Forwarding Plane Device Policy Authentication for Service Flow Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In network architectures with separated control and forwarding planes, multiple control plane network elements can lead to malicious control of service flows, resulting in incorrect reachability between peer ends due to limitations in controller range and network management.
Innovation Solution
A processing method and apparatus that determine, based on a correspondence between control domain identifiers and service flow identifiers, whether to allow a control domain to operate a service flow processing policy, ensuring that only authorized domains manage service flows by receiving operation requests, obtaining identifiers, and authenticating control domain permissions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If multiple control plane network elements are deployed to handle service flows, then the network can process more service flows, but the risk of malicious control increases and service flow reachability cannot be guaranteed
Solution Approach 1:
The patent segments the control plane into multiple control domains, where each control domain is assigned to manage specific service flows. This segmentation prevents any single control domain from having unrestricted access to all service flows, thereby reducing the risk of malicious control while maintaining the ability to handle multiple service flows simultaneously. The forwarding plane device maintains a mapping between service flows and their authorized control domains, ensuring that only permitted control domains can modify or manage particular service flows.
2Adaptability or versatility
If control plane and forwarding plane are separated, then network flexibility and programmability are improved, but the complexity of managing multiple control plane elements increases
Solution Approach 1:
The patent introduces an intermediary mechanism in the form of a forwarding plane device that acts as a mediator between multiple control domains and the service flows. This intermediary maintains authorization information and mapping relationships, simplifying the management complexity by centralizing the coordination function. Control domains interact with the forwarding plane device rather than directly managing service flows, which reduces the overall system complexity while preserving network flexibility and adaptability.
3Ease of operation
If any control domain can operate any service flow processing policy, then system operation is simplified, but unauthorized modifications and malicious control occur
Solution Approach 1:
The patent implements preliminary action by pre-establishing authorization relationships between control domains and service flows before any policy operations occur. The forwarding plane device stores mapping information that identifies which control domains are authorized to manage which service flows. When a control domain attempts to operate a service flow processing policy, the forwarding plane device first verifies the authorization based on pre-stored mapping information. This preliminary authorization check simplifies operation for authorized domains while preventing unauthorized modifications by malicious domains.
Data Source
Figure 1~2a
Figure 2b~3
Figure 4A
AI summary
The present invention provides processing method, apparatus, and system for a service flow processing policy. The method includes: receiving, by a forwarding plane device, an operation request of a service flow processing policy from a first control domain, where the operation request of the service flow processing policy includes a service flow identifier corresponding to a to-be-processed policy; obtaining an identifier of the first control domain according to the operation request of the service flow processing policy; determining whether to allow the first control domain to operate the to-be-processed policy; and if the forwarding plane device determines to allow the first control domain to operate the to-be-processed policy, operating the to-be-processed policy according to the operation request of the service flow processing policy. Authentication is performed on a control domain that sends an operation request, and a corresponding operation is performed when the control domain is allowed to perform an operation. This prevents a service flow from being maliciously controlled, and ensures that the service flow correctly reaches a peer end.