Digital security intelligent terminal for water management
By building a Linux-based KVM virtualization platform and a converged communication network architecture, the network vulnerability of the water management system was solved, achieving stable and secure operation, isolation and collaboration between business processes, and simplifying management procedures.
Patent Information
- Application Number
- CN202310041058.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-01-12
- Publication Date
- 2025-11-28
- Estimated Expiration
- 2043-01-12
AI Technical Summary
Existing water management systems suffer from problems such as complex management platforms, large workload, heavy reliance on external network resources, and insufficient network security when facing cyberattacks.
It adopts a Linux-based KVM virtualization underlying platform, combined with a converged communication network architecture, a next-generation software network firewall/log auditing system, a data interconnection front-end system, and data edge computing nodes to build a fully virtualized architecture, achieving secure communication, isolation, and scalability capabilities.
It improved the network security and collaboration of the water management system, enabled secure and reliable communication between business operations, reduced management complexity and resource dependence, and enhanced the system's stability and scalability.
Smart Images

Figure CN116094805B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of security management, in particular to a water management digital security intelligent terminal. BACKGROUND
[0002] In recent years, the industrial control system of urban key information infrastructure (water, water conservancy, gas, etc.) has been attacked by hacker systems. Network attack events targeting core infrastructure have increased, serving as a stern warning of the possibility of network attacks, their enormous destructive power, and the vulnerability of infrastructure. After a series of reinforcement and security operation of the water management business system, the stability and redundancy of the system have been guaranteed to some extent, but there are still problems such as complex management platform, large amount of work input, and large dependence on external resources in network operation. In order to better solve the stable and safe operation demand of the terminal business, a water management digital security intelligent terminal is designed. SUMMARY
[0003] The present application is to overcome the above-mentioned deficiencies in the prior art, and provides a water management digital security intelligent terminal capable of stable and safe operation.
[0004] In order to achieve the above-mentioned purpose, the following technical solutions are adopted in the present application:
[0005] A water management digital security intelligent terminal, based on a KVM virtualization bottom layer platform, performs virtualization deployment on a communication network architecture, a next-generation software network firewall / log audit system, a data interconnection front-end system, and a data edge computing node, and builds an intensive and fractal full virtualization architecture containing a VServer virtual host, a Vsan virtual storage, a Vnet virtual network, a Vsafe virtual secure interconnection, a Vservice virtual service, and a Vmanage unified virtual management.
[0006] The current water data transmission system has completed a standardized system and a unified backup architecture based on virtualization. Under the premise that the next-generation firewall and log audit both support software deployment based on X86, the transmission system can be safely expanded based on node virtualization, with security throughout the system, improving the collaboration within the system and strengthening the linkage between security services and operation and maintenance personnel within the system. The water management digital security intelligent terminal of the present application, as a hardware container in the transmission system, realizes edge computing node end-to-end secure communication, reasonable isolation, function replication, increased capacity, and extended range through the design of the above-mentioned architecture, and uses a unified cloud management platform (water digital security intelligent platform) to complete the overall registration, configuration management, operation and maintenance, upgrade, and control of the system.
[0007] As preferred, the KVM virtualization bottom layer refers to completing the virtualization of CPU and memory through KVM.ko and KVM_intel related to computing resources, completing the memory allocation and management required by the system, and reserving interfaces for subsequent access to the cloud management platform by interacting with the KVM kernel through the IOCTL system call.
[0008] As preferred, the KVM virtualization bottom layer platform is built by installing the basic components of KVM to realize the establishment of the subsequent network, storage, and virtual machine, wherein the distributed storage is used on the storage to complete block storage, file storage, and object storage; the full-flash block storage is used for block storage, 2-copy or 3-copy virtual disks are created, and manual and timed backups of the intelligent terminal service provided by the bottom layer platform are completed to back up multiple hard disks.
[0009] As preferred, a hard disk has multiple backup chains, each backup chain includes one full backup node and multiple incremental backup nodes; two nodes are high-availability to each other, the data between the nodes are synchronized, and when initiating a backup, any node is randomly selected as the master node of the backup task to play a role in load balancing.
[0010] As preferred, the converged communication network architecture refers to a basic network structure with multi-link bandwidth aggregation and network logical isolation capability based on services, which aggregates multiple types of links of multiple operators to form a total channel, and can independently divide different services on demand to form different secondary channels, thereby achieving network layer isolation between services.
[0011] As preferred, the implementation of the converged communication network architecture is divided into two layers, the first layer is the user internal network, and the second layer is the cross-user and cross-site network interconnection; specifically, deploying NGFW in the virtualization environment of the virtualization bottom layer platform is used as a multi-tunnel slicing isolation between the upper service system; for terminal users, different services are distinguished by using different physical ports to complete the isolation between different services, and more detailed security domain access control strategies are used to provide access control between services to complete the deployment of security and reliability.
[0012] As preferred, the data interconnection front-end system refers to integrating basic communication connection services, completing the security management of different services through physically isolated ports, and separating data interconnection and data processing, designing data edge computing nodes, integrating basic data processing tools, and completing the basic processing of interconnected data, including storage, retrieval, processing, and transformation, to finally provide guarantee work for the transmission of the whole data.
[0013] The beneficial effects of the present application are: realizing the edge computing node end-to-end secure communication, reasonable isolation, function replication, increasing capacity, extending range; achieving network layer isolation between services, while improving the security of the network in the basic communication layer and the data application layer; completing the communication demand of service large architecture isolation and small part intercommunication. BRIEF DESCRIPTION OF DRAWINGS
[0014] Figure 1 is a terminal architecture diagram of the present application;
[0015] Figure 2 is a schematic diagram of the fusion communication network architecture in the present application. DETAILED DESCRIPTION
[0016] The present application will be further described below in combination with the drawings and specific embodiments.
[0017] As Figure 1 described in the embodiments, a water management digital security intelligent terminal is provided, which is based on a KVM virtualization underlying platform, and the fusion communication network architecture, next-generation software network firewall / log audit system, data interconnection front-end system, data edge computing node and other security services and applications are deployed in a virtualized manner to build an intensive and fractal full virtualization architecture including VServer virtual host, Vsan virtual storage, Vnet virtual network, Vsafe virtual secure interconnection, Vservice virtual service and Vmanage unified virtual management (SAAS, IAAS, PASS and HAAS deployment are supported).
[0018] KVM is the basic underlying architecture technology support of the terminal, and is also the most mainstream open source server virtualization technology at present. The KVM virtualization underlying layer completes the virtualization of CPU and memory through KVM.ko and KVM_intel related to the company's self-developed computing resources, completes the memory allocation and management required by the system, and interacts with the KVM kernel through the IOCTL system call to reserve interfaces for subsequent access to the cloud management and control platform.
[0019] The KVM virtualization underlying platform is built by installing the basic components of KVM to implement the establishment of the subsequent network, storage, virtual machine, etc., wherein the distributed storage is used on the storage to complete the block storage, file storage, and object storage; the full-flash block storage is used for the block storage, according to the security requirements, 2 copies or 3 copies of virtual disks are created, and manual and timing backups of the intelligent terminal service provided by the underlying platform are completed to achieve the backup of multiple hard disks (including system disk and data disk). One hard disk has multiple backup chains, each backup chain includes one full backup node and multiple incremental backup nodes; the two nodes are high-availability to each other, the data between the nodes are synchronized, and when initiating backup, any node is randomly selected as the master node of the backup task. At the same time, through the cloud management platform, the business is migrated between two Zones or relies on asynchronous replication of storage to establish the same resources in the remote end.
[0020] The converged communication network architecture is the basic network architecture of the terminal, mainly using the SDWAN application definition network technology, that is, the basic network structure with the ability of multi-link bandwidth convergence and network logical isolation based on business, which can converge multiple types of links of different operators to form a total channel, and can divide different services on this basis to form independent secondary channels according to specific application requirements, so as to achieve network layer isolation between services and improve the security of the network in the basic communication layer and the data application layer.
[0021] As shown in Figure 2 The implementation of the converged communication network architecture is divided into two layers, the first layer is the user internal network, and the second layer is the network interconnection between cross-user and cross-site; specifically, the NGFW is deployed in the virtualization environment of the virtualization underlying platform as a multi-tunnel slicing isolation between the upper service system; for terminal users, different services are distinguished by using different physical ports to complete the isolation between different services, and more detailed security domain access control strategies are used to provide access control between services to complete the deployment of security and reliability. Finally, the converged communication network architecture is used to complete the communication requirements of the large architecture isolation and small part interconnection of the business.
[0022] The data interconnection front-end is the basic service architecture of the terminal, which integrates basic communication connection services including commonly used OPC, MQTT, etc., and completes the security management of different services provided by the physical isolated port; for the safe and stable intelligent connection function of the terminal, the data interconnection and data processing are separated, the data edge computing node is designed as the data processing architecture of the terminal, which integrates basic data processing tools to complete the basic processing of interconnected data including storage, retrieval, processing, transformation, and finally provides breakpoint resume and other guarantee work for the transmission of the whole data.
[0023] Meanwhile, the whole terminal overall security management is completed through the company's self-developed digital operation and maintenance platform running in the converged communication network architecture, and the monitoring and alarm of the IN, OUT direction flow usage, service PV / UV number, running log, TCP / IP process quantity of the terminal CPU, memory, disk and each network card are completed.
[0024] The terminal hardware technical specifications are as follows:
[0025] Hard disk: 12 pieces of 35" / 2.5" hard disk; 12 pieces of 35" / 2.5" hard disk; 24 pieces of 2.5" hard disk; 24 pieces of 2.5" hard disk;
[0026] Network card: 2 Intel I350-BT21 GbE LAN; 2 Intel I350-BT21 GbE LAN, 2 JL82599 gigabit optical; 2 Intel I350-BT21 GbE LAN; 2 Intel I350-BT21 GbE LAN, 2 JL82599 gigabit optical;
[0027] System node: The system supports two easily-pluggable high-performance dual-server nodes;
[0028] CPU: Single node supports two Intel E52600V3 / V4 processors;
[0029] Memory: Single node maximum supports 512G DDR4-2133 / 2400 ECC-RDIMM, 1024G ECC-LRDIMM;
[0030] Power supply: 1600W 1+1 redundant platinum efficiency power supply is adopted;
[0031] System size: 760mm*448mm*88mm (deep*wide*high), net weight 19kg, gross weight 22kg.
[0032] The current water data transmission system has completed the standardization system and unified backup architecture based on virtualization, and under the premise that the next-generation firewall and log audit both start to support software deployment based on X86, the transmission system can be safely expanded based on node virtualization, and security is run through the whole system, the coordination of the system is improved, and the linkage between the security services and operation and maintenance personnel in the system is strengthened. The water management digital security intelligent terminal of the application is a hardware container in the transmission system, which realizes the end-to-end safe communication, reasonable isolation, function replication, capacity increase and range extension of the edge computing node through the design of the above-mentioned architecture, and uses the unified cloud management and control platform (water digital security intelligent platform) to complete the overall registration, configuration management, operation and maintenance, upgrading and control of the system.
Claims
1. A digital security intelligent terminal for water management, characterized in that, The KVM virtualization underlying platform based on Linux is used to perform virtualization deployment on a converged communication network architecture, a next-generation software network firewall / log audit system, a data interconnection front-end system and a data edge computing node, and to build an intensive and fractal full virtualization architecture including a VServer virtual host, a Vsan virtual storage, a Vnet virtual network, a Vsafe virtual secure interconnection, a Vservice virtual service and a Vmanage unified virtual management, wherein the converged communication network architecture refers to a basic network structure having a multi-link bandwidth convergence and a network logical isolation capability based on services, and a total channel is formed by converging multiple links of different types of operators, and independent secondary channels of different services are divided on demand based on the total channel, so that network layer isolation between services is achieved, and the converged communication network architecture is implemented in two layers, a first layer being an internal network of a user and a second layer being a network interconnection between users and cross-site networks; specifically, the NGFW is deployed in the virtualization environment of the virtualization underlying platform and is used as a multi-tunnel slice isolation between the NGFW and an upper service system; for terminal users, different physical ports are used to distinguish different services to complete isolation between different services, and a more refined security domain access control strategy is used to provide access control between services and complete secure and reliable deployment; The KVM virtualization underlying platform refers to the virtualization of CPU and memory by KVM.ko and KVM_intel related to computing resources to complete memory allocation and management required by the system, and the KVM kernel is interacted with through an IOCTL system call to reserve an interface for a subsequent cloud management and control platform. The data interconnection front-end system refers to a basic communication connection service integrated through physically isolated ports to complete security management of different services, and separates data interconnection from data processing, designs a data edge computing node integrated with basic data processing tools to complete basic processing of interconnected data, including storage, retrieval, processing and transformation, and finally provides guarantee work for transmission of the whole data.
2. The digital security intelligent terminal for water management according to claim 1, characterized in that, The KVM virtualization underlying platform is built by installing basic components of KVM to implement establishment of subsequent networks, storages and virtual machines, wherein distributed storage is used on the storage to complete block storage, file storage and object storage; the block storage uses full-flash block storage to create two or three copies of virtual disks, and manual and timed backup of the intelligent terminal service is provided by the underlying platform to complete backup of multiple hard disks.
3. The digital security intelligent terminal for water management according to claim 2, characterized in that, Each hard disk has multiple backup chains, each backup chain includes one full backup node and multiple incremental backup nodes; two nodes are high-availability to each other, data between the nodes are synchronized, and when a backup is initiated, a random node is selected as a master node of the backup task to play a role of load balancing.
Citation Information
Patent Citations
Implementation method of water conservation cloud platform
CN103051714A
Construction method of meteorological information infrastructure resource cloud platform
CN115225664A