A fusion type soft and hard bypass intelligent management and control platform
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- NANJING CHUANGWANG NETWORK TECH CO LTD
- Filing Date
- 2026-05-27
- Publication Date
- 2026-06-26
AI Technical Summary
Existing bypass solutions suffer from issues such as decentralized control, fragmented hardware and software bypass, lack of centralized management, slow fault response, and poor compatibility, making it difficult to meet the requirements of high-reliability network scenarios.
It adopts a converged hardware and software bypass intelligent management and control platform, which integrates control units and physical bypass modules. Through unified control unit scheduling, it realizes fine-grained bypass at the software layer and direct communication at the physical layer. It supports internal I2C bus communication and redundancy design, and provides a web management interface for full-link status monitoring and policy configuration.
It improves hardware resource reuse rate, achieves millisecond-level fault response, adapts to high real-time scenarios, reduces procurement and deployment costs, and improves operation and maintenance efficiency and equipment reliability.
Smart Images

Figure CN122293485A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network communication technology, and specifically to a converged hardware and software Bypass intelligent management and control platform. Background Technology
[0002] Currently, in high-availability network environments, mainstream bypass protection falls into two categories: First, security devices often have built-in bypass modules, custom-developed by individual vendors. These modules have proprietary hardware interfaces and switching logic, leading to high adaptation costs when multiple vendors coexist. Furthermore, they only protect the device itself, failing to detect faults in other devices in the serial link. The redundant integration of bypass hardware across multiple devices results in resource waste, and the dispersed state makes global monitoring difficult. Second, dedicated physical bypass devices operate independently of security devices, performing only physical layer connectivity control. They lack protocol integration with security devices and cannot detect software faults. Their switching logic is simplistic and does not support fine-grained strategies. Multi-link deployments require individual configuration for each device, and numerous cable connections introduce additional points of failure.
[0003] Both types of solutions operate in a decentralized, uncoordinated manner at the underlying architecture level, exhibiting inherent structural flaws. First, control and execution are deeply intertwined. Whether integrated into the security device's bypass module or a dedicated bypass device, the control logic is fixed in the local hardware, lacking a unified control center. This prevents multiple devices from coordinating their strategies, forcing them to operate independently. Second, software bypass and physical bypass are severely disconnected. While security devices can detect software faults, they cannot provide robust physical fallback. Dedicated physical bypass devices can only identify physical link connectivity issues, failing to detect software-level anomalies such as device "freezing" or performance overload. The two cannot complement each other on the same platform. Third, existing solutions lack centralized management, creating "information silos" of status information across multiple devices. Maintenance personnel must log into each device individually to check, making fault localization time-consuming and labor-intensive. Most importantly, in a serial deployment scenario, the failure detection and switching delays of multiple nodes will accumulate, resulting in an excessively long overall convergence time. This simply cannot meet the high reliability requirements of scenarios such as industrial control and high-frequency financial transactions, which require network jitter to reach the millisecond or even sub-millisecond level. Summary of the Invention
[0004] To address the aforementioned technical shortcomings, the purpose of this invention is to provide an integrated hardware and software bypass intelligent management platform that solves the problems of decentralized control, fragmented hardware and software bypass, lack of centralized management, slow fault response, and poor compatibility in existing bypass solutions.
[0005] To solve the above-mentioned technical problems, the present invention adopts the following technical solution: In a first aspect, the present invention provides an integrated hardware and software Bypass intelligent management and control platform, the platform including a control unit and at least one physical Bypass module; The control unit runs fusion control software, which includes a security device monitoring module, a software bypass control module, a physical bypass control module, and a server process module. The control unit is connected to an external switching chip device via a network, and the external switching chip device is connected to at least one security tool; The security device monitoring module is used to monitor the status of security tools through at least one of message detection, port status polling, and packet loss analysis. The software bypass control module is used to send a software bypass command to the external switching chip device when the security device monitoring module detects a security tool failure. The physical bypass control module is used to issue control commands to the physical bypass module; The physical bypass module is connected in series in the network link, and the physical bypass module includes a bypass switching unit; The Bypass switching unit is used to perform physical pass-through of the network link according to control commands or autonomous triggering; The server process module is used to provide a web management interface to achieve centralized monitoring and policy configuration of the entire link status.
[0006] Preferably, in one possible implementation of the first aspect, the control unit further includes a main processor module, and the fusion control software runs on the main processor module; The control unit is equipped with a management network port and a console debugging interface. The management network port is connected to the management port of an external switching chip device, and the console debugging interface is used for local command line configuration. The front panel of the control unit is also equipped with a group of status indicator lights to indicate power, fault, and bypass status.
[0007] Preferably, in one possible implementation of the first aspect, the control unit communicates with the physical Bypass module via an internal I2C bus; The physical bypass module also includes a local controller that monitors the heartbeat connection with the control unit.
[0008] Preferably, in one possible implementation of the first aspect, the local controller determines that the control unit has failed when it has not received a heartbeat from the control unit for a continuous period of time, and controls the Bypass switching unit to perform a physical pass-through.
[0009] Preferably, in one possible implementation of the first aspect, the Bypass switching unit includes a physical relay that triggers a physical pass-through when the device loses power.
[0010] Preferably, in one possible implementation of the first aspect, the physical bypass module includes two sets of independent bypass ports, each set of bypass ports including an inlet and an outlet; The physical bypass module's inlet is connected to the upstream network device, the physical bypass module's outlet is connected to the external switching chip device, and the external switching chip device's downstream is connected to the downstream network device. A single physical bypass module is used to protect two independent network links simultaneously.
[0011] Preferably, in one possible implementation of the first aspect, the platform chassis is a 1U rack-mount structure, and the chassis is provided with a control unit slot, at least one physical bypass module slot, and a temperature control and heat dissipation system; The control unit and physical bypass module support hot-swapping; The temperature-controlled heat dissipation system includes a fan module that supports hot-swapping and automatically adjusts its speed according to the slot temperature.
[0012] Preferably, in one possible implementation of the first aspect, the platform has a built-in redundant power supply module that supports redundant configuration and hot-swappable replacement.
[0013] Secondly, the present invention provides a method for operating a converged hardware and software bypass intelligent management and control platform, the method being based on the converged hardware and software bypass intelligent management and control platform as described in the first aspect, comprising: The control unit ensures that the physical bypass module is in normal working condition. The security device monitoring module monitors the status of security tools connected to the external switching chip device and detects the forwarding plane status of the external switching chip device; When a security tool malfunction is detected, the software bypass control module sends a software bypass command to the external switching chip device; External switching chip devices adjust the traffic forwarding path according to software bypass instructions, allowing traffic to bypass faulty security tools; The physical bypass control module monitors the status of the external switching chip device and the platform itself. When a complete failure of the external switching chip device, a power outage of the platform, or a failure of the control unit is detected, the physical bypass mode is triggered. In physical bypass mode, the bypass switching unit performs physical pass-through, allowing the network link to bypass the platform and external switching chip equipment. The server process module provides a web management interface that displays the real-time status of security tools, software bypass status, and physical bypass module health information, and responds to the administrator's manual bypass commands.
[0014] Thirdly, the present invention provides a network system including an external switching chip device, at least one security tool, and a converged hardware and software Bypass intelligent management and control platform as described in the first aspect.
[0015] The beneficial effects of this invention are as follows: This invention integrates the control unit and the physical bypass module into a 1U rack-mount device, which improves the hardware resource reuse rate, allows a single device to be expanded to protect multiple links, and reduces procurement and deployment costs.
[0016] By using a unified control unit for scheduling, deep collaboration between refined bypass at the software layer and direct access at the physical layer is achieved, eliminating protection blind spots.
[0017] Employing internal I2C bus communication and a hardware watchdog mechanism, fault response is achieved in milliseconds, making it suitable for high real-time scenarios. The standardized monitoring protocol is compatible with heterogeneous security devices from multiple vendors, breaking down barriers between proprietary solutions.
[0018] The built-in web management interface enables centralized monitoring of the entire process status, unified policy distribution, and automatic fault location, significantly improving operational efficiency.
[0019] Modular hot-swappable design and redundant power supply configuration ensure high reliability of the device itself, avoid the risk of "protector failure", and provide integrated intelligent bypass protection for scenarios such as data centers and industrial networks. Attached Figure Description
[0020] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0021] Figure 1 This application provides a schematic diagram of the internal structure of an integrated hardware and software Bypass intelligent management and control platform.
[0022] Figure 2 This application provides a schematic diagram of the front panel of an integrated hardware and software Bypass intelligent management and control platform device. Detailed Implementation
[0023] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0024] Example 1: As Figure 1 As shown, this invention provides a converged hardware and software bypass intelligent management platform. The platform adopts a standard 1U rack-mount structure, with integrated control unit slots, physical bypass module slots, and a temperature control and cooling system inside the chassis. A schematic diagram of the device's front panel is shown below. Figure 2 As shown, the platform includes a control unit and at least one physical bypass module. Both the control unit and the physical bypass module adopt a modular design and support hot-swapping. The chassis has a built-in redundant power supply module, supporting redundant configuration and hot-swapping replacement to ensure continuous power supply to the equipment. The temperature control and cooling system includes a fan module, which supports hot-swapping. The system automatically adjusts the fan speed according to the slot temperature through the fan control module to maintain stable operation of the equipment within a suitable temperature range.
[0025] The control unit inserts into a dedicated slot and connects to the physical bypass module, power supply, and cooling system via a backplane. The control unit contains a main processor module, which employs a general-purpose computing architecture and features onboard DDR4 memory and storage chips. The converged control software runs on the main processor module and includes a security device monitoring module, a software bypass control module, a physical bypass control module, and a server process module. The front panel of the control unit features a management network port, a console debugging interface, and a group of status indicator lights. The management network port is an RJ45 interface, supporting 10 / 100 / 1000M auto-sensing, used to connect to the management port of an external switching chip device. The console debugging interface is an RJ45 serial port used for local command-line configuration and initial debugging. The status indicator lights include power indicators, fault indicators, and bypass status indicators, used to visually display the device's operating status.
[0026] The control unit communicates with the physical bypass module via an internal I2C bus. The physical bypass module inserts into its slot and connects to the backplane via a standard gold-finger interface. Each physical bypass module includes a local controller, a bypass switching unit, and a network interface. The local controller monitors the heartbeat connection with the control unit and controls the bypass switching unit's operation. The bypass switching unit includes a high-reliability physical relay that triggers a physical pass-through when the device loses power, ensuring uninterrupted link operation during power outages. If the local controller fails to receive a heartbeat from the control unit consecutively, it determines that the control unit has failed and controls the bypass switching unit to execute a physical pass-through. The physical bypass module provides two independent bypass ports, each containing one ingress and one egress. A single physical bypass module can simultaneously protect two independent network links. The physical bypass module's ingress connects to the upstream network device, and its egress connects to the external switching chip device. The downstream of the external switching chip device connects to the downstream network device.
[0027] The security device monitoring module monitors the status of security tools through at least one of the following methods: packet inspection, port status polling, and packet loss analysis. Packet inspection is achieved by sending probe packets to the security tool connected in series with the external switching chip device and waiting for a response; port status polling is achieved by reading the port status information of the external switching chip device; and packet loss analysis is achieved by statistically analyzing the port traffic forwarding data of the external switching chip device. The monitored objects include the hardware status and software operating status of the security tool, covering various fault types such as no heartbeat response, interface status being closed, traffic packet loss exceeding a set threshold, and no response from the device management interface.
[0028] When the security device monitoring module detects a security tool malfunction, the software bypass control module sends a software bypass command to the external switching chip device. This command contains bypass rules for the faulty security tool. The external switching chip device receives and applies these rules, adjusting its internal traffic forwarding path to allow traffic to bypass the faulty security tool and be forwarded directly. The software bypass control module also responds to manual bypass commands from the administrator. In scenarios involving device upgrades or maintenance, the administrator can issue manual bypass commands through the web management interface provided by the server process module, which the software bypass control module receives and executes.
[0029] The physical bypass control module sends control commands to the physical bypass module via the internal I2C bus. The physical bypass control module monitors the status of the external switching chip device and the platform itself in real time, including the overall operating status of the external switching chip device, the operating status of the control unit, and the power supply status of the platform. When a complete failure of the external switching chip device, a power outage of the platform, or a failure of the control unit is detected, the physical bypass control module triggers the physical bypass mode. In physical bypass mode, the bypass switching unit performs physical pass-through, the network link bypasses the platform and the external switching chip device, and traffic is transmitted directly through the physical relay-connected inlet and outlet.
[0030] The server process module provides a web management interface for centralized monitoring and policy configuration of the entire link status. The web management interface displays real-time status of security tools, software bypass status, and physical bypass module health information. Security tool status includes normal, faulty, bypassed, and health details. Software bypass status includes the currently bypassed device, bypass reason, and duration. Physical bypass module health information includes module temperature, voltage, and relay status. The web management interface responds to administrator manual bypass commands, supporting single-device security tool software bypass and recovery, entire link physical bypass and recovery, batch bypass policy distribution, and monitoring threshold modification. Monitoring thresholds include heartbeat interval, timeout count, and load threshold. The web management interface also displays key status of external switching chip devices, link traffic trend graphs, historical fault records, and switchover logs. The system supports multiple alarm methods such as Syslog, SNMPTrap, and email; all operations and events are recorded in local logs.
[0031] A typical deployment topology for the platform in the network is as follows: upstream network devices connect to the physical bypass module ingress, the physical bypass module egress connects to an external switching chip device, and the external switching chip device connects to downstream network devices. At least one security tool, including a firewall, intrusion detection system, intrusion prevention system, and load balancer, is connected in series on the external switching chip device. The management port of the control unit is connected to the management port of the external switching chip device via the network.
[0032] The platform operates in three modes: normal forwarding, software bypass, and physical bypass. In normal forwarding mode, the device powers on and completes a self-test. The control unit sends a command to the physical bypass module via the internal I2C bus, putting the bypass switching unit into a non-pass-through state, disconnecting the relay, and allowing normal traffic flow into and out of the device. The security device monitoring module sends heartbeat probe messages to each security tool connected in series on the external switching chip device, polling the interface status and establishing a health baseline for the security tools. The traffic path is as follows: upstream network devices enter the device through the physical bypass module, are transmitted through internal circuitry to the external switching chip device, are forwarded internally by the external switching chip device, are processed sequentially by the connected security tools, and finally transmitted to downstream network devices.
[0033] In software bypass mode, when the security device monitoring module detects a malfunction in a security tool, the software bypass control module generates bypass rules based on preset policies, instructing the external switching chip device to adjust its forwarding path and bypass the faulty device. The control unit sends new traffic forwarding rules to the external switching chip device through the management network port, while the physical bypass module remains in a non-pass-through state. The external switching chip device receives and applies the policy, bypassing the faulty device, and other security tools continue to process traffic. The control unit continuously monitors the status of the faulty device, and upon detecting that it has recovered, automatically sends a recovery command to the external switching chip device, reinjecting traffic back into the device. The system records the bypass event and reports an alarm, highlighting the fault point on the web management interface.
[0034] In physical bypass mode, physical bypass is triggered when there is a complete failure of the external switching chip device, a platform power outage, a control unit failure, or when the administrator manually issues a physical pass-through command for the entire link. When the control unit is still operational, the physical bypass control module issues a physical pass-through command to the physical bypass module via the internal I2C bus, and the local controller drives the relay to engage. When the control unit fails or the platform loses power, the local controller autonomously triggers the relay to engage. The traffic path changes to upstream network devices entering through the physical bypass module, then directly transmitting traffic from the exit point to downstream network devices via a physical pass-through connection through the relay, completely bypassing the platform's internal circuitry, external switching chip device, and all security tools. After the device recovers, the control unit issues a recovery command to the physical bypass module via the I2C bus, driving the relay to disengage and exiting the physical bypass state.
[0035] Example 2: This invention provides a working method for an integrated hardware and software Bypass intelligent management and control platform, which is implemented based on the integrated hardware and software Bypass intelligent management and control platform.
[0036] Specifically, after the platform starts, the control unit first sends a command to the physical bypass module to put the bypass switching unit into a non-pass-through state, disconnecting the relay and ensuring that service traffic can enter and exit the device normally. The security device monitoring module continuously monitors the operating status of the security tools connected to the external switching chip device through packet inspection, port status polling, and packet loss analysis, while also detecting the forwarding plane status of the external switching chip device.
[0037] When the security device monitoring module detects faults in a security tool, such as no heartbeat response, interface closure, or packet loss exceeding a threshold, the software bypass control module immediately generates a corresponding bypass rule and sends a software bypass command to the external switching chip device. The external switching chip device receives and applies the rule, adjusts the internal traffic forwarding path, and allows traffic to bypass the faulty security tool and continue transmission, while other normal security tools maintain their original processing flow.
[0038] The physical bypass control module synchronously monitors the overall operating status of the external switching chip device, the platform power supply status, and the operating status of the control unit. If a complete failure of the external switching chip device, a power outage of the platform, or a control unit failure is detected, the physical bypass control module immediately triggers the physical bypass mode.
[0039] The Bypass switching unit performs a physical pass-through action in physical Bypass mode, directly connecting the ingress and egress of the network link through an internal physical relay, allowing traffic to completely bypass the platform's internal circuitry, external switching chip devices, and all security tools.
[0040] The server process module runs a web management interface that displays the real-time running status of security tools, the trigger status of software bypass, and health information such as temperature and voltage of physical bypass modules. It also responds to manual bypass commands issued by the administrator through the interface and supports bypass recovery of a single security tool, physical pass-through recovery of the entire link, and batch policy adjustment operations.
[0041] Example 3: The present invention provides a network system including an external switching chip device, at least one security tool, and a converged hardware and software Bypass intelligent management and control platform.
[0042] The external switching chip device is connected to a security tool. The integrated hardware and software Bypass intelligent management platform has a physical Bypass module connected in series in the network link, and the control unit is connected to the management port of the external switching chip device through the network.
[0043] Security tools are connected in series between the ports of the external switching chip device. The physical bypass module's inlet is connected to the upstream network device, and its outlet is connected to the external switching chip device. The external switching chip device's downstream is connected to the downstream network device.
[0044] Obviously, those skilled in the art can make various modifications and variations to this invention without departing from its spirit and scope. Therefore, if these modifications and variations fall within the scope of the claims of this invention and their equivalents, this invention also intends to include these modifications and variations.
Claims
1. A converged hardware and software bypass intelligent management and control platform, characterized in that, The platform includes a control unit and at least one physical bypass module; The control unit runs fusion control software, which includes a security device monitoring module, a software bypass control module, a physical bypass control module, and a server process module. The control unit is connected to an external switching chip device via a network, and the external switching chip device is connected to at least one security tool; The security device monitoring module is used to monitor the status of security tools through at least one of message detection, port status polling, and packet loss analysis. The software bypass control module is used to send a software bypass command to the external switching chip device when the security device monitoring module detects a security tool failure. The physical bypass control module is used to issue control commands to the physical bypass module; The physical bypass module is connected in series in the network link, and the physical bypass module includes a bypass switching unit; The Bypass switching unit is used to perform physical pass-through of the network link according to control commands or autonomous triggering; The server process module is used to provide a web management interface to achieve centralized monitoring and policy configuration of the entire link status.
2. The integrated hardware and software bypass intelligent management and control platform as described in claim 1, characterized in that, The control unit also includes a main processor module, and the fusion control software runs on the main processor module; The control unit is equipped with a management network port and a console debugging interface. The management network port is connected to the management port of an external switching chip device, and the console debugging interface is used for local command line configuration. The front panel of the control unit is also equipped with a group of status indicator lights to indicate power, fault, and bypass status.
3. The integrated hardware and software bypass intelligent management and control platform as described in claim 1, characterized in that, The control unit communicates with the physical bypass module via an internal I2C bus. The physical bypass module also includes a local controller that monitors the heartbeat connection with the control unit.
4. The integrated hardware and software bypass intelligent management and control platform as described in claim 3, characterized in that, When the local controller fails to receive a heartbeat from the control unit for a continuous period of time, it determines that the control unit has failed and controls the Bypass switching unit to perform a physical pass-through.
5. The integrated hardware and software bypass intelligent management and control platform as described in claim 4, characterized in that, The Bypass switching unit includes a physical relay that triggers a physical pass-through when the device loses power.
6. The integrated hardware and software bypass intelligent management and control platform as described in claim 1, characterized in that, The physical bypass module includes two sets of independent bypass ports, each set of bypass ports containing one inlet and one outlet; The physical bypass module's inlet is connected to the upstream network device, the physical bypass module's outlet is connected to the external switching chip device, and the external switching chip device's downstream is connected to the downstream network device. A single physical bypass module is used to protect two independent network links simultaneously.
7. The integrated hardware and software bypass intelligent management and control platform as described in claim 1, characterized in that, The platform has a 1U rack-mount chassis, which includes a control unit slot, at least one physical bypass module slot, and a temperature control and heat dissipation system. The control unit and physical bypass module support hot-swapping; The temperature control and heat dissipation system includes a fan module that supports hot-swapping and automatically adjusts its speed according to the slot temperature.
8. The integrated hardware and software bypass intelligent management and control platform as described in claim 1, characterized in that, The platform has a built-in redundant power supply module, which supports redundant configuration and hot-swappable replacement.
9. A working method for an integrated hardware and software bypass intelligent management and control platform, characterized in that, The method is based on a converged hardware and software Bypass intelligent management platform as described in any one of claims 1 to 8, comprising: The control unit ensures that the physical bypass module is in normal working condition. The security device monitoring module monitors the status of security tools connected to the external switching chip device and detects the forwarding plane status of the external switching chip device; When a security tool malfunction is detected, the software bypass control module sends a software bypass command to the external switching chip device; External switching chip devices adjust the traffic forwarding path according to software bypass instructions, allowing traffic to bypass faulty security tools; The physical bypass control module monitors the status of the external switching chip device and the platform itself. When a complete failure of the external switching chip device, a power outage of the platform, or a failure of the control unit is detected, the physical bypass mode is triggered. In physical bypass mode, the bypass switching unit performs physical pass-through, allowing the network link to bypass the platform and external switching chip equipment. The server process module provides a web management interface that displays the real-time status of security tools, software bypass status, and physical bypass module health information, and responds to the administrator's manual bypass commands.
10. A network system, characterized in that, It includes an external switching chip device, at least one security tool, and a converged hardware and software Bypass intelligent management platform as described in any one of claims 1 to 8.