WO2011120454A2 - Procédé et hôte destinés à mettre en place une transmission sécurisée de paquets de données dans un réseau à espace multi-adresses et multi-ralliement - Google Patents

Procédé et hôte destinés à mettre en place une transmission sécurisée de paquets de données dans un réseau à espace multi-adresses et multi-ralliement Download PDF

Info

Publication number
WO2011120454A2
WO2011120454A2 PCT/CN2011/073638 CN2011073638W WO2011120454A2 WO 2011120454 A2 WO2011120454 A2 WO 2011120454A2 CN 2011073638 W CN2011073638 W CN 2011073638W WO 2011120454 A2 WO2011120454 A2 WO 2011120454A2
Authority
WO
WIPO (PCT)
Prior art keywords
location
source host
host
location information
local
Prior art date
Application number
PCT/CN2011/073638
Other languages
English (en)
Chinese (zh)
Other versions
WO2011120454A3 (fr
Inventor
徐小虎
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Priority to PCT/CN2011/073638 priority Critical patent/WO2011120454A2/fr
Priority to CN201180000592.1A priority patent/CN102204221B/zh
Publication of WO2011120454A2 publication Critical patent/WO2011120454A2/fr
Publication of WO2011120454A3 publication Critical patent/WO2011120454A3/fr

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1441Countermeasures against malicious traffic
    • H04L63/1458Denial of Service

Definitions

  • the present invention relates to the field of communication technologies, and in particular, to a method and a host for implementing secure transmission of data packets under traffic engineering control in a multi-homed multi-address space network.
  • the network architecture is a network protocol system for the next generation Internet (Internet).
  • the Node ID introduces a Locator Domain (LD) to identify a network using an independent address space.
  • the address The space may be the fourth version of the Internet Protocol (IPV4, Internet Protocol version 4), the sixth version of the Internet Protocol (IP V6, Internet Protocol version 6) or other protocol address space.
  • IPV4 Internet Protocol version 4
  • IP V6, Internet Protocol version 6 the sixth version of the Internet Protocol version 6
  • Different LDs can use different address spaces.
  • CN core network
  • EN Edge Network
  • the EN can be directly connected to the CN or indirectly connected to the CN through other ENs.
  • a border router connecting different ENs is called an edge border router (ER, Egdg router), and a border router connecting CN and EN is called a core edge router (CER).
  • ER edge border router
  • CER core edge router
  • the CN and each EN in the Node ID network architecture use separate address spaces. These CNs or ENs with independent address spaces are different LDs, which are identified by LD ID.
  • Both the network host (host) and the border router have a globally unique identifier (ID, indenifier). When the mobile host and the mobile routing device move, the ID remains unchanged.
  • ID globally unique identifier
  • locator which is the IP address. If the source and destination of the data packet are in the same LD, then forwarding the data packet can be implemented according to the locator inside the LD; if the source and destination of the data packet are not in one LD, that is, data between different LDs. Packet forwarding is performed through the core edge router indenifier (CER ID).
  • CER ID core edge router indenifier
  • the CER is used to issue a default route to the down-link EN.
  • the default route is the route used when no matching route is found.
  • the host added to the EN first sends a registration message along the default route to the CER.
  • the registration message includes the host identifier (HI, Host Indenifier) and locator of the host, and the locator is the local location information of the host in the current LD;
  • CER Save the mapping relationship between HI and locator, so that the CER knows how to reach the host connected to it when sending the packet.
  • DHT Distributed Hash Table
  • the local location information of all the hosts in the LD is registered in the DHT of the CN. Therefore, the EN and the CN can only adopt the tree structure networking, resulting in limited networking structure and support. The implementation of attribution is more complicated. At the same time, if two ENs with different LDs communicate, they must pass the CN, even if the EN of the two different LDs are close to each other in physical distance, which makes the forwarding route unsatisfactory.
  • LD ID location-based identification
  • Packet forwarding which solves the problem of the network ID architecture of the Node ID network architecture.
  • this multi-address space network is still addressed according to the shortest path principle. It does not have network-level traffic engineering control capabilities, which tends to cause the shortest path network to be blocked, and other network paths are idle. Traffic engineering is how to effectively use integrated network bandwidth when there are multiple parallel or alternate paths. Traffic engineering balances the traffic load between different links, routers, and switches in the network, so that all of these devices are neither over-utilized nor underutilized to effectively utilize the resources of the entire network.
  • the Chinese invention patent discloses a method and a device for implementing traffic engineering in a multi-homed multi-address space network, and this invention patent describes in detail that the first host belongs to The first location domain and the second location domain, when the second host belongs to the third location domain, the first host sends a data packet to the second host.
  • the process is: the first host sends a data packet to the second host by using the border router, and the border router determines whether the location domain identifier and the location domain information of the source host carried in the data packet meet the traffic engineering. If not, the location source host is reset. Identification and local location information.
  • the data packets between different LDs are transmitted under the control of traffic engineering, and the network resources are utilized reasonably, and the data packets are transmitted efficiently and quickly.
  • the method of implementing traffic engineering in the existing multi-address space network is when the source host site border router is carried in the outbound station and in the data packet.
  • the destination host will communicate with the source host using the modified source host's location domain identifier and local location information. If this In the case where the data packet is hijacked by the hacker and the location domain identifier and local location information of the source host carried in the data packet are modified into the location domain identifier and local location information of another host, the destination host sends the data packet to another one. Host.
  • DDOS Distributed Denial of Service
  • Embodiments of the present invention provide a method and a host for implementing secure transmission of data packets under traffic engineering control in a multi-homed multi-address space network capable of avoiding DDOS attacks.
  • a method for implementing secure packet transmission in a multi-homed multi-address space network includes:
  • the source host sends the first data packet to the destination host, where the source host belongs to at least the first location domain and the second location domain, and the first data packet carries the active host identifier and a set of location domain identifiers and local parts of the source host.
  • Location information; the location domain identifier and the local location information of the source host correspond to a location domain in a location domain to which the source host belongs;
  • a location reset confirmation request information carries a location domain identifier and local location information of the source host acquired by the destination host from the received first data packet; the locally saved source
  • the host location domain identifier and the local location information are location domain identifiers and local location information of the source host acquired by the destination host when communicating with the source host for the previous time; when the source carried in the received location reset confirmation request information is confirmed
  • the location domain identifier and the local location information of the host are not the location domain identifier and the local location information of the source host carried by the first data packet, but are still a set of location domain identifiers and local location information corresponding to the source host.
  • the destination host may send a data packet to the source host according to the set of location domain identifiers and local location information of the source host, and the set of location domain identifiers and local location information of the source host is the reset source host location domain identifier and Local location information;
  • a method for implementing secure packet transmission in a multi-homed multi-address space network includes:
  • the destination host receives the first data packet sent by the source host, where the source host belongs to at least the first location domain and the second location domain;
  • the location reset confirmation request information carries the location domain identifier and the local location information of the source host obtained from the received first data packet;
  • the data packet is sent to the source host according to the location domain identifier and the local location information of the reset source host, and the data packet sent by the destination host to the source host carries the location domain identifier and the local location information of the reset source host.
  • a source host including:
  • a sending unit configured to send a first data packet to a destination host, where the source host belongs to at least a first location domain and a second location domain, where the first data packet carries an active host identifier and a set of location domains of the source host Identification and local location information; the location domain identifier and local location information correspond to a location domain in a location domain to which the source host belongs; a receiving unit, configured to receive a location domain identifier and local location information of the source host obtained by the destination host from the received first data packet, and a source host location domain identifier and local location information saved locally by the destination host And returning the confirmation request information, where the location reset confirmation request information carries the location domain identifier and the local location information of the source host acquired by the destination host from the received first data packet;
  • the source host location domain identifier and local location information saved locally are location domain identifiers and local location information of the source host acquired by the destination host when communicating with the source host.
  • the sending unit is further configured to: when confirming that the location domain identifier and the local location information of the source host carried in the received location reset confirmation request information are not the source host that is carried by the first data packet when being sent.
  • the location domain identifier and the local location information but still a set of location domain identifiers and local location information corresponding to the source host, the source host location domain identifier and the local location information have been reset to the destination host,
  • the reset information is used to indicate that the location domain identifier and the local location information of the source host carried in the received location reset confirmation request information are not the location domain identifier of the source host that is carried by the first data packet when being sent.
  • the destination host can send data packets to the source host according to the set of location domain identifiers and local location information of the source host, and the source host
  • a set of location domain identifiers and local location information is a reset source host location domain identifier and local location information
  • the receiving unit is further configured to receive a data packet sent by the destination host to the source host according to the reset source host location domain identifier and local location information.
  • a destination host including:
  • a receiving unit configured to receive a first data packet sent by the source host, where the source host belongs to at least a first location domain and a second location domain;
  • An obtaining unit configured to obtain, from the received first data packet, a source host identifier, a location domain identifier of the source host, and local location information; the location domain identifier and the local location information and a location domain to which the source host belongs Corresponding to a location field;
  • a sending unit configured to send a location reset when confirming that the location domain identifier and the local location information of the source host acquired from the first data packet are different from the source host location domain identifier and the local location information saved on the destination host Confirming the request information to the source host, and the location reset confirmation request information carries the a location domain identifier and local location information of the source host obtained from the received first data packet;
  • the receiving unit is further configured to receive a source host location domain that is sent by the source host in response to the location reset acknowledgement request information Information that the identification and local location information have been reset;
  • a confirmation unit configured to confirm, according to the reset information, that the location domain identifier and the local location information of the source host obtained from the received first data packet are the location domain identifier and the locality of the reset source host location information;
  • the sending unit is further configured to send a data packet to the source host according to the location domain identifier and the local location information of the reset source host, where the data packet sent by the destination host to the source host carries the location of the reset source host. Domain ID and local location information.
  • the embodiment of the present invention describes a method for implementing secure transmission of data packets under traffic engineering control in a multi-homed multi-address space network from the perspective of a source host and a destination host, and the destination host obtains the first data packet sent from the source host.
  • the location domain identifier and the local location information of the source host are different from the location domain identifier and the local location information of the source host saved in the previous communication
  • the location reset confirmation request information is actively sent, and the source sent by the source host is received.
  • the data packet will be sent to the source host to continue the previous communication.
  • the method for implementing secure transmission of data packets under traffic engineering control in the multi-homed multi-address space network can effectively prevent the first data packet from being hijacked by the hacker and then in the first data packet.
  • the carried location domain identifier and local location information are modified to the location domain identifier and local location information of other hosts, and then sent to the destination host, so that the destination host sends the data packet to other hosts.
  • DDOS attacks If the hacker hijacks the first data packet sent by the multiple source hosts to the destination host, and modifies the location domain identifier and the local location information in the first data packet to the location domain identifier and the local location information of the same host, Multiple destination hosts send data packets to this host, causing the host's bandwidth and computing resources to be consumed, which is commonly referred to as DDOS attacks.
  • FIG. 1 is a schematic diagram of a first embodiment of a method for implementing secure transmission of data packets in an embodiment of the present invention
  • FIG. 2 is a schematic diagram of a second embodiment of a method for implementing secure transmission of data packets in an embodiment of the present invention
  • FIG. 4 is a schematic diagram of an embodiment of a source host and a destination host in an embodiment of the present invention.
  • Embodiments of the present invention provide a method for implementing secure transmission of data packets under traffic engineering control in a multi-homed multi-address space network, which can effectively avoid DDOS attacks.
  • the embodiments of the present invention also provide corresponding source hosts and destination hosts. The details are described below separately.
  • a first embodiment of a method for implementing secure transmission of a data packet in an embodiment of the present invention includes:
  • the source host sends the first data packet to the destination host, where the first data packet sent by the source host to the destination host carries the active host identifier and the location domain identifier and local location information of the source host.
  • the source host ID is unique, and the source host's location domain identifier and local location information correspond.
  • the source host belongs to the first location domain and the second location domain.
  • the source host may also belong to more than two location domains at the same time, the location domain identifier of the source host, and the local location information and the location of the location.
  • the domain is corresponding.
  • the location domain identifier and the local location information of the source host are two groups, respectively:
  • the location domain identifier and the local location information of the source host are the identifier of the first location domain and the location information of the source host in the first location domain;
  • the location domain identifier and local location information of the source host are the identity of the second location domain and the location information of the source host in the second location domain.
  • the location domain identifier and the local location information of the source host carried in the first data packet may be used by the source host when communicating with the destination host. Group location domain ID and local location information.
  • 102 Receive a location reset acknowledgement request message returned by the destination host, where the location reset acknowledgement request information carries a location domain identifier and local location information of the source host obtained by the destination host from the received first data packet.
  • the location reset confirmation request information is used to discover, at the destination host, the location domain identifier and the local location information of the source host acquired from the received first data packet, and the locally saved source host location domain identifier and local location information.
  • the request source host confirms whether the location domain identifier and the local location information of the source host obtained from the received first data packet are the location domain identifier and local location information owned by the source host, and the source host is requested.
  • the location domain identifier and the local location information of the source host are the location domain identifier and the local location information of the source host carried by the first data packet; wherein the locally saved source host location domain identifier and the local The location information is a location domain identifier and local location information of the source host acquired by the destination host when communicating with the source host.
  • the first data packet sent by the source host to the destination host passes through the intermediate device, the first data packet is likely to be based on the preset traffic engineering policy by the intermediate device.
  • the location domain identifier and the local location information of the source host carried by the source host when the first data packet is sent are the identifier of the first location domain and the location information of the source host in the first location domain
  • the location domain identifier and the local location information of the source host are the location information of the second location domain and the location information of the source host in the second location domain
  • the local location information is the identifier of the second location domain and the location information of the source host in the second location domain
  • the location domain identifier and the local location information of the reset source host are the identifier of the first location domain and the source host is in the first Location information in a location domain.
  • the location domain identifier and the local location information of the source host carried in the received location reset confirmation request information are a set of location domain identifiers and local location information corresponding to the source host, and determine that the received The location domain identifier and the local location information of the source host carried in the location reset confirmation request information are the location domain identifier and the local location information of the source host carried by the first data packet.
  • the source host location domain identifier and the local location information of the source host carried in the received location reset acknowledgement request information are not the location domain identifier and part of the source host carried by the first data packet when transmitting Location information, but still a set of location domain identifiers and local location information corresponding to the source host, the source host location domain identifier and the local location information have been reset to the destination host; the reset information is used to indicate The location domain identifier and the local location information of the source host carried in the received location reset confirmation request information are not the location domain identifier and the local location information of the source host carried by the first data packet, but still It is a set of location domain identifiers and local location information of the source host.
  • the destination host can send data packets to the source host according to the set of location domain identifiers and local location information of the source host; the set of location domain identifiers and local parts of the source host Location information is reset Source host location domain ID and local location information.
  • a method for implementing secure transmission of data packets under traffic engineering control in a multi-homed multi-address space network is described from the perspective of a source host.
  • the location is The location domain identifier and the local location information of the source host carried in the reset confirmation request information are determined. If it is determined that the location domain identifier and the local location information of the source host have been reset, the reset information is sent to the destination host to prompt
  • the destination host may send a data packet to the source host, and then the source host receives the data packet sent by the destination host to the source host according to the reset source host location domain identifier and local location information.
  • the method for implementing secure transmission of data packets under traffic engineering control in the multi-homed multi-address space network can effectively prevent the first data packet from being carried in the first data packet after being hijacked by the hacker.
  • the location domain identifier and the local location information are modified to the location domain identifier and the local location information of other hosts, and then sent to the destination host, so that the destination host sends the data packet to other hosts.
  • DDOS attacks If the hacker hijacks the first data packet sent by multiple source hosts to its destination host, and modifies the location domain identifier and local location information in the first data packet to the location domain identifier and local location information of the same host, Causes multiple destination hosts to send data packets to this host, causing the host's bandwidth and computing resources to be consumed, which is commonly referred to as DDOS attacks.
  • the determining step 103 in the foregoing embodiment may be omitted, and the received location reset is directly confirmed.
  • the location domain identifier and the local location information of the source host carried in the confirmation request information are not the location domain identifier and the local location information of the source host carried by the first data packet, but are still a group of locations corresponding to the source host. For the domain identifier and local location information, the source host location domain identifier and the local location information have been reset to the destination host.
  • the source host identifier is unique.
  • the source host's location domain identifier and the local location information are corresponding.
  • the source host belongs to the first location domain and the second location domain. In fact, the source host may also belong to the same.
  • the location domain identifier and the local location information of the source host correspond to the home location domain.
  • the location domain identifier and the local location information of the source host are two groups, respectively:
  • the location domain identifier and the local location information of the source host are the identifier of the first location domain and the location information of the source host in the first location domain;
  • the location domain identifier and local location information of the source host are the identity of the second location domain and the location information of the source host in the second location domain.
  • step 204 Determine whether the location domain identifier and the local location information of the source host obtained from the first data packet are the same as the source host location domain identifier and the local location information saved on the destination host, where the target host is configured.
  • the saved source host location domain identifier and the local location information are the location domain identifiers and local location information of the source host that are acquired by the destination host when the host host communicates with the source host. If not, step 204 is performed.
  • the method of the embodiment of the present invention may further include: querying, according to the source host identifier obtained from the received first data packet, a source host saved on the destination host. Correspond to the source host location domain identifier and local location information.
  • the location reset confirmation request information carries the location domain identifier and the local location information of the source host obtained from the received first data packet.
  • the location reset confirmation request information is used to request the source host to confirm whether the location domain identifier and the local location information of the source host obtained from the received first data packet are a set of location domain identifiers and local locations owned by the source host. Information, and the request source host confirms whether the location domain identifier and the local location information of the source host acquired from the received first data packet are the location domain of the source host carried by the first data packet when being sent. Identification and local location information.
  • the first data packet sent by the source host to the destination host passes through the intermediate device, the first data packet is likely to be based on the preset traffic engineering policy by the intermediate device.
  • the location domain identifier and the local location information of the source host carried by the source host when the first data packet is sent are the identifier of the first location domain and the location information of the source host in the first location domain
  • the reset source host The location domain identifier and the local location information are the identifier of the second location domain and the location information of the source host in the second location domain; if the source host sends the first data packet, the location domain identifier and the local location information of the source host are The identifier of the second location domain and the location information of the source host in the second location domain, and the location domain identifier and the local location information of the reset source host are the identifier of the first location domain and the source host in the first location domain location information.
  • the reset information is used to indicate that the location domain identifier and the local location information of the source host carried in the received location reset acknowledgement request information are not the location domain of the source host carried by the first data packet when being sent. Identification and local location information, but still a set of location domain identifiers and local location information of the source host.
  • the destination host can send data packets to the source host according to the set of location domain identifiers and local location information of the source host; the source host The set of location domain identifiers and local location information is the reset source host location domain identifier and local location information.
  • a method for implementing secure transmission of data packets under traffic engineering control in a multi-homed multi-address space network is described in the perspective of a destination host. After receiving the first data packet sent by the source host, the destination host finds the first The location domain identifier and local location information of the source host carried in the data packet are different from the location domain identifier and local location information of the source host acquired in the previous communication, and the location reset confirmation request information is actively sent to the source host, and is received.
  • the method for implementing secure transmission of data packets under traffic engineering control in the multi-homed multi-address space network can effectively prevent the first data packet from being carried in the first data packet after being hijacked by the hacker.
  • the location domain identifier and the local location information are modified to the location domain identifier and the local location information of other hosts, and then sent to the destination host, so that the destination host sends the data packet to other hosts. If the hacker hijacks the first data packet sent by multiple source hosts to its destination host, and modifies the location domain identifier and local location information in the first data packet to the location domain identifier and local location information of the same host, Causes multiple destination hosts to send data packets to this host, causing the host's bandwidth and computing resources to be consumed, which is commonly referred to as DDOS attacks.
  • the determining step 203 in the foregoing embodiment may also be omitted, directly confirming from the first data packet.
  • the location reset confirmation request information is sent to the source host.
  • the source host 301 is dual-homed to the fourth version of the Internet Protocol address space 304 and the sixth version of the Internet Protocol address space 305 through the edge router 303 of the user network 302.
  • the fourth version of the internet protocol address space 304 is connected to the sixth version of the internet protocol address space 308 by the border router 306, and the sixth version of the internet protocol address space 305 is connected to the sixth version of the internet protocol address space 308 by the border router 307.
  • the destination host 311 is home to the sixth version of the internet protocol address space 308 via the user network 310.
  • the location domain identifier and the local location information of the source host 301 in the fourth version of the Internet Protocol address space 304 are the location domain identifier of the fourth version of the Internet Protocol address space 304 and the source host 301 in the fourth version of the Internet Protocol address space 304, respectively.
  • the location information is represented by LD ID1 and locatorl respectively;
  • the location domain identifier and the local location information of the source host 301 in the sixth version Internet Protocol address space 305 are the location domain identifier of the sixth version Internet Protocol address space 305 and the source host 301, respectively.
  • the location information in the sixth version of the Internet Protocol Address Space 305 is represented by LD ID2 and locator2, respectively.
  • the location domain identifier and the local location information of the destination host 311 are the location domain identifier of the sixth version Internet Protocol address space 308 and the location information of the destination host 311 in the sixth version Internet Protocol address space 308, respectively, and are represented by LD ID3 and locator3, respectively.
  • the process in which the source host 301 transmits the first data packet to the destination host 311 is as follows:
  • the source host 301 communicates with the destination host 311, the source host 301 uses LD ID1 and locator1, and the source host 301 sends the first data packet to the destination host 311.
  • the first data packet carries the host ID, LD ID1, locatorl, LD3 and locator3.
  • the source host 301 transmits the first data packet to the edge router 303 through the user network 302, and the edge router 303 checks whether the host ID carried in the first data packet, LD ID1 and locatorl comply with the traffic engineering, if the fourth version of the Internet Protocol address space at the moment The network line where the 304 is located is busy, and the network line where the sixth version of the Internet Protocol address space 305 is located is idle, then the location domain identifier and the local location information carried in the first data packet do not conform to the traffic engineering, and the edge router 303 will source the host 301.
  • the location domain identifier and the local location information of the source host carried by the first data packet sent to the destination host 311 are reset, and the reset location domain identifier and local location information are LD ID2 and locator2, that is, the location in the first data packet.
  • the sixth version of the Internet Protocol address space 305 is selected for transmission.
  • the first data packet carries the host ID, LD ID2, locator2, LD3 and locator3 after resetting, and is transmitted to the border router 307 via the sixth version of the Internet Protocol address space 305, and the border router 307 is based on the destination host in the first data packet.
  • the location domain identifier LD3 transmits the first data packet to the sixth version of the Internet Protocol address space 308, and the edge router 309 finds the location of the destination host 311 according to the location information locator3 of the destination host carried in the first data packet, and the first data is obtained.
  • the packet is sent to the destination host 311.
  • the destination host 311 After receiving the first data packet, the destination host 311 finds the correspondence between the host ID and the LD ID 1 and locator1 saved in the previous communication with the source host 301 according to the host ID carried in the first data packet, and determines the first data. Whether LD ID2 and locator2 carried in the packet are the same as LD ID1 and locator1 saved in the previous communication. After the judgment is found to be different, the destination host 311 sends a location reset confirmation request message to the source host 301, and the location reset confirmation request information carries the LD ID2 and the locator2.
  • the source host 301 After receiving the location reset confirmation request information sent by the destination host 311, the source host 301 carries the two sets of location identifiers of the LD ID2 and the locator2 and the source host 301 in the location reset confirmation request information. Comparing with the local location information, that is, comparing with LD ID 1 and locator 1, LD ID2 and locator2, and determining that LD ID2 and locator2 carried in the location reset confirmation request information are a set of location domains of the source host 301. Identification and local location information, and not the LD ID1 and locator1 carried when the first data packet is sent, the location domain identifier and the local location information have been reset, the transmission location domain identifier and the local location information have been reset to the destination Host 311.
  • the destination host 311 After receiving the information of the location domain identifier and the local location information sent by the source host 301, the destination host 311 sends the data packet to the source host 301 using LD ID2 and locator2.
  • the source host 301 After receiving the data packet sent by the destination host 311, the source host 301 sends the data packet to the destination host.
  • the location domain identifier and the local location information carried in the first data packet sent by the source host are reset by the edge router under the control of the traffic engineering and then transmitted to the destination host, and the destination host sends the location reset confirmation request information to the source host actively.
  • the data packet is sent to the source host after receiving the information that the location domain identifier and local location information sent by the source host have been reset.
  • the location domain identifier and the local location information are modified to the location domain identifier and the local location information of other hosts, and then sent to the destination host, so that the destination host sends the first data packet to other hosts. If the hacker hijacks the first data packet sent by multiple source hosts to its destination host, and modifies the location domain identifier and local location information in the first data packet to the location domain identifier and local location information of the same host, Causes multiple destination hosts to send data packets to this host, causing the host's bandwidth and computing resources to be consumed, which is commonly referred to as DDOS attacks.
  • the source host 40 in the embodiment of the present invention includes:
  • the sending unit 401 is configured to send the first data packet to the destination host, where the source host belongs to at least the first location domain and the second location domain, where the first data packet carries the active host identifier and a set of locations of the source host a domain identifier and local location information; the location domain identifier and local location information correspond to a location domain in a location domain to which the source host belongs;
  • the receiving unit 402 is configured to receive, by the destination host, the identifier that is obtained from the received first data packet.
  • Location reset identification request information returned when the location domain identifier and local location information of the source host are different from the source host location domain identifier and local location information saved locally by the destination host, and the location reset confirmation request information carries The location host identifier and the local location information of the source host obtained by the destination host from the received first data packet; the location reset confirmation request information is used to discover the first data packet received from the destination host.
  • the request source host confirms the source host obtained from the received first data packet.
  • the location domain identifier and the local location information are location domain identifiers and local location information owned by the source host, and requesting the source host to confirm the location domain identifier and the local location of the source host obtained from the received first data packet Whether the information is a location domain identifier and local location information of the source host carried by the first data packet when being sent;
  • the determining unit 403 is configured to determine whether the location domain identifier and the local location information of the source host carried in the received location reset confirmation request information are a set of location domain identifiers and local location information corresponding to the source host, and determine Whether the location domain identifier and the local location information of the source host carried in the received location reset confirmation request information are location domain identifiers and local location information of the source host carried by the first data packet;
  • the sending unit 401 is further configured to: when the determining unit determines that the location domain identifier and the local location information of the source host carried in the received location reset confirmation request information are not the first data packet being sent Information about the location domain identifier and local location information of the source host, but still a set of location domain identifiers and local location information corresponding to the source host, the source host location domain identifier and the local location information have been reset to the a destination host, where the reset information is used to indicate that the location domain identifier and the local location information of the source host carried in the received location reset acknowledgement request information are not carried by the first data packet when being sent The location domain identifier and local location information of the source host, but still a set of location domain identifiers and local location information corresponding to the source host.
  • the destination host can send data to the source host according to the set of location domain identifiers and local location information of the source host.
  • the set of location domain identifiers and local location information of the source host is the reset source host location domain identifier and local location information;
  • Said reception unit 402, according to destination host is further configured to receive bits of the source host reset The domain ID and local location information are sent to the source host.
  • the location domain identifier and the local location information of the source host are at least two groups, respectively: the location domain identifier and the local location information of the source host are the identifier of the first location domain and the source host is in the first location domain. Location information; and,
  • the location domain identifier and local location information of the source host are the identity of the second location domain and the location information of the source host in the second location domain.
  • the location domain identifier and the local location information of the source host carried in the first data packet may be used when the source host communicates with the destination host for the previous time.
  • a set of location domain identifiers and local location information may be used when the source host communicates with the destination host for the previous time.
  • the location reset confirmation request information is used to discover, at the destination host, the location domain identifier and the local location information of the source host acquired from the received first data packet, and the locally saved source host location domain identifier and local location information.
  • the request source host confirms whether the location domain identifier and the local location information of the source host obtained from the received first data packet are the location domain identifier and local location information owned by the source host, and the source host is requested.
  • the locally saved source host location domain identifier and local location information are location domain identifiers and local location information of the source host acquired by the destination host when communicating with the source host.
  • the first data packet sent by the source host to the destination host passes through the intermediate device, the first data packet is likely to be based on the preset traffic engineering policy by the intermediate device. And resetting the location domain identifier and the local location information of the source host carried in the first data packet sent by the source host according to the preset traffic engineering policy.
  • the location domain identifier and the local location information of the source host carried by the source host when the first data packet is sent are the identifier of the first location domain and the location information of the source host in the first location domain
  • the location domain identifier and the local location information of the source host are the location information of the second location domain and the location information of the source host in the second location domain
  • the local location information is the identifier of the second location domain and the location information of the source host in the second location domain
  • the location domain identifier and the local location information of the reset source host are the identifier of the first location domain and the source host is in the first Location information in a location domain.
  • the determining unit 403 may be omitted in the source host provided by the embodiment of the present invention.
  • the sending unit 401 is further configured to: confirm the source host carried in the received location reset confirmation request information.
  • the location domain identifier and the local location information are not the location domain identifier and the local location information of the source host carried by the first data packet, but are still a set of location domain identifiers and local location information corresponding to the source host.
  • the source host location domain identifier and the local location information have been reset to the destination host.
  • the destination host 50 in this embodiment includes:
  • the receiving unit 501 is configured to receive a first data packet sent by the source host, where the source host belongs to at least the first location domain and the second location domain.
  • the obtaining unit 502 is configured to obtain, from the received first data packet, a source host identifier, a location domain identifier of the source host, and local location information; the location domain identifier and the local location information and a location domain to which the source host belongs Corresponding to a location field in ;
  • the determining unit 503 is configured to determine whether the location domain identifier and the local location information of the source host obtained from the first data packet are the same as the source host location domain identifier and the local location information saved on the destination host, where The source host location domain identifier and the local location information saved on the destination host are location domain identifiers and local location information of the source host acquired by the destination host when communicating with the source host.
  • the sending unit 504 is configured to: when the determining unit determines that the location domain identifier and the local location information of the source host acquired from the first data packet are different from the source host location domain identifier and the local location information saved on the destination host, Sending a location reset confirmation request message to the source host, where the location reset confirmation request information carries the location domain identifier and the local location information of the source host obtained from the received first data packet; the location reset confirmation request The information is used to request the source host to confirm whether the location domain identifier and the local location information of the source host obtained from the received first data packet are a set of location domain identifiers and local location information owned by the source host, and request The source host confirms whether the location domain identifier and the local location information of the source host obtained from the received first data packet are the location domain identifier and the local location information of the source host carried by the first data packet when being sent. ;
  • the receiving unit 501 is further configured to receive information that the source host location domain identifier and the local location information that are sent by the source host in response to the location reset acknowledgement request information are reset; the reset The information indicating that the location domain identifier and the local location information of the source host carried in the received location reset acknowledgement request information are not the location domain identifier and the local location of the source host carried by the first data packet when being sent Information, but still a set of location domain identifiers and local location information of the source host.
  • the destination host can send data packets to the source host according to the set of location domain identifiers and local location information of the source host; this set of locations of the source host
  • the domain identifier and local location information are the reset source host location domain identifier and local location information.
  • the confirming unit 505 is configured to confirm, according to the reset information, that the location domain identifier and the local location information of the source host acquired from the received first data packet are the location domain identifier of the reset source host and Local location information;
  • the sending unit 504 is further configured to send a data packet to the source host according to the location domain identifier and the local location information of the reset source host, where the data packet sent by the destination host to the source host carries the reset source host. Location domain ID and local location information.
  • the destination host 50 of the embodiment of the present invention further includes:
  • the querying unit 506 is configured to query, according to the source host identifier obtained from the received first data packet, a correspondence between a source host identifier saved on the destination host and a source host location domain identifier and local location information.
  • the determining unit 503 may be omitted from the source host provided by the embodiment of the present invention.
  • the sending unit 504 is further configured to: confirm the location domain identifier of the source host obtained from the first data packet. And sending the location reset confirmation request information to the source host when the local location information is different from the source host location domain identifier and the local location information saved on the destination host.
  • the source host 40 and the destination host 50 in this embodiment send the first data packet to the receiving unit 501 of the destination host 50 in the sending unit 401, and the obtaining unit 502 obtains the source host identifier from the received first data packet.
  • the determining unit 503 determines whether the location domain identifier and the local location information of the source host carried by the first data packet and the location domain identifier and the local location information of the source host saved in the previous communication are Similarly, if not, the sending unit 504 sends a location reset confirmation request message, and after receiving the location reset confirmation request information, the receiving unit 402 of the source host 40 determines the location of the source host carried by the location reset confirmation request information.
  • the domain identifier and the local location information are determined, for example, the location domain identifier of the source host carried in the location reset confirmation request information is determined.
  • the local location information is all the location domain identifiers and local location information of the source host 40, but is not the location domain identifier and the local location information carried by the source host when the first data packet is sent, and the sending unit 401 issues the location domain identifier and the local source host.
  • the location information has been reset to the destination host 50. After the receiving unit 501 of the destination host 50 receives the reset information, the confirmation unit 505 confirms the received first data packet according to the reset information.
  • the sending unit 503 sends a data packet, and the data packet sent by the destination host 50 to the source host 40 carries
  • the receiving unit 402 received by the source host 40 receives the data packet sent by the destination host 50, and the sending unit 401 of the source host 40 sends the data packet to the destination host 50.
  • the source host 40 and the destination host 50 provided by the embodiments of the present invention can effectively avoid DDOS attacks.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

La présente invention concerne, dans des modes de réalisation, un procédé destiné à mettre en place une transmission sécurisée de paquets de données dans un réseau à espace multi-adresses et multi-ralliement. Le procédé comprend : quand un identifiant de domaine d'emplacement et des informations d'emplacement locales d'un hôte source transportés dans un premier paquet de données qui est transmis depuis l'hôte source et reçu par un hôte de destination sont différents de l'identifiant de domaine d'emplacement et des informations d'emplacement locales de l'hôte source stockés dans une communication précédente, l'hôte de destination transmet activement les informations de demande de confirmation de remise à zéro de l'emplacement ; après réception des informations par l'hôte source que l'identifiant de domaine d'emplacement et que les informations d'emplacement locales de l'hôte source ont été remises à zéro, l'hôte de destination transmet les paquets de données vers l'hôte source conformément à l'identifiant de domaine d'emplacement et aux informations d'emplacement locales remis à zéro de l'hôte source. Un hôte source et un hôte de destination correspondants sont également prévus par les modes de réalisation de la présente invention. Puisqu'un mécanisme de transmission sécurisée de paquets de données est établi entre l'hôte de destination et l'hôte source, avec les solutions techniques de la présente invention, les attaques de déni de service distribué (DDOS) sur d'autres hôtes dans le réseau peuvent être évitées, les attaques étant causées par modification de l'identifiant du domaine d'emplacement et des informations d'emplacement locales transportées dans les paquets de données par les pirates.
PCT/CN2011/073638 2011-05-04 2011-05-04 Procédé et hôte destinés à mettre en place une transmission sécurisée de paquets de données dans un réseau à espace multi-adresses et multi-ralliement WO2011120454A2 (fr)

Priority Applications (2)

Application Number Priority Date Filing Date Title
PCT/CN2011/073638 WO2011120454A2 (fr) 2011-05-04 2011-05-04 Procédé et hôte destinés à mettre en place une transmission sécurisée de paquets de données dans un réseau à espace multi-adresses et multi-ralliement
CN201180000592.1A CN102204221B (zh) 2011-05-04 2011-05-04 多归属多地址空间网络中实现数据包安全传送的方法及主机

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2011/073638 WO2011120454A2 (fr) 2011-05-04 2011-05-04 Procédé et hôte destinés à mettre en place une transmission sécurisée de paquets de données dans un réseau à espace multi-adresses et multi-ralliement

Publications (2)

Publication Number Publication Date
WO2011120454A2 true WO2011120454A2 (fr) 2011-10-06
WO2011120454A3 WO2011120454A3 (fr) 2012-04-05

Family

ID=44662823

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2011/073638 WO2011120454A2 (fr) 2011-05-04 2011-05-04 Procédé et hôte destinés à mettre en place une transmission sécurisée de paquets de données dans un réseau à espace multi-adresses et multi-ralliement

Country Status (2)

Country Link
CN (1) CN102204221B (fr)
WO (1) WO2011120454A2 (fr)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US9953529B2 (en) * 2015-07-20 2018-04-24 GM Global Technology Operations LLC Direct vehicle to vehicle communications

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20070211638A1 (en) * 2006-03-04 2007-09-13 Lee Sung-Hyuck System and method for reserving resources in a mobile network environment using multiple interfaces
CN101547428A (zh) * 2009-04-27 2009-09-30 华为技术有限公司 业务处理方法和业务处理装置
CN101552714A (zh) * 2008-03-31 2009-10-07 华为技术有限公司 一种多归属多地址空间网络中实现流量工程的方法和设备
CN101753419A (zh) * 2008-12-08 2010-06-23 华为技术有限公司 发送数据、转发数据的方法、设备和多地址空间移动网络

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20070211638A1 (en) * 2006-03-04 2007-09-13 Lee Sung-Hyuck System and method for reserving resources in a mobile network environment using multiple interfaces
CN101552714A (zh) * 2008-03-31 2009-10-07 华为技术有限公司 一种多归属多地址空间网络中实现流量工程的方法和设备
CN101753419A (zh) * 2008-12-08 2010-06-23 华为技术有限公司 发送数据、转发数据的方法、设备和多地址空间移动网络
CN101547428A (zh) * 2009-04-27 2009-09-30 华为技术有限公司 业务处理方法和业务处理装置

Also Published As

Publication number Publication date
WO2011120454A3 (fr) 2012-04-05
CN102204221A (zh) 2011-09-28
CN102204221B (zh) 2013-04-24

Similar Documents

Publication Publication Date Title
CN102571587B (zh) 报文转发方法和设备
JP4975190B2 (ja) IPv6ネットワーク内のホストの探索方法
EP2426885B1 (fr) Procédé, dispositif et système de communication en réseau privé virtuel mobile
US20080080513A1 (en) Anycast routing method and apparatus for supporting service flow in internet system
WO2011041967A1 (fr) Procédé de communication anonyme, procédé d'enregistrement, procédé et système d'envoi et de réception d'informations
JP3813571B2 (ja) 境界ルータ装置、通信システム、ルーティング方法、及びルーティングプログラム
JP5147995B2 (ja) ホスト・アイデンティティ・プロトコル・サーバ・アドレス構成
JP2006086800A (ja) ソースアドレスを選択する通信装置
JP2019515555A (ja) 識別情報指向型ネットワークの匿名識別情報及びプロトコル
WO2008151557A1 (fr) Procédé, équipement et système ip mobile de serveur mandataire pour déclencher une optimisation de route
WO2011131097A1 (fr) Procédé de traitement de message de données, système et nœud de service d'accès
WO2013004134A1 (fr) Procédé de routage, nœud et système pour un réseau point à point
WO2014000226A1 (fr) Procédé, dispositif et système de commande de trajet dans un réseau
WO2014173235A1 (fr) Procédé, commande et système de génération d'itinéraires de transmission
WO2009121265A1 (fr) Procédé et équipement pour mettre en œuvre une ingénierie de trafic dans un réseau à hébergement multiple et à espace adresse multiple
WO2013023465A1 (fr) Procédé d'interconnexion et d'intercommunication entre un réseau à séparation d'adresse url et d'identifiant et un réseau classique, et ilr et asr associés
WO2011072549A1 (fr) Procédé, appareil et système permettant une communication entre des sites qui ne sont pas sous protocole à séparation entre localisateur et identifiant (non-lisp) et des sites lisp
WO2011120454A2 (fr) Procédé et hôte destinés à mettre en place une transmission sécurisée de paquets de données dans un réseau à espace multi-adresses et multi-ralliement
US9025606B2 (en) Method and network node for use in link level communication in a data communications network
US20110235588A1 (en) Method, device, and multi-address space mobile network for sending data and forwarding data
WO2012075768A1 (fr) Procédé et système de contrôle de réseau de séparation de localisateur/identifiant
WO2015039563A1 (fr) Procédé et dispositif de mise en œuvre d'un réseau privé virtuel de couche 3
JP4357310B2 (ja) 複数のネットワークに同時接続する通信方法および通信装置
WO2009033398A1 (fr) Système de réseau mobile à espace d'adresses multiples, routeur et procédé de transmission de données
CN102638390A (zh) 基于dhcp snooping的三层交换装置及方法

Legal Events

Date Code Title Description
WWE Wipo information: entry into national phase

Ref document number: 201180000592.1

Country of ref document: CN

121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 11762028

Country of ref document: EP

Kind code of ref document: A2

NENP Non-entry into the national phase in:

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 11762028

Country of ref document: EP

Kind code of ref document: A2