Trusted path establishment method and apparatus, and storage medium
By introducing device verification network elements and network orchestrators to obtain the trusted status of network devices and establish trusted paths, the path security problem in SDN networks is solved, and the security and privacy of data transmission are improved, preventing data leakage and unauthorized access.
Patent Information
- Application Number
- PCT/CN2025/097985
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-05-29
- Filing Date
- 2025-05-29
- Publication Date
- 2025-12-04
AI Technical Summary
In SDN networks, the demand for data privacy and security is constantly increasing, but existing technologies cannot meet the requirements for path security. This can lead to sensitive data being transmitted through insecure paths, posing risks of data leakage and unauthorized access, especially in virtualization and resource-sharing scenarios where security and privacy issues are particularly prominent.
By introducing a device verification network element, the network orchestrator sends status request information to the device verification network element to obtain the trusted status of the network device, establish a trusted path, ensure path security, prevent sensitive data from being transmitted through an insecure path, and prevent data leakage or unauthorized access by obtaining the trusted status of the network device.
It improves the security and privacy of data transmission, prevents hacker attacks and illegal parsing, protects the security of sensitive data and private information, and reduces the risk of the system being maliciously tampered with and data being stolen.
Smart Images

Figure CN2025097985_04122025_PF_FP_ABST
Abstract
Description
Trusted path establishment method, apparatus, and storage medium
[0001] This disclosure claims priority to Chinese patent application No. 202410685136.4, filed on May 29, 2024, the entire contents of which are incorporated herein by reference. Technical Field
[0002] This disclosure relates to the field of communication technology, and in particular to a trusted path establishment method and apparatus, as well as a storage medium. Background Technology
[0003] Software-defined networking (SDN) is a revolutionary network architecture with flexible scalability and programmability, capable of meeting diverse business needs. SDN allows network administrators to control and manage network resources and traffic through software, rather than through traditional network devices. Furthermore, SDN separates the network's control plane from its data plane, enabling network administrators to configure and manage the network more flexibly and quickly. Summary of the Invention
[0004] Firstly, a trusted path establishment method is provided, applied to a network orchestrator. The trusted path establishment method includes: sending status request information to a device verification network element, the status request information including the identification information of the network device; receiving status response information sent by the device verification network element, the status response information including the trusted status of the network device; obtaining trusted path requirement information; and establishing a trusted path based on the trusted status of the network device and the trusted path requirement information.
[0005] Secondly, another trusted path establishment method is provided, which is applied to device verification network elements. The trusted path establishment method includes: receiving status request information sent by the network orchestrator, the status request information including the identification information of the network device; querying the trusted status of the network device based on the identification information; and sending status response information to the network orchestrator, the status response information including the trusted status of the network device.
[0006] Thirdly, a trusted path establishment apparatus is provided, comprising: a sending module, a receiving module, and a processing module. The sending module sends status request information to the device verification network element, the status request information including the identification information of the network device. The receiving module receives status response information sent by the device verification network element, the status response information including the trusted status of the network device. The processing module obtains trusted path requirement information. The processing module is also used to establish a trusted path based on the trusted status of the network device and the trusted path requirement information.
[0007] Fourthly, another trusted path establishment device is provided, comprising a receiving module, a processing module, and a sending module. The receiving module receives status request information sent by the network orchestrator, the status request information including the identification information of the network device. The processing module queries the trusted status of the network device based on the identification information. The sending module sends status response information to the network orchestrator, the status response information including the trusted status of the network device.
[0008] Fifthly, another trusted path establishment apparatus is provided, which includes a processor that, when executing a computer program, implements the trusted path establishment method as described in the first or second aspect.
[0009] A sixth aspect provides a computer-readable storage medium including computer instructions. When executed, the computer instructions implement the trusted path establishment method as described in the first or second aspect.
[0010] In a seventh aspect, this disclosure provides a computer program product comprising computer instructions. When executed by a processor, these computer instructions implement the trusted path establishment method as described in the first or second aspect.
[0011] Eighthly, this disclosure provides a computer program comprising computer instructions. When executed by a processor, these computer instructions implement the trusted path establishment method as described in the first or second aspect. Attached Figure Description
[0012] The accompanying drawings are provided to further understand the technical solutions of this disclosure and constitute a part of the specification. They are used together with the embodiments of this disclosure to explain the technical solutions of this disclosure and do not constitute a limitation on the technical solutions of this disclosure.
[0013] Figure 1 is a schematic diagram of an SDN architecture according to an embodiment of the present disclosure.
[0014] Figure 2 is a schematic diagram of a TPCM according to an embodiment of the present disclosure.
[0015] Figure 3 is a schematic diagram of the architecture of a network system according to an embodiment of the present disclosure.
[0016] Figure 4 is an interactive schematic diagram of a trusted path establishment method according to an embodiment of the present disclosure.
[0017] Figure 5 is an interactive schematic diagram of another trusted path establishment method according to an embodiment of the present disclosure.
[0018] Figure 6 is a flowchart illustrating a trusted path establishment method according to an embodiment of the present disclosure.
[0019] Figure 7 is a schematic diagram of the structure of a network domain according to an embodiment of the present disclosure.
[0020] Figure 8 is a schematic diagram of a trusted path establishment method according to an embodiment of the present disclosure.
[0021] Figure 9 is a complete interactive diagram of a trusted path establishment method according to an embodiment of the present disclosure.
[0022] Figure 10 is a schematic diagram of a trusted path establishment device according to an embodiment of the present disclosure.
[0023] Figure 11 is a schematic diagram of another trusted path establishment apparatus according to an embodiment of the present disclosure.
[0024] Figure 12 is a schematic diagram of another trusted path establishment device according to an embodiment of the present disclosure. Detailed Implementation
[0025] The technical solutions of the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this disclosure, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this disclosure without creative effort are within the scope of protection of this disclosure.
[0026] In the description of this disclosure, unless otherwise stated, " / " means "or," for example, A / B can mean A or B. "And / or" in this document is only used to describe the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can mean: only A, only B, and A and B. Furthermore, "at least one" means one or more, and "multiple" means two or more. The words "first," "second," etc., do not limit the quantity or order of execution, and "first," "second," etc., do not necessarily imply difference. It should be noted that in this disclosure, words such as "exemplary" or "for example" are used to describe examples, illustrations, or explanations.
[0027] Any embodiment or design described in this disclosure using terms such as "exemplary" or "for example" should not be construed as being more preferred or advantageous than other embodiments or designs. Specifically, the use of terms such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner. In embodiments of this disclosure, "instruction" can include direct instruction and indirect instruction. For example, taking the first control information hereinafter as an example, the first control information can directly carry information A itself or its index to achieve the purpose of directly instructing information A; or, the first control information can also carry information B that is related to information A, thereby achieving the purpose of indirectly instructing information A while instructing information B.
[0028] SDN, as a flexible, scalable, and programmable network architecture, can meet diverse business needs. However, due to the increasing demands for data privacy and security, SDN is gradually failing to meet these requirements. On the control plane, SDN's routing and orchestration algorithms do not consider path security, potentially leading to the transmission of sensitive data through insecure paths. On the data plane, the trustworthiness of network devices, as a crucial foundation for network connectivity, cannot be guaranteed, potentially resulting in data leakage or unauthorized access.
[0029] For example, when network devices are attacked by hackers or contain unauthorized software and applications, security risks such as end-to-end encryption failure during data transmission and unauthorized parsing of private data may occur. These risks are particularly pronounced in virtualization and resource-sharing scenarios. In such situations, hackers may attack network devices to obtain sensitive data or illegally parse private data, leading to serious security and privacy issues. Therefore, establishing trusted paths is an important security mechanism that can protect the integrity and confidentiality of data and information. Through trusted path orchestration, services such as trusted slicing and trusted traffic routing can be implemented, effectively reducing the security risks of malicious system tampering and data theft, and improving service quality. Trusted paths ensure the security of data during transmission, prevent hacker attacks and unauthorized parsing, and protect the security of sensitive data and private information.
[0030] Based on this, this disclosure provides a trusted path establishment method. By introducing a device verification network element, the network orchestrator can directly send status request information to the device verification network element to obtain the trusted status of the network device. This ensures path security considering the path orchestration algorithm in the control plane, preventing sensitive data from being transmitted through insecure paths and improving data security and privacy. Furthermore, by obtaining the trusted status of the network device, the trustworthiness of the network device is ensured, preventing data leakage or unauthorized access, further enhancing data security and privacy.
[0031] To facilitate understanding of the trusted path establishment method provided in this disclosure, the following technical concepts are described in detail.
[0032] 1. SDN technical architecture.
[0033] SDN is an emerging network architecture characterized by centralized and programmable network control functions. As shown in Figure 1, SDN can be divided into three layers: the top layer is the service layer, which includes various service applications; the middle layer is the control layer, mainly responsible for orchestrating data plane resources and maintaining network topology and state information; and the bottom layer is the forwarding layer, responsible for data processing, forwarding, and state collection. This architecture separates the network control layer from the forwarding layer, allowing network control functions to be transferred from network devices to external computing devices, thereby achieving centralized control and dynamic adjustment of the network. The control layer centrally controls network devices through standard interfaces. Network devices generate forwarding tables by receiving control signaling and process traffic data according to these tables, thus eliminating the need for complex distributed network protocols for data forwarding.
[0034] In an SDN architecture, it is difficult for a single SDN controller to control all forwarding capabilities at the network layer. A network orchestrator can connect to all SDN controllers, has the function of collecting and maintaining a global view of network resources and resource status, and can perform resource orchestration and orchestration policy distribution operations according to business needs.
[0035] 2. Trusted computing technology
[0036] A Trusted Platform Module (TPM) is a microchip designed to provide essential security-related functions, primarily involving encryption keys. Installed on a computer's motherboard, the TPM communicates with the rest of the system via a hardware bus. Devices containing TPMs can create and encrypt encryption keys so that these keys can only be decrypted by the TPM. This process, often called "wrapping" or "binding" keys, helps prevent key leakage. Each TPM has a master wrapping key, called the stored root key, which is stored within the TPM itself. The private portion of the stored root key or authentication key created within the TPM is never exposed to any other component, software, process, or user. The TPM chip features platform integrity metrics and remote authentication capabilities, used to assess the integrity of the platform's startup and runtime processes and the integrity of its running code, as well as to externally prove the trustworthiness of the TPM platform's own state. The TPM module can acquire the trusted characteristics of the hardware and software of the device platform it resides on, recording the execution integrity status of all hardware and software modules of the platform, thereby constructing a trust chain for the trusted computing platform. If any module is maliciously infected, its trust chain value will inevitably change.
[0037] The Trusted Platform Control Module (TPCM) is a hardware module integrated into a trusted platform. Figure 2 shows a schematic diagram of the TPCM framework. It is primarily used to establish and secure trusted sources, providing a range of trusted computing functions including trusted platform control, integrity measurement, secure storage, trusted reporting, and cryptographic services. The TPCM mainly comprises basic software, functional services, and basic hardware modules. It can interact with computing components through the computing component interface, with the Trusted Cryptography Module (TCM) through the trusted cryptography module interface, and with modules such as the trusted software base and TPCM management through functional interfaces. The TCM employs the SM series of national cryptographic algorithms, providing trusted roots and cryptographic operation functions. Similar to the TPM, TPCM and TCM also possess remote verification and integrity measurement capabilities.
[0038] The trusted path establishment method provided in this disclosure can be applied to the network system shown in Figure 3. Figure 3 shows a schematic diagram of the architecture of a network system according to an embodiment of this disclosure. As shown in Figure 3, the network system includes a network orchestrator, a device authentication network element, and an SDN controller.
[0039] In some embodiments, the network orchestrator is used to manage the trusted state of network devices and to orchestrate trusted paths.
[0040] For example, a network orchestrator can collect, verify, update, and maintain the trusted state of network devices. For instance, the management of the trusted state of network devices by a network orchestrator is described in detail below (1) through (4).
[0041] (1) Data collection: The trusted status of network devices is periodically collected from the device verification network element. This trusted status is the evaluation result of the trusted status provided by the device verification network element based on the trusted measurement of the network devices.
[0042] (2) Verification: Verify the trusted status of the network device sent by the device verification network element, including verifying the signature, device verification network element certificate, etc.
[0043] (3) Update: The network orchestrator queries the device verification network element to query the trusted status of a specific network device.
[0044] (4) Maintenance: The network orchestrator maintains the trusted status of network devices in its managed domain.
[0045] Another example is that a network orchestrator can establish and maintain the topology of trusted paths and orchestrate trusted paths to formulate an orchestration strategy for trusted paths. For example, the orchestration of trusted paths by a network orchestrator is described in detail below as shown in (1) and (2).
[0046] (1) Establishment and maintenance of trusted network path topology: Based on the trusted status of network devices reported by the device verification network element, establish a mapping relationship between the orchestratable resources of network devices and trusted network devices, including: network device orchestratable resource device identifiers, interface identifiers, virtual interface identifiers, etc., that can be associated with the device identifiers in the trusted status of network devices. When both network devices are trusted, the path or virtual path between the two network devices is considered trusted. Construct a trusted network path topology based on the trusted status of network devices and maintain this trusted network path topology.
[0047] (2) Trusted Path Orchestration: Receive relevant business requirements for trusted paths from the business system, perform trusted path orchestration, and formulate trusted path strategies.
[0048] In some embodiments, the device authentication network element is used to manage information related to network devices. This device authentication network element is also referred to as a network device remote authentication function network element, and this disclosure does not limit its scope. For example, as shown in Figures 1 to 3 below, the management of network device-related information by the device authentication network element is described in detail.
[0049] 1. Management of network devices
[0050] (1) Maintenance of network devices: Receive the registration information of network devices, obtain the trusted computing module identification information, certificate information, public key information, etc. in the corresponding network devices, and maintain and update them.
[0051] (2) Management of network device measurement-related information: Obtaining, storing, and maintaining trusted measurement information from network devices. The device verification network element can periodically obtain trusted measurement information for all network devices, or obtain specific trusted measurement information from network devices through a challenge-response mode. When the device verification network element and the network device are not in the same management domain or are not directly routable, the device verification network element can obtain the trusted measurement information of the network device from the network management system.
[0052] (3) Remote verification benchmark and evaluation strategy acquisition and maintenance functions
[0053] Network devices can also submit their trust metrics information to the device verification network element through a remote attestation process. This allows the device verification network element to remotely maintain and update the network device's trust metrics information, remote attestation benchmarks, and evaluation strategies. The benchmarks are used to compare with the network device's trust metrics information to assess the network device's trustworthiness. For example, reference benchmarks can be obtained and periodically / incrementally updated using customized methods, and the maintenance and evaluation strategies can be implemented through methods such as obtaining them via an interface provided by the trusted computing module vendor or directly deploying policy files. This disclosure does not limit the scope of these methods.
[0054] (4) Maintenance of trusted measurement information of network devices: Store and update trusted measurement information of network devices.
[0055] 2. Assessment of the Trustworthiness of Network Devices
[0056] Based on the acquired network device trust measurement information, the remote proof benchmark value of the network device trust status, and the evaluation strategy, the trust status of the network device is evaluated, and then the trust status of the network device is determined.
[0057] It should be noted that if the network device's trust status is included in the network device's trust measurement information, then the network device's trust status can be directly obtained without evaluation.
[0058] 3. Synchronization of the trusted status of network devices
[0059] (1) In response to the network orchestrator’s query request for the trusted status of the network device, return the trusted status of the network device.
[0060] (2) When the trusted state of a network device changes, the synchronization condition can be actively triggered to notify the network orchestrator of the changed trusted state of the network device.
[0061] In some embodiments, the SDN controller is used to uniformly monitor and control network devices in the underlying forwarding plane. It performs link discovery, topology management, and flow table distribution through southbound protocols such as Open Flow, providing a standard northbound interface to upper-layer applications. Upper-layer applications can use this interface to effectively schedule and configure resources in the underlying network to achieve automatic and flexible network management. The SDN controller can act as the command center of the network system, issuing control commands to network devices to instruct them to forward traffic, but it does not execute the control commands itself.
[0062] It should be noted that Figure 3 is only an exemplary framework diagram. The number of devices included in Figure 3 and the names of each device are not limited. In addition to the devices shown in Figure 3, the communication system may also include other devices, such as network devices.
[0063] The application scenarios of the embodiments disclosed herein are not limited. The system architecture and business scenarios described in the embodiments of this disclosure are for the purpose of more clearly illustrating the technical solutions of the embodiments of this disclosure, and do not constitute a limitation on the technical solutions provided by the embodiments of this disclosure. As will be known to those skilled in the art, with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided by the embodiments of this disclosure are also applicable to similar technical problems.
[0064] The embodiments of this disclosure will now be described in conjunction with the accompanying drawings.
[0065] Figure 4 illustrates an interactive schematic diagram of a trusted path establishment method provided according to this disclosure. As shown in Figure 4, it includes, for example, the following steps S401 to S405.
[0066] In S401, the network orchestrator sends a status request message to the device authentication network element. Correspondingly, the device authentication network element receives the status request message sent by the network orchestrator.
[0067] The status request information includes the identification information of the network device.
[0068] In some embodiments, the network orchestrator requests the trusted status of a specific network device by sending identification information carrying that specific network device to the device authentication network element.
[0069] For example, network devices include at least one of the following: IP (Internet Protocol) network devices (CPE (Customer Premises Equipment), switches, routers, BRAS (Broadband Remote Access Server) devices), transmission network devices (OTN (Optical Transport Network) devices), access network devices (ONU (Optical Network Unit), multi-functional ONT (Optical Network Terminal), OLT (Optical Line Terminal) devices, etc.) and other non-transparent forwarding network devices.
[0070] In S402, the device verification network element queries the trusted status of network devices based on identification information.
[0071] It should be noted that the device authentication network element is used to manage and evaluate the trusted status of network devices, and it can store the trusted status of network devices. Upon receiving a status request message from the network orchestrator, the device authentication network element can query the trusted status of the corresponding network device based on the network identification information carried in the status request message.
[0072] In S403, the device authentication element sends status response information to the network orchestrator. Correspondingly, the network orchestrator receives the status response information sent by the device authentication element.
[0073] Status response information includes the trusted status of network devices.
[0074] For example, if the network orchestrator has not previously requested the trusted status of the aforementioned network device from the device verification network element, the network orchestrator stores the trusted status of the aforementioned network device upon receiving the status response information.
[0075] In another example, if the network orchestrator has previously requested the trusted status of the aforementioned network device from the device verification network element, the network orchestrator updates the trusted status of the corresponding network device and can re-establish a trusted path based on the updated trusted status of the network device.
[0076] In S404, the network orchestrator obtains the required information for trusted paths.
[0077] The required information for a trusted path includes at least one of the following: trusted network slice information, source address information, and destination address information.
[0078] In some embodiments, the network orchestrator receives trusted path requirement information sent by the user terminal through the business system.
[0079] For example, a user may use a user terminal to send a request for a trusted path through a business system in at least one of the following situations: needing to ensure the security and reliability of specific business traffic, needing to isolate specific business traffic, needing to meet the Quality of Service (QoS) requirements of specific business, needing to protect specific business traffic from network attacks and unauthorized access, or needing to meet the compliance requirements of specific business.
[0080] In S405, the network orchestrator establishes trusted paths based on the trusted status of network devices and the required trusted paths.
[0081] In some embodiments, as shown in FIG5, the device verification network element determines the trusted status of the network device according to the following S501 to S503.
[0082] In S501, the device authentication network element sends a measurement request message to the network device. Correspondingly, the network device receives the measurement request message sent by the device authentication network element.
[0083] The measurement request information carries a random number (nonce) generated by the device verification network element to request trusted measurement information from the network device.
[0084] It should be noted that when a device verifies a network element requesting trusted measurement information from a network device, it can specify to request specific trusted measurement information.
[0085] In S502, the network device sends a measurement response message to the device authentication element. Correspondingly, the device authentication element receives the measurement response message sent by the network device.
[0086] The measurement response information includes at least one of the following: certificate information of the network device, and trusted measurement information of the network device.
[0087] It should be noted that, depending on the actual deployment, network devices may contain one or more trusted computing modules. These trusted computing modules can be at least one of the following: a trusted platform module (TPM), a trusted platform control module (TPCM), a trusted cryptography module (TCM), and a secure element (SE), among other security chips and application systems. They possess capabilities such as trusted measurement of network device hardware and software and runtime status, key generation capabilities, key storage capabilities, and remote authentication capabilities. This disclosure does not impose any limitations on these capabilities.
[0088] In some embodiments, the network device obtains its own trusted measurement information from its internal trusted computing module, and signs the nonce carried in the trusted measurement information and the measurement request information based on the network device's own private key AKpri to generate measurement response information. In addition, the measurement response information should also include information such as the network device's AK certificate, so that the device can verify the digital signature of the measurement response information by the network element.
[0089] It should be understood that before the network device generates the measurement response information, the trusted computing module in the network device has already generated a pair of public and private keys, AKpub and AKpri, which are mainly used for signing the trusted measurement information of the network device and applying for an AK certificate.
[0090] In S503, the device verification network element determines the trusted status of the network device based on the metric response information.
[0091] In some embodiments, the device verifies the integrity and timeliness of the trusted measurement information carried in the network element verification measurement response information, and compares it with the benchmark value of the trusted measurement information to generate an evaluation result of the network device's trusted status, thereby determining the trusted status of the network device.
[0092] The baseline value for the trust metric information is a preset value. By comparing the trust metric information with the corresponding baseline value, the trust status of network devices can be assessed more accurately.
[0093] In other embodiments, the trusted computing module of the network device has a trusted state evaluation function, which can directly evaluate the trusted state of the network device. In this case, the trusted computing module of the network device carries the trusted state of the network device in the measurement response information. After receiving the measurement response information, the device verification network element can directly determine the trusted state of the network device without evaluation.
[0094] In some embodiments, as shown in FIG6, the network orchestrator establishes a trusted path according to the following S601 to S603.
[0095] In S601, the parameter information of the trusted path is determined based on the required information of the trusted path.
[0096] The parameter information of a trusted path is used to characterize the configuration parameters of the trusted path. The parameter information of a trusted path includes at least one of the following: routing information, link state information, network quality of service (QoS), and latency information.
[0097] In some embodiments, the network orchestrator determines the parameter information of a trusted path from relevant data stored locally, based on the trusted path requirement information. For example, when a business system initiates a business orchestration request to the network orchestrator, such as trusted network slicing, trusted traffic routing for a specific source IP address range or destination address range, the network orchestrator queries the trusted status information of devices stored locally and selects orchestratable resources from network devices with a "trusted" status.
[0098] In S602, an orchestration strategy for trusted paths is generated based on the parameter information of trusted paths and the trusted status of network devices.
[0099] In some embodiments, the orchestration strategy, for example but not limited to, involves trusted paths consisting of trusted network devices, meaning that all network devices traversed by network traffic are in a "trusted" state. The network orchestrator first selects network devices in a "trusted" state as a pool of candidate devices. Then, based on other network parameters related to the devices in the pool, such as network reachability, link state information, QoS information, and other conventional orchestration parameters, it performs trusted path orchestration, ultimately achieving the capability that all network devices in the trusted path are trusted devices. If the pool of candidate devices composed of "trusted" network devices cannot meet the service requirements (e.g., it does not meet service connectivity or other higher-weighted requirements), then the service cannot be orchestrated using trusted paths and will be orchestrated using a normal orchestration method.
[0100] It should be understood that the trusted state of a network device is used to characterize its trustworthiness. Based on the trusted state, network devices can be categorized as trusted or untrusted. When establishing a trusted path, it should be ensured that all network devices along the path are trusted.
[0101] For example, the network orchestrator performs trusted path orchestration based on trusted path parameter information and the trusted status of network devices, and generates trusted path orchestration strategies.
[0102] In S603, an orchestration policy is sent to the SDN controller to establish a trusted path.
[0103] For example, the network orchestrator issues a trusted path orchestration policy to the SDN controller to establish a trusted path. When the trusted path involves different network domains, the network orchestrator needs to send the trusted path orchestration policy to the SDN controller in each of the multiple network domains. After receiving the trusted path orchestration policy, the SDN controller sends the corresponding orchestration policy to the associated network device to complete the establishment of the trusted path. For example, as shown in Figure 7, Figure 7 includes multiple network domains, namely Network Domain 1 and Network Domain 2. Different network domains have different SDN controllers, and each network domain includes at least one network device. Different network domains differ in their IP devices and transmission devices. Furthermore, the trusted computing modules of network devices in different network domains manage the trusted state of the network devices in different ways. For example, they can directly connect to the device verification network element, directly send the trusted measurement information of the network device to the device verification network element, or forward the trusted measurement information of the network device to the device verification network element through the corresponding network management function network element (not shown in Figure 7).
[0104] It should be noted that network domain 1 in Figure 7 also includes the EMS / NMS system. The EMS (element management system) / NMS (internet management system) is used for device management, performance management, fault management, and security management of network devices. When the EMS / NMS system has the function of collecting and evaluating trusted measurement information of network devices, the device verification network element can obtain the trusted measurement information and trusted status of the network devices from the EMS / NMS system.
[0105] Figure 8 illustrates a trusted path establishment method according to this disclosure. The network orchestrator, based on trusted path requirement information and the trusted status of network devices, orchestrates trusted paths, generates trusted path policies, and distributes them to the corresponding network devices via the SDN controller to complete the establishment of trusted paths. For example, network domain 1 in Figure 8 contains one untrusted device and four trusted devices; therefore, trusted paths are established only on the four trusted devices in network domain 1. Network domain 2 contains three untrusted devices and two trusted devices; therefore, trusted paths are established only on the two trusted devices in network domain 1.
[0106] Figure 9 shows a complete interaction diagram of a trusted path establishment method according to the present disclosure, including, for example, the following S901 to S908.
[0107] In S901, the network orchestrator sends a status request message to the device authentication network element. Correspondingly, the device authentication network element receives the status request message sent by the network orchestrator.
[0108] The status request information includes the identification information of the network device.
[0109] In S902, the device verification network element queries the trusted status of network devices based on identification information.
[0110] In S903, the device authentication element sends status response information to the network orchestrator. Correspondingly, the network orchestrator receives the status response information sent by the device authentication element.
[0111] Status response information includes the trusted status of network devices.
[0112] In S904, the user terminal sends a trusted path request to the network orchestrator through the service system. Correspondingly, the network orchestrator receives the trusted path request information sent by the user terminal through the service system.
[0113] The required information for a trusted path includes at least one of the following: trusted network slice information, source address information, and destination address information.
[0114] In S905, the network orchestrator determines the parameter information of the trusted path based on the trusted path requirement information.
[0115] The parameters of a trusted path include at least one of the following: routing information, link state information, network quality of service (QoS), and latency information.
[0116] In S906, the network orchestrator generates an orchestration strategy for trusted paths based on the parameter information of trusted paths and the trusted status of network devices.
[0117] In S907, the network orchestrator sends orchestration policies to the SDN controller. The SDN controller then receives the orchestration policies from the network orchestrator.
[0118] In S908, the SDN controller sends orchestration policies to network devices. Correspondingly, the network devices receive the orchestration policies sent by the SDN controller.
[0119] The corresponding descriptions of S901 to S908 can be found in the descriptions above, and will not be repeated here.
[0120] In this way, by introducing a device verification network element, the network orchestrator can directly send status request information to the device verification network element to obtain the trusted status of the network device. This ensures path security considering the path orchestration algorithm in the control plane, preventing sensitive data from being transmitted through insecure paths and improving data security and privacy. Furthermore, by obtaining the trusted status of the network device, the trustworthiness of the network device is ensured, preventing data leakage or unauthorized access, further enhancing data security and privacy.
[0121] It should be understood that the trusted state of a network device changes when its configuration changes or when it malfunctions. In the event of a change in the trusted state of a network device, the device authentication element can proactively notify the network orchestrator of the changed trusted state through event triggering.
[0122] For example, when the trusted state of a network device changes, the device authentication element sends the changed trusted state to the network orchestrator. Correspondingly, the network orchestrator receives the changed trusted state from the device authentication element and updates the trusted state of the network device based on the changed trusted state.
[0123] For example, if the trusted state of a network device changes, the security and privacy of the established trusted path may not be guaranteed. Upon receiving the changed trusted state, the network orchestrator regenerates the orchestration policy for the trusted path based on the changed trusted state, thereby re-establishing the trusted path.
[0124] In this way, the network orchestrator can regenerate the orchestration policy of trusted paths based on the changed trusted state, ensuring the security and privacy of trusted paths. Furthermore, by updating trusted paths in real time, the network orchestrator can respond promptly to changes in the trusted state of network devices, reducing the risk of network attacks and data breaches.
[0125] The foregoing primarily describes the solutions provided by the embodiments of this disclosure from a methodological perspective. To achieve the aforementioned functions, it includes corresponding hardware structures and / or software modules for executing each function. Those skilled in the art should readily recognize that, in conjunction with the units and algorithm steps of the various examples described in the embodiments disclosed herein, the embodiments of this disclosure can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this disclosure.
[0126] This disclosure embodiment can divide the trusted path establishment device into functional modules according to the above method example. For example, each function can be divided into a separate functional module, or two or more functions can be integrated into one processing module. The integrated module can be implemented in hardware or as a software functional module. In some embodiments, the module division in this disclosure embodiment is illustrative and is only a logical functional division; other division methods may be used in actual implementation.
[0127] Figure 10 is a schematic diagram of a trusted path establishment device according to an embodiment of the present disclosure. As shown in Figure 10, the trusted path establishment device 100 includes a communication module 1001 and a processing module 1002. The communication module 1001 includes a sending module and a receiving module.
[0128] The sending module is used to send status request information to the device verification network element. The status request information includes the identification information of the network device.
[0129] The receiving module is used to receive status response information sent by the device verification network element. The status response information includes the trusted status of the network device.
[0130] Processing module 1002 is used to obtain the required information for trusted paths.
[0131] The processing module 1002 is also used to establish a trusted path based on the trusted status of network devices and the demand information of trusted paths.
[0132] In some embodiments, the required information for a trusted path includes at least one of the following: trusted network slice information, source address information, and destination address information.
[0133] In some embodiments, the processing module 1002 is configured to: determine the parameter information of a trusted path based on the demand information of the trusted path, wherein the parameter information of the trusted path is used to characterize the configuration parameters of the trusted path; generate an orchestration policy for the trusted path based on the parameter information of the trusted path and the trusted status of the network device; and send the orchestration policy to the SDN controller to establish a trusted path.
[0134] In some embodiments, the parameter information of the trusted path includes at least one of the following: routing information, link state information, network service quality (QoS), and latency information.
[0135] In some embodiments, the processing module 1002 is configured to: receive trusted path requirement information sent by the user terminal through the business system.
[0136] In some embodiments, the receiving module is further configured to: receive the changed trusted status sent by the device verification network element, and update the trusted status of the network device based on the changed trusted status.
[0137] Figure 11 is a schematic diagram of another trusted path establishment apparatus according to an embodiment of the present disclosure. As shown in Figure 11, the trusted path establishment apparatus 110 includes a communication module 1101 and a processing module 1102. The communication module 1101 includes a sending module and a receiving module.
[0138] The receiving module is used to receive status request information sent by the network orchestrator. The status request information includes the identification information of the network device.
[0139] Processing module 1102 is used to query the trusted status of network devices based on identification information.
[0140] The sending module is used to send status response information to the network orchestrator. The status response information includes the trusted status of the network devices.
[0141] In some embodiments, the processing module 1102 is further configured to: send measurement request information to the network device; receive measurement response information sent by the network device, the measurement response information including at least one of the following: certificate information of the network device, trusted measurement information of the network device; and determine the trusted status of the network device based on the measurement response information.
[0142] In some embodiments, the processing module 1102 is further configured to: send the changed trusted state to the network orchestrator when the trusted state of the network device changes.
[0143] In the case of implementing the functions of the integrated modules described above in hardware, this disclosure provides a schematic diagram of the trusted path establishment apparatus shown in FIG12. As shown in FIG12, the trusted path establishment apparatus 120 includes: a processor 1202 and a bus 1204. In some embodiments, the trusted path establishment apparatus 120 may further include a memory 1201. In some embodiments, the trusted path establishment apparatus 120 may further include a communication interface 1203.
[0144] Processor 1202 may implement or execute various exemplary logic blocks, modules, and circuits described in conjunction with this disclosure. Processor 1202 may be a central processing unit, a general-purpose processor, a digital signal processor, an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof, and may implement or execute the various exemplary logic blocks, modules, and circuits described in conjunction with this disclosure. Processor 1202 may also be a combination that implements computational functions, for example, including one or more microprocessor combinations, a combination of a DSP (digital signal processor) and a microprocessor, etc.
[0145] The communication interface 1203 is used to connect with other devices via a communication network. This communication network can be Ethernet, wireless access network, wireless local area network (WLAN), etc.
[0146] The memory 1201 may be a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions, random access memory (RAM) or other type of dynamic storage device capable of storing information and instructions, or electrically erasable programmable read-only memory (EEPROM), disk storage medium or other magnetic storage device, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but is not limited thereto.
[0147] In one implementation, the memory 1201 can exist independently of the processor 1202. The memory 1201 can be connected to the processor 1202 via a bus 1204 and is used to store instructions or program code. When the processor 1202 calls and executes the instructions or program code stored in the memory 1201, it can implement the trusted path establishment method provided in this embodiment.
[0148] In another implementation, the memory 1201 can also be integrated with the processor 1202.
[0149] Bus 1204 can be an extended industry standard architecture (EISA) bus, etc. Bus 1204 can be divided into address bus, data bus, control bus, etc. For ease of illustration, only one thick line is used to represent it in Figure 12, but this does not mean that there is only one bus or one type of bus.
[0150] This disclosure also provides a computer-readable storage medium (e.g., a non-transitory computer-readable storage medium) including computer-executable instructions that, when executed on a computer, cause the computer to perform the methods provided in the above embodiments.
[0151] This disclosure also provides a computer program product that can be directly loaded into a memory and contains software code. After being loaded and executed by a computer, the computer program product can implement the methods provided in the above embodiments.
[0152] Those skilled in the art will recognize that the functions described in this disclosure in one or more of the foregoing examples can be implemented using hardware, software, firmware, or any combination thereof. When implemented in software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or code on a computer-readable medium. Computer-readable media include computer storage media and communication media. Communication media include any medium that facilitates the transfer of a computer program from one place to another. Storage media can be any available medium accessible to a general-purpose or special-purpose computer.
[0153] The above description is merely a specific embodiment of this disclosure, but the scope of protection of this disclosure is not limited thereto. Any changes or substitutions within the technical scope disclosed in this disclosure should be included within the scope of protection of this disclosure. Therefore, the scope of protection of this disclosure should be determined by the scope of the claims.
Claims
1. A trusted path establishment method applied to a network orchestrator, comprising: sending state request information to a device verification network element, the state request information comprising identification information of a network device; receiving state response information sent by the device verification network element, the state response information comprising a trusted state of the network device; obtaining requirement information of a trusted path; establishing the trusted path based on the trusted state of the network device and the requirement information of the trusted path.
2. The method of claim 1, wherein, The requirement information of the trusted path comprises at least one of the following: slice information of a trusted network, source address information, and target address information.
3. The method of claim 1 or 2, wherein, The establishing of the trusted path based on the trusted state of the network device and the requirement information of the trusted path comprises: determining parameter information of the trusted path based on the requirement information of the trusted path, the parameter information of the trusted path being used to represent configuration parameters of the trusted path; generating an orchestration strategy of the trusted path based on the parameter information of the trusted path and the trusted state of the network device; and sending the orchestration strategy to a software defined network (SDN) controller to establish the trusted path.
4. The method of claim 3, wherein, The parameter information of the trusted path comprises at least one of the following: routing information, link state information, network quality of service (QoS), and delay information.
5. The method of any one of claims 1 to 4, wherein, The obtaining of the requirement information of the trusted path comprises: receiving the requirement information of the trusted path sent by a user terminal through a service system.
6. The method of any one of claims 1 to 5, further comprising: receiving a changed trusted state sent by the device verification network element; and updating the trusted state of the network device based on the changed trusted state.
7. A trusted path establishment method applied to a device verification network element, comprising: receiving state request information sent by a network orchestrator, the state request information comprising identification information of a network device; inquiring a trusted state of the network device based on the identification information; and sending state response information to the network orchestrator, the state response information comprising the trusted state of the network device.
8. The method of claim 7, further comprising: sending measurement request information to the network device; receiving measurement response information sent by the network device, the measurement response information comprising at least one of the following: certificate information of the network device and trusted measurement information of the network device; and determining the trusted state of the network device based on the measurement response information.
9. The method of claim 7 or 8, further comprising: in a case where the trusted state of the network device changes, sending a changed trusted state to the network orchestrator. a sending module, a receiving module, and a processing module; 10. A trusted path establishment apparatus comprising: the sending module is configured to send state request information to a device verification network element, the state request information comprising identification information of a network device; the receiving module is configured to receive state response information sent by the device verification network element, the state response information comprising a trusted state of the network device; the processing module is configured to obtain requirement information of a trusted path. The processing module is further configured to establish the trusted path based on the trusted state of the network device and the requirement information of the trusted path.
11. A trusted path establishment apparatus comprising: The receiving module, the processing module, and the sending module; The receiving module is configured to receive state request information sent by the network orchestrator, the state request information comprising identification information of the network device; The processing module is configured to query the trusted state of the network device based on the identification information; The sending module is configured to send state response information to the network orchestrator, the state response information comprising the trusted state of the network device. 12.A trusted path establishment apparatus, comprising a processor, the processor implements the trusted path establishment method according to any one of claims 1 to 6 or the trusted path establishment method according to any one of claims 7 to 9 when executing a computer program.
13. A computer readable storage medium, wherein, The computer readable storage medium comprises computer instructions; wherein when the computer instructions are executed, the trusted path establishment method according to any one of claims 1 to 6 or the trusted path establishment method according to any one of claims 7 to 9 is implemented. 14.A computer program product, comprising computer instructions, the computer instructions implement the trusted path establishment method according to any one of claims 1 to 6 or the trusted path establishment method according to any one of claims 7 to 9 when executed by a processor. 15.A computer program, comprising computer instructions, the computer instructions implement the trusted path establishment method according to any one of claims 1 to 6 or the trusted path establishment method according to any one of claims 7 to 9 when executed by a processor.
Citation Information
Patent Citations
Communication network processing method and device, electronic equipment and readable storage medium
CN112468448A
Service orchestration method and device and storage medium
CN115277578A
Routing calculation method, device and equipment and storage medium
CN116032816A
Communication method and device
CN117641342A
End-to-end arrangement method and system based on intention, electronic equipment and medium
CN117729144A