Method and device for checking policy of longitudinal encryption authentication apparatus, terminal and medium
By automating the matching of communication tunnels and policy information of the vertical encryption authentication device, the inefficiency caused by reliance on manual verification in existing technologies is solved, enabling fast and accurate policy verification and improving the security and efficiency of the power monitoring system.
Patent Information
- Application Number
- CN202510922534.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-04
- Publication Date
- 2025-11-21
- Estimated Expiration
- 2045-07-04
AI Technical Summary
Existing vertical encryption authentication devices rely heavily on manual verification for policy analysis, resulting in low verification efficiency and an inability to effectively correlate policy information at both ends of a symmetrical tunnel, making it difficult to meet the real-time requirements of network security protection.
By automatically collecting the communication tunnel set of the vertical encryption authentication device, matching symmetrical tunnels and extracting policy information from both ends, and using the matching results of internal network IP, external network IP, port, protocol type and policy direction, the policy verification result is determined, reducing the reliance on manual review.
It realizes automated verification of the vertical encryption authentication device strategy, quickly identifies asymmetric issues in the strategy configuration, improves verification efficiency, reduces the workload of manual review, and enhances the security protection capability of the power monitoring system.
Smart Images

Figure CN120582898B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of power monitoring system network security, and particularly relates to a policy checking method and device for longitudinal encryption authentication devices, a terminal and a medium. BACKGROUND
[0002] In a power monitoring system, a longitudinal encryption authentication device (such as a longitudinal encryption authentication device) undertakes an important responsibility of protecting the communication security between a master station and a plant station. Each level of operation and maintenance unit of a power grid deploys a longitudinal encryption authentication device at the longitudinal connection between a production control area and a dispatching data network. The device provides a two-way identity authentication, data encryption and access control service for the communication of a dispatching data network between an upper and lower dispatching mechanism or a control system at the master station and the substation end.
[0003] The existing policy analysis method of the longitudinal encryption authentication device only matches the five-tuple of the policy through a simple regular expression, filters out the non-compliant policy, and then manually checks and eliminates the defects. This method only identifies simple problem policies by matching keywords and generates corresponding alarms, and seriously depends on manual checking to ensure the accuracy of the checking result, thereby causing the technical problem of low checking efficiency. SUMMARY
[0004] The present application provides a policy checking method and device for longitudinal encryption authentication devices, a terminal and a medium, which are used to solve the technical problem of low checking efficiency caused by the fact that the existing policy analysis of the longitudinal encryption authentication device seriously depends on manual checking to ensure the accuracy of the checking result.
[0005] To solve the above technical problems, the first aspect of the present application provides a policy checking method for longitudinal encryption authentication devices, comprising:
[0006] According to the configuration state of the longitudinal encryption authentication device in the power monitoring system, a communication tunnel set of the longitudinal encryption authentication device is obtained;
[0007] According to the communication tunnel sets of different longitudinal encryption authentication devices, the tunnel information in one communication tunnel set is matched with the tunnel information in other communication tunnel sets, so as to determine the symmetric tunnel that matches successfully according to the tunnel matching result;
[0008] According to the longitudinal encryption authentication devices at both ends of the symmetric tunnel, the policy information of the two longitudinal encryption authentication devices under the symmetric tunnel is extracted, and the first policy information and the second policy information are obtained respectively;
[0009] According to the matching result of the first policy information and the second policy information, the policy checking result of the longitudinal encryption authentication device is determined.
[0010] Preferably, the tunnel information in one communication tunnel set is matched with the tunnel information in another communication tunnel set to determine, according to the tunnel matching result, that the matched symmetric tunnels include:
[0011] The inner network IP and the outer network IP of the tunnel in one communication tunnel set are matched with the outer network IP and the inner network IP of the tunnel in another communication tunnel set, and if the matching is successful, it is determined that the two tunnels matched are symmetric tunnels.
[0012] Preferably, the policy information includes: inner network IP, outer network IP, inner network port, outer network port, protocol type and policy direction.
[0013] Preferably, according to the matching result of the first policy information and the second policy information, the policy checking result of the longitudinal encryption authentication device includes:
[0014] According to the inner network port, the outer network port, the protocol type and the policy direction in the first policy information and the second policy information, if the inner network IP in the first policy information and the outer network IP in the second policy information, the outer network IP in the first policy information and the inner network IP in the second policy information, the inner network port in the first policy information and the outer network port in the second policy information, the outer network port in the first policy information and the inner network port in the second policy information, the protocol type in the first policy information and the protocol type in the second policy information are consistent, and the policy direction in the first policy information and the policy direction in the second policy information are opposite, it is determined that the tunnel policy corresponding to the first policy information and the second policy information are symmetric policies.
[0015] When the tunnels between any two connected longitudinal encryption authentication devices are symmetric tunnels and the tunnel policies of each symmetric tunnel are symmetric policies, it is determined that the policy checking result between the two connected longitudinal encryption authentication devices is normal.
[0016] Preferably, after extracting the policy information of the two longitudinal encryption authentication devices under the symmetric tunnel, it further includes:
[0017] Traverse the policy information, and when any three of the inner network IP, the outer network IP, the protocol type and the service port in the two policy information are the same, the policy information is processed by merging, wherein the service port is the outer network port when the policy direction is forward, the inner network port when the policy direction is reverse, or the port range smaller one of the outer network port and the inner network port when the policy direction is bidirectional.
[0018] Preferably, it further includes:
[0019] Asymmetric tunnels and asymmetric policies that fail to match are counted;
[0020] According to the matching failure records in each asymmetric tunnel and asymmetric policy, an abnormal type classification result is obtained.
[0021] Preferably, before matching the tunnel information in one communication tunnel set with the tunnel information in other communication tunnel sets according to the communication tunnel sets of different longitudinal encryption authentication devices, the method further comprises:
[0022] According to the identification of each longitudinal encryption authentication device and the association relationship of the identification, the longitudinal encryption authentication devices having a direct connection relationship are determined, so that the communication tunnel sets are matched according to the longitudinal encryption authentication devices having a direct connection relationship.
[0023] The second aspect of the present application provides a policy checking device of a longitudinal encryption authentication device, comprising:
[0024] A tunnel set information acquisition unit is configured to acquire a communication tunnel set of a longitudinal encryption authentication device according to a configuration state of the longitudinal encryption authentication device in a power monitoring system.
[0025] A tunnel matching unit is configured to match the tunnel information in one communication tunnel set with the tunnel information in other communication tunnel sets according to the communication tunnel sets of different longitudinal encryption authentication devices, so as to determine a symmetric tunnel that matches successfully according to a tunnel matching result.
[0026] A tunnel policy extraction unit is configured to extract policy information of two longitudinal encryption authentication devices under the symmetric tunnel according to the longitudinal encryption authentication devices at two ends of the symmetric tunnel, to obtain first policy information and second policy information respectively.
[0027] A tunnel policy matching unit is configured to determine a policy checking result of the longitudinal encryption authentication device according to a matching result of the first policy information and the second policy information.
[0028] The third aspect of the present application provides a policy checking terminal of a longitudinal encryption authentication device, comprising a memory and a processor.
[0029] The memory is configured to store program code for implementing the policy checking method of the longitudinal encryption authentication device provided in the first aspect of the present application.
[0030] The processor is configured to read and execute the program code.
[0031] The fourth aspect of the present application provides a computer readable storage medium, wherein the computer readable storage medium stores program codes, and the program codes are used to be read and executed by a processor to implement the policy checking method of the longitudinal encryption authentication device according to the first aspect of the present application.
[0032] From the above technical solutions, the present application has the following advantages:
[0033] The scheme provided by the present application provides a special policy symmetry checking method for the bus encryption authentication device of the power monitoring system. First, the tunnel information in one communication tunnel set is matched with the tunnel information in other communication tunnel sets according to the obtained communication tunnel sets of different longitudinal encryption authentication devices, so as to determine the symmetric tunnel according to the tunnel matching result. Then, the policy information of the two longitudinal encryption authentication devices under the symmetric tunnel is extracted according to the longitudinal encryption authentication devices at both ends of the symmetric tunnel, and the policy checking result of the longitudinal encryption authentication device is determined through the matching result of the two groups of policy information. The scheme can more quickly and accurately identify the asymmetric problem in the policy configuration through automatic collection of tunnel sets, matching of symmetric tunnels and bidirectional verification of policies, so as to filter out normal symmetric policies and abnormal asymmetric policies, reduce the dependence on manual review, and improve the efficiency of policy checking of the longitudinal encryption authentication device. BRIEF DESCRIPTION OF DRAWINGS
[0034] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the drawings needed to be used in the embodiments or the prior art description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0035] Figure 1 The flowchart of the policy checking method of the longitudinal encryption authentication device provided by the present application.
[0036] Figure 2 The structural diagram of the policy checking device of the longitudinal encryption authentication device provided by the present application.
[0037] Figure 3 The structural diagram of the policy checking terminal of the longitudinal encryption authentication device provided by the present application. DETAILED DESCRIPTION
[0038] In the prior art, the power monitoring system relies on a longitudinal encryption authentication device to ensure the security of communication between a master station and a station, and a traditional strategy checking method screens abnormal strategies by matching strategy quintuples through a regular expression, and then the abnormal strategies are confirmed by manual review. This way is inefficient in processing massive tunnels and strategy timeliness, cannot effectively associate the strategy information of the two ends of a symmetric tunnel, results in a long time-consuming checking process and insufficient accuracy, and is difficult to meet the real-time demand of network security protection. For example, when there are tens of thousands of tunnel strategies in the system, manual checking needs to be compared one by one, and abnormal strategies or normal strategies are easily missed or misjudged.
[0039] Therefore, the embodiments of the present application provide a strategy checking method and device of a longitudinal encryption authentication device, a terminal and a medium, to solve the technical problem of low checking efficiency caused by the fact that the existing strategy analysis of the longitudinal encryption authentication device relies heavily on manual checking to ensure the accuracy of the checking result.
[0040] In order to make the purposes, features and advantages of the present application more obvious and easy to understand, the technical solutions in the embodiments of the present application will be described clearly and completely below in combination with the drawings in the embodiments of the present application. Obviously, the following described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor fall within the scope of protection of the present application.
[0041] First, a detailed description of an embodiment of a strategy checking method of a longitudinal encryption authentication device provided by the present application is given as follows.
[0042] Please refer to Figure 1 The strategy checking method of the longitudinal encryption authentication device provided by the embodiments of the present application includes the following steps.
[0043] Step 101, according to the configuration state of the longitudinal encryption authentication device in the power monitoring system, a communication tunnel set of the longitudinal encryption authentication device is obtained;
[0044] Step 102, according to the communication tunnel sets of different longitudinal encryption authentication devices, the tunnel information in one communication tunnel set is matched with the tunnel information in other communication tunnel sets, so as to determine the symmetric tunnel according to the tunnel matching result;
[0045] Step 103, according to the longitudinal encryption authentication devices at the two ends of the symmetric tunnel, the strategy information of the two longitudinal encryption authentication devices under the symmetric tunnel is extracted, and the first strategy information and the second strategy information are obtained respectively;
[0046] Step 104, according to the matching result of the first strategy information and the second strategy information, the strategy checking result of the longitudinal encryption authentication device is determined.
[0047] The communication tunnel set refers to a set of tunnel information configured in the longitudinal encryption authentication device, and can be obtained by analyzing the device configuration file or calling the management interface, and contains parameters such as the end point address, port and protocol type of the tunnel. The symmetric tunnel refers to the tunnel between the two devices as the communication object, for example, the source address of tunnel A is consistent with the destination address of tunnel B, and the destination address of tunnel A is consistent with the source address of tunnel B. The policy information includes the access control rules of the two ends of the tunnel, such as the source address, the destination address, the port range and the protocol type, which can be extracted by traversing the device policy table. The policy checking result is used to identify whether the policies of the two ends of the symmetric tunnel meet the bidirectional communication requirements, for example, when the address mapping and port range of the two end policies are completely matched and the directions are opposite, it is determined that the policy is normal.
[0048] Specifically, first, the communication tunnel configuration data of all longitudinal encryption authentication devices in the power monitoring system is collected to form the tunnel set of each device. For example, the tunnel set of device A contains ten tunnels, and each tunnel record contains internal network IP, external network IP and port information. Then, the tunnel set of device A is compared with the tunnel set of device B. If the internal network IP and the external network IP of a tunnel of device A correspond to the external network IP and the internal network IP of a tunnel of device B respectively, it is determined that the two tunnels are symmetric tunnels. Then, for each pair of symmetric tunnels, the policy information configured by the two devices under the tunnel is extracted, for example, the policy of device A allows network traffic from the internal network IP to the external network IP, and the policy of device B requires network traffic response from the external network IP to the internal network IP. Finally, whether the address, port and protocol type of the policy are consistent and whether the policy direction is opposite are compared to determine whether the policy is symmetric. If the policies corresponding to all symmetric tunnels meet the symmetric condition, the checking result is normal.
[0049] The present scheme can process massive policy data in batches through automatic collection of tunnel sets, matching of symmetric tunnels and bidirectional verification of policies. For example, in a system containing tens of thousands of policies, the traditional method needs to check each policy manually, while the present scheme can complete the symmetry verification of all policies within a few minutes, realizing the automatic verification of the policies of the longitudinal encryption authentication device, and quickly identifying the asymmetric problems in the policy configuration. For example, when the inbound policy of a tunnel lacks the corresponding outbound policy, the system can immediately mark it as abnormal, avoiding communication interruption caused by missing policies. At the same time, the method provides data support for policy optimization, such as automatically generating policy collection suggestions to reduce the number of redundant policies, thereby improving the security protection capability of the power monitoring system.
[0050] More specifically, the policy information mentioned in the above embodiments includes internal network IP, external network IP, internal network port, external network port, protocol type and policy direction.
[0051] The internal network IP refers to the network address of the internal network device connected to the longitudinal encryption authentication device, and can be achieved by analyzing the local interface parameters of the device configuration file, and is used to identify the internal network location of the communication initiator or receiver.
[0052] The external network IP refers to the network address of the longitudinal encryption authentication device on the public network side, and can be achieved by reading the external interface configuration parameters of the device, and is used to establish the endpoint identification when cross-network communication is established.
[0053] The internal network port refers to the communication port number used by the internal network device, and can be achieved by analyzing the source port field in the strategy rule, and is used to limit the access range of the internal service.
[0054] The external network port refers to the communication port number mapped by the longitudinal encryption authentication device on the external network side, and can be obtained by the target port field in the strategy configuration, and is used to control the access path of the external request.
[0055] The protocol type refers to the transmission layer protocol used in the communication process, which can include TCP, UDP or ICMP type, and can be achieved by matching the protocol identifier in the strategy rule, and is used to ensure that the transmission mechanism of the two communication parties is consistent.
[0056] The strategy direction refers to the transmission direction definition of the data flow, which can be set to forward, reverse or bidirectional, and can be achieved by analyzing the direction identifier in the strategy rule, and is used to constrain the access control logic of the communication tunnel.
[0057] Specifically, when extracting the strategy information of the two ends of the symmetric tunnel, the mapping relationship between the internal network IP and the external network IP, the corresponding conversion of the port number, the consistency of the protocol type and the complementarity of the strategy direction are obtained at the same time, and the complete strategy comparison dimension is constructed. For example, when a communication tunnel is established between two longitudinal encryption authentication devices, the external network port of the forward strategy of the first device is 8080 and the protocol type is TCP, and the corresponding internal network port of the reverse strategy of the second device also needs to be 8080 and the protocol type needs to be matched, and the strategy direction needs to be set to reverse to realize the access control of bidirectional communication. By including the above six elements in the strategy matching condition, the strategy omission or misjudgment caused by single dimension matching can be avoided.
[0058] On the basis of the above basic embodiment, the internal network IP and the external network IP of the tunnel in one of the communication tunnel sets are matched with the external network IP and the internal network IP of the tunnel in the other communication tunnel set, and if the matching is successful, it is determined that the two tunnels matched successfully are symmetric tunnels.
[0059] The symmetric tunnel refers to the two communication tunnels forming a corresponding relationship with each other in the end point address, and specifically, the inner network IP and the outer network IP of one tunnel correspond to the outer network IP and the inner network IP of the other tunnel, respectively. The feature ensures the bidirectional reachability of the communication tunnel through the bidirectional address matching mechanism.
[0060] For example, assuming that Tx is the tunnel of the master station longitudinal encryptor and Ti is the tunnel of the factory station longitudinal encryptor, the determination condition is as follows:
[0061] Tx.srcIP (inner network address) == Ti.dstIP (outer network address);
[0062] Tx.dstIP (outer network address) == Ti.srcIP (inner network address);
[0063] If the condition is met, it is determined that Tx and Ti are symmetric tunnels.
[0064] Specifically, in the power monitoring system, the communication tunnels between the longitudinal encryption authentication devices need to meet the bidirectional policy symmetry requirement. By comparing the tunnel inner network IP and the tunnel outer network IP in the first device tunnel set with the tunnel outer network IP and the tunnel inner network IP in the second device tunnel set, if they are completely consistent, it is determined that the two tunnels constitute a symmetric relationship. For example, when the inner network IP of the first tunnel is 192.168.1.1 and the outer network IP is 10.0.0.1, if there is a second tunnel with an inner network IP of 10.0.0.1 and an outer network IP of 192.168.1.1, the two are identified as symmetric tunnels. Thus, the system can automatically filter out the tunnel pairs that meet the bidirectional communication requirement, providing basic data for subsequent policy symmetry verification.
[0065] The scheme can accurately identify the symmetric tunnel structure required for bidirectional communication by establishing a mutual mapping matching rule of the tunnel end point address, avoiding the inefficient operation of manually checking the tunnel corresponding relationship, realizing the automatic checking of the communication tunnel symmetry, reducing the workload of manual review, and at the same time ensuring the accuracy of the tunnel basic data required for policy comparison, providing reliable input conditions for subsequent policy consistency verification.
[0066] Further, the application further proposes that according to the inner network port, the outer network port, the protocol type and the policy direction in the first policy information and the second policy information, if the inner network IP in the first policy information and the outer network IP in the second policy information, the outer network IP in the first policy information and the inner network IP in the second policy information, the inner network port in the first policy information and the outer network port in the second policy information, the outer network port in the first policy information and the inner network port in the second policy information, the protocol type in the first policy information and the protocol type in the second policy information are consistent, and the policy direction in the first policy information and the policy direction in the second policy information are opposite, it is determined that the tunnel policy corresponding to the first policy information and the second policy information are mutual symmetric policies; when the tunnels between any two connected longitudinal encryption authentication devices are symmetric tunnels and the tunnel policies of each symmetric tunnel are symmetric policies, it is determined that the policy checking result between the two connected longitudinal encryption authentication devices is normal.
[0067] The inner network port refers to a communication port used by the internal network side of the longitudinal encryption authentication device, which can be specifically expressed in the form of a numerical range, such as 80 to 8080, for identifying internal service types. The outer network port refers to a communication port used by the external network side of the longitudinal encryption authentication device, which can be specifically defined in the form of a discrete numerical value or a range, such as 443 or 1024-65535, for identifying external access targets. The protocol type refers to a network protocol used in the communication process, which can be specifically identified by TCP, UDP or ICMP protocol type codes, such as the numerical value 6 corresponding to TCP. The policy direction refers to the transmission direction of data flow, which can be specifically described by enumeration values such as forward, reverse or bidirectional, such as forward indicating the flow from the inner network to the outer network.
[0068] For example, assuming that Rx is the policy under the symmetric tunnel of the main station encryption machine, and Ri is the policy under the symmetric tunnel of the factory station encryption machine:
[0069] Rx.srcIP (inner network address) == Ri.dstIP (outer network address);
[0070] Rx.dstIP (outer network address) == Ri.srcIP (inner network address);
[0071] Rx.srcPort (inner network port) == Ri.dstPort (outer network port);
[0072] Rx.dstPort (outer network port) == Ri.srcPort (inner network port);
[0073] Rx.Protocol == Ri.Protocol;
[0074] (Rx.direction == "forward" and Ri.direction == "reverse") or (Rx.direction == "reverse" and Ri.direction == "forward").
[0075] If all the above conditions are matched, it is determined that Rx and Ri are symmetric strategies, otherwise they are asymmetric strategies.
[0076] Specifically, after the symmetric tunnel is established, the policy parameters of the two end devices need to be verified by bidirectional mapping. For example, when the inner network IP in the first policy information is 192.168.1.1 and the outer network IP is 10.0.0.1, the second policy information needs to satisfy the outer network IP of 192.168.1.1 and the inner network IP of 10.0.0.1. In terms of port mapping, if the inner network port of the first policy is 80 and the outer network port is 5000, the outer network port of the second policy needs to be 80 and the inner network port needs to be 5000. The protocol type needs to be completely consistent, for example, both ends use TCP protocol. The policy direction needs to form a complementary relationship, for example, when the first policy is forward, the second policy must be reverse. When all parameters satisfy the above symmetric relationship, the system automatically determines that the policy symmetry is normal, and no manual intervention verification is needed.
[0077] The scheme introduces a bidirectional parameter mapping mechanism, which forces the policy direction to form a complementary relationship, and can accurately identify such configuration abnormalities through direction comparison, so as to automatically identify policy direction configuration errors and avoid communication failures caused by one-way policy conflicts. For example, when the master station end is configured with an outbound policy but the sub-station end is not configured with a corresponding inbound policy, the system can immediately mark the abnormal policy, which significantly shortens the fault positioning time compared with the traditional manual checking method. At the same time, through the accurate matching of the port mapping relationship, the service unavailability problem caused by the mismatch of the inner and outer network ports can be effectively prevented, and the integrity and consistency of the policy configuration are improved.
[0078] Further, the present application further comprises traversing the policy information after extracting the policy information of the two longitudinal encryption authentication devices under the symmetric tunnel, and merging the policy information when any three of the inner network IP, the outer network IP, the protocol type and the service port in the two policy information are the same, wherein the service port is the outer network port when the policy direction is forward, the inner network port when the policy direction is reverse, or the outer network port and the inner network port when the policy direction is bidirectional, and the port range of one of the outer network port and the inner network port is smaller.
[0079] The service port refers to a port identifier corresponding to a policy direction, and can be dynamically determined by analyzing the policy direction field, for example, the external network port is selected as the service port when the policy direction is forward, and the internal network port is selected as the service port when the policy direction is reverse. This feature is used to establish a unified port comparison benchmark when merging policies, avoiding port matching failure caused by direction differences. The policy merging process refers to integrating multiple policies that meet the conditions into a single entry, which can be achieved by creating a policy merging rule library and performing a redundant policy replacement operation. This process can eliminate duplicate policy entries and reduce the computational complexity of subsequent policy matching.
[0080] Specifically, after obtaining the policy information generated by the devices at both ends of the symmetric tunnel, the system traverses all policy entries and performs merging judgment. For example, when it is found that the internal network IP, external network IP and protocol type of two policies are the same, and the forward external network port of one policy and the reverse internal network port of the other policy are the same, the two policies are merged into a bidirectional policy. During the merging process, the selection of the service port is dynamically adjusted according to the policy direction, for example, when the policy direction is bidirectional, the smaller port value between the external network port and the internal network port is taken as the service port identifier after merging. In this way, multiple policies that need to be processed separately are integrated into a single policy entry, effectively reducing the redundancy of the policy set.
[0081] By introducing the service port dynamic determination mechanism and the policy merging rule, the present scheme can systematically eliminate redundant policy entries while ensuring the integrity of the policy semantics, reducing the number of policies that need to be processed during manual review. Through the above technical solution, multiple policies with overlapping communication characteristics can be automatically identified and merged and optimized, for example, forward and reverse independent policies that need to be maintained are integrated into a bidirectional policy. This processing reduces the size of the policy set, reduces the computational complexity of policy matching, and avoids the risk of policy conflicts caused by duplicate policies, providing a more streamlined data basis for subsequent policy review.
[0082] Further, the present application also proposes the following additional steps:
[0083] Step 105, count the asymmetric tunnels and asymmetric policies that fail to match, classify according to the matching failure records in each asymmetric tunnel and asymmetric policy, and obtain an abnormal type classification result.
[0084] The asymmetric tunnel refers to a communication tunnel in which the communication tunnel parameters of the two longitudinal encryption authentication devices are inconsistent in the tunnel matching process, and can be determined by the failure of bidirectional matching of the internal and external network IP addresses and port numbers of the two ends of the tunnel, for example, when the internal network IP of tunnel A does not match the external network IP of tunnel B, an asymmetric tunnel is formed. The asymmetric policy refers to a security policy with inconsistent parameters in the policy information matching process, for example, when the external network port range of the first policy does not contain the internal network port of the second policy, the policy is asymmetric. The matching failure record refers to the parameter difference information recorded by the system in the tunnel matching and policy matching process, and the comparison results of the key parameters in each matching operation can be stored in a log file. The abnormal type classification result refers to the output of classifying the matching failure reasons according to the preset rules, for example, different fault modes such as IP address mismatch, port range exclusion, and protocol type conflict are distinguished.
[0085] Specifically, after the symmetry of the tunnel and the policy is matched, the system automatically collects all the unsuccessfully matched tunnel and policy data. For each matching failure instance, the system extracts the key parameter differences such as internal and external network IP addresses, port numbers, and protocol types, for example, when the internal network IP of tunnel A is 192.168.1.1 and the external network IP of corresponding tunnel B is 192.168.1.2, the system will record the IP address mismatch event. Then, based on the preset classification rule library, instances with the same parameter difference mode are classified into the same abnormal type, for example, all source IP address mismatch instances are classified as “address configuration error”, and instances in which the port range is not covered are classified as “port policy conflict”. The classification process can be achieved by establishing a feature vector matching mechanism, for example, the feature vector of each matching failure instance is calculated for similarity with the predefined abnormal type feature template.
[0086] The scheme can cluster and analyze configuration errors with the same root cause through an automatic classification mechanism, for example, it can automatically identify that a certain type of device has a narrow port range setting problem, which significantly improves the problem positioning efficiency. Through the above technical scheme, the application can effectively identify systematic error patterns in policy configuration, for example, it can find that a certain type of device has a policy configuration template defect under a specific protocol type. Through automatic classification of abnormal types, operation and maintenance personnel can quickly locate high-frequency configuration error types, for example, they can batch correct address configuration errors, which provides a clear improvement direction for policy optimization and reduces the workload of manual review.
[0087] Further, the application further includes the following additional steps before the tunnel information matching according to the communication tunnel set of different longitudinal encryption authentication devices in step 102:
[0088] Step 1020, according to the identification of each longitudinal encryption authentication device, combined with the association relationship of the identification, the longitudinal encryption authentication devices with direct connection relationship are determined, so as to match the communication tunnel set according to the longitudinal encryption authentication devices with direct connection relationship.
[0089] Among them, the identification refers to the identity information for uniquely identifying the longitudinal encryption authentication device, which can be realized by device serial number, MAC address or device name. Through the identification, the position of the device in the network topology can be accurately located.
[0090] Among them, the association relationship refers to the connection configuration information between the longitudinal encryption authentication devices, which can be realized by network topology configuration file or device naming rule mapping table. Through the analysis of the association relationship, the device pairs actually connected by physical link can be screened out.
[0091] Specifically, in the power monitoring system, the longitudinal encryption authentication devices are usually deployed between specific network nodes. By reading the identification recorded in the device configuration file, such as device name, and combining the corresponding relationship of the device naming rule mapping table, two devices with direct connection relationship can be screened out. For example, the longitudinal encryption machines of the master station and the plant station can be identified by the device name. Generally, the naming rule of the encryption machine on the master station side is "city name + security partition", and the naming rule of the encryption machine on the plant station side is voltage level + station name + security partition. The encryption machines of the master station and the plant station can also be manually marked to ensure that the devices on both ends correspond one by one.
[0092] The combination of identification and association relationship in the scheme limits the matching range to the devices actually connected by physical link, effectively reducing the data processing amount. Through the above technical scheme, the present application can accurately locate the device pairs with actual communication demand, avoid executing invalid strategy check on irrelevant devices, thereby reducing system resource consumption and improving strategy check efficiency. At the same time, the association relationship is verified to ensure the accuracy of tunnel matching, preventing the problem of strategy omission caused by network topology misjudgment.
[0093] The following is a verification example of the strategy check method of the longitudinal encryption authentication device provided in the present application, as follows:
[0094] Suppose that in a certain power monitoring system, the XX power supply bureau (master station) and the transformer station A and the transformer station B establish tunnels through encryption machines respectively, with the following configurations:
[0095] 1) Master station configuration:
[0096] Tunnel information:
[0097] Tunnel 1: 192.168.1.1 (master station) → 10.0.0.1 (transformer station A);
[0098] Tunnel 2: 192.168.1.1 (Master) -> 172.16.168.1 (Substation B).
[0099] The policy information is shown in Table 1 below:
[0100]
[0101] 2) Substation A configuration:
[0102] Tunnel information:
[0103] Tunnel A: 10.0.0.1 -> 192.168.1.1.
[0104] The policy information is shown in Table 2 below:
[0105]
[0106] 3) Substation B configuration:
[0107] Tunnel information:
[0108] Tunnel B: 172.16.168.1 -> 192.168.1.1.
[0109] The policy information is shown in Table 3 below:
[0110]
[0111] 4) Based on the above information, an example of the matching situation is as follows:
[0112] Tunnel information:
[0113] Substation A's tunnel matches Master Tunnel 1;
[0114] Substation B's tunnel matches Master Tunnel 2;
[0115] Policy information:
[0116] Type 1 (Normal, merged service and symmetric):
[0117] Master: 192.168.1.36~37 (0~65535) -> 10.0.0.136 (8801~8804, 12404);
[0118] Substation A: 10.0.0.136 (8801~8804, 12404) 192.168.1.36~37 (0~65535);
[0119] Merged service refers to service ports 8801~8804 plus port 12404.
[0120] Type 2 (normal, normal symmetry):
[0121] Master station: 192.168.1.123 (0~65535) -> 172.16.168.123 (22);
[0122] Substation A: 172.16.168.123 (22) 192.168.1.123 (0~65535);
[0123] Type 3 (abnormal, policy asymmetric - completely irrelevant):
[0124] Master station: 192.168.1.123 (3306) -> 172.16.168.123 (8080);
[0125] Substation B: 172.16.168.136 (3306) 192.168.1.236~237 (0~65535);
[0126] Type 4 (abnormal, policy asymmetric - service port too wide):
[0127] Master station: 192.168.1.123 (0~65535) -> 172.16.168.123 (8080~8082);
[0128] Substation B: 172.16.168.136 (8080) 192.168.1.236~237 (0~65535).
[0129] The above is a detailed description of an embodiment of a policy checking method of a longitudinal encryption authentication device provided by the present application. The following is a detailed description of an embodiment of a policy checking device of a longitudinal encryption authentication device provided by the present application.
[0130] Please refer to Figure 2 The policy checking device of the longitudinal encryption authentication device provided by the present application comprises:
[0131] A tunnel set information acquisition unit 201 is configured to acquire a communication tunnel set of the longitudinal encryption authentication device according to a configuration state of the longitudinal encryption authentication device in the power monitoring system.
[0132] A tunnel matching unit 202 is configured to match tunnel information in one communication tunnel set with tunnel information in other communication tunnel sets according to the communication tunnel sets of different longitudinal encryption authentication devices, so as to determine a symmetric tunnel that matches successfully according to a tunnel matching result.
[0133] The tunnel policy extraction unit 203 is configured to extract policy information of two longitudinal encryption authentication devices under a symmetric tunnel according to longitudinal encryption authentication devices at two ends of the symmetric tunnel, and obtain first policy information and second policy information respectively.
[0134] The tunnel policy matching unit 204 is configured to determine a policy checking result of the longitudinal encryption authentication device according to a matching result of the first policy information and the second policy information.
[0135] Further, the policy checking device for the longitudinal encryption authentication device provided in the application can further include:
[0136] The abnormal policy classification unit 205 is configured to count asymmetric tunnels and asymmetric policies with matching failures, classify the asymmetric tunnels and the asymmetric policies with matching failures according to matching failure records in the asymmetric tunnels and the asymmetric policies, and obtain an abnormal type classification result.
[0137] The device matching unit 2020 is configured to determine longitudinal encryption authentication devices with a direct connection relationship according to identification marks of the longitudinal encryption authentication devices and in combination with an association relationship of the identification marks, so as to match the communication tunnel set according to the longitudinal encryption authentication devices with the direct connection relationship.
[0138] As shown in the above-mentioned method embodiment, the application further provides a policy checking terminal for the longitudinal encryption authentication device. Figure 3 The terminal implementation types include but are not limited to personal computers, industrial computers, servers and embedded intelligent devices, and the main components of the terminal include a memory 33 and a processor 31, wherein the memory 33 and the processor 31 can be connected through a communication bus 34.
[0139] The memory 33 is configured to store program codes, and the program codes are used to implement the policy checking method for the longitudinal encryption authentication device provided in the above-mentioned embodiment.
[0140] The processor 31 is configured to read and execute the program codes.
[0141] The application further provides a computer readable storage medium, and the computer readable storage medium stores program codes, and the program codes are used to be read and executed by the processor to implement the policy checking method for the longitudinal encryption authentication device provided in the above-mentioned embodiment.
[0142] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the terminal, the device and the unit described above can refer to the corresponding processes in the above-mentioned method embodiments, and will not be described here.
[0143] In several embodiments provided in the present application, it should be understood that the disclosed terminal, device and method can be implemented in other manners. For example, the described device embodiments are merely schematic. For example, the division of the units is merely a logical function division. There can be another division manner for the actual implementation, for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections between the units can be indirect couplings or communication connections through some interfaces, devices or units, and can be electrical, mechanical or in other forms.
[0144] The terms "first", "second", "third", "fourth" and the like in the description of the specification and the above drawings (if any) are used to distinguish similar objects, and are not necessarily used to describe a particular order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in other than the order shown or described herein. In addition, the terms "comprise" and "have" and any variations thereof, are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device that includes a list of steps or units as an element does not necessarily limit those steps or units to the clearly listed ones, but can include other steps or units that are not clearly listed or inherent to such processes, methods, products or devices.
[0145] It should be understood that in the present application, "at least one" means one or more, and "multiple" means two or more. "And / or" is used to describe the association relationship of the associated objects, which means that there can be three relationships, for example, "A and / or B" can represent three cases of only A, only B and A and B existing at the same time, where A and B can be singular or plural. The character " / " generally represents an "or" relationship between the front and rear associated objects. "At least one of the following" or similar expressions means any combination of these items, including any combination of single or multiple items. For example, at least one of a, b or c can represent a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.
[0146] The units described as separate components can or can not be physically separated, and the components shown as units can or can not be physical units, i.e., they can be located in one place, or can be distributed on multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the embodiments.
[0147] In addition, each function unit in each embodiment of the present application can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software function unit.
[0148] The integrated unit, if realized in the form of a software function unit and sold or used as an independent product, can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the present application, essentially or in the form of a contribution to the prior art, or all or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various media that can store program codes. The above-described embodiments are only used to illustrate the technical solutions of the present application, and not to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacements to some of the technical features; and these modifications or replacements do not cause the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A strategy verification method for a vertical encryption authentication device, characterized in that, include: Based on the configuration status of the vertical encryption authentication device in the power monitoring system, obtain the communication tunnel set of the vertical encryption authentication device. Based on the communication tunnel sets of different vertical encryption authentication devices, the tunnel information in one communication tunnel set is matched with the tunnel information in other communication tunnel sets, so as to determine the successfully matched symmetrical tunnel based on the tunnel matching results; Based on the vertical encryption authentication devices at both ends of the symmetrical tunnel, the policy information of the two vertical encryption authentication devices under the symmetrical tunnel is extracted to obtain the first policy information and the second policy information, respectively. The policy information includes: internal network IP, external network IP, internal network port, external network port, protocol type and policy direction. Based on the internal network port, external network port, protocol type, and policy direction in the first and second policy information, if the internal network IP in the first policy information is the same as the external network IP in the second policy information, the external network IP in the first policy information is the same as the internal network IP in the second policy information, the internal network port in the first policy information is the same as the external network port in the second policy information, the external network port in the first policy information is the same as the internal network port in the second policy information, the protocol type in the first policy information is the same as the protocol type in the second policy information, and the policy direction in the first policy information is opposite to the policy direction in the second policy information, then the tunnel policies corresponding to the first and second policy information are determined to be symmetrical policies. If the tunnel between any two connected vertical encryption authentication devices is a symmetrical tunnel and the tunneling strategy of each symmetrical tunnel is a symmetrical strategy, then the strategy verification result between the two connected vertical encryption authentication devices is determined to be normal.
2. The strategy verification method for a vertical encryption authentication device according to claim 1, characterized in that, The tunnel information in one set of communication tunnels is matched with the tunnel information in other sets of communication tunnels. Based on the tunnel matching results, the successfully matched symmetrical tunnels are identified as follows: The internal and external IP addresses of tunnels in one set of communication tunnels are matched with the external and internal IP addresses of tunnels in another set of communication tunnels. If a match is found, the two matched tunnels are determined to be symmetrical tunnels.
3. The strategy verification method for a vertical encryption authentication device according to claim 1, characterized in that, After extracting the policy information of the two vertical encryption authentication devices under the symmetric tunnel, the process also includes: Traverse the policy information. When any three of the following three items are the same in two policy information, namely internal IP, external IP, protocol type, and service port, the policy information is merged. The service port is the external port when the policy direction is forward, the internal port when the policy direction is reverse, or the smaller of the external and internal port when the policy direction is bidirectional.
4. The strategy verification method for a vertical encryption authentication device according to claim 1, characterized in that, Also includes: Asymmetric tunneling and asymmetric strategies for statistical matching failures; The anomaly type classification results are obtained by classifying the matching failure records in each asymmetric tunnel and asymmetric strategy.
5. The strategy verification method for a vertical encryption authentication device according to claim 1, characterized in that, Before matching the tunnel information in one communication tunnel set with the tunnel information in other communication tunnel sets based on different vertical encryption authentication devices, the process further includes: Based on the identification marks of each vertical encryption authentication device and the association relationships of the identification marks, the vertical encryption authentication devices with direct connection relationships are identified, so as to match the communication tunnel set based on the vertical encryption authentication devices with direct connection relationships.
6. A strategy verification device for a vertical encryption authentication device, characterized in that, include: The tunnel set information acquisition unit is used to acquire the communication tunnel set of the vertical encryption authentication device according to the configuration status of the vertical encryption authentication device in the power monitoring system. The tunnel matching unit is used to match the tunnel information in one communication tunnel set with the tunnel information in other communication tunnel sets based on the communication tunnel sets of different vertical encryption authentication devices, so as to determine the successfully matched symmetrical tunnel based on the tunnel matching results. The tunnel policy extraction unit is used to extract policy information of the two vertical encryption authentication devices under the symmetrical tunnel based on the vertical encryption authentication devices at both ends of the symmetrical tunnel, and obtain first policy information and second policy information respectively. The policy information includes: internal network IP, external network IP, internal network port, external network port, protocol type and policy direction. The tunnel policy matching unit is configured to determine that the tunnel policies corresponding to the first policy information and the second policy information are symmetrical policies based on the internal network port, external network port, protocol type, and policy direction in the first policy information and the second policy information. If the internal network IP in the first policy information matches the external network IP in the second policy information, the external network IP in the first policy information matches the internal network IP in the second policy information, the internal network port in the first policy information matches the external network port in the second policy information, the external network port in the first policy information matches the internal network port in the second policy information, the protocol type in the first policy information matches the protocol type in the second policy information, and the policy direction in the first policy information is opposite to the policy direction in the second policy information, then the tunnel policies corresponding to the first policy information and the second policy information are determined to be symmetrical policies. If the tunnels between any two connected vertical encryption authentication devices are symmetrical tunnels and the tunnel policies of each symmetrical tunnel are symmetrical policies, then the policy verification result between the two connected vertical encryption authentication devices is determined to be normal.
7. A policy verification terminal for a vertical encryption authentication device, characterized in that, include: Memory and processor; The memory is used to store program code, which is used to implement the strategy verification method of a vertical encryption authentication device as described in any one of claims 1 to 5; The processor is used to read and execute the program code.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium contains program code that is read and executed by a processor to implement a strategy verification method for a vertical encryption authentication device as described in any one of claims 1 to 5.
Citation Information
Patent Citations
Message data transmission method, device and system
CN111371549A
Self-adaptive substation longitudinal encryption host verification method and terminal
CN113783837A