A trusted security protection method, device, electronic device and storage medium

By verifying the identity information of the external network module and the internal network module in the gate gate equipment, the problem of private disassembly and tampering of the core devices of the gate gate equipment is solved, ensuring the trustworthiness and security of the gate gate equipment and the security of data exchange.

CN114329422BActive Publication Date: 2025-08-22NSFOCUS INFORMATION TECHNOLOGY CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111542168.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-16
Publication Date
2025-08-22
Estimated Expiration
2041-12-16

AI Technical Summary

Technical Problem

The prior art cannot effectively verify the credible security of the gate gate equipment itself, especially when the core components inside the gate gate equipment are privately disassembled and tampered with, resulting in an increase in security risks.

Method used

By obtaining the identity information to be verified by the external network module and the internal network module in the gate device, and using the internal network module and the external network module for consistency verification, ensuring that the external network verification results and the internal network verification results are allowed to be data exchanged only, using the hash algorithm to generate unique identification information, and encrypt and decrypt through the trusted platform module.

Benefits of technology

It realizes that while ensuring the trustworthy and security of the gate gate equipment, it effectively improves the security of data exchange, prevents core devices from being illegally tampered with, and ensures the reliability and security of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114329422B_ABST
    Figure CN114329422B_ABST
Patent Text Reader

Abstract

The present application relates to the field of information security technology, and in particular to a trusted security protection method, device, electronic device and storage medium for ensuring the trusted security of the network gateway device itself. The method comprises: respectively obtaining the external network identity information to be verified of the external network module and the internal network identity information to be verified of the internal network module in the network gateway, and performing consistency verification on the external network identity information to be verified through the internal network module to obtain the external network verification result, and performing consistency verification on the internal network identity information to be verified through the external network module to obtain the internal network verification result, and allowing data exchange between the external network and the internal network when it is determined that both the external network verification result and the internal network verification result are verified. Since the present application allows data exchange between the external network and the internal network after the identity information of both the external network module and the internal network module are verified, the trusted security of the network gateway device itself can be ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of information security technology, and in particular to a trusted security protection method, device, electronic device and storage medium. Background Art

[0002] With the development of informatization, for security reasons, network construction in many important areas needs to be physically isolated to ensure network security in core areas.

[0003] As a core product that physically isolates network boundaries, a gatekeeper device is responsible for ensuring the secure and efficient transmission of data between networks with different security levels. If the gatekeeper device itself is attacked from the outside, especially if its core components are unauthorizedly disassembled or tampered with, the gatekeeper's physical isolation properties will be lost, posing a serious security risk and making cross-domain secure exchange impossible.

[0004] To prevent unauthorized disassembly and tampering of the core components within a network gatekeeper, the prior art primarily uses physical methods (such as plastic glue or wax seals) to secure the core components (isolated switching components, memory, and hard drives). However, this method cannot guarantee that the core components cannot be disassembled or tampered with, nor can it verify the trustworthiness and security of the network gatekeeper itself. Therefore, verifying the trustworthiness and security of the network gatekeeper itself is a pressing issue. Summary of the Invention

[0005] The embodiments of the present application provide a trusted security protection method, device, electronic device and storage medium to ensure the trusted security of the network gateway device itself.

[0006] The present invention provides a reliable security protection method, including:

[0007] Respectively obtaining the external network identity information to be verified of the external network module and the internal network identity information to be verified of the internal network module in the network gate, wherein the external network identity information to be verified is used to verify the credibility of the external network module, and the internal network identity information to be verified is used to verify the credibility of the internal network module, the external network module is used to exchange data with the external network, and the internal network module is used to exchange data with the internal network;

[0008] Performing a consistency check on the identity information to be verified on the external network through the internal network module to obtain an external network verification result, and performing a consistency check on the identity information to be verified on the internal network through the external network module to obtain an internal network verification result;

[0009] When it is determined that both the external network verification result and the internal network verification result are verified to be passed, data exchange between the external network and the internal network is allowed.

[0010] Optionally, the step of separately obtaining the external network identity information to be verified of the external network module and the internal network identity information to be verified of the internal network module includes:

[0011] Mapping the external network device information corresponding to its own components through the external network module to obtain first external network identification information identifying the external network module, and encrypting the first external network identification information to obtain the external network identity information to be verified; and

[0012] The intranet module maps the intranet device information corresponding to its own components to obtain first intranet identification information identifying the intranet module, and encrypts the first intranet identification information to obtain the intranet identity information to be verified.

[0013] Optionally, verifying the external network identity information to be verified by the internal network module to obtain an external network verification result includes:

[0014] Obtaining the external network identity information to be verified sent by the external network module through the internal network module, and decrypting the external network identity information to be verified to obtain second external network identification information;

[0015] A consistency check is performed based on the second external network identification information and the first external network identity information stored in the internal network module to obtain an external network verification result.

[0016] Optionally, determining the external network verification result based on whether the second external network identification information is consistent with the first external network identity information stored in the internal network module includes:

[0017] If the second external network identification information is consistent with the first external network identity information, the external network verification result is that the external network identity information to be verified has passed the verification;

[0018] If the second external network identification information is inconsistent with the first external network identity information, the external network verification result is that the verification of the external network identity information to be verified fails.

[0019] Optionally, after performing consistency verification on the external network identity information to be verified by the internal network module and obtaining the external network verification result, and before allowing data exchange between the external network and the internal network, the method further includes:

[0020] The external network verification result is sent to the external network module through the internal network module, so that the external network module determines whether the external network identity information to be verified is verified according to the external network verification result.

[0021] Optionally, performing consistency verification on the identity information to be verified on the intranet by the external network module to obtain an intranet verification result includes:

[0022] Obtaining the intranet identity information to be verified sent by the intranet module through the external network module, and decrypting the intranet identity information to be verified to obtain second intranet identification information;

[0023] A consistency check is performed based on the second intranet identification information and the first intranet identity information stored in the external network module to obtain an intranet verification result.

[0024] Optionally, determining the intranet verification result based on whether the second intranet identification information is consistent with the first intranet identity information stored in the external network module includes:

[0025] If the second intranet identification information is consistent with the first intranet identity information, the intranet verification result is that the intranet identity information to be verified has passed verification;

[0026] If the second intranet identification information is inconsistent with the first intranet identity information, the intranet verification result is that the intranet identity information to be verified fails verification.

[0027] Optionally, after determining the intranet verification result based on whether the second intranet identification information is consistent with the first intranet identity information stored in the extranet module, and before allowing data exchange between the extranet and the intranet, the method further includes:

[0028] The intranet verification result is sent to the intranet module through the external network module, so that the intranet module determines whether the intranet identity information to be verified is verified according to the intranet verification result.

[0029] Optionally, the method further includes:

[0030] When it is determined that the external network verification result or the internal network verification result is verification failure, the alarm module is triggered to sound an alarm.

[0031] Optionally, the method further includes:

[0032] When the internal network module fails to decrypt the external network identity information to be verified, or when the external network module fails to decrypt the internal network identity information to be verified, the alarm module is triggered to sound an alarm.

[0033] Optionally, the external network module and the internal network module further include respective security units; the security units are used to encrypt the first external network identification information and the first internal network identification information, or to decrypt the external network identity information to be verified and the internal network identity information to be verified.

[0034] The present invention provides a reliable security protection device, including:

[0035] an acquisition unit, configured to respectively acquire external network identity information to be verified of an external network module and internal network identity information to be verified of an internal network module in the network gate, wherein the external network identity information to be verified is used to verify the credibility of the external network module, and the internal network identity information to be verified is used to verify the credibility of the internal network module, the external network module is used to exchange data with the external network, and the internal network module is used to exchange data with the internal network;

[0036] a verification unit, configured to perform a consistency check on the identity information to be verified on the external network through the internal network module to obtain an external network verification result, and to perform a consistency check on the identity information to be verified on the internal network through the external network module to obtain an internal network verification result;

[0037] The determining unit is configured to allow data exchange between the external network and the internal network when it is determined that both the external network verification result and the internal network verification result are verified to be passed.

[0038] Optionally, the acquiring unit is specifically configured to:

[0039] Mapping the external network device information corresponding to its own components through the external network module to obtain first external network identification information identifying the external network module, and encrypting the first external network identification information to obtain the external network identity information to be verified; and

[0040] The intranet module maps the intranet device information corresponding to its own components to obtain first intranet identification information identifying the intranet module, and encrypts the first intranet identification information to obtain the intranet identity information to be verified.

[0041] Optionally, the verification unit is specifically configured to:

[0042] Obtaining the external network identity information to be verified sent by the external network module through the internal network module, and decrypting the external network identity information to be verified to obtain second external network identification information;

[0043] A consistency check is performed based on the second external network identification information and the first external network identity information stored in the internal network module to obtain an external network verification result.

[0044] Optionally, determine the external network verification result in the following ways:

[0045] If the second external network identification information is consistent with the first external network identity information, the external network verification result is that the external network identity information to be verified has passed the verification;

[0046] If the second external network identification information is inconsistent with the first external network identity information, the external network verification result is that the verification of the external network identity information to be verified fails.

[0047] Optionally, after performing consistency verification on the external network identity information to be verified by the intranet module and obtaining the external network verification result, and before allowing data exchange between the external network and the intranet, the device further includes a first sending unit, configured to:

[0048] The external network verification result is sent to the external network module through the internal network module, so that the external network module determines whether the external network identity information to be verified is verified according to the external network verification result.

[0049] Optionally, the verification unit is specifically configured to:

[0050] Obtaining the intranet identity information to be verified sent by the intranet module through the external network module, and decrypting the intranet identity information to be verified to obtain second intranet identification information;

[0051] A consistency check is performed based on the second intranet identification information and the first intranet identity information stored in the external network module to obtain an intranet verification result.

[0052] Optionally, determine the intranet verification result in the following ways:

[0053] If the second intranet identification information is consistent with the first intranet identity information, the intranet verification result is that the intranet identity information to be verified has passed verification;

[0054] If the second intranet identification information is inconsistent with the first intranet identity information, the intranet verification result is that the intranet identity information to be verified fails verification.

[0055] Optionally, after determining the intranet verification result based on whether the second intranet identification information is consistent with the first intranet identity information stored in the extranet module, and before allowing data exchange between the extranet and the intranet, the device further includes a second sending unit configured to:

[0056] The intranet verification result is sent to the intranet module through the external network module, so that the intranet module determines whether the intranet identity information to be verified is verified according to the intranet verification result.

[0057] Optionally, the device further includes a first alarm unit, configured to:

[0058] When it is determined that the external network verification result or the internal network verification result is verification failure, the alarm module is triggered to sound an alarm.

[0059] Optionally, the device further includes a second alarm unit, configured to:

[0060] When the internal network module fails to decrypt the external network identity information to be verified, or when the external network module fails to decrypt the internal network identity information to be verified, the alarm module is triggered to sound an alarm.

[0061] Optionally, the external network module and the internal network module further include respective security units; the security units are used to encrypt the first external network identification information and the first internal network identification information, or to decrypt the external network identity information to be verified and the internal network identity information to be verified.

[0062] An embodiment of the present application provides an electronic device, including a processor and a memory, wherein the memory stores a computer program, and when the computer program is executed by the processor, the processor performs the steps of any one of the above-mentioned trusted security protection methods.

[0063] An embodiment of the present application provides a computer-readable storage medium, which includes a computer program. When the program code is run on an electronic device, the computer program is used to enable the electronic device to perform the steps of any one of the above-mentioned trusted security protection methods.

[0064] An embodiment of the present application provides a computer program product, which includes a computer program, and the computer program is stored in a computer-readable storage medium; when a processor of an electronic device reads the computer program from the computer-readable storage medium, the processor executes the computer program, so that the electronic device performs the steps of any one of the above-mentioned trusted security protection methods.

[0065] The beneficial effects of this application are as follows:

[0066] The embodiments of the present application provide a trusted security protection method, device, electronic device and storage medium. In the embodiments of the present application, the external network identity information to be verified of the external network module and the internal network identity information to be verified of the internal network module in the network gate are obtained respectively, and the external network identity information to be verified is verified by the internal network module to obtain the external network verification result, and the internal network identity information to be verified is verified by the external network module to obtain the internal network verification result. When it is determined that the external network verification result and the internal network verification result are both verified, data exchange is allowed between the external network and the internal network. By verifying the identity information of the external network module and the internal network module, and after the identity information of the external network module and the internal network module are both verified, data exchange is allowed between the external network and the internal network, which can ensure the trusted security of the network gate device itself.

[0067] Other features and advantages of the present application will be described in the following description, and in part will become apparent from the description, or will be understood by practicing the present application. The purposes and other advantages of the present application can be realized and obtained by the structures particularly pointed out in the written description, claims, and drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0068] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0069] Figure 1 This is a schematic structural diagram of a network gateway device in an embodiment of the present application;

[0070] Figure 2 A flow chart of a trusted security protection method in an embodiment of the present application;

[0071] Figure 3 This is a system architecture diagram of a trusted security protection method in an embodiment of the present application;

[0072] Figure 4 This is an interactive flow chart of a trusted security protection method in an embodiment of the present application;

[0073] Figure 5 This is a flow chart of an external network processing unit in an embodiment of the present application;

[0074] Figure 6 This is a flow chart of an intranet processing unit in an embodiment of the present application;

[0075] Figure 7 This is a schematic structural diagram of a trusted security protection device according to an embodiment of the present application;

[0076] Figure 8 The present invention is a schematic diagram of the hardware structure of an electronic device to which an embodiment of the present application is applied. DETAILED DESCRIPTION

[0077] To make the purpose, technical solutions, and advantages of the embodiments of this application more clear, the technical solutions of this application will be clearly and completely described below in conjunction with the drawings in the embodiments of this application. Obviously, the described embodiments are part of the embodiments of the technical solutions of this application, but not all of them. Based on the embodiments described in this application document, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the technical solutions of this application.

[0078] The following is an introduction to some concepts involved in the embodiments of this application.

[0079] A network gatekeeper is an information security device that connects two independent host systems using a solid-state switch read-write medium with various control functions. Because the two independent host systems are isolated by the network gatekeeper, there is no physical or logical connection between the systems for communication, no information transmission protocol, and no protocol-based information exchange; only protocol-free data file transfer. Therefore, the network gatekeeper physically isolates and blocks all network connections that could potentially attack the intranet, preventing external attackers from directly invading, attacking, or disrupting the intranet, thereby ensuring the security of internal hosts.

[0080] Hash algorithm: By transforming an input of arbitrary length into an output of fixed length through a hash algorithm, a data can be converted into a flag, which has a very close relationship with each byte of the source data. In the embodiment of the present application, the device information of the external network module and the internal network module are mapped respectively through the hash algorithm, and the unique identification information of the external network module and the internal network module can be obtained respectively.

[0081] A Trusted Platform Module (TPM) is a security chip that complies with the TPM (Trusted Platform Module) standard. It effectively protects devices from unauthorized access and serves as both a key generator and key management device. In the embodiments of this application, the TPM is the security unit, used to encrypt and decrypt information exchanged between the external and internal network modules, and store their identity information.

[0082] The following is a brief introduction to the design concept of the embodiment of this application:

[0083] With the development of informatization, for security reasons, network construction in many important areas needs to be physically isolated to ensure network security in core areas.

[0084] The network gate device consists of three parts: external network processing unit, dedicated isolation switching device and internal network processing unit. Figure 1As shown, the external network processing unit is connected to the low-security domain network, while the internal network processing unit is connected to the high-security domain network. The internal and external network processing units exchange cross-domain information via an isolation switch. The internal and external network processing units consist of two independent systems that exchange cross-domain information via a proprietary isolation switch. The two processing systems are unaware of each other's presence, thus ensuring physical isolation. As a core product at the boundary of physically isolated networks, the network gatekeeper is responsible for ensuring secure and efficient data transmission between networks of different security levels. If the network gatekeeper itself is attacked from outside, especially if the proprietary isolation switch within the network gatekeeper is replaced with a simple network card, the physical isolation feature of the network gatekeeper will be lost, posing a serious security risk and rendering secure cross-domain communication between networks of different security domains ineffective. Furthermore, to facilitate maintenance and authorization of shipped devices, network gatekeeper manufacturers do not want the core components of the internal and external network processing units of the network gatekeeper device to be disassembled, replaced, or upgraded without authorization.

[0085] To prevent unauthorized disassembly and tampering of the core components within a network gatekeeper, the prior art primarily uses physical methods (such as plastic glue or wax seals) to secure the core components (isolated switching components, memory, and hard drives). However, this method cannot guarantee that the core components cannot be disassembled or tampered with, nor can it verify the trustworthiness and security of the network gatekeeper itself. Therefore, verifying the trustworthiness and security of the network gatekeeper itself is a pressing issue.

[0086] In view of this, the embodiments of the present application provide a trusted security protection method, device, electronic device and storage medium. In the embodiments of the present application, the external network identity information to be verified of the external network module and the internal network identity information to be verified of the internal network module in the network gate are obtained respectively, and the external network identity information to be verified is verified by the internal network module to obtain the external network verification result, and the internal network identity information to be verified is verified by the external network module to obtain the internal network verification result. When it is determined that the external network verification result and the internal network verification result are both verified, data exchange is allowed between the external network and the internal network. By performing identity information verification on the external network module and the internal network module, and after the identity information of the external network module and the internal network module are both verified, data exchange is allowed between the external network and the internal network. Data exchange can be carried out while ensuring the trustworthiness and security of the network gate device, effectively improving the security of data exchange.

[0087] The preferred embodiments of the present application are described below in conjunction with the drawings in the specification. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present application and are not used to limit the present application. In addition, the embodiments and features in the embodiments of the present application can be combined with each other if there is no conflict.

[0088] like Figure 2FIG. 1 is a flowchart of an implementation method of a trusted security protection method provided in an embodiment of the present application. The specific implementation process of the method is as follows:

[0089] S201: The network gatekeeper obtains the external network identity information to be verified of the external network module and the internal network identity information to be verified of the internal network module respectively;

[0090] Among them, the external network module is used to exchange data with the external network, and the internal network module is used to exchange data with the internal network. The external network module and the internal network module exchange data through an isolation switching device; the external network identity information to be verified is used to: verify the credibility of the external network module, and the internal network identity information to be verified is used to: verify the credibility of the internal network module. The external network identity information to be verified and the internal network identity information to be verified can be used to determine whether the external network module and the internal network module have been illegally tampered with, thereby verifying the credibility of the external network module and the internal network module.

[0091] S202: The network gatekeeper performs a consistency check on the identity information to be verified on the external network through the internal network module to obtain an external network verification result, and also performs a consistency check on the identity information to be verified on the internal network through the external network module to obtain an internal network verification result;

[0092] S203: When the network gatekeeper determines that both the external network verification result and the internal network verification result are verified to be passed, data exchange between the external network and the internal network is allowed.

[0093] Among them, when the external network verification results and the internal network verification results are both verified to be passed, it means that the network gate device is trustworthy and secure, and data can be exchanged between the low security domain (external network) and the high security domain (intranet) through the network gate device.

[0094] In an embodiment of the present application, identity information verification is performed on the external network module and the internal network module, and after the identity information of both the external network module and the internal network module are verified, data exchange is allowed between the external network and the internal network, thereby ensuring the trustworthy security of the network gateway device itself and further effectively improving the security of data exchange.

[0095] Optionally, obtain the external network identity information to be verified through the following methods:

[0096] First, the external network module maps the external network device information corresponding to its own components to obtain the first external network identification information that identifies the external network module, and then encrypts the first external network identification information through the security unit of the external network module to obtain the external network identity information to be verified.

[0097] Specifically, when the network gateway device is started, the device information of the CPU, memory, network card, hard disk and proprietary isolation device of the external network module is obtained, and the device information is mapped to the first external network identification information through the hash algorithm. The identification information obtained at this time is unique and corresponds one-to-one with the device information. Different device information will be mapped to different identification information. Then, the first external network identification information is used to obtain the external network identity information to be verified.

[0098] In an embodiment of the present application, the intranet module and the extranet module both include their own security units. The security unit of the extranet module stores a private key for encrypting the information it wants to send, a public key for decrypting the information sent by the intranet module, and the identity information of the intranet module.

[0099] Optionally, obtain the identity information to be verified on the intranet through the following methods:

[0100] First, the intranet module maps the intranet device information corresponding to its own components to obtain the first intranet identification information that identifies the intranet module. Then the security unit of the intranet module encrypts the first intranet identification information to obtain the intranet identity information to be verified.

[0101] Specifically, the method for obtaining the identity information to be verified on the intranet is as described above for obtaining the identity information to be verified on the extranet, which will not be described in detail here.

[0102] In an embodiment of the present application, the security unit of the intranet module stores a private key for encrypting information to be sent by itself, a public key for decrypting information sent by the external network module, and identity information of the external network module.

[0103] Optionally, after obtaining the external network identity information to be verified, the internal network module performs a consistency check on the external network identity information to be verified:

[0104] First, the external network identity information to be verified sent by the external network module is obtained through the internal network module, and the external network identity information to be verified is decrypted through the security unit of the internal network module to obtain the second external network identification information; then, a consistency check is performed based on the second external network identification information and the first external network identity information stored in the security unit of the internal network module to obtain the external network verification result: if the second external network identification information is consistent with the first external network identity information, the external network verification result is that the external network identity information to be verified is verified successfully; if the second external network identification information is inconsistent with the first external network identity information, the external network verification result is that the external network identity information to be verified is verified unsuccessfully.

[0105] Among them, the first external network identity information stored in the security unit of the internal network module is obtained by hash calculation based on the initial external network module device information before the network gateway device leaves the factory. Therefore, the first external network identity information and the second external network identification information are checked for consistency to verify whether the external network module has been replaced or tampered with.

[0106] It should be noted that, after decrypting the external network identity information to be verified, the second external network identification information obtained is essentially the same as the first external network identification information, and "first" and "second" are only used to distinguish them.

[0107] Optionally, after obtaining the external network verification result, the internal network module also needs to send the external network verification result to the external network module, so that the external network module determines whether the external network identity information to be verified is verified based on the external network verification result.

[0108] Optionally, after obtaining the identity information to be verified on the intranet, the external network module performs a consistency check on the identity information to be verified on the intranet:

[0109] First, the intranet identity information to be verified sent by the intranet module is obtained through the external network module, and the intranet identity information to be verified is decrypted through the security unit of the external network module to obtain the second intranet identification information; then, a consistency check is performed based on the second intranet identification information and the first intranet identity information stored in the security unit of the external network module to obtain the intranet verification result: if the second intranet identification information is consistent with the first intranet identity information, the intranet verification result is that the intranet identity information to be verified is verified successfully; if the second intranet identification information is inconsistent with the first intranet identity information, the intranet verification result is that the intranet identity information to be verified is verified failed.

[0110] Among them, the first intranet identity information stored in the security unit of the external network module is obtained by hash calculation based on the initial device information of the intranet module before the network gateway device leaves the factory. Therefore, the first intranet identity information and the second intranet identification information are checked for consistency to verify whether the intranet module has been replaced or tampered with.

[0111] It should be noted that, after decrypting the intranet identity information to be verified, the second intranet identification information obtained is essentially the same as the first intranet identification information, and "first" and "second" are only used for distinction.

[0112] Optionally, after obtaining the intranet verification result, the external network module also needs to send the intranet verification result to the intranet module, so that the intranet module determines whether the intranet identity information to be verified is verified based on the intranet verification result.

[0113] Optionally, the alarm module can be triggered to sound an alarm in the following situations:

[0114] Case 1: The external network verification result is verification failure;

[0115] Case 2: The intranet verification result is verification failure;

[0116] Case 3: The intranet module fails to decrypt the identity information to be verified on the external network;

[0117] Case 4: The external network module fails to decrypt the identity information to be verified on the internal network.

[0118] See Figure 3 , which is a system architecture diagram of a trusted security protection method in an embodiment of the present application, applied to a network gate, including the following modules:

[0119] The external network processing unit (i.e., external network module) includes: an external network trusted computing module TPM (i.e., security unit), a trusted startup measurement module, and a front isolation card;

[0120] The external network TPM has non-volatile memory (NV) and platform control registers (PCR). NV is used to store external network trusted policy deployment, and PCR is used to store measurement results.

[0121] The external network trusted policy deployment mainly includes the following policy information: the private key of the external network processing unit, the public key of the internal network processing unit and the internal network identity information;

[0122] The intranet processing unit (i.e., intranet module) includes: intranet trusted computing module TPM (i.e., security unit), trusted startup measurement module and rear isolation card;

[0123] The intranet TPM contains NV and PCR. The intranet NV is used to store the intranet trusted policy. The intranet trusted policy mainly includes the following policy information: the private key of the intranet processing unit, the public key of the external network processing unit and the external network identity information.

[0124] The trusted boot measurement module in the internal and external network processing units is mainly responsible for: obtaining the device information of this unit; calling the peer verification module to obtain the trusted policy from the NV in its own TPM module, encrypting it and sending the identity information to be verified to the peer for verification, and waiting to receive the verification result of the peer, decrypting the result using the trusted policy in the NV, storing the measurement result of the peer verification module in the measurement storage module, and writing it to the PCR in each TPM.

[0125] After the trusted boot measurement module is completed, the trusted verification modules in the internal and external network processing units check the PCR register value in the TPM. If the value is 0, it means that the system is untrusted and the buzzer is triggered; otherwise, the system starts normally.

[0126] The following combination Figure 3 , introduces a specific embodiment of the trusted security protection method in this application:

[0127] Before the network gateway device leaves the factory, the information of the core components of the internal and external network processing units (central processing unit, hard disk, network card, isolation card) is obtained and hash calculation is performed to generate the identity information of each system. The respective identity information and public key are stored in the NV of the trusted computing module of the opposite unit, and the private key information of the internal and external unit processing units is stored in the NV of their own trusted computing module.

[0128] When the network gate system is started, the external network processing unit will first obtain the information of its own internal core components and perform hash calculation to generate identification information, encrypt the identification information using the external network processing unit private key stored in the TPM's NV, and send the identity information to be verified to the internal network processing unit; the internal network processing unit system receives the identity information to be verified from the external network processing system, decrypts it using the external network processing unit public key in its own TPM, obtains the external network system module identification information and compares it with the external network identity information in its own TPM, and writes the verification result into the PCR register in the TPM. If the result is true, it means that the systems at both ends are trustworthy. If the result is false, it means that the systems at both ends have been illegally tampered with, and the buzzer is called to alarm; at the same time, the internal network processing unit The core component information in the system is hashed to generate identification information, and the verification results of the internal network processing unit identification information and the external network identity information are encrypted using the internal network processing unit private key and then fed back to the external network processing unit; the external network processing unit uses the internal network processing unit public key in its own TPM to decrypt, and uses the internal network identity information in its own TPM to compare with the internal network identity information to be verified. If the result is true, it means that the systems at both ends are trustworthy. If the result is false, it means that the systems at both ends have been illegally tampered with, and the buzzer is called to alarm; at the same time, the verification result is fed back to the internal network processing unit. After receiving the internal network verification result, the internal network processing unit performs an AND operation with the PCR value in the TPM. If the result is true, it means that the systems at both ends are reliable. If the result is false, it means that the systems at both ends have been illegally tampered with.

[0129] See Figure 4 , which is an interactive flow chart of a trusted security protection method in an embodiment of the present application, mainly used to introduce the interactive logic between the external network processing unit and the internal network processing unit, including the following steps:

[0130] S401: External network trusted policy deployment;

[0131] S402: Intranet trusted policy deployment;

[0132] S403: The external network processing unit generates external network identification information based on its own device information, and sends the encrypted external network identity information to be verified to the internal network processing unit;

[0133] S404: The intranet processing unit compares the decrypted external network identification information with the stored external network identity information to obtain an external network verification result, and generates the intranet identity information to be verified based on its own device information;

[0134] S405: Sending the encrypted external network verification result and the internal network identity information to be verified to the external network processing unit;

[0135] S406: The external network processing unit compares the decrypted internal network identification information with the stored internal network identity information to obtain an internal network verification result;

[0136] S407: Send the encrypted intranet verification result to the intranet processing unit;

[0137] S408: Receive the intranet verification result and perform an AND operation on the intranet verification result and the external network verification result. If the result is true, the two ends are determined to be credible and data exchange is allowed to start. If the result is false, the two ends are not credible and data exchange is not allowed to start.

[0138] S409: If both the intranet verification result and the extranet verification result are true, then both ends are determined to be credible and data exchange is allowed to start; if the result is false, then both ends are untrustworthy and data exchange is not allowed to start.

[0139] The following combination Figure 5 、 Figure 6 , introduces another embodiment of the trusted security protection method in this application, including the following steps:

[0140] 1. Before the gateway device leaves the factory, a hash calculation is performed based on the information of the core components (CPU, memory, network card, hard disk and proprietary isolation switch components) in the external network processing unit and internal network processing unit system of the gateway device to generate unique internal and external network processing unit identity information:

[0141] 2. Complete the external network trusted policy deployment in the NV of the TPM in the external network processing unit, and complete the internal network trusted policy deployment in the NV of the TPM in the internal network processing unit;

[0142] 3. After the external network processing unit is started, the external network identification information is first generated based on the information of the core components (CPU, memory, network card, hard disk and proprietary isolation switch components) in the current external network processing unit. The identification information is generated by the following algorithm. Here, the SM3 algorithm is used to calculate and generate a unique hash value. In actual applications, it is not limited to SM3. Algorithms such as SHA-256, SHA-384 and SHA-512 can be selected:

[0143] SM3sum(cpu_sn, "#", harddisk_sn, "#", memory_sn, "#", ethernet_id, "#", isolated_sn);

[0144] 4. The peer verification module of the external network processing unit obtains the private key of the external network processing unit from the NV of the external network TPM, encrypts the identity information to be verified using the private key, generates the identity information to be verified, and sends it to the internal network processing unit through the front isolation card;

[0145] 5. After receiving the identity information to be verified from the external network processing unit, the internal network processing unit uses the external network processing unit public key in the NV of the internal network TPM to decrypt it. If the decryption fails, the verification failure result is directly stored in the PCR in the internal network TPM, and the process jumps to step 7.

[0146] 6. If the decryption is successful, the external network identification information in the identity information to be verified is compared with the external network identity information in the NV of the internal network TPM, and the external network verification result is stored in the PCR of the internal network TPM. If the result is true, it is written to 1, and if the result is false, it is written to 0;

[0147] 7. The intranet processing unit system obtains the device information of the core components (CPU, memory, network card, hard disk and proprietary isolation switch components) in the current intranet processing unit and generates intranet identification information through a hash algorithm. The intranet identification information is generated using the following algorithm:

[0148] SM3sum(cpu_sn, "#", harddisk_sn, "#", memory_sn, "#", ethernet_id, "#", isolated_sn);

[0149] 8. The intranet processing unit peer verification module obtains the intranet processing unit private key from the NV in the intranet TPM, uses the private key to encrypt the intranet identification information and the external network verification result, and sends it to the external network processing unit through the post-isolation card.

[0150] 9. After receiving the verification response from the internal processing unit, the external processing unit decrypts the information using the internal processing unit's public key in the NV of the external TPM. If the decryption fails, the verification result is directly written to the PCR register in the external TPM and the process goes to step 11.

[0151] 10. If the decryption is successful, compare the internal network identification information in the response verification message with the internal network identity information in the NV of the external network TPM, and write the internal network verification result into the PCR in the external network TPM;

[0152] 11. The peer verification module of the external network processing unit encrypts the internal network verification result using the private key of the external network processing unit and sends it to the internal network processing unit;

[0153] 12. After receiving the external network verification result response message, the internal network processing unit peer verification module uses the external network processing unit public key in the TPM of the internal network processing unit to decrypt it, obtains the external network verification result, performs an AND operation on it, and writes the result to the PCR register value in the TPM.

[0154] 13. The trusted verification modules of the internal and external network system units read the values ​​from the PCR of their respective TPMs. If the value is 1, it indicates that the systems at both ends are trusted. If the value is 0, it indicates that the systems at both ends are untrusted, and the buzzer is triggered.

[0155] Based on the same inventive concept, the present application embodiment also provides a reliable security protection device. Figure 7 As shown, it is a schematic diagram of the structure of the trusted security protection device 700, which may include:

[0156] An acquisition unit 701 is configured to respectively acquire external network identity information to be verified of an external network module and internal network identity information to be verified of an internal network module in a network gatekeeper. The external network identity information to be verified is used to verify the credibility of the external network module, and the internal network identity information to be verified is used to verify the credibility of the internal network module. The external network module is used to exchange data with the external network, and the internal network module is used to exchange data with the internal network.

[0157] Verification unit 702, configured to perform consistency verification on the external network identity information to be verified through the internal network module to obtain an external network verification result, and perform consistency verification on the internal network identity information to be verified through the external network module to obtain an internal network verification result;

[0158] The determining unit 703 is configured to allow data exchange between the external network and the internal network when it is determined that both the external network verification result and the internal network verification result are verified to be passed.

[0159] Optionally, the acquiring unit 701 is specifically configured to:

[0160] Mapping the external network device information corresponding to its own components through the external network module to obtain first external network identification information that identifies the external network module, and encrypting the first external network identification information to obtain external network identity information to be verified; and

[0161] The intranet module maps the intranet device information corresponding to its own components to obtain first intranet identification information identifying the intranet module, and encrypts the first intranet identification information to obtain intranet identity information to be verified.

[0162] Optionally, the verification unit 702 is specifically configured to:

[0163] Obtain the external network identity information to be verified sent by the external network module through the internal network module, and decrypt the external network identity information to be verified to obtain the second external network identification information;

[0164] A consistency check is performed based on the second external network identification information and the first external network identity information stored in the internal network module to obtain an external network verification result.

[0165] Optionally, determine the external network verification result in the following ways:

[0166] If the second external network identification information is consistent with the first external network identity information, the external network verification result is that the external network identity information to be verified has been verified;

[0167] If the second external network identification information is inconsistent with the first external network identity information, the external network verification result is that the external network identity information to be verified fails to be verified.

[0168] Optionally, after performing consistency verification on the identity information to be verified on the external network through the internal network module and obtaining the external network verification result, before allowing data exchange between the external network and the internal network, the device further includes a first sending unit 704, which is configured to:

[0169] The external network verification result is sent to the external network module through the internal network module, so that the external network module determines whether the external network identity information to be verified is verified according to the external network verification result.

[0170] Optionally, the verification unit 702 is specifically configured to:

[0171] Obtain the intranet identity information to be verified sent by the intranet module through the external network module, and

[0172] Decrypt the identity information to be verified on the intranet to obtain the second intranet identification information;

[0173] A consistency check is performed based on the second intranet identification information and the first intranet identity information stored in the external network module to obtain an intranet verification result.

[0174] Optionally, determine the intranet verification result in the following ways:

[0175] If the second intranet identification information is consistent with the first intranet identity information, the intranet verification result is that the intranet identity information to be verified has been verified;

[0176] If the second intranet identification information is inconsistent with the first intranet identity information, the intranet verification result is that the intranet identity information to be verified fails to be verified.

[0177] Optionally, after determining the intranet verification result based on whether the second intranet identification information is consistent with the first intranet identity information stored in the extranet module, and before allowing data exchange between the extranet and the intranet, the apparatus further includes a second sending unit 705, configured to:

[0178] The intranet verification result is sent to the intranet module through the external network module, so that the intranet module determines whether the identity information to be verified in the intranet is verified according to the intranet verification result.

[0179] Optionally, the device further includes a first alarm unit 706, configured to:

[0180] When the external network verification result or the internal network verification result is determined to be verification failure, the alarm module is triggered to alarm.

[0181] Optionally, the device further includes a second alarm unit 707, configured to:

[0182] When the internal network module fails to decrypt the identity information to be verified on the external network, or when the external network module fails to decrypt the identity information to be verified on the internal network, the alarm module is triggered to sound an alarm.

[0183] Optionally, the external network module and the internal network module further include respective security units 708 ; the security units are used to encrypt the first external network identification information and the first internal network identification information, or decrypt the external network identity information to be verified and the internal network identity information to be verified.

[0184] For the convenience of description, the above parts are divided into modules (or units) according to their functions and described separately. Of course, when implementing this application, the functions of each module (or unit) can be implemented in the same or multiple software or hardware.

[0185] Those skilled in the art will appreciate that various aspects of the present application can be implemented as systems, methods, or program products. Therefore, various aspects of the present application can be specifically implemented in the following forms: a complete hardware implementation, a complete software implementation (including firmware, microcode, etc.), or an implementation that combines hardware and software aspects, which may be collectively referred to herein as a "circuit," "module," or "system."

[0186] Based on the same inventive concept as the above method embodiment, an electronic device is also provided in the embodiment of the present application. In one embodiment, the electronic device may be a server. In this embodiment, the structure of the electronic device may be as follows: Figure 8 As shown, it includes a memory 801 , a communication module 803 and one or more processors 802 .

[0187] Memory 801 is used to store computer programs executed by processor 802. Memory 801 may mainly include a program storage area and a data storage area. The program storage area may store an operating system and programs required for running instant messaging functions, while the data storage area may store various instant messaging messages and operating instruction sets.

[0188] Memory 801 may be a volatile memory, such as random-access memory (RAM); a non-volatile memory, such as read-only memory, flash memory, a hard disk drive (HDD), or a solid-state drive (SSD); or any other medium capable of carrying or storing a desired computer program in the form of instructions or data structures and accessible by a computer, but is not limited thereto. Memory 801 may be a combination of the above memories.

[0189] The processor 802 may include one or more central processing units (CPUs) or digital processing units, etc. The processor 802 is configured to implement the above-mentioned trusted security protection method when calling the computer program stored in the memory 801 .

[0190] The communication module 803 is used to communicate with terminal devices and other servers.

[0191] The specific connection medium between the memory 801, the communication module 803 and the processor 802 is not limited in the embodiment of the present application. Figure 8 In the embodiment, the memory 801 and the processor 802 are connected via a bus 804. Figure 8 The connections between the other components are shown in bold lines, which are only for illustration and are not intended to be limiting. The bus 804 can be divided into an address bus, a data bus, a control bus, etc. For ease of description, Figure 8 The diagram shows a single thick line, but this does not indicate that there is only one bus or one type of bus.

[0192] The memory 801 stores a computer storage medium, which stores computer executable instructions. The computer executable instructions are used to implement the trusted security protection method of the embodiment of the present application. The processor 802 is used to execute the above-mentioned trusted security protection method, such as Figure 2 shown.

[0193] In some possible implementations, various aspects of the trusted security protection method provided by the present application may also be implemented in the form of a program product, which includes a computer program. When the program product is run on an electronic device, the computer program is used to enable the electronic device to execute the steps of the trusted security protection method according to various exemplary embodiments of the present application described above in this specification. For example, the electronic device may execute the following steps: Figure 2 Steps shown.

[0194] The program product may employ any combination of one or more readable media. The readable medium may be a readable signal medium or a readable storage medium. The readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or component, or any combination thereof. More specific examples of readable storage media (a non-exhaustive list) include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof.

[0195] The program product of the embodiment of the present application may be a portable compact disc read-only memory (CD-ROM) and include a computer program, and can be run on a computing device. However, the program product of the present application is not limited thereto. In this document, a readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with a command execution system, device, or device.

[0196] A readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, which carries a readable computer program. Such a propagated data signal may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A readable signal medium may also be any readable medium other than a readable storage medium that can transmit, propagate, or transfer a program for use by or in conjunction with a command execution system, apparatus, or device.

[0197] The computer program embodied on the readable medium may be transmitted using any appropriate medium, including but not limited to wireless, wireline, optical fiber cable, RF, etc., or any suitable combination of the foregoing.

[0198] The computer program for performing the operations of the present application may be written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Java, C++, and the like, as well as conventional procedural programming languages ​​such as "C" or similar programming languages. The computer program may be executed entirely on the user computing device, partially on the user device, as a stand-alone software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device may be connected to the user computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0199] It should be noted that although several units or subunits of the device are mentioned in the detailed description above, this division is merely exemplary and not mandatory. In fact, depending on the embodiment of the application, the features and functions of two or more units described above can be embodied in a single unit. Conversely, the features and functions of a single unit described above can be further divided and embodied by multiple units.

[0200] Furthermore, although the operations of the method of the present application are described in a particular order in the accompanying drawings, this does not require or imply that the operations must be performed in this particular order, or that all illustrated operations must be performed to achieve the desired results. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step, and / or one step may be decomposed into multiple steps.

[0201] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, the present application may adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain a computer-usable computer program.

[0202] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program commands. These computer program commands can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the commands executed by the processor of the computer or other programmable data processing device generate commands for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0203] These computer program instructions may also be stored in a computer readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising a command device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0204] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0205] Although the preferred embodiments of the present application have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present application.

[0206] Obviously, those skilled in the art may make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalents, this application is intended to include these modifications and variations.

Claims

1. A trusted security protection method, characterized in that: Applied to a network gatekeeper, the method includes: Respectively obtaining the external network identity information to be verified of the external network module and the internal network identity information to be verified of the internal network module in the network gate, wherein the external network identity information to be verified is used to verify the credibility of the external network module, and the internal network identity information to be verified is used to verify the credibility of the internal network module, the external network module is used to exchange data with the external network, and the internal network module is used to exchange data with the internal network; Performing a consistency check on the identity information to be verified on the external network through the internal network module to obtain an external network verification result, and performing a consistency check on the identity information to be verified on the internal network through the external network module to obtain an internal network verification result; When it is determined that both the external network verification result and the internal network verification result are verified to be passed, data exchange between the external network and the internal network is allowed.

2. The method according to claim 1, wherein The step of respectively obtaining the external network identity information to be verified of the external network module and the internal network identity information to be verified of the internal network module in the network gate includes: Mapping the external network device information corresponding to its own components through the external network module to obtain first external network identification information identifying the external network module, and encrypting the first external network identification information to obtain the external network identity information to be verified; and The intranet module maps the intranet device information corresponding to its own components to obtain first intranet identification information identifying the intranet module, and encrypts the first intranet identification information to obtain the intranet identity information to be verified.

3. The method according to claim 1, wherein The verifying the identity information to be verified on the external network by the internal network module to obtain the external network verification result includes: Obtaining the external network identity information to be verified sent by the external network module through the internal network module, and decrypting the external network identity information to be verified to obtain second external network identification information; A consistency check is performed based on the second external network identification information and the first external network identity information stored in the internal network module to obtain an external network verification result.

4. The method according to claim 3, wherein The performing consistency verification based on the second external network identification information and the first external network identity information stored in the internal network module to obtain an external network verification result includes: If the second external network identification information is consistent with the first external network identity information, the external network verification result is that the external network identity information to be verified has passed the verification; If the second external network identification information is inconsistent with the first external network identity information, the external network verification result is that the verification of the external network identity information to be verified fails.

5. The method according to claim 1, wherein After performing consistency verification on the external network identity information to be verified by the internal network module and obtaining the external network verification result, and before allowing data exchange between the external network and the internal network, the method further includes: The external network verification result is sent to the external network module through the internal network module, so that the external network module determines whether the external network identity information to be verified is verified according to the external network verification result.

6. The method according to claim 1, wherein The performing consistency verification on the identity information to be verified on the intranet by the external network module to obtain the intranet verification result includes: Obtaining the intranet identity information to be verified sent by the intranet module through the external network module, and decrypting the intranet identity information to be verified to obtain second intranet identification information; A consistency check is performed based on the second intranet identification information and the first intranet identity information stored in the external network module to obtain an intranet verification result.

7. The method according to claim 6, wherein The performing consistency verification based on the second intranet identification information and the first intranet identity information stored in the external network module to obtain an intranet verification result includes: If the second intranet identification information is consistent with the first intranet identity information, the intranet verification result is that the intranet identity information to be verified has passed verification; If the second intranet identification information is inconsistent with the first intranet identity information, the intranet verification result is that the intranet identity information to be verified fails verification.

8. The method according to claim 1, wherein After performing consistency verification on the identity information to be verified on the intranet by the external network module and obtaining the intranet verification result, and before allowing data exchange between the external network and the intranet, the method further includes: The intranet verification result is sent to the intranet module through the external network module, so that the intranet module determines whether the intranet identity information to be verified is verified according to the intranet verification result.

9. The method according to any one of claims 1 to 8, wherein: The method further comprises: When it is determined that the external network verification result or the internal network verification result is verification failure, the alarm module is triggered to sound an alarm.

10. The method according to claim 3 or 6, characterized in that The method further comprises: When the internal network module fails to decrypt the external network identity information to be verified, or when the external network module fails to decrypt the internal network identity information to be verified, the alarm module is triggered to sound an alarm.

11. The method according to claim 2, wherein The external network module and the internal network module also include respective security units; the security unit is used to encrypt the first external network identification information and the first internal network identification information, or decrypt the external network identity information to be verified and the internal network identity information to be verified, or store the first external network identity information and the first internal network identity information.

12. A reliable safety protection device, characterized in that: The device includes: an acquisition unit, configured to respectively acquire external network identity information to be verified of an external network module and internal network identity information to be verified of an internal network module in the network gate, wherein the external network identity information to be verified is used to verify the credibility of the external network module, and the internal network identity information to be verified is used to verify the credibility of the internal network module, the external network module is used to exchange data with the external network, and the internal network module is used to exchange data with the internal network; a verification unit, configured to perform a consistency check on the identity information to be verified on the external network through the internal network module to obtain an external network verification result, and to perform a consistency check on the identity information to be verified on the internal network through the external network module to obtain an internal network verification result; The determining unit is configured to allow data exchange between the external network and the internal network when it is determined that both the external network verification result and the internal network verification result are verified to be passed.

13. An electronic device, characterized in that: The method comprises a processor and a memory, wherein the memory stores a computer program, and when the computer program is executed by the processor, the processor is enabled to perform the steps of any one of the methods of claims 1 to 11.

14. A computer-readable storage medium, characterized in that The method comprises a computer program. When the computer program is run on an electronic device, the computer program is used to enable the electronic device to execute the steps of any one of the methods of claims 1 to 11.

15. A computer program product, characterized in that The method comprises a computer program stored in a computer-readable storage medium; when a processor of an electronic device reads the computer program from the computer-readable storage medium, the processor executes the computer program, so that the electronic device performs the steps of any one of the methods described in claims 1 to 11.

Citation Information

Patent Citations

  • Bidirectional authentication method, device and system

    CN104270346A

  • Router and routing method for connecting inner network and outer network based on application layer

    CN107018154A