device based on the second routing information. If there is no link information status table, the verification information generation device can directly analyze the obtained second routing information to determine the link status information.

[0102] The verification information generation device uses connectivity analysis to calculate and analyze the link state information corresponding to the second routing information, determines the communication path reachable by each second network interface, and determines the access address information of each device in the communication path corresponding to each second network interface based on the communication path of each second network interface, thus obtaining the source prefix information.

[0103] Step 204b: Based on each second network interface and the corresponding source prefix information, obtain the first source address verification table.

[0104] In this embodiment of the disclosure, each second network interface and its corresponding source prefix information are stored according to the correspondence relationship to obtain a first source address verification table.

[0105] Based on the foregoing embodiments, in other embodiments of this disclosure, step 204a can be implemented by steps b11 to b13:

[0106] Step b11: Calculate and analyze the link state information in the second routing information based on connectivity to determine the set of reachable devices corresponding to each second network interface.

[0107] In this embodiment, starting with the verification information generating device, connectivity is used to calculate and analyze the link state information in the second routing information. During the calculation and analysis, a connectivity search method can be used to obtain the set of reachable devices corresponding to each second network interface. It should be noted that during the search process, devices in each communication path obtained for the same second network interface are searched only once. That is, the devices included in the set of reachable devices are determined through a single search analysis. Specifically, assuming the set of reachable devices includes the path port->A->B->C->AD, when searching for a port, the search starts from the port, sequentially determining device A, device B, and device C, and then no further searches are performed because device A has already been searched.

[0108] Step b12: Detect whether each reachable device set includes a co-located device and obtain the detection result.

[0109] Among them, co-location devices are at least two devices that belong to the same network layer and have a direct, logically reachable link in a bidirectional neighbor state.

[0110] In this embodiment of the disclosure, the reachable device set for each second network interface is analyzed to determine whether the reachable device set includes at least two devices belonging to the same network layer, and whether there are co-location devices with a direct link between the at least two devices, thereby obtaining the detection result.

[0111] Step b13: Based on the detection results, determine the source prefix information corresponding to the second network interface.

[0112] In this embodiment, when a co-located device exists, the detection result can indicate the specific device that is a co-located device, and the source prefix information of the corresponding second network interface can be analyzed based on the specific device. When no co-located device exists, the detection result directly indicates that no co-located device exists. In this way, the verification information generating device directly analyzes the set of reachable devices to determine the source prefix information.

[0113] Based on the foregoing embodiments, in other embodiments of this disclosure, step b13 can be implemented by step b131 or step b132:

[0114] Step b131: If the detection result includes at least one group of peer devices, perform connectivity analysis based on the devices in the corresponding reachable device set other than at least one group of peer devices and the first detected device in each group of peer devices to determine the source prefix information corresponding to the second network interface.

[0115] In this embodiment of the disclosure, when the detection result indicates at least one group of peer devices belonging to the peer device, the verification information generating device determines the first retrieved device from each group of peer devices, and performs connectivity analysis based on the first detected device in each group of peer devices and the devices in the reachable device set other than at least one group of peer devices to obtain the communication link corresponding to the second network interface. In this way, the source prefix information corresponding to the second network interface can be determined.

[0116] Step b132: If the detection result indicates that there is no co-located device, perform connectivity analysis on the corresponding reachable device set to determine the source prefix information corresponding to the second network interface.

[0117] In this embodiment of the disclosure, when the detection result indicates that there is no co-located device, the verification information device uses connectivity to determine the communication link of the corresponding second network interface for all devices in the set of reachable devices excluding co-located devices, thereby determining the source prefix information corresponding to the second network interface.

[0118] Based on the foregoing embodiments, the overall implementation idea of ​​the verification information generation method provided in this disclosure is as follows: based on connectivity calculation, determine a list of all devices reachable through a specified port; combine the source prefix information announced on these devices to obtain the source prefix information reachable through the specified port. This facilitates subsequent data packet source address checks, ensuring that only packets with source addresses within these source prefix ranges can pass, otherwise they will be discarded.

[0119] The process involves obtaining a list of reachable devices for each port based on connectivity calculations. Then, combining this list with the source prefix information published by each device in the reachable device list, a final Source Address Validation in Networks (SAVNET) table is generated. On devices requiring source address detection, connectivity calculations are performed based on an IGP-type Link State Database (LSDB) to obtain the IGP nodes reachable from the devices in the reachable device list within the domain. The source prefix information is then calculated based on the routing information published by these IGP nodes. Finally, the SAVNET table for the IGP protocol is generated based on the port and source prefix information.

[0120] The process of publishing routing information to calculate source prefix information can be achieved by using the IGP protocol to transmit the source prefix, that is, by using the IGP link state PDU (LSP) flooding mechanism to transmit the information to all devices. In this way, based on the information transmission process, the devices in the reachable device list can be obtained.

[0121] When performing connectivity calculations, the IGP protocol needs to consider situations where at least two devices are deployed at the same network layer (e.g., access layer, aggregation layer, core layer), and these two devices are directly connected via a crosslink (also known as a direct link), and the link is operational (i.e., co-located devices). If co-located devices exist, performing connectivity calculations according to the above process would result in identical source prefix information for all ports, thus negating the protective function. Therefore, to avoid this situation, connectivity calculations are performed only on one of the co-located devices.

[0122] Furthermore, the source prefix is ​​transmitted using the BGP protocol, and information is carried through BGP routes. Internally deployed BGP route reflectors reflect the BGP SAVNET routes to each BGP device. The BGP route information includes the source prefix, next-hop information, and community attribute information. Specifically, the community attribute information can be used to filter routes used for source prefix calculation. This can involve two scenarios: one where only routes with specified community attribute information are used for calculation and updating the BGP SAVNET table; and another where routes with community attribute information are not considered when updating the BGP SAVNET table. The next-hop information is used to associate with the SAVNET table of the IGP protocol. For example, the implementation process can be illustrated below: The BGP-published route information is 2000:: / 64, and the next-hop information is 1000:: / 64. The IGP protocol's SAVNET table records the source prefix 1000:: / 64, with the corresponding port being I2. Thus, it can be determined that the BGP's next-hop information 1000:: / 64 matches the source prefix 1000:: / 64 recorded in the IGP protocol's SAVNET table. Therefore, it can be determined that the port corresponding to the BGP-published route information 2000:: / 64 is I2. This allows the BGP protocol's SAVNET table, including the source prefix 2000:: / 64 and port I2, to be obtained from the IGP protocol's SAVNET table based on the next-hop information.

[0123] It should be noted that the default route :: / 0 can match any prefix, therefore the default route should be ignored when calculating the SAVNET within the domain and not included in the SAVNET table. Thus, after obtaining the SAVNET table, the generated SAVNET table is sent to the forwarding layer, which can then use this SAVNET table to perform security checks on the source addresses of received packets.

[0124] Based on the aforementioned overall approach, this disclosure provides an application embodiment of a verification information generation method, specifically including the following steps:

[0125] Step c11: Generate SAV rules based on the IGP protocol prefix.

[0126] The IGP protocol publishes the SAVNET source prefix in the manner of IGP routing. The IGP protocol carries the SAVNET source prefix information in the LSP it publishes and spreads it to the entire domain through the flooding of the LSP.

[0127] The IGP protocol uses the reachability algorithm, i.e. the aforementioned connectivity, to calculate the reachability information of each network node interface (NNI). Combined with the source address validation (SAV) source prefix published by the corresponding IGP node, it calculates the SAV source prefix information on each port and generates the SAVNET table.

[0128] The specific calculation process can be shown below:

[0129] Step 1: Before starting SAVNET rule calculation, save the existing SAVNET rule table to identify changes to SAVNET rule table entries.

[0130] Step 2: Traverse all interfaces of the node to be calculated and perform SAVNET rule calculation for each interface.

[0131] The node to be calculated corresponds to the verification information generation device. The process of calculating SAVNET rules for each interface specifically includes steps 3 to 10.

[0132] Step 3: Clear the access flags of all nodes, mark the starting node as visited, and then start traversing from the starting node.

[0133] The traversal method can be either the breadth-first search (BFS) algorithm or other traversal methods.

[0134] Step 4: Add the calculated nodes adjacent to the interface to the queue and mark them as visited. Simultaneously check for peer devices; if peer devices exist, mark the peer device nodes as visited as well.

[0135] Step 5: Get the first node from the queue.

[0136] Step 6: Process the current node, add all adjacent unvisited nodes to the queue, and mark them as visited.

[0137] Step 7: Generate SAVNET rules for the calculated interface of the current node based on the source prefix of the current node.

[0138] Step 8: Repeat steps 5 through 7 until the queue is empty.

[0139] Step 9: Repeat steps 2 through 8 until the SAVNET rules for each interface of the device are calculated.

[0140] Step 10: Merge the SAVNET rule entries for all interfaces of the device, merge entries with the same prefix into a single entry, and integrate the interfaces of each entry into the interface list of a single entry.

[0141] The IGP protocol uses a reachability algorithm to calculate a list of nodes reachable by each interface, and then combines this with the source prefix information published by the node to finally generate the SAVNET rule table.

[0142] Correspondingly, for example, in the application scenario shown in Figure 3 where there are no loops, the approximate implementation process for determining the SAVNET table using the above implementation process can be as follows:

[0143] Based on the aforementioned steps 1 to 9, we can obtain: 1.1: A1->B; 1.2: B1->C, B2->D; 2.1: A2->E; 2.2: E1->F; Finally, the SAVNET rule entries can be obtained as: (P1,A1), (P2,A1), (P3,A2).

[0144] For example, in the application scenario shown in Figure 4, where there is a loop but no co-located device, the approximate implementation process for determining the SAVNET table using the above implementation process can be as follows:

[0145] Based on the aforementioned steps 1 to 9, we can obtain: 1.1: A1->B; 1.2: B1->C, B2->D, B3->E; 1.3: E1->F; 2.1: A2->E; 2.2: E1->F, E2->B; 2.3: B1->C, B2->D; Finally, we can determine that the SAVNET rule entries are: (P1,A1), (P2,A1), (P3,A1), (P3,A2), (P1,A2), (P2,A2).

[0146] For example, in the application scenario shown in Figure 5 where there are co-located devices, the approximate implementation process for determining the SAVNET table using the above-described process can be as follows:

[0147] In Figure 5, MB1 and MB2 are devices at the same level. During connectivity checks, if MB1 and MB2 are at the same level, only the first detected device needs to be processed. That is, if MB1 is detected first, connectivity calculation is performed on MB1, while MB2 is not. However, when MB1 and MB2 are devices at the same level, but the direct link between MB1 and MB2 is disconnected, connectivity calculation is performed on MB2 after MB1.

[0148] Taking the connectivity calculation of interface B1 of device MB1, with MB1 and MB2 being co-located devices as an example, after calculating from interface B1 to device Bras1, and then from Bras1 to MB2, we can obtain: 1.1: MB1->Bras2; the corresponding result is: (P1, MB1). If the direct link between MB1 and MB2 does not exist or is broken, then for the connectivity calculation of interface B1 of device MB1, we can obtain: 1.1: MB1->Bras1; 1.2: Bras1->MB2; 1.3: MB2->Bras2; MB2->PB1 MB2->PB2; 1.4 PB1->PB2 PB2->PB1; the results are: (P1, MB1), (P2, MB1). At the same time, we also need to traverse the other interfaces of MB1 and the interface of MB2 accordingly. The traversal method is described above and will not be elaborated here.

[0149] For example, in the multi-homed access application scenario shown in Figure 6, the data flow within the 10:0:0:2:: / 80 subnet between nodes D and F will be forwarded from device D. Device D is configured with a static route 10:0:0:0:2:: / 80 and its cost value is configured to be a large value, such as 10000. Similarly, device F is configured with a static route 10:0:0:0:1:: / 80 and its cost value is... If the value is a large value, such as 10000, the configured static routes are transmitted via LSP through the IGP protocol and used for SAVNET source prefix calculation. Using the above implementation process, the SAVNET table can be determined as follows: (10:0:0:0:1:: / 80,A1), (10:0:0:0:2:: / 80,A2); (10:0:0:0:2:: / 80,A1), (10:0:0:0:1:: / 80,A2). It should be noted that because the configured static route Cost value is large, it will not affect correct route selection.

[0150] Step c12: Generate SAV rules for the BGP protocol based on the BGP protocol publishing prefix and the SAV rules generated by the IGP protocol.

[0151] In this process, the SAVNET source prefix is ​​calculated using the BGP protocol. The reachability information within the domain still needs to be transmitted via the LSDB using the IGP protocol. Thus, based on the SAVNET table of the IGP protocol obtained from the aforementioned calculation, the SAVNET table of the IGP is iterated to the next-hop information of the BGP route to generate the SAVNET table of the BGP protocol for the corresponding NNI downlink interface.

[0152] The specific implementation process can be referred to in the following steps:

[0153] Step 1: Obtain the IGP protocol SAVET table.

[0154] Step 2: The BGP protocol receives routing information, including source prefix information, next-hop address information, and community attribute information. It first filters based on the community attribute information. If the information carries the specified community attribute used to identify the source prefix, it proceeds to step 3; otherwise, no further processing is performed.

[0155] Step 3: Based on the next-hop information, perform a longest match search in the SAVNET table of the IGP protocol. If a matching source prefix is ​​found, continue to Step 4; otherwise, stop subsequent processing.

[0156] Step 4: Find the source prefix corresponding to the outgoing interface in the SAVNET table of the IGP protocol and generate the SAVNET table of the BGP source prefix.

[0157] The outgoing interface corresponds to the aforementioned target source prefix information.

[0158] Step 2, the filtering process for BGP protocol community attribute information, can include the following two scenarios: One scenario is ignoring the BGP protocol community attribute information added to the SAVNET table. In this case, the route prefix carrying this community attribute information can be ignored when adding it to the corresponding SAVNET table of the BGP protocol, which can specifically prevent spoofed attack traffic from certain internal users. Example use case: Configure routing policies on Broadband Remote Access Server (BRAS) or Service Router (SR) devices to distribute the user routes corresponding to the user traffic to be filtered, carrying the BGP community attribute value that is ignored when adding it to the SAVNET table, to the provincial network aggregation router PB or the metropolitan area network core router MB.

[0159] Upon receiving this routing information, the MB or PB device will use routing policy matching to ignore BGP community attribute parameters added to the SAVNET table and set the route prefix to not be added to the SAVNET table.

[0160] For route prefixes that are not allowed to be marked with SAVNET table tags, the generation algorithm for SAVNET table protection per device interface does not allow the generation of corresponding SAVNET tables.

[0161] Another scenario involves allowing incremental addition of BGP community attribute parameters to the SAVNET table. In this case, the corresponding route prefix carrying the community attribute parameter can be added to the SAVNET table prefix.

[0162] For example, consider the scenario shown in Figure 7, where the BGP protocol publishes a SAVNET source prefix and iterates to the IGP protocol's SAVNET entry. When the BGP protocol publishes the SAVNET source prefix, the next-hop address of the source prefix can have the following three possibilities:

[0163] 1) The next-hop route of the BGP source prefix is ​​introduced into the IGP protocol for publication.

[0164] In this protocol, the BGP protocol advertises the source prefix P1, and the next-hop information is the interface address 10::1. The route 10:: / 64 associated with this next-hop information is advertised by the IGP protocol. Therefore, on device A, through reachability calculation using the IGP protocol, the outgoing interface of the next-hop 10::1 of the BGP source prefix can be calculated as A1. Then, this outgoing interface list is iterated onto the BGP source prefix, ultimately generating the BGP SAVNET entry (P1, A1).

[0165] 2) The next hop of the BGP protocol source prefix is ​​introduced into the BGP protocol for publication.

[0166] In this protocol, the BGP protocol publishes the source prefix P1, with the next hop being the interface address 10::1. The route 10:: / 64, which has this next hop information, is also published by the BGP protocol, with its next hop being the BGP loopback interface address 33::33. It can be determined that the route 33::33 / 128 is published by the IGP protocol. Therefore, on device A, through reachability calculations using the IGP protocol, the outgoing interface of the next hop 33::33 / 128 can be calculated to be A1. The BGP protocol finds that the outgoing interface of the next hop address 33::33 is A1, and iterates this outgoing interface list to the source prefix next hop 10:: / 64, generating a SAVNET entry for the prefix 10:: / 64 as (10:: / 64, A1). Then, this generated SAVNET entry is iterated to the source prefix P1, generating a SAVNET entry for the source prefix P1 as (P1, A1).

[0167] 3) When publishing the source prefix in the BGP protocol, modify the next hop to the loopback address of the BGP protocol.

[0168] Specifically, when the BGP protocol publishes the source prefix, it modifies the next hop from the original interface address 10::1 to the BGP loopback interface address 33::33 using a configuration command. That is, when publishing the source prefix P1, the next hop address is changed to the BGP address 33::33. Thus, through IGP reachability calculations, the outgoing interface of the next hop 33::33 can be calculated as A1. The BGP protocol then iterates this outgoing interface onto the source prefix P1, generating a SAVNET entry (P1, A1) for the source prefix P1.

[0169] For clarity, in the application scenario implementation diagrams corresponding to Figures 3 to 7, A, B, C, D, ... represent devices, A1, A2, ..., B1, B2, ..., C1, C2, ... represent device interfaces, and P1, P2, ... represent source prefix information.

[0170] Thus, the embodiments of this disclosure dynamically generate SAVNET entries based on existing IGP and BGP protocols, which can achieve precise protection for more scenarios such as asymmetric routing, multi-homed asymmetric access of users within the domain, and traffic bypass. It also saves additional packet overhead and complex path calculation overhead, and reduces latency. In other words, it achieves low-overhead, fast-convergence, and easy-to-deploy dynamic precise protection within the autonomous system.

[0171] It should be noted that the descriptions of the same steps and contents as in other embodiments in this embodiment can be found in the descriptions in other embodiments, and will not be repeated here.

[0172] The verification information generation method provided in this disclosure determines the first routing information corresponding to the BGP type through a verification information generation device, and then obtains a second source address verification table based on the first routing information and a first source address verification table. In this way, by supplementing the existing first source address verification table with the first routing information of the BGP type using the verification information generation device, a second source address verification table is obtained. This solves the problem that current source address verification technology is not perfect, resulting in relatively low Internet security. It proposes a method for determining information in source address verification technology, dynamically generating SAVNET entries based on the actual Internet state, so that the address information of received data packets can be verified and processed according to this table. This achieves low-overhead, fast-convergence, and easily deployable dynamic and precise protection within an autonomous system.

[0173] Based on the foregoing embodiments, the present disclosure provides a verification information generation apparatus, which can be applied to the verification information generation method provided in the embodiments corresponding to FIG1 and FIG2. Referring to FIG8, the verification information generation apparatus 3 may include: a determining unit 31 and a first processing unit 32; wherein:

[0174] Determining unit 31 is used to determine the first routing information corresponding to the Border Gateway Protocol (BGP) type;

[0175] The first processing unit 32 is used to obtain a second source address verification table based on the first routing information and the first source address verification table.

[0176] In other embodiments of this disclosure, the first processing unit includes: a determining module and a processing module; wherein:

[0177] The determining module is configured to determine the community attribute information included in the first routing information if the first indication information is detected; wherein the first indication information is used to instruct the generation of a second source address verification table based on the community attribute information;

[0178] The processing module is used to analyze and process the first routing information and the first source address verification table based on the community attribute information to obtain the second source address verification table.

[0179] In other embodiments of this disclosure, the processing module is specifically used to implement the following steps:

[0180] If the group attribute information is the first attribute information, determine the next-hop information included in the first routing information; wherein, the next-hop information is related to the group attribute information;

[0181] Determine the first network interface corresponding to the source prefix that matches the next-hop information from the first source address verification table;

[0182] A second source address verification table is generated based on the target source prefix information corresponding to the first network interface and the first routing information; wherein the target source prefix information is associated with the next hop information.

[0183] In other embodiments of this disclosure, the first processing unit further includes: a generation module; wherein:

[0184] The determination module is further configured to determine the next-hop information included in the first routing information if the second indication information is detected; wherein the second indication information indicates that community attribute information is not considered when generating the second source address verification table;

[0185] The determination module is also used to determine the first network interface corresponding to the source prefix that matches the next-hop information from the first source address verification table;

[0186] The generation module is also used to generate a second source address verification table based on the target source prefix information corresponding to the first network interface and the first routing information; wherein the target source prefix information is associated with the next hop information.

[0187] In other embodiments of this disclosure, prior to the first processing unit, the apparatus further includes: an acquisition unit and a second processing unit; wherein:

[0188] The acquisition unit is used to acquire the second routing information corresponding to the Interior Gateway Protocol (IGP) type;

[0189] The second processing unit is used to analyze and process the second routing information based on connectivity, and generate the first source address verification table.

[0190] In other embodiments of this disclosure, the second processing unit includes: an analysis module and an acquisition module; wherein:

[0191] The analysis module is used to calculate and analyze the link state information corresponding to the second routing information based on connectivity, and to determine the source prefix information corresponding to each second network interface included in the verification information generating device.

[0192] The module is used to obtain the first source address verification table based on each second network interface and the corresponding source prefix information.

[0193] In other embodiments of this disclosure, the analysis module is specifically used to implement the following steps:

[0194] Based on connectivity, the link state information in the second routing information is calculated and analyzed to determine the set of reachable devices corresponding to each second network interface.

[0195] Detect whether each reachable device set includes a peer device and obtain the detection result; where a peer device is at least two devices belonging to the same network layer and having a direct link in the connected state.

[0196] Based on the detection results, the source prefix information corresponding to the second network interface is determined.

[0197] In other embodiments of this disclosure, when the analysis module determines the source prefix information corresponding to the second network interface based on the detection results, it can be implemented through the following steps:

[0198] If the detection result includes at least one group of peer devices, connectivity analysis is performed based on the devices in the corresponding reachable device set other than at least one group of peer devices and the first detected device in each group of peer devices to determine the source prefix information corresponding to the second network interface.

[0199] If the detection result indicates that there is no co-located device, perform connectivity analysis on the corresponding set of reachable devices to determine the source prefix information corresponding to the second network interface.

[0200] It should be noted that the process of information interaction between units and modules in this embodiment can be referred to the description in other embodiments, and will not be repeated here.

[0201] The verification information generation apparatus provided in this embodiment determines the first routing information corresponding to the BGP type through the verification information generation device, and then obtains a second source address verification table based on the first routing information and the first source address verification table. In this way, by supplementing the existing first source address verification table with the first routing information of the BGP type to obtain the second source address verification table, the apparatus solves the problem that current source address verification technology is not perfect, resulting in relatively low Internet security. It proposes a method for determining information in source address verification technology, dynamically generating SAVNET entries based on the actual Internet state, so that the address information of received data packets can be verified and processed according to this table. This achieves low-overhead, fast-convergence, and easily deployable dynamic and precise protection within an autonomous system.

[0202] Based on the foregoing embodiments, the present disclosure provides a verification information generation device, which can be applied to the verification information generation method provided in the embodiments corresponding to FIG1-2. Referring to FIG9, the verification information generation device 4 may include: a communication interface 41, a memory 42, a processor 43, and a communication bus 44; wherein:

[0203] Memory 42 is used to store executable information;

[0204] The communication bus 44 is used to realize the communication connection between the communication interface 41, the processor 43 and the memory 42;

[0205] The processor 43 is used to execute the verification information generation program stored in the memory 42 to implement the verification information generation method provided in the embodiments corresponding to Figures 1 and 2, which will not be described in detail here.

[0206] Based on the foregoing embodiments, the present disclosure provides a computer-readable storage medium, hereinafter referred to as a storage medium, which stores one or more programs that can be executed by one or more processors to implement the verification information generation method provided with reference to the embodiments of FIG1-2, which will not be described again here.

[0207] Based on the foregoing embodiments, this disclosure also provides a computer program product, including a computer program that can be executed by the processor 43 of the verification information generation device 4 to complete any of the foregoing method steps.

[0208] Those skilled in the art will understand that embodiments of this disclosure can be provided as methods, systems, or computer program products. Therefore, this disclosure can take the form of hardware embodiments, software embodiments, or embodiments combining software and hardware aspects. Furthermore, this disclosure can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage and optical storage) containing computer-usable program code.

[0209] This disclosure is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this disclosure. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in one or more flowchart illustrations and / or one or more block diagrams.

[0210] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means that implement the functions specified in one or more flowcharts and / or one or more block diagrams.

[0211] These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, such that the instructions, which execute on the computer or other programmable apparatus, provide steps for implementing the functions specified in one or more flowcharts and / or one or more block diagrams.

[0212] The above description is merely a preferred embodiment of this disclosure and is not intended to limit the scope of protection of this disclosure.

Claims

1. A method for generating verification information, the method comprising: determining first routing information corresponding to a Border Gateway Protocol (BGP) type; and obtaining a second source address verification table based on the first routing information and a first source address verification table. The step of obtaining the second source address verification table based on the first routing information and the first source address verification table comprises: detecting first indication information, determining group attribute information included in the first routing information if the first indication information is detected, wherein the first indication information indicates that the second source address verification table is generated according to the group attribute information; and analyzing and processing the first routing information and the first source address verification table based on the group attribute information to obtain the second source address verification table. The step of analyzing and processing the first routing information and the first source address verification table based on the group attribute information to obtain the second source address verification table comprises: determining next hop information included in the first routing information if the group attribute information is first attribute information, wherein the next hop information has a correlation with the group attribute information; determining a first network interface corresponding to a source prefix matching the next hop information from the first source address verification table; and generating the second source address verification table based on the first network interface and target source prefix information corresponding to the next hop information in the first routing information, wherein the target source prefix information has a correlation with the next hop information.

2. The method of claim 1, wherein, The method further comprises: determining next hop information included in the first routing information if second indication information is detected, wherein the second indication information indicates that the group attribute information is not considered when the second source address verification table is generated; determining a first network interface corresponding to a source prefix matching the next hop information from the first source address verification table; and generating the second source address verification table based on the first network interface and target source prefix information corresponding to the next hop information in the first routing information, wherein the target source prefix information has a correlation with the next hop information. Before the step of obtaining the second source address verification table based on the first routing information and the first source address verification table, the method further comprises: obtaining second routing information corresponding to an Interior Gateway Protocol (IGP) type; and generating the first source address verification table by analyzing and processing the second routing information based on connectivity. The step of generating the first source address verification table by analyzing and processing the second routing information based on connectivity comprises: calculating and analyzing link state information corresponding to the second routing information based on connectivity to determine source prefix information corresponding to each second network interface included in a verification information generation device; and obtaining the first source address verification table based on each second network interface and the corresponding source prefix information.

3. The method of claim 2, wherein, The step of calculating and analyzing the link state information corresponding to the second routing information based on connectivity to determine source prefix information corresponding to each second network interface included in a verification information generation device comprises: calculating and analyzing link state information in the second routing information based on connectivity to determine a set of reachable devices corresponding to each second network interface. ​ ​ ​ 4. The method of claim 2, wherein, ​ ​ ​ ​ 5. The method according to any one of claims 1 to 4, wherein, ​ ​ ​ 6. The method of claim 5, wherein, ​ ​ ​ 7. The method according to claim 6, wherein, ​ ​ detecting whether the peer device is included in each of the set of reachable devices, to obtain a detection result; wherein the peer device is at least two devices belonging to the same network level and having a direct link in an on state; determining the source prefix information corresponding to the second network interface based on the detection result.

8. The method of claim 7, wherein, The determining the source prefix information corresponding to the second network interface based on the detection result comprises: if the detection result includes at least one peer device group, performing connectivity analysis on devices in the set of reachable devices except the at least one peer device group and the first detected device in each of the at least one peer device group, to determine the source prefix information corresponding to the second network interface; if the detection result indicates that there is no peer device, performing connectivity analysis on the set of reachable devices, to determine the source prefix information corresponding to the second network interface.

9. An authentication information generating apparatus, the apparatus comprising: a determining unit and a first processing unit; wherein: The determining unit is configured to determine first routing information corresponding to a border gateway protocol (BGP) type. The first processing unit is configured to obtain a second source address verification table based on the first routing information and a first source address verification table.

10. A verification information generating device, said device comprising at least: a communication interface, a memory, a processor and a communication bus; wherein: The memory is configured to store executable instructions. The communication bus is configured to realize communication connection among the communication interface, the processor and the memory. The processor is configured to execute the verification information generation program stored in the memory, to realize the steps of the verification information generation method in any one of claims 1 to 8.

11. A storage medium having a verification information generation program stored thereon, the verification information generation program being executed to realize the steps of the verification information generation method in any one of claims 1 to 8.

12. A computer program product comprising a computer program, the computer program being executed by a processor to realize the steps of the verification information generation method in any one of claims 1 to 8.

Citation Information

Patent Citations

  • Method and apparatus for counting BGP community attribute or extended community attribute flow values

    CN106713162A

  • Flow message forwarding method, client, controller and storage medium

    CN115473812A

  • Verification information generation method and device, equipment, storage medium and computer program product

    CN118827138A

  • Method and device for collecting traffic flow value of BGP community attribute or BGP extended community attribute

    US20200328964A1